AI DetectiveArticle 50(2) and C2PA overview →

Practical guide · e-commerce

AI product images and C2PA: test every delivery route

An AI image can be marked when it is created, then become several different files before a shopper sees it. Check the copy that actually reaches the product page.

AI product imagery is a useful place to find a C2PA workflow gap. One generated packshot may be cropped for a product page, resized by an image CDN, supplied to a marketplace, placed in an email and offered as a press download. Those are not necessarily the same file.

This is technical general information, not legal advice. A lawyer can assess whether a particular obligation applies to a particular service.

Why a product-image folder is not enough

A team may correctly keep a marked original in its asset library. But the customer normally sees a derivative: a WebP thumbnail, a CDN-resized JPEG, or an image fetched from a product-feed URL. A normal metadata setting is not proof that a cryptographically signed C2PA record is still there.

The useful questionDo not ask only whether the original campaign image has a record. Ask which exact file appears on the product page, reaches a marketplace, or can be downloaded by a customer.

Map the routes before changing anything

  1. Creation. Record where the AI image first enters your system and whether that file verifies.
  2. Asset management. Note any DAM, CMS or manual editing step that creates a new version.
  3. Delivery. List the public routes separately: product-page image, feed, marketplace upload, newsletter and download.
  4. Transformation. Include image-CDN resizing, format conversion and optimisation. These are often invisible to the content team but matter to the delivered file.

A small test that gives a useful answer

  1. Choose one newly created AI product image and retain the source file.
  2. Check the source with a C2PA-aware verifier.
  3. Publish it through one real product route, without a special test shortcut.
  4. Download or save the exact public image that a shopper receives.
  5. Check that delivered copy separately and record the date, URL or route, format and both results.

Repeat this for each materially different route. If the source verifies but a delivered copy does not, you have found a technical fact about the workflow—not proof that every route behaves the same way. It may mean signing needs to happen at a different point, or that a delivery route needs a different configuration. Test before making a public promise.

Keep campaign and catalogue evidence separate

A campaign image and a catalogue image can use the same original but travel through different systems. Treat them as separate routes. The same principle applies to customer downloads, to metadata settings, and to social-media uploads.

Check the product image that reaches the shopper

Compare one marked source with the actual public delivery copy. The useful result is whether each file has a verifiable C2PA record.

Check a file freeinfo@aidetective.eu