# Content Credentials and C2PA: What Is Inside an AI Image? · Easy AI Act Image Labels

> C2PA, Content Credentials and IPTC DigitalSourceType explained: who writes the marker, how you check it, and what deletes it. As of September 1, 2026.

URL: https://easyaiactlabels.com/en/guides/content-credentials-c2pa/

[Guides](/en/guides/) /Technology

# Content Credentials and C2PA: What Is Inside an AI Image?

Last updated: 16 September 2026 Responsible: Martin Jäger 9 min read

Short answer

Content Credentials (C2PA) and IPTC DigitalSourceType are machine-readable provenance entries that the generating AI tool writes into the image file; a marker that is found is evidence of AI origin, a missing marker says nothing. On September 1, 2026, 34 of 47 measured models wrote a marker, and a screenshot or format conversion deletes it again. A marker can only be checked on the original file, in Shopify via the stored file in the media library, never via the re-encoded copy the storefront delivers.

An AI image can carry its own origin: a machine-readable entry in the file, written by the tool that generated it. These entries are called Content Credentials (technically, a C2PA manifest) and IPTC DigitalSourceType. They are why some AI images in a store can be found automatically, and why this never covers every image. Below: what the file contains, who writes it, how you check it, and where it gets lost.

## What is stored in an image file with Content Credentials?

Provenance data sits in three layers of the file’s metadata, invisible in the image itself:

Layer

What it contains

Example (measured September 1, 2026)

C2PA manifest (Content Credentials)

A cryptographically signed record: signer (certificate), tool or model, actions (created, edited, converted, watermarked), DigitalSourceType

ChatGPT image: signer “OpenAI OpCo, LLC”, model “gpt-image 2.0”, actions created, converted, watermarked

IPTC DigitalSourceType

A plain-text field in the XMP or IPTC block naming the type of origin

trainedAlgorithmicMedia (“Created using Generative AI”) for fully generated images; compositeWithTrainedAlgorithmicMedia for your own material with an AI component

Other metadata (EXIF, plain-text XMP)

Software or camera entries without a signature

Shopify Tinker: CreatorTool “Tinker (product\_still\_life)”, Credit “Tinker”

Key point: a marker is a statement by the generating tool, not a measurement of the image. Asked whether C2PA detects AI content, the IPTC FAQ of July 8, 2026, answers: “No … They simply extract the data that was put there by its creator or publisher.” A marker that is found is evidence that the tool recorded an AI origin. A missing marker says nothing. The image may be a photo, an unmarked AI image, or an AI image whose marker was lost along the way.

## Who writes the marker: the generator, the image editor, or you?

**The generator.** The provider (Anbieter) of the AI system is responsible for the machine-readable marking under Article 50(2) of the AI Act (Regulation (EU) 2024/1689). Providers whose systems were placed on the market before August 2, 2026, have until December 2, 2026, to comply with Article 50(2) (Article 111(4), inserted by Regulation (EU) 2026/1744; EUR-Lex retrieved August 31, 2026). Gaps in marker coverage are therefore normal in fall 2026.

**The image editor.** Tools that modify an existing photo write markers too. Canva sets trainedAlgorithmicMedia for an image generated purely from a prompt (signed by OpenAI, model gpt-image 2.0), but compositeWithTrainedAlgorithmicMedia, signed by Canva, for your own photo with an AI-generated background (measured September 1, 2026). Adobe Firefly embeds no manifest, only an XMP pointer to a cloud manifest at Adobe; a verification tool needs network access to resolve it.

**The aggregator writes nothing.** With services that bundle many models, the signature comes from whoever actually runs the model, not from the service itself. In 51 files from Magnific/Freepik, Freepik did not appear in a single signature chain. The signers were OpenAI, Google, Byteplus, Black Forest Labs, fal, Ideogram, Recraft, and Microsoft. Two Grok files carried a complete manifest signed by a self-signed “ephemeral CA” without a trust anchor: a verification tool sees the statement but cannot confirm who made it (September 1, 2026). Whether a marker is included depends on the individual catalog entry: Flux.1 carried a manifest, Flux.1 Fast did not, despite the same base model.

**You.** As a merchant, you are a deployer (Betreiber) under Article 3(4) of the AI Act. Your obligation arises not from Article 50(2) but from Article 50(4): the visible disclosure on the image (see [Do I have to label AI images in my store?](/en/guides/ai-images-labelling-obligation/)). The Commission guidelines C(2026) 5054 of July 20, 2026, state in paragraph 117 that deployers cannot rely on the marker embedded by the provider. The marker helps you find the images to check for a label; it is not the label.

## Which tools write a marker and which do not?

On September 1, 2026, the lakör test bench read 59 files: 47 catalog entries of one aggregator via API, four cross-checks from its web interface, six files from five other tools, and two controls. Of these, 43 carried a provenance marker. The Shopify image editor was tested separately the same day. The numbers apply to that day and those export paths; a quarterly retest is planned, the next after the December 2, 2026 deadline.

Tool class

Tested

With marker

Finding (September 1, 2026)

Chat assistants (ChatGPT, Google Gemini)

2

2

C2PA with trainedAlgorithmicMedia; Gemini also declares its SynthID watermark in the manifest

Design and editing tools (Canva, Adobe Firefly)

3

3

Canva distinguishes generated from edited; Firefly only via cloud pointer

Shopify Tinker

1

1

Writes C2PA and IPTC

Model catalog via aggregator (Magnific/Freepik, 47 entries via API)

47

34

Signature from the party that runs the model (model maker or inference service, such as fal for Flux.1); 13 entries without a marker, including Mystic, Classic, Krea 2, Luma, Flux.1 Fast, Qwen Image 3.0

Web interface cross-checks (Magnific)

4

3

Loss only where the download changed the format

Controls (real phone photo, screenshot)

2

0

As expected: EXIF with camera data, or almost nothing

Shopify image editor “Generate background” (separate measurement in the store)

1

0

File without any metadata block

Midjourney

0

\-

Not measured, no test image available

One special case: the Shopify image editor delivers no metadata block on the unchanged original (2,014,705 bytes). Whether Shopify sets no marker or loses it in its own processing cannot be determined from the outside (September 1, 2026; revisit after December 2, 2026).

## How do you check whether an image carries a marker?

1.  **Use the original, not a copy.** Markers survive only as long as nobody re-encodes the file.
2.  **Read the file with a verification tool.** c2patool, the C2PA command-line tool, reads manifests; exiftool shows XMP and IPTC fields such as DigitalSourceType. Without a command line, the free [AI image checker](/en/ai-image-checker/) on this website reads both markers directly in the browser; the file does not leave the device.
3.  **In Shopify: read the stored original, not the storefront view.** For files in the media library (Content > Files), Shopify keeps the untouched original and exposes it through the Admin API as originalSource. On September 1, 2026, 47 of 47 uploaded test images were byte-identical there to the local file, all 34 markers preserved. Visitors mostly get re-encoded copies without markers: via the storefront CDN address, only 5 of 34 markers came through on September 1, 2026; via the image URL that the Admin API returns for display, 0 of 3 on September 10, 2026. Scanning the online store from the outside measures the image pipeline, not the provenance.
4.  **Know the state “not verifiable.”** Collection images uploaded directly to the collection have no media library original and cannot be checked (measured September 10, 2026). The fix: upload the image under Content > Files and select it from there in the collection.

The app Easy AI Act Image Labels reads the original through the Admin API, never the storefront copy; what it cannot check is listed under [Limits](/en/faq/).

## Which export paths destroy the marker?

Every re-encoding of the pixels creates a new file. The C2PA manifest is never carried over; the XMP field with the DigitalSourceType survives only in exceptional cases (in Shopify for PNG, not for JPEG). All measurements below: September 1, 2026, unless noted.

Path

What happens

Evidence

Screenshot

The operating system creates a new file from pixels

From a marked file: a JPEG with 144 bytes of EXIF and 54 bytes of IPTC, no provenance entry

Right-click save from a preview

Often delivers the downscaled, re-encoded web version

Test bench rule, not measured

Format conversion on download

The export dialog converts PNG to JPEG or vice versa

Recraft V4.1: as a native PNG, a 3,174-byte manifest; as a JPEG from the web interface, nothing

Compressors, messengers, preview sharing

TinyPNG, WhatsApp, Slack, or the AirDrop preview can re-encode and strip metadata

Test bench rule, not measured

Shopify CDN delivery

Scaled copies are re-encoded; the original stays stored

see step 3 above (September 1 and 10, 2026)

Four rules:

1.  Use the tool’s official download button, never a screenshot, never right-click.
2.  Choose the highest resolution offered, never “optimized for web”.
3.  Keep the native output format; decline any conversion.
4.  Upload directly to the store; put nothing in between.

Are you allowed to remove markers deliberately? The AI Act does not prohibit third parties from removing them; the Commission recommends preserving them (guidelines C(2026) 5054, paragraph 98; retrieved August 31, 2026). Binding prohibitions come from terms of use and platform rules: the Black Forest Labs Usage Policy prohibits removing or suppressing C2PA credentials and watermarks (retrieved August 31, 2026). Per its help page (support.google.com/merchants/answer/6324350, retrieved September 14, 2026), Google Merchant Center requires the IPTC marker DigitalSourceType on AI-generated feed images and prohibits removing it. Whether Shopify passes the marker from the original file on to Merchant Center is unmeasured as of September 14, 2026; a spot check on a feed image with exiftool is worthwhile.

## What does the marker mean for your labeling obligation?

The marker answers the question “Which images come from an AI tool?” for the share of images whose tool wrote it and whose export path preserved it. It does not answer whether an image must be visibly labeled; that is decided under Article 50(4) of the AI Act by whether the image is liable to mislead, for instance a product that looks different from what is delivered (Commission guidelines of July 20, 2026, paragraphs 113 to 116; [details in the obligation guide](/en/guides/ai-images-labelling-obligation/)).

Nor does it replace the label: only a label on the image is visible. The official version is the EU icon with the abbreviation “AI” in three variants, exclusively with English wording (Commission page on the EU icons, dated August 10, 2026, retrieved August 31, 2026). The label word in other EU languages is a lakör translation, not an official file.

In practice: markers on the original are evidence and a solid basis for an automatic inventory; results from probability detectors are hints; a missing marker says nothing. If you know an image comes from an AI tool, label it whether or not a marker was found.

## Frequently asked questions

### Does C2PA detect whether an image is AI-generated?

No. C2PA and IPTC carry an entry that the generating tool wrote into the file; they measure nothing in the image, as the IPTC FAQ of July 8, 2026, states explicitly. A verification tool only reads the marker; it does not judge the pixels.

### My image has no marker. Does that mean it is not an AI image?

That cannot be concluded. On September 1, 2026, 13 of 47 measured models wrote no marker, nor did the Shopify image editor, and a screenshot or format conversion deletes every marker. A missing marker says nothing; label whatever you know to be an AI image, regardless.

### Is the marker in the file enough as a label under the AI Act?

No. The machine-readable marking is a provider obligation under Article 50(2); as a deployer, you are responsible for the visible disclosure under Article 50(4). The Commission guidelines of July 20, 2026, state in paragraph 117 that deployers cannot rely on the embedded marker.

### Why does my verification tool find no marker in the store, although the original file has one?

Because the store mostly delivers re-encoded copies. Via the storefront CDN address, only 5 of 34 markers came through on September 1, 2026; via the image URL that the Admin API returns for display, 0 of 3 on September 10, 2026. The stored original in the media library kept all 34 markers on September 1, 2026, so check the original file, not the storefront view.

### Which AI tools write a marker?

In the measurement of September 1, 2026, ChatGPT, Google Gemini, Canva, Adobe Firefly, and Shopify Tinker wrote a marker, as did 34 of 47 catalog entries via Magnific/Freepik. Mystic, Krea 2, Luma, and the Shopify image editor, among others, wrote none; Midjourney was not measured. The full table is in the section “Which tools write a marker” above.

## Sources

1.  Regulation (EU) 2024/1689 (AI Act), Articles 3, 50, 111. [eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) (accessed 31 August 2026)
2.  Regulation (EU) 2026/1744 (Digital Omnibus on AI), Article 1(39)(b) (new Article 111(4)). [eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2026/1744/oj) (accessed 31 August 2026)
3.  European Commission, Guidelines on the implementation of the transparency obligations under Article 50 (C(2026) 5054 final, July 20, 2026), paragraphs 98, 113 to 117. [ec.europa.eu](https://ec.europa.eu/newsroom/dae/redirection/document/131215) (accessed 31 August 2026)
4.  European Commission, EU icons for labelling AI-generated content (page dated August 10, 2026). [digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content) (accessed 31 August 2026)
5.  IPTC NewsCodes, Digital Source Type: trainedAlgorithmicMedia. [cv.iptc.org](http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia) (accessed 31 August 2026)
6.  C2PA, Coalition for Content Provenance and Authenticity (specification, verification tool c2patool). [c2pa.org](https://c2pa.org) (accessed 14 September 2026)
7.  Google Merchant Center Help, answer/6324350 (image requirements, IPTC DigitalSourceType). [support.google.com](https://support.google.com/merchants/answer/6324350) (accessed 14 September 2026)

This article is general information, not legal advice. Whether an image needs a label is your decision; for your specific case, please ask a lawyer.

Read next

[05 · Practice Shopify Magic and the EU AI Act: What Applies to You?](/en/guides/shopify-magic-ai-act/) [06 · Practice Do AI images from before August 2, 2026 need a label?](/en/guides/images-uploaded-before-august-2026/)

I find the AI evidence. You confirm with one click.

[Coming soon to the Shopify App Store](/en/how-it-works/)
