Law

The provenance label does not survive the upload, and the specification says so

The AI Act asks for machine readable marking and California will ban stripping it. A C2PA manifest is one box in an MP4, and the upload rebuilds the container.

8 min updated 28 July 2026

14of the 99 conformant products, the ones that can validate a credential
8of the 14 validators that accept video, against 49 generators emitting MP4
$5,000per violation under California AB 853, and each day is a discrete violation
5distinct top level box layouts across 30 MP4 files in this repository

Section A.5.3 of the C2PA 2.2 specification says exactly where a Content Credential goes in a video file. The box containing the manifest store shall appear before the first mdat box and before any moov box, after ftyp so the brand checks still work. One box, near the front, in a container that every upload rebuilds. The standard's own explainer asks whether the provenance metadata can be removed, and answers in three words: Yes it can. Article 50(2) of Regulation (EU) 2024/1689 asks for outputs marked in a machine-readable format and says nothing about whether the marking is still there when somebody goes to read it.

The loss is three words into the standard's own FAQ

That FAQ answer keeps going. That is why the specification includes durable Content Credentials, it says, combining a hard binding, cryptographic hashing, with a soft binding such as watermarking or fingerprinting.

The implementation guidance, version 2.3, section 4.2.1, is blunter. Asset metadata, including any C2PA Manifest Store present, may be routinely removed or corrupted by legacy or non-C2PA capable platforms during distribution. Routinely. This is common on platforms that display asset renditions, it continues, and whilst these renditions may not create user perceptible change, they nevertheless change the underlying binary representation of the digital content.

Soft bindings, says the paragraph after it, identify the active manifest once it has become decoupled from its asset. Nobody writes the rescue procedure before the shipwreck unless the shipwreck is expected.

A rebuilt container carries the boxes its writer knows

The manifest does not sit in a box called c2pa. It rides in a uuid box with a sixteen byte extended type, because browsers based on Chromium will immediately fail playback when they encounter any unknown top-level boxes. So the credential travels in a box the world already tolerates.

I walked the top level boxes of the 30 MP4 files in this repository, 17 from our own renderer and 13 clips a diagnostic run downloaded or captured. Five distinct layouts, and not one file carrying a top level uuid box. Twenty put moov before the first mdat and ten put it after, and two of the twenty are fragmented, with moof and mdat pairs repeating to the end. One file is 88,821 bytes of rendered bar chart: ftyp at offset 0, free at 32, mdat at 40, moov at 85,796. Insert a manifest box at offset 32 and free, mdat and moov all shift by its length, and every absolute offset recorded inside moov shifts with them.

The specification names what a platform does next. The action c2pa.transcoded is a conversion of one encoding to another, including resolution scaling, bitrate adjustment and encoding format change. The action c2pa.repackaged converts one container format to another with no transcoding at all.

The upload does not delete your credential. It writes a new file that never had one.
FigureWhere a Content Credential is lost between export and a viewer's screen
1Export writes the manifest boxafter ftyp, before the first mdat, before any moov2The hard binding hashes everything but that boxthat box is a mandatory entry in the hash exclusions array3Upload makes renditionsc2pa.transcoded: scaling, bitrate change, format change4The container is rebuiltoffsets move, and an unrecognised box is not carried over5The player finds nothing, or a mismatchno manifest store present, or assertion.bmffHash.mismatch6Recovery, if somebody built ita soft binding is looked up, and a person reviews the near match

Stops and their wording come from the C2PA 2.2 technical specification (section A.5.3 on placement, section 18.6.2 on the hash, and the status codes in section 15.12.2) and from section 4.2 of the C2PA 2.3 implementation guidance. This is the path the specification itself describes, not a measurement of any platform: no primary source publishes a survival rate for a manifest through a video transcode.

The signature covers every box in the file except the one carrying it

Copying the box across by hand would not save it, and section 18.6.2 says why. All bytes of the file are added to the BMFF hash excluding the boxes named in an exclusions array, and if the manifest is embedded, the box containing it shall be one of those entries. The absolute file byte offset is then part of the input hashed for any root box, so a root box in the hash cannot change position in the file.

Move the boxes and the hard binding fails, whether a pixel changed or not. That is the design. Section 9.2 says a hard binding determines values that can match only this asset and no other, not even other assets derived from it or renditions produced from it. And a rendition, at definition 2.2.5, is exactly what an upload produces.

The validator answers assertion.bmffHash.mismatch, and section 15.5.5 concedes what that leaves: if the hard binding does not match, it is unknown if that is because of modification of the asset or because the wrong C2PA Manifest Store was located. A red cross is not a finding.

Adaptive delivery adds a problem specific to video. For fragmented MP4 an identical uuid manifest box has to sit in every initialization segment, and appending the individual files of a split asset back together will not produce a single file which is C2PA-compliant.

The platforms that read credentials attach a condition the explainers drop

TikTok announced on 9 May 2024 that it was the first video sharing platform to put Content Credentials into practice. The sentence everybody quotes: Content Credentials attach metadata to content, which we can use to instantly recognize and label AIGC. The sentence nobody quotes comes straight after. This means that the increase in auto-labeled AIGC on TikTok may be gradual at first, since it needs to have the Content Credentials metadata for us to identify and label it.

YouTube says the same at length. Captured with a camera appears in the expanded description only if the creator used tools with built-in C2PA support at version 2.1 or higher, and its list of edits to avoid names edits that break the chain of provenance. Both platforms describe a label downstream of a manifest arriving intact.

The C2PA conformance program publishes the list of products that passed. Of the 99 records conformant on or before 7 July 2026, 85 are generator products and 14 are validators. Eight of the 14 declare video at all, against 49 of the 85 generators that emit MP4. The 14 are phone galleries and inspection tools: Adobe Content Authenticity Inspect, Xiaomi Gallery and In Reality's c2pa_view among them. Not one large distribution platform. That register covers only vendors who applied and passed, so it undercounts quiet readers. It is still the only public list there is.

No disclosure rule names C2PA, and California's stripping ban turns on one adverb

Article 50(2) requires providers of AI systems generating synthetic audio, image, video or text to mark the outputs in a machine-readable format, detectable as artificially generated or manipulated, with solutions that are effective, interoperable, robust and reliable as far as this is technically feasible. Recital 133 lists the candidates: watermarks, metadata identifications, cryptographic methods for proving provenance, logging methods, fingerprints or other techniques. Metadata is the second of five named techniques, and the list ends with or other techniques. C2PA is named nowhere in the regulation, and anyone reading Article 50(2) as a C2PA mandate supplied that noun themselves.

The Commission's FAQ on Article 50 goes further: deployers cannot simply rely on the machine-readable marking embedded in the content by the provider under Article 50(2) of the AI Act to fulfil their disclosure obligation. What a deployer owes has to be perceivable by natural persons, with visible or audible labels, without any specific technical tools.

California went at the loss itself. AB 853, Wicks, chaptered as Chapter 674 of the Statutes of 2025, bars a large online platform from knowingly stripping, to the extent technically feasible, provenance data or a digital signature compliant with widely adopted specifications. It is operative on 1 January 2027, a large online platform is one above 2,000,000 unique monthly users, the penalty is $5,000 per violation, and each day in violation counts again.

A transcode does not knowingly strip a box. It writes a new container and does not copy a box it never recognised, which is the failure the C2PA guidance calls routine. Whether that is knowing, and whether carrying one box through a dozen renditions is technically feasible, the statute's text does not answer.

The stripping percentages in circulation have no sample behind them

Go looking for a number and one arrives at once. Imatag, a watermarking vendor, writes on its own C2PA page that a 2018 study conducted by Imatag revealed a startling reality: 80% of 50,000 images analyzed across 750 websites had their metadata removed. Another page, with no author and no method, puts the 2026 figure at effectively 100% for major social platforms. I followed the first back to Imatag's post of 11 May 2018. It reports 85 per cent of images online carrying no metadata, from over 40 million sampled, social media excluded. Then 8 per cent of photos on 750 editorial websites keeping data that identifies the author, from 50,000 images. Then 82 per cent of photographers saying they fill metadata in. None of the three is that sentence.

So the circulating figure is three numbers from one page welded together: a rounded 82 per cent from the photographer survey, a sample size from the editorial count, and a verb from the 40 million scan. The 2026 half has no source at all. Even repaired it would measure the wrong thing: IPTC and XMP fields in JPEGs, counted by a vendor with no published method, three years before C2PA had a specification.

What does exist is older and better. IPTC tested 15 social media sites in 2016 and found exactly one, Behance, that both retained and displayed embedded metadata. It named the mechanism in a sentence: the metadata was preserved if the size of the image remained unchanged, but if the image was rescaled, the metadata was stripped. Tim Bray, at the IPTC Photo Metadata Conference in September 2025, put it plainly: there are very few Content Credentials out there on the Internet. He also said the fair part: on social media privacy is a key issue, and stripping the metadata is arguably a good default choice.

The honest form of this finding is a mechanism, not a rate.
FigureOne MP4, before and after the transcode
One MP4 file, before and after an upload transcode. Widths are not to scale. C2PA manifest store As exported ftyp uuid moov mdat The hard binding hashes every box in the file except this one, and records where each box starts. uuid not carried into the new container After upload ftyp moov mdat moov now starts earlier, so every byte offset it records has changed. ftyp rewritten by whatever writes the new file uuid the manifest store, carried only by a writer that knows the box moov rewritten: it records the byte offsets into mdat mdat re-encoded, so its bytes change by definition

Box order and the placement rule are from section A.5.3 of the C2PA 2.2 specification, and the exclusion of the manifest box from its own hash is from section 18.6.2. The verdicts in the legend are what a re-encode necessarily does to each box, not a test of any named service. The lower band is the ftyp, moov, mdat layout carried by 6 of the 13 clip files among the 30 MP4 files measured in this repository.

What to do about it

  1. Host the signed master yourself and point people at it. The copy a platform re-encoded is a different file, and the credential on it is either gone or failing its own hash.
  2. Put the disclosure in the picture and in the narration, and treat the manifest as the machine readable extra rather than as the disclosure.
  3. Before promising anyone that a platform will read your credential, open the C2PA conforming products list and look for a validator from that platform.

Questions people actually ask

does c2pa metadata survive uploading a video to youtube or tiktok?

No primary source publishes a survival rate, and the C2PA implementation guidance, version 2.3, says a manifest store may be routinely removed or corrupted by legacy or non-C2PA capable platforms during distribution. The mechanism is the transcode: the manifest rides in a uuid box near the front of the container, and an upload that makes renditions writes a new container. TikTok's own May 2024 announcement says its automatic label needs the content to have the Content Credentials metadata for TikTok to identify and label it.

what is a soft binding in c2pa, and why does it exist?

A soft binding is a watermark or a fingerprint that lets a manifest be found again after it has been separated from the file, and the C2PA specification defines a Durable Content Credential as one for which such a binding exists. It exists because the implementation guidance says manifests are routinely removed during distribution. The guidance also says soft bindings must not be substituted for hard bindings, and that fingerprint matching is near rather than exact, so it recommends the retrieved credentials be presented to a person for manual review.

does the eu ai act require c2pa content credentials?

No. Article 50(2) of Regulation (EU) 2024/1689 requires providers of generative AI systems to mark outputs in a machine-readable format, with solutions that are effective, interoperable, robust and reliable as far as this is technically feasible, and Recital 133 offers watermarks, metadata identifications, cryptographic provenance methods, logging methods and fingerprints as candidate techniques. C2PA is not named. The Commission's FAQ on Article 50 adds that a deployer cannot simply rely on the provider's embedded machine readable marking to meet its own disclosure obligation.

is it illegal for a platform to strip provenance metadata?

In California it becomes unlawful on 1 January 2027, when the section added by AB 853, Chapter 674 of the Statutes of 2025, bars a large online platform from knowingly stripping compliant provenance data or digital signatures, to the extent technically feasible. A large online platform there means one above 2,000,000 unique monthly users, and the penalty is $5,000 per violation with each day counted separately. Whether a routine transcode that fails to carry an unrecognised box is knowing stripping is not answered by the statute's text.

where is the c2pa manifest stored inside an mp4 file?

In a uuid box carrying a C2PA extended type, which section A.5.3 of the 2.2 specification requires to sit after the ftyp box, before the first mdat box and before any moov box. The specification uses a uuid box rather than a c2pa box because Chromium based browsers fail playback immediately on an unknown top-level box. Of the 30 MP4 files measured in this repository, in 5 distinct top level layouts, none carried a top level uuid box at all.

Sources

  1. C2PA, Content Credentials: C2PA Technical Specification 2.2
  2. C2PA, C2PA Implementation Guidance 2.3
  3. C2PA, C2PA and Content Credentials Explainer 2.2
  4. C2PA, Conforming Products List
  5. Official Journal of the EU, Regulation (EU) 2024/1689 (Artificial Intelligence Act)
  6. European Commission, Transparency obligations under Article 50 AI Act
  7. California Legislature, AB 853 (Wicks), Chapter 674, Statutes of 2025
  8. TikTok Newsroom, Partnering with our industry to advance AI transparency and literacy
  9. YouTube Help, Building trust on YouTube: Captured with a camera disclosure
  10. IPTC, Many Social Media Sites Still Remove Image Rights Information From Photos
  11. Imatag, State of image metadata in 2018
  12. Imatag, Integrating Watermarking into C2PA Standards
  13. Tim Bray, C2PA Investigations

Every figure on this page comes from one of these. Where two of them measure the same thing differently, the article says so rather than picking the flattering one.

While you are here

Your website, as a video.