AI DetectiveArticle 50(2) and C2PA overview →

Practical guide · OpenAI images

OpenAI images already have C2PA: what still needs checking

An OpenAI image may leave the generator with Content Credentials. That is useful evidence at the starting point. It is not, by itself, evidence that the same record reaches your customer or audience.

It is easy to hear “OpenAI already marks the image” and close the issue. But a typical business workflow has more steps: your application fetches the image, a server optimises it, a designer crops it, a customer downloads it, or a platform processes it again. A C2PA provenance record can be removed in those steps.

This is technical information, not legal advice. Whether a particular obligation applies to your product should be assessed with legal advice.

What is already there

OpenAI has said that images generated through its image tools include C2PA Content Credentials. The record is cryptographically signed information attached to the image file, rather than a visible watermark. It can tell a verifier something about the file’s origin and later edits.

The useful distinction“The provider marked its original file” and “our user received a marked file” are two different statements. The second one needs a test of your own delivery route.

Where the record commonly disappears

Do not assume your code is neutral just because it does not visibly edit an image. C2PA data is often lost when a file is resized, recompressed, converted between formats, stripped of metadata, passed through an image CDN, or re-exported by a design tool. A social platform can also make its own copy.

That does not mean a mark always disappears. LinkedIn and TikTok commonly preserve C2PA data, while Facebook and Instagram often remove it on upload. Treat every route as something to verify, not as a permanent platform promise. See also our guide to C2PA survival on social media.

A small test that answers the real question

  1. Generate one test image and save the original file unchanged.
  2. Check that original with a C2PA-aware verifier, such as the free AI Detective file check.
  3. Run the same file through each real route: API delivery, download, CDN, CMS, design export, and any platform upload that matters.
  4. Download the delivered version and check it again.
  5. Record the route, date, file type and result. Repeat after a material workflow change.

Keep the source file and the delivered-file result separate in your records. A pass at the source proves that the source carried a record; it does not make a claim about a later copy.

If your route removes it

First find the exact step that changes the file. Sometimes it can be configured to keep metadata or to avoid an unnecessary conversion. If it cannot, the practical solution is to put reliable marking into the workflow at the appropriate controlled point and keep an audit trail of what was issued. Do not replace the record with only a logo or “AI-made” caption: a visible label does not provide a machine-readable provenance record. Our watermark guide explains the difference.

Want to test your real route?

Upload a source file and its delivered copy to compare what remains. For a workflow-level check, ask us for a short mapping call.

Check a file freeAsk about a workflow check