AI DetectiveArticle 50(2) and C2PA overview →

Practical guide · C2PA metadata

C2PA and metadata: what is the difference?

A “preserve metadata” setting is not proof that C2PA Content Credentials survived. Here is the practical difference — and a small test that shows what your recipient gets.

“Keep the metadata” sounds like a sensible instruction. But ordinary image metadata and C2PA Content Credentials are not the same thing. Treating them as the same is how a team can believe a file is still marked when the proof has already gone.

This is technical information, not legal advice. A lawyer can assess whether a particular legal obligation applies to a particular service.

What people usually mean by metadata

A file can carry ordinary metadata such as its camera model, creation date, copyright field, author name, location, or editing-software tag. This information can be useful, but it is commonly rewritten or removed when a file is exported, optimised or uploaded. It is not, by itself, a cryptographically signed statement about origin.

The plain distinctionMetadata is information about a file. A C2PA Content Credentials record is signed provenance information that a verifier can validate. One does not automatically turn into the other.

What C2PA adds

C2PA attaches a signed manifest to the asset. Depending on the workflow, it can record the issuer, the tool or process used, and later actions. A verifier can test whether the manifest is still connected to the file it describes.

That does not make C2PA magic. If a later step makes a fresh copy without the manifest, the new copy may retain a few ordinary tags or a visible logo while no longer carrying the C2PA record. The right question is therefore not “does the file still have metadata?” but “does the delivered file still have a valid C2PA record?”

Why an optimisation setting can mislead

Many CMS and CDN controls say “preserve metadata”. They may preserve EXIF or IPTC fields, but they are not automatically a promise about C2PA. Conversely, a route can remove ordinary metadata yet handle C2PA differently. Do not infer the result from a setting label; test the actual before-and-after files.

A five-minute check

  1. Keep one original file from the point where it was marked.
  2. Check it with a C2PA-aware verifier.
  3. Send that exact file through one real route: your CMS, image CDN, download flow or design export.
  4. Download the version a user receives and check it again.
  5. Record the route, date, output format and both results.

If the source file passes and the delivered file does not, you have located a technical workflow issue. Find the first step that creates the unmarked copy; a setting, conversion or a controlled signing point may need changing.

Do not use a visible label as the fallback

A caption such as “made with AI” can be useful for people, but it does not replace machine-readable provenance. The same is true of a logo watermark. Read our guide on why a visible AI watermark is not enough, and keep the source and delivered-file results separate in your records.

Check the file that reaches the user

Upload a source file and a delivered copy separately. The useful answer is whether each carries a C2PA record, not whether it merely contains some metadata.

Check a file freeinfo@aidetective.eu