C2PA vs SynthID: What Each One Actually Proves About an Image

September 30, 2026 · 6 min read

You upload a photo to find out if it is AI-generated. One tool says "Content Credentials found." Another says "SynthID detected." A third says nothing at all. Same image, three different answers. These are two different systems that prove two different things.

The short version

C2PA (usually called Content Credentials) is a signed record of an image's history that lives in the file's metadata. It can tell you which tool made the image, what edits happened, and when. But a screenshot or a routine upload can wipe it out.

SynthID is Google DeepMind's invisible watermark. It lives in the pixels themselves, so it survives screenshots, crops, and compression. The tradeoff is that it carries almost no detail. It answers one question: was a participating AI tool involved?

The big AI labs now use both, because each covers the other's weak spot.

What C2PA actually is

C2PA is an open technical standard for recording where a piece of media came from and how it changed. Content Credentials is the consumer-facing name for the same technology. If you have seen a small "CR" badge on an image, that is it.

The standard launched in 2021, started by Adobe, Microsoft, the BBC, Intel, Arm, and Truepic. It is now an open project with more than 6,000 members and affiliates running live applications, according to the coalition's own announcement in early 2026.

A compatible camera or app writes a small signed record, called a manifest, directly into the file. The manifest can log the capture device, the editing software, timestamps, and whether AI had a hand in it.

The signing is what makes it trustworthy. C2PA uses the same kind of certificates that secure banking sites, so if anyone alters the image or the record after signing, the seal visibly breaks. Think of it as a signed logbook that travels with the photo. It does not promise the story inside is true. It promises nobody tampered with the logbook after it was signed.

What SynthID actually is

SynthID takes the opposite approach. Instead of attaching a note to the file, Google DeepMind's system nudges the content itself. During generation, it makes tiny adjustments to pixel values in a pattern that a matching detector can read back later. Human eyes see no difference.

Because the mark lives in the pixels, it is built to survive cropping, compression, filters, rotation, and even screenshots. Those are exactly the things that erase metadata-based signals.

At Google I/O in May 2026, Google said more than 100 billion images and videos already carry the watermark. At the same event it announced that OpenAI, Kakao, ElevenLabs, and NVIDIA were adopting it. The same month, OpenAI started embedding SynthID in ChatGPT images alongside Content Credentials.

The one difference that changes everything

C2PA lives in the metadata. SynthID lives in the pixels. Almost every practical difference follows from that single fact.

Metadata sits in the file's container, in a tidy box next to the image data. It is rich and detailed, but easy to remove. Take a screenshot and you create a brand-new file with none of the original manifest. The pixels get copied faithfully, so a SynthID watermark rides along in that screenshot intact.

C2PA carries a deep, detailed history but is fragile in the wild. SynthID carries almost no detail but survives the messy way images travel online.

What each one can and cannot tell you

A valid C2PA manifest can show you the tool that made the image, the software that edited it, when it happened, and sometimes who published it. What it cannot do is judge whether that story is true. It only confirms the record is properly signed and untouched, and it only helps if the manifest survived the trip.

SynthID answers a narrower question: was this made or edited by a participating AI tool? A hit can even flag that only part of an image was generated. But it will not name the exact model, it will not give you an edit history, and it goes silent for any tool that never implemented the watermark, which is still most AI generators.

One more practical difference: SynthID detection runs on Google's proprietary infrastructure. The watermark pattern and the detector are not open source, so no independent developer can build a SynthID checker. You can check through the Gemini app today, and Google says verification is coming to Search and Chrome.

The mistake almost everyone makes

People see "no Content Credentials" or "no watermark found" and conclude the image must be real. That is reading the result backwards.

A blank result has plenty of innocent explanations. The platform stripped the metadata on upload. An export tool dropped it. A screenshot wiped it clean. The image came from an AI tool that never watermarks anything. A positive hit is meaningful. A miss is close to silent.

That is also why our checker refuses to give you an "AI probability" score. When a file carries no signals, the honest answer is "we cannot tell," not a reassuring number.

How to check an image in under a minute

You do not need special software. Two free checks cover most everyday situations.

First, upload the original file (not a screenshot) to a Content Credentials reader to see any C2PA history. Our checker at the top of this page does exactly that, entirely in your browser, along with a read of the file's EXIF metadata.

Second, for a SynthID check, open the Gemini app, upload the image, and ask whether it was created or edited by Google AI. Google's standalone detector portal still has limited access, and OpenAI runs a separate preview at openai.com/verify that checks images from its own tools.

When an image carries both signals, you get the full story plus a mark that survives sharing. When it carries neither, you have learned nothing yet.

Want to check an image yourself? Upload it and read its provenance signals in seconds.

Try the free checker