It is easy to hear “OpenAI already marks the image” and close the issue. But a typical business workflow has more steps: your application fetches the image, a server optimises it, a designer crops it, a customer downloads it, or a platform processes it again. A C2PA provenance record can be removed in those steps.
This is technical information, not legal advice. Whether a particular obligation applies to your product should be assessed with legal advice.
What is already there
OpenAI has said that images generated through its image tools include C2PA Content Credentials. The record is cryptographically signed information attached to the image file, rather than a visible watermark. It can tell a verifier something about the file’s origin and later edits.
Where the record commonly disappears
Do not assume your code is neutral just because it does not visibly edit an image. C2PA data is often lost when a file is resized, recompressed, converted between formats, stripped of metadata, passed through an image CDN, or re-exported by a design tool. A social platform can also make its own copy.
That does not mean a mark always disappears. LinkedIn and TikTok commonly preserve C2PA data, while Facebook and Instagram often remove it on upload. Treat every route as something to verify, not as a permanent platform promise. See also our guide to C2PA survival on social media.
A small test that answers the real question
- Generate one test image and save the original file unchanged.
- Check that original with a C2PA-aware verifier, such as the free AI Detective file check.
- Run the same file through each real route: API delivery, download, CDN, CMS, design export, and any platform upload that matters.
- Download the delivered version and check it again.
- Record the route, date, file type and result. Repeat after a material workflow change.
Keep the source file and the delivered-file result separate in your records. A pass at the source proves that the source carried a record; it does not make a claim about a later copy.
If your route removes it
First find the exact step that changes the file. Sometimes it can be configured to keep metadata or to avoid an unnecessary conversion. If it cannot, the practical solution is to put reliable marking into the workflow at the appropriate controlled point and keep an audit trail of what was issued. Do not replace the record with only a logo or “AI-made” caption: a visible label does not provide a machine-readable provenance record. Our watermark guide explains the difference.
Want to test your real route?
Upload a source file and its delivered copy to compare what remains. For a workflow-level check, ask us for a short mapping call.
Check a file freeAsk about a workflow check