Anthropic released a free browser tool for checking content credentials
The checker verifies C2PA credentials and processes files locally, up to 100MB. Content credentials only work while nothing strips them, and almost everything does.
Anthropic has released a free browser-based tool for verifying C2PA content credentials, at claude.com/check-content. Files are processed on the user's own device — "your file stays on your device" — and it accepts several formats up to 100MB.
C2PA, the Coalition for Content Provenance and Authenticity, defines a standard for cryptographically signed metadata recording how a file was made and what has happened to it since. The tool reads that metadata and reports what it says.
Doing it locally is the right design. A verification service that requires uploading the file gives the verifier a copy of everything anyone checks, which is a poor property for a tool people will use on sensitive material.
What credentials can and cannot establish
A content credential is a signed assertion of provenance. Present and valid, it tells you what a specific piece of software claims about how the file was produced.
Absent, it tells you nothing at all — and this is the limitation that governs the entire approach. Credentials are metadata, and ordinary operations remove metadata as a matter of course. A screenshot has no credential. A re-encode strips it. Most social platform upload pipelines discard it. Copying an image out of one application and into another usually loses it.
So the practical result is that a credential's presence is weak positive evidence and its absence is no evidence. Most authentic material a person encounters will have no credential, because it has passed through a pipeline that removed it, and treating unsigned content as suspect would flag nearly everything.
The regulation that needs this to work
The EU's transparency rules took effect on 2 August, requiring certain systems to disclose when content has been generated or altered by AI. Content credentials are the leading technical mechanism for satisfying that obligation.
The mismatch is that the obligation is about informing the person who encounters the content, and a credential attached at generation does not survive to that point. A provider can sign what it produces. It cannot ensure a European viewer sees the signature, because the intervening pipeline is not under its control.
No one has solved this. Watermarking that survives re-encoding is more robust and considerably weaker as evidence, because it is not cryptographically signed and can be forged or removed by a determined party. Platform-level preservation of credentials would work, and requires the platforms to implement it.
Why it is worth having anyway
The useful cases are narrow and real: verifying material that has come through a controlled pipeline, checking whether a file that claims to carry credentials actually does, and giving newsrooms, courts and insurers a way to confirm provenance on documents where the chain has been preserved deliberately.
Those are exactly the settings where the stakes justify preserving metadata, and where the alternative — expert forensic analysis — is slow and expensive.
The context makes it timelier than it looks. WIRED and the Tech Transparency Project documented hundreds of Meta ads over nine months containing AI-generated child sexual abuse imagery, some manipulating photographs of real children. The Institute for Strategic Dialogue tracked 150 AI-remixed extremist videos across 71 TikTok accounts with 5.4 million views. Four teachers have described sexualised AI images made by students.
A local credential checker does not address any of those, because none of that material carries credentials. It is infrastructure for a world where provenance is preserved, and that world does not exist yet.
Runs the newsroom. Rename this profile in the studio to your own byline.
Related
Every weekday, the AI stories that moved money or shipped code.
No cross-posting, unsubscribe anytime. See all newsletters