Folder or image file featuring a chain and signature seal, representing signed files and secure documentation

Public notebook

The hand signing the file

When authenticity ceases to be a judgement and becomes signed metadata

In a previous text, I argued that in the age of AI suspicion, the value of what is handmade shifts from the surface of the image to its provenance: it is not the hand that is worth more, but the hand that can be believed. That piece concluded with a phrase that is worth developing now, as it contains a greater shift than it appears: the credible hand is no longer just that of the artist, the expert, or the witness. It is also the hand that signs the file.

This shift now possesses a technical name and a concrete infrastructure. It is called C2PA, and it warrants close inspection, as it is quietly altering where the authenticity of an image resides.

1. What is C2PA

C2PA—the Coalition for Content Provenance and Authenticity—is a coalition developing an open standard to certify the origin and history of digital content. Its instrument is the so-called Content Credentials: a type of signed, durable, and verifiable metadata, which Adobe describes with a useful metaphor—a “nutrition label” for the file. This label can record who captured or generated the image, with which tool, what edits it subsequently underwent, and which signature validates each step.

The decisive factor is not the visible label, but what lies beneath: a technical architecture of manifests, assertions, cryptographic signatures, and validation. C2PA does not offer an opinion on the image. It does not view the work as a critic would. It maintains a chain of verifiable statements regarding what has happened to the file. The question “is it authentic?” is fragmented into more technical inquiries: who signed it?, what does the manifest assert?, which part of the file is cryptographically linked?, what occurred after the signature?, what authority recognises the signer?

This is neither science fiction nor a mere promise. There are already cameras that incorporate it as standard—Leica launched the M11-P as the first camera with integrated Content Credentials, and Nikon is working on compatible models in collaboration with press agencies—and tools such as Adobe Firefly automatically apply credentials to the content they generate. The infrastructure is being deployed while its necessity is still being debated.

2. From judgment to signed metadata

To see what is changing, one must recall what authenticity once was. In the art market, it was never a purely visual matter: it depended on a constellation of practices—expert attribution, catalogue raisonné, documentary provenance, material analysis, appraisal, institutional inscription, archive. A combination of gaze, document, authority, and market. A situated judgement, exercised by someone with recognised competence, almost always after the fact: retrospective.

C2PA does not eliminate this ecosystem. It shifts part of its weight to another moment: that of the generation, editing, and publication of the file. Authenticity ceases to be a unitary judgment issued at the end and becomes a chain of states signed from the beginning. It is no longer merely a matter of certifying “this work belongs to X,” but of reconstructing “this file was captured or generated by these agents, with these tools, at these times, and subsequently edited in this manner, under these signatures.” Less aura of the unique origin; more traceability of operations. A procedural authenticity.

3. Post-NFT: from property as aura to provenance as infrastructure

It is useful here to place this within recent genealogy, as it is easy to mistake it for something we have already seen. The NFT promised to resolve a specific wound in digital art: the impossibility of scarcity and stable provenance in infinitely copyable files. However, its dominant grammar was not provenance as a common infrastructure, but singularity as a tradable asset. The NFT responded above all to one question: who owns or transfers this token? It was, one might say, a first spectacularised version of digital provenance: it resolved the symbolic ownership of a scarce identifier, not the reliability of the material or editorial chain of the content.

C2PA responds to a different question: what verifiable history accompanies this file? It does not tokenise the work to sell it; it instruments the file so that it may be audited. Its political economy is different: it does not seek to create commercial scarcity, but to render provenance legible. If the NFT placed digital provenance under the market spotlight, C2PA removes it from that stage and converts it into a silent infrastructure of trust, auditing, and compliance. The post-NFT phase, viewed in this light, does not abandon digital provenance: it shifts it from property as aura towards provenance as infrastructure.

4. What it proves and what it does not

Herein lies the distinction that is most important to maintain, as its confusion would be dangerous. C2PA can prove relative integrity: that what is signed still corresponds to the validated content, and that the chain of manifests has not been broken or altered without leaving a trace. It can render post-signature manipulation evident. That is significant, and for photojournalism, institutional archives, or exhibition documentation, it may soon become a basic requirement for circulation.

However, C2PA does not prove the truth of what the image represents. It is not constructed to detect deepfakes through forensic analysis nor to verify facts, as the World Privacy Forum report on the standard emphasises. A file may possess valid credentials and still be misleading: through framing, omission, staging, pre-capture manipulation, or because the human assertions incorporated into the flow are false. The authenticity that C2PA provides is authenticity of provenance, not truth of representation.

In art, this is even productive: a work may be deliberately fictitious and possess an intact provenance; fiction is not a defect of origin. In journalism, however, it is delicate, because the public may confuse a valid signature with a true fact. The dangerous illusion will be precisely that: taking signed provenance for cultural truth. C2PA improves traceability; it does not resolve hermeneutics. Knowing where an image originates does not inform us of its meaning, nor whether what it depicts occurred as it appears.

5. The machine as a reader of provenance

There is one further change, and it is the one I consider most profound. The recipient of authenticity is no longer solely human. The European Artificial Intelligence Act requires, in Article 50, that synthetic content be marked in a machine-readable format and be detectable as artificially generated or manipulated. In other words: provenance is inscribed so that it may also be read by platforms, search engines, archives, moderation systems, institutions, and automatic classification models.

In this regime, a work or a cultural image will not only be seen: it will be read by validation infrastructures before reaching anyone. Provenance becomes a condition of institutional legibility. Anything lacking a credential may appear suspicious—even if legitimate—simply because the infrastructure does not know how to read it. And therein lies the underlying risk: that authenticity shifts from being a debatable expert judgement to a technical administration of visibility.

6. Authority does not disappear: it changes location

It is prudent not to idealise the standard simply because it is open. C2PA incorporates a trust model: signer identity, certificates, trust lists. This means that the technical validity of a signature does not, by itself, equate to truth; it depends on which signer is recognised as reliable. The question “whom do we believe?” does not dissolve. It transforms into “which signer do we accept as trustworthy?”. The infrastructure does not eliminate authority: it relocates it within certificates, lists, organisations, and platforms.

And that relocation carries a cost that should be named. The openness of the standard does not guarantee symmetry in adoption. Whoever controls the tools of creation, distribution, or visualisation will have the capacity to decide which provenance is seen and which remains opaque. Large institutions and platforms with signing capacity will be more credible than an artist, a collective, or a community archive without access to certified infrastructure. Signed provenance can thus reproduce, with a technical and neutral appearance, very old cultural inequalities.

7. What this means for art

I shall pick up the thread from where I left it. I maintain in this Notebook that institutional validation does not reflect a prior value: it produces it. C2PA is a further turn of the screw on that thesis, now in the form of infrastructure. It does not certify that something is authentic: it incorporates authenticity into the file as verifiable data, and in doing so, it redistributes who possesses the authority to uphold it.

For art, this opens three fronts simultaneously. In the production of digital work, it allows for a shift from a vague curatorial statement—'work created with AI'—to a granular traceability of tool, process, and agents. In documentation, it converts the record of a process into a chain of signed evidence. And in conservation, an institution that adopts the standard will not only conserve works: it will conserve chains of evidence production. A new aesthetics of provenance may even emerge, where the value of a work does not depend solely on the final image but on the transparency or the verifiable singularity of its process.

But the profound shift is not aesthetic. It is administrative and epistemic: a portion of trust moves from human judgement to signed metadata. That gain—greater traceability—is tied to a new dependency: on signing systems, trust lists, platforms, and viewers. The credible hand is multiplied. It is no longer just that of the artist who created the work: it is also that of the person who signed the file, the person who certified the signer, and the person who programmed the viewer that decides to show you that signature. It is worth examining them all. Because the question 'where does this come from?' will increasingly have an impeccable technical answer—and will still require, afterwards, someone who knows how to ask what it means. That second question, fortunately, no infrastructure can sign for us: it remains ours, and in that, there is more freedom than loss.

On open conversation

This text continues the reflection initiated in The Credible Hand and intersects with the line on blockchain and registration that I am working on at KChain. If anyone wishes to intervene from the fields of digital conservation, copyright, museology, or the development of provenance standards, the notebook remains open.

Sources

Coalition for Content Provenance and Authenticity (C2PA). Content Credentials: C2PA Technical Specification, v2.4. https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html

C2PA. “Verifying Media Content Sources.” https://c2pa.org/

Content Authenticity Initiative (CAI). “How it works.” https://contentauthenticity.org/how-it-works

Adobe (2026). “Content Credentials overview.” https://helpx.adobe.com/creative-cloud/apps/adobe-content-authenticity/content-credentials/overview.html

Kaye, Kate; Dixon, Pam (2025). Privacy, Identity and Trust in C2PA: A Technical Review and Analysis of the C2PA Digital Media Provenance Framework. World Privacy Forum. https://worldprivacyforum.org/media/documents/c2pa_report.pdf

European Union (2024). Regulation (EU) 2024/1689 (AI Act), art. 50. http://data.europa.eu/eli/reg/2024/1689/oj

European Commission (2026). “Code of Practice on Transparency of AI-Generated Content.” https://digital-strategy.ec.europa.eu/en/faqs/code-practice-transparency-ai-generated-content

Radermecker, Anne-Sophie V.; Ginsburgh, Victor (2023). “Questioning the NFT ‘Revolution’ within the Art Ecosystem.” Arts, 12(1), 25. https://doi.org/10.3390/arts12010025

Bourron, Christine (2023). “Comprehensive Analysis of the Trade of NFTs at Major Auction Houses: From Hype to Reality.” Arts, 12(5), 212. https://doi.org/10.3390/arts12050212

Whitaker, Amy (2019). “Art and Blockchain: A Primer, History, and Taxonomy of Blockchain Use Cases in the Arts.” Artivate, 8(2), 21-46. https://doi.org/10.34053/artivate.8.2.2


Discover more from Juan A. Esteban

Subscribe to receive the latest entries via email.

Español English (UK)