“Keep the metadata” sounds like a sensible instruction. But ordinary image metadata and C2PA Content Credentials are not the same thing. Treating them as the same is how a team can believe a file is still marked when the proof has already gone.
This is technical information, not legal advice. A lawyer can assess whether a particular legal obligation applies to a particular service.
What people usually mean by metadata
A file can carry ordinary metadata such as its camera model, creation date, copyright field, author name, location, or editing-software tag. This information can be useful, but it is commonly rewritten or removed when a file is exported, optimised or uploaded. It is not, by itself, a cryptographically signed statement about origin.
What C2PA adds
C2PA attaches a signed manifest to the asset. Depending on the workflow, it can record the issuer, the tool or process used, and later actions. A verifier can test whether the manifest is still connected to the file it describes.
That does not make C2PA magic. If a later step makes a fresh copy without the manifest, the new copy may retain a few ordinary tags or a visible logo while no longer carrying the C2PA record. The right question is therefore not “does the file still have metadata?” but “does the delivered file still have a valid C2PA record?”
Why an optimisation setting can mislead
Many CMS and CDN controls say “preserve metadata”. They may preserve EXIF or IPTC fields, but they are not automatically a promise about C2PA. Conversely, a route can remove ordinary metadata yet handle C2PA differently. Do not infer the result from a setting label; test the actual before-and-after files.
A five-minute check
- Keep one original file from the point where it was marked.
- Check it with a C2PA-aware verifier.
- Send that exact file through one real route: your CMS, image CDN, download flow or design export.
- Download the version a user receives and check it again.
- Record the route, date, output format and both results.
If the source file passes and the delivered file does not, you have located a technical workflow issue. Find the first step that creates the unmarked copy; a setting, conversion or a controlled signing point may need changing.
Do not use a visible label as the fallback
A caption such as “made with AI” can be useful for people, but it does not replace machine-readable provenance. The same is true of a logo watermark. Read our guide on why a visible AI watermark is not enough, and keep the source and delivered-file results separate in your records.
Check the file that reaches the user
Upload a source file and a delivered copy separately. The useful answer is whether each carries a C2PA record, not whether it merely contains some metadata.
Check a file freeinfo@aidetective.eu