What a Verified Photo Actually Proves
Apple Reference Image attests that a camera saw something. C2PA attests to an edit history. Those are different claims, they fail in different ways, and neither one answers the question people think it answers.

What a Verified Photo Actually Proves 📷
Apple announced Apple Reference Image this month: on the iPhone 18 Pro and Pro Max, the camera can save a shot twice — once as the normal editable photo, and once as a reference image carrying an identifier that attests it came off a real sensor rather than a model. Apple calls that second file a digital negative.
Notably, Apple did not adopt C2PA Content Credentials, which Nikon, Canon and Google's Pixel line have. Apple's stated objection is structural: C2PA attaches provenance after capture and then certifies the chain of edits from that point forward, which means the chain can be compromised anywhere along its length.
We build synthetic people for a living, so we have an unusual stake in this. It is worth being precise about what each approach proves, because the gap between that and what people will assume it proves is where the trouble lives.
Two different claims
A reference image is a claim about origin. It says: a sensor in a device of this type captured these photons, and here is a value that is hard to forge without that sensor. It says nothing about what happened afterwards, because it is not in the editing path at all — it is a sealed copy set aside at the moment of capture.
A content credential is a claim about history. It says: this file started somewhere, then these operations were applied, and each step signed its work. It is a chain, and like any chain it is exactly as strong as its weakest signer.
These solve adjacent problems and it is easy to talk past the difference. "Is this photo real?" is answered by the first. "Is this photo of what it claims to be?" is answered by neither.
The failure modes are not symmetric
A chain fails gradually and invisibly. Every tool that touches the file has to participate. One that does not strips the credential, and a stripped credential is indistinguishable from a photo that never had one. In practice the great majority of images that pass through a screenshot, a messaging app, a re-encode or a crop in an unaware editor arrive with nothing attached. The absence of provenance is the normal case, which makes its absence uninformative.
A negative fails at the edges. It is a strong claim, narrowly scoped, and its weaknesses are the ones you would expect from anything hardware-anchored: it only exists where the hardware exists, it tells you nothing about the photograph that circulates (only about the sealed copy), and it requires somebody to actually go and check the two against each other. The verification step is a separate action that most viewers will never take.
Both are worth having. Neither is a detector.
The problem no provenance system touches
Point a verified camera at a high-quality screen showing a generated image.
The sensor genuinely saw photons. The attestation is genuinely valid. The resulting file is, by every technical measure the system can apply, a real photograph — of a fake. This is the analog hole, it is decades old, and no amount of cryptography at the capture boundary closes it, because the system is attesting to the capture and the capture really happened.
Which is the honest summary of this entire category: provenance establishes where a file came from, not whether its contents are true. Those have never been the same question. A photograph has always been able to lie about context, framing, and timing without a single pixel being altered.
What this means for synthetic media
Here is where our own interest shows, and where we would rather be explicit than sound reassuring.
If you build systems that produce convincing synthetic people — as we do — the right posture is not to argue that detection will keep up. It will not, reliably, and a product that depends on a detector staying ahead is built on sand. The durable answer is the same one these provenance systems reach for from the other direction: make the provenance structural rather than forensic.
Concretely, that means the label travels with the interaction rather than being inferred from it. A synthetic participant should be identified as synthetic by the system that runs it, at all times, as a property of the session rather than a watermark someone has to go looking for. The claim "this is an AI" should not be something you detect. It should be something the platform states, because the platform is the one that knows.
That is a weaker guarantee than cryptography in one sense — it holds only inside a system that chooses to enforce it — and a much stronger one in practice, because it does not require the viewer to run a check they will never run.
Apple's negative and C2PA's chain are both attempts to get authenticity out of the forensic business and into the structural one. The disagreement between them is about where to put the anchor, and it is a real disagreement worth watching. The thing to resist is the conclusion that either one will let you look at an image and know.
Sources: Apple Security Research · Nieman Lab