← Back to tool

What is C2PA, and why is it inside your AI-generated images?

Guide · updated 25 September 2026

If you've generated an image with a tool like ChatGPT/DALL·E, Adobe Firefly, or a recent phone camera and then run it through a metadata scanner, you may have found something called a C2PA manifest sitting inside the file — often tens of kilobytes of structured data you never knowingly added. Here's what it actually is.

The short version

C2PA stands for the Coalition for Content Provenance and Authenticity — an industry standards body backed by Adobe, Microsoft, OpenAI, Google, camera makers, and major news organizations. Its specification defines a standard way to attach a tamper-evident record to a piece of media, describing where it came from and what's been done to it. When a platform labels an image "AI-generated," it's very often reading this exact record.

What's actually inside the manifest

A C2PA manifest is a structured container (technically a JUMBF box, borrowed from the JPEG standards family) holding several distinct pieces:

Why it's there even when you didn't ask for it

Most mainstream AI image generators now embed C2PA data by default as part of industry commitments around AI transparency. It's not something malicious or unique to any one platform — it's closer to how a camera has always written EXIF data into every photo automatically, whether you wanted it there or not.

Does removing it hide that an image is AI-generated?

Removing the C2PA manifest removes that particular signal, but it doesn't affect any watermarking baked directly into the pixels themselves (some platforms use invisible pixel-level watermarks, like Google's SynthID, which survive metadata stripping and require different detection methods entirely). It's worth being honest with yourself about why you're removing it: for ordinary privacy reasons — not wanting a platform, employer, or stranger to see which tool and account generated an image, or wanting a clean file for archival — that's a reasonable, common use case. Using metadata removal specifically to misrepresent AI-generated content as authentic in contexts where that distinction has legal or ethical weight (journalism, evidence, academic submissions) is a different matter, and stripping the manifest doesn't change what the image actually is.

How to check if your files have it

Use the View mode on AiEraser's homepage — it decodes the manifest structure directly (claim generator, actions, signature algorithm, and more) rather than just reporting "metadata found."

Related guides