2.8

Adoption status: cameras, phones, AI tools

A working inventory of who has shipped, who has paused, and who has promised. Adoption status changes monthly; the snapshot below is current as of mid-2026.

C2PA adoption in 2026 is best described as broad but shallow. The major actors in every relevant industry — cameras, smartphones, AI generators, editing software, wire services, social platforms, browsers — have announced support. The depth of that support varies enormously. Some are shipping signed capture in flagship hardware; some have a single product line with the feature toggleable; some have published a roadmap without yet shipping anything user-visible. This page tries to give a working snapshot.

Adoption is moving fast enough that any printed snapshot is partially obsolete. The trajectory matters more than any single line item. Three patterns are stable: high-end professional capture devices are converging on default-on C2PA, consumer flagship phones are converging on opt-in C2PA, and the large commercial AI generators have made backend signing standard. The middle of the market — midrange phones, prosumer cameras, smaller AI tools — lags substantially.

Cameras

The camera industry was the earliest non-Adobe segment to ship C2PA. The Leica M11-P, released October 2023, was the first commercial camera with built-in C2PA signing using a hardware-protected key. When the Content Credentials function is switched on, the camera signs both DNG and JPEG files with capture-time assertions including device and capture metadata.

Sony added C2PA support to the α-series (α1, α7S III, α7 IV, and then the α9 III) through firmware updates starting in March 2024, as part of its Camera Authenticity Solution; signing requires a license aimed at news organizations, and the list of supported bodies has grown since. Canon added C2PA signing to the EOS R1 and EOS R5 Mark II through a July 2025 firmware update, initially for registered news agencies, and launched its paid Authenticity Imaging System for newsrooms in May 2026. Fujifilm joined the CAI in 2024 and announced C2PA support for X and GFX bodies via firmware, without a firm timetable.

Nikon shipped C2PA in the Z6 III with firmware 2.00 in August 2025. Within days, researchers showed that the camera's multiple-exposure mode would sign composites built from images the camera never captured; Nikon suspended its Authenticity Service in early September 2025 and revoked every certificate it had issued. The incident became a teaching case in the practical importance of certificate revocation infrastructure. As of mid-2026 the service had not been restored.

CameraC2PA sinceStatus mid-2026
Leica M11-POctober 2023Opt-in, hardware-rooted
Sony α1 / α7S III / α7 IV / α9 III2024 firmwareAvailable with license, varies by body
Canon EOS R1 / EOS R5 Mark II2025 firmwareAvailable to news organizations
Nikon Z6 IIIAugust 2025 (suspended September 2025)Suspended; certificates revoked
Fujifilm X / GFX seriesAnnounced 2024Announced, via firmware

Smartphones

The Samsung Galaxy S25 (January 2025) was the first major flagship to attach C2PA credentials, but only to images edited with its Galaxy AI tools, not to ordinary camera captures. The Google Pixel 10 (August 2025) was the first phone with C2PA on by default for every photo taken with the stock Pixel Camera app, with signing keys held in the Titan M2 security chip; Google Photos adds credentials when an image is edited, including with AI tools such as Magic Editor.

Apple is not a C2PA member and, as of iOS 26, the iPhone neither produces nor displays Content Credentials. iOS 27 betas in mid-2026 revealed a separate Apple provenance feature, "Apple Reference Image," and it is not yet public whether it interoperates with C2PA.

The Truepic mobile SDK provides C2PA-compliant capture for any iOS or Android app that integrates it, used in insurance, real estate, and humanitarian documentation workflows where capture-side provenance is operationally required. Truepic's deployments are one of the largest mobile C2PA capture footprints outside the flagship-phone segment.

AI generators

The large commercial AI image generators have largely made C2PA signing standard. Adobe Firefly has emitted C2PA manifests since its first commercial release in 2023; OpenAI added C2PA manifests to DALL·E 3 images in early 2024 and includes them in Sora and its later image models; Google attaches C2PA Content Credentials alongside SynthID to images from its Nano Banana (Gemini image) models. Anthropic began attaching C2PA credentials to image files generated by Claude in August 2026. The manifests typically mark the asset with an IPTC trainedAlgorithmicMedia digital source type and identify the generating tool.

The major open-weights ecosystem — Stable Diffusion and its derivatives, Flux, the various community fine-tunes — does not produce C2PA manifests by default. Some integrations (ComfyUI plugins, certain forks) add C2PA emission, but the typical local-deployment user produces unmarked images. This is the gap that the EU AI Act's marking obligation, applicable from 2 August 2026 (with a grace period to 2 December 2026 for systems already on the market), will be tested against: large commercial providers will comply; individual users running open weights will not, and the enforcement question is unresolved.

Editors

Adobe's Creative Cloud applications (Photoshop, Lightroom, Premiere, Illustrator) are the dominant C2PA-aware editing surface. Content Credentials are toggleable per asset and, in newer releases, default-on for AI-assisted edits. Capture One added beta Content Credentials support in version 16.5, appending its edit history to JPEG and TIFF exports while preserving earlier credentials. Many other editors, Affinity Photo among them, still do not write Content Credentials and drop existing manifests on re-save.

Video editing support is less mature than still-image support; the video story is more complex due to the timeline-edit nature of the workflow, and the relevant spec work is ongoing in the C2PA 2.x line.

Wire services and publishers

Wire services have been early testers: Reuters ran an end-to-end C2PA pilot with Canon in 2023, and the Associated Press and AFP have taken part in C2PA work and camera-maker pilots since. Credentialed delivery is not yet universal across any wire feed.

The BBC, CBC, and the New York Times have led Project Origin's editorial-side work, surfacing Content Credentials inline on selected published pieces. The user-facing display patterns established in these pilots have influenced the broader Content Credentials UI conventions.

Platforms

Platform support for C2PA is the most uneven part of the ecosystem. The platform policies page covers the current state in detail. LinkedIn displays a Content Credentials icon on credentialed images. TikTok reads C2PA manifests to auto-label AI-generated uploads. Meta reads C2PA and IPTC signals to apply its "AI info" labels, but does not surface the manifest itself. YouTube uses C2PA for its "Captured with a camera" label on video. X strips manifests with no inline display.

The Adobe-operated Content Credentials Verify site (verify.contentauthenticity.org) remains the primary fallback for users wanting to validate an image they have downloaded, regardless of where it came from. Browser-native validation has not produced a shipping default-on feature in any major browser.

Note "C2PA support" is not a single feature. A camera that signs at capture but a phone that cannot validate, an editor that preserves but a platform that strips, a generator that emits but a viewer that cannot display — each is a partial implementation. End-to-end credentialed delivery to an end user remains the exception, not the rule.

Browsers and consumer surfaces

Browser support is the bottleneck for mass-market visibility. No major browser — Chrome, Edge, Firefox, or Safari — displays Content Credentials natively by default.

The browser-extension ecosystem provides a workaround. Adobe's Content Credentials extension for Chrome and extensions from other C2PA members provide on-page badges for C2PA-enabled images. Install counts are modest, meaning the vast majority of readers encounter C2PA-credentialed images with no visible signal that the credentials exist.

What this map implies

For producers, the implication is that emitting C2PA pays off in editorial and evidentiary contexts even when consumer-side visibility is limited. A wire service that ships credentialed images has them validatable by other newsrooms and by courts, even if a typical reader sees no badge. For consumers, the implication is that the absence of a credential is almost always a non-signal — the consumer's tooling probably could not display one anyway — and that verification workflows have to assume a non-credentialed default.

Where the field is moving

The next twelve to eighteen months will determine whether C2PA reaches mass-market visibility through the browser layer. If Chrome, Edge, or Safari ships default-on display, consumer awareness will jump and producer incentives will shift accordingly. If they do not, C2PA remains a specialist tool — important in evidentiary and editorial workflows, invisible in casual consumption. The signaling from the major browser vendors through 2025 has been ambiguous; the most likely outcome is partial display (badges on supported file formats, no warnings on unsupported ones) at some point in 2026 or 2027.

The other inflection point is the EU AI Act's marking obligation, which took effect on 2 August 2026 (systems already on the market have until 2 December 2026). Commercial AI providers operating in the EU will need to ensure machine-readable marking on synthetic outputs. C2PA is the de facto answer for image generators; the enforcement experience over the second half of 2026 will reveal how the regulation interacts with the messy reality of provider-side compliance and consumer-side detection.