A file with no Content Credential has no verifiable C2PA account of its history available in that file. That observation does not establish how its pixels were made. The file may predate adoption, come from a device without credential support, or have passed through software that omitted an existing manifest. Synthetic generation is one possibility among many, not the inference licensed by absence alone.
The C2PA technical specification defines a way to package assertions about an asset into a manifest, bind the manifest to the content and sign its claim. A validator can check the binding and signature and assess the signer under a trust model. A manifest may record ingredients and actions as an asset changes. It is a system for assessing recorded provenance, including whether a claim remains intact; it is not a sensor test or a direct test of whether a scene is true. The C2PA explainer explicitly distinguishes provenance from factual accuracy of depicted content.
A chain can be incomplete even when a manifest exists
Consider a camera file with a signed capture claim. If an editor changes the image and issues a new manifest referencing the original as an ingredient, the chain can describe both stages. If the editor does not support Content Credentials, that modification may not be recorded in a continuous chain. A later signed manifest can attest to the resulting asset, but it cannot retroactively prove every undocumented intermediate action. The analyst must read the assertions actually made rather than treating a valid signature as a blanket approval of the whole history.
Screenshots are an especially clear boundary. They create a new image of displayed pixels; any original embedded credential may no longer accompany the new file. Format conversion, a platform re-encode, cropping and some export paths may also remove or invalidate an embedded manifest. C2PA also allows external manifests, so “not embedded” and “no recoverable provenance” are not always equivalent. The acquisition path matters.
Nor does a conventional EXIF camera-model field replace a signed credential. EXIF can assist reconstruction of file history, but without independent context it does not establish who set the field. Conversely, a valid C2PA assertion is evidence that a signer made a particular claim about bound content. How much confidence to place in the claim depends on the signer, the capture path and whether the claim addresses the question being asked.
Origin evidence when provenance is unavailable
If credentials are missing, seek earlier copies, source-system records and information about the transformations applied. Pixel-level examination may then address questions the provenance record cannot answer. RHEM Labs’ SPOT research investigates whether noise-residue characteristics support physical camera capture over synthetic generation under specified models. That evidence is distinct from a signed creation history. Neither substitutes for the other: a manifest can describe a generation action without measuring a sensor signal, while a sensor-oriented result cannot reconstruct every step in a file’s custody.
The reportable result should be specific. “No C2PA manifest was found in the supplied derivative” describes an examination of that object. “The image was AI-generated” is a separate origin conclusion requiring separate evidence. Keeping those statements apart prevents a provenance gap from becoming a false positive.