Provenance labels build trust, and the industry keeps making them smaller

Pixel 10 signs every photo it takes. Seeing the signature takes three taps and a scroll.

· 5 min read

Every photo the Pixel 10's camera app takes is signed. Google built it properly. The signing keys live in a separate security chip, each image gets its own certificate so no two photos can be linked to each other, and a trusted clock keeps the timestamp honest when you shoot somewhere without a signal. Under the C2PA's conformance program it holds the highest assurance level currently defined.

To see any of it, you open the photo, tap the three-dot menu, tap About, and scroll to a section called "How this was made." On the web version of Google Photos you can't see it at all.

Own an older Pixel? Your photos aren't signed, and nothing on the screen tells you. Mine's a three-year-old Pixel 7a. I opened a photo I'd taken on it, made the same taps, and the About panel had nothing to say either way: no credential, and no line telling me there wasn't one.

Last week's content badge was a label with no proof behind it. This is the reverse, and it's the more expensive mistake.

The research says show it

The strongest evidence for provenance labels came out this year, from a team at the University of Bergen. Christoph Trattner and colleagues showed 6,114 people in the US, the UK and Norway a set of news previews, some with a Content Credentials label under the photo and some without. The label came in three strengths, from a bare logo up to a full account of where the image came from, how it was verified and what had been edited.

The label worked. People rated the images as more transparent and more credible, and they trusted the outlet more. More detail bought more trust, and the outlets that started with the least trust gained the most. The Sun and HuffPost gained more than the BBC and CBS.

A smaller study at CHI in 2024 adds a location. Errol Francis and colleagues found that visual provenance did its best work on the article page, where the reader already was.

If you're deciding whether showing your work pays, that's about as clean an answer as audience research gives.

Then read the limitations section

Trattner's team is careful, and the paragraph that matters comes near the end: "Given that our experimental setup prominently featured the provenance label and image, this likely amplified their perceived effectiveness. News organizations involved in early C2PA pilot studies have tended toward smaller, less detailed labels to reduce visual clutter."

The study that proved the label works also reports that the people shipping it are shrinking it.

The BBC is the good-faith version of that choice. BBC R&D has studied provenance display since 2021 and helped build the standard. When it attached Content Credentials to BBC Verify stories in 2024, it tucked them into a drop-down, because the full record was "overwhelming and time consuming to read" and it wanted the article experience left intact. Its own quantitative research then found "a primarily neutral impact on trust." You may have seen a BBC figure saying 83% of people trusted the media more after seeing the credentials. That came from a self-selecting group answering three multiple-choice questions. The BBC published both numbers.

Meta moved faster. In April 2024 it announced a "Made with AI" label. By July that had become the less accusatory "AI info," which you could click for more. In September, for images that had only been edited with AI tools, the label came off the post and went into its menu. Meta's stated reason was accuracy: the old label kept landing on lightly retouched photos. That's a fair reason, and the result is a label fewer people will see.

Each of these is a sensible call by a team that wanted the proof to exist. Put together, they describe an industry that pays for the cryptography and economizes on the part a reader meets.

Seen, and still misread

Visibility is half of it. The other half showed up in a 2023 study with two Adobe co-authors, one of them the head of Adobe's Content Authenticity Initiative, which makes the findings harder to wave away. Kevin Feng and colleagues built a social feed using the C2PA's recommended indicator, a small icon in the corner of an image that opens a panel when you click it, and put 595 people in front of it.

Provenance helped them doubt manipulated images, which is the point. When a credential showed up as incomplete or invalid, though, some of them stopped believing photos that were honest. And they kept merging two questions: who signed this, and is it true. A signature answers the first. People read it as an answer to the second. The icon didn't help. One participant called it "just a random one it seems," and a couple of others mistook it for the three-dot menu on the post.

Google is straight about the difference. Under a heading called "What Content Credentials don't do," its help page says they don't "Tell you if a photo or video is real or fake." That's correct, and it lives on a help page, describing a panel three taps deep.

Mere disclosure

None of this is new. In 2012 the Royal Society wrote a report on how science should share its data, with Onora O'Neill on the working group, and it put the whole problem in one line: "Mere disclosure of data has very little value per se." To count as open, information had to be accessible, intelligible and assessable, which the report noted was "something not always achieved by generic metadata."

Content Credentials are generic metadata with excellent cryptography. The Pixel 10's signature can't be forged, and it's filed where you'd have to know to look.

The part your team owns

If you run a creative or marketing team, some of the tools you already pay for may be attaching these credentials to your work. Whether they survive the trip to a social platform is a separate fight. Where they survive, what happens next is a design decision, and it's being made by default.

I couldn't find a single study that measures how many people ever tap through to one. I'd bet the number is small, and the fact that I can't check is its own finding.

The research does settle where the proof should sit: on the work, in the reader's line of sight, which is where Francis found it did the most. It also says the wording matters as much as the placement. Feng's participants read a signature as a guarantee, and some read a broken credential as the mark of a fake, so the label has to say plainly what it vouches for and what a damaged record means for an honest photo.

That's layout and copy, the work a creative team does every day. The engineers finished their half. The proof is sitting in an About panel, waiting for someone whose job is making things seen.

Work together

Have a project in mind?

I help purpose-driven organizations build the technology they need to tell their stories. If that sounds like you, let's talk.

Get in touch with Five59 Labs →