The Generation Side Is Stamping C2PA. The Distribution Side Has Not Written a Word About It.
- Runway, 2026-09-16: "Runway’s real time model outputs will carry C2PA provenance signals so the content can be traced back to its origin, just like any other Runway output." That is the generation sid
- TikTok’s Integrity and Authenticity chapter was diffed block by block on 2026-09-21 against the version effective 2026-09-24: verbatim identical, and the chapter does not mention C2PA anywhere. Joinin
- C2PA published a clarification on 2026-01-22 that its technical specification contains no standard TDM (text and data mining) assertion. A Content Credential is a provenance record. It is not a declar
- Autocomplete tells the rest of the story: 8 of the 10 suggestions under "content credentials remove" are removal plus a tool, online, free or Photoshop. No platform shipped an opt-out switch, so a mar
Two announcements, three weeks apart, about the same label. One of them was made by a company that makes video. The other was made by a company that decides who sees video. They do not refer to each other, and reading them in the same sitting is the fastest way to understand why "AI content will be labeled" has not turned into anything you can observe in your feed.
What the generation side committed to
On 2026-09-16, Runway published a post about how it moderates real-time generation. Real-time output breaks the usual order of operations — normally you screen the prompt, generate, then screen the finished file, but with streaming the viewer sees frames before any final check exists. The post describes moving to synchronous per-frame review that cuts the stream when something goes wrong, plus a full-context pass before download or share, on the stated reasoning that "an individual frame of a video may seem fine but actually be problematic in the context of the full video."
Buried in that engineering post is a provenance commitment, verbatim:
"Runway's real time model outputs will carry C2PA provenance signals so the content can be traced back to its origin, just like any other Runway output."<br>— Runway, "Moderation in Real Time", 2026-09-16
That is unambiguous and it is the direction the whole generation side has been moving. The file leaves the model with a cryptographically signed manifest saying where it came from. So far so good — right up until the file leaves the tool.
What the distribution side has written: nothing
On 2026-09-21 we diffed TikTok's Community Guidelines chapter by chapter, comparing the version live today against the version that takes effect on 2026-09-24. The "Integrity and Authenticity" chapter — the chapter that carries the rules on synthetic media, authenticity and platform manipulation — came back verbatim identical across all 23 of its text blocks. And in both versions, the chapter does not contain the string C2PA anywhere. Neither does the rest of the rulebook.
Here is where people make a leap that the record does not support. C2PA's own news feed records that TikTok joined the C2PA steering committee on 2026-07-28. That is real, and it is meaningful as a signal of intent. It is also, precisely, membership in a standards body.
Joining a standards committee is a statement about where a company wants the industry to go. It is not a statement that the standard is being checked, enforced, or even read on the way into the feed.
We cannot tell you what TikTok does with a C2PA manifest on upload, because TikTok has not written it down. Not in the current guidelines, not in the version effective September 24. Anyone describing platform-side Content Credentials detection as an operating rule is describing something that is not in the text. If you find a platform announcement that says otherwise, that announcement — not the committee seat — is the thing to cite.

The thing a Content Credential does not say
There is a second gap, and this one catches people who are trying to do the right thing. A large number of creators have concluded that attaching Content Credentials to their work functions as a signal that the work must not be scraped for model training. It does not, and C2PA has said so itself.
On 2026-01-22, C2PA published a clarification responding to European stakeholder consultations and questionnaires that had referenced so-called "C2PA TDM Assertions." The substance: the C2PA technical specification contains neither a standard assertion for TDM — text and data mining, which is the legal frame for training-data opt-outs — nor the related standard mechanisms.
So the honest summary is narrow:
- A Content Credential is a provenance record. It says where a file came from and what was done to it, signed by someone.
- It is not a licence, a copyright registration, or an opt-out. Stamping your work does not encode a rights reservation, because the spec has no field for one.
- It is not a detector, either. It tells you something about files that carry it. It says nothing at all about files that do not.
That last asymmetry is the crux. Provenance standards are built to verify presence, not to prove absence. An unlabeled file is not evidence of a human origin; it is evidence of nothing.
Why there is a whole market for taking the label off
Search behavior is a good instrument for finding places where a platform did not ship a switch people want. Pull the autocomplete family for "content credentials remove" and you get ten suggestions, of which eight are removal plus a tool, online, free, or Photoshop — remove content credentials online, remove the label, remove from image, remove from image online free, remove in Photoshop, remove on LinkedIn.
The Chinese-language equivalent is structurally the same query family aimed at a domestic platform's AI label. Two languages, two ecosystems, one shape: nobody was given an "I do not want this tag" control, so a market grew where the control should have been.
What are those tools actually doing? Almost all of them do one of two mechanically boring things: strip the metadata manifest, or re-encode the file so the manifest does not survive. Neither changes the pixels and neither makes an AI-generated file not AI-generated. What it does is destroy the chain of custody — after which the file is no longer "verified human," it is simply unverifiable, which is the same state as every unlabeled file on the internet. You give up the ability to prove where something came from and receive, in return, ambiguity.
And the class of these tools that genuinely deserves caution is the one that asks you to sign in. A metadata operation on your own file has no reason to need an account on a social platform. If a site offering to clean up an image wants a login, the login is the product. That is the same failure mode we walked through in the piece on removing content credentials; this article is the layer above it — why the demand exists at all.
The other honest reason people land on those searches: the label showed up and they do not know why. Applying a stock filter, exporting through an editor with an AI feature, or running an upscaler can all put a Content Credential on an image with no generative model involved, which is its own confusion (why a content credentials label got added, and on the Chinese platform side, four different things called "AI" of which only one can be switched off).

What to actually do with this
Three decisions follow from the gap, and none of them require betting on which way the standard goes:
- Keep your own provenance regardless of what platforms do. Project files, prompt records, source footage, export dates. The value of that archive does not depend on any platform reading a manifest, and it is what an appeal or a rights dispute actually runs on.
- Follow each platform's own disclosure rule, not the standard. The rule that binds you is the one in the rulebook of the platform you publish on — TikTok's AI-content disclosure requirements, for instance, live in its own text and are enforced by its own systems, entirely independently of whether it reads C2PA. We went through those in is AI content against TikTok's rules and monetizing AI-generated video on TikTok.
- Stop treating an absent label as a claim. Yours or anyone else's. The spec verifies what is there and is silent about what is not.
If you produce at volume across several accounts, the version of this that matters is mundane: know which engine produced which clip, keep that record on your side, and disclose per platform according to that platform's own text. NoobClaw's video pipeline is organized that way — each account's material generated against its own brief, with a human review step before anything publishes — which is a workflow property, not a compliance certificate.
FAQ
Does TikTok detect C2PA Content Credentials on upload?
TikTok has not written that down. We diffed the Community Guidelines chapter by chapter on 2026-09-21, including the version effective 2026-09-24, and the Integrity and Authenticity chapter does not mention C2PA — nor does any other chapter. TikTok did join the C2PA steering committee in July 2026, which is a statement of direction rather than a description of an enforcement mechanism. Until a platform documents what it does with a manifest, nobody can tell you what it does.
If I attach Content Credentials, does that stop my work being used for AI training?
No. C2PA published a clarification on 2026-01-22 stating that its technical specification contains neither a standard TDM — text and data mining — assertion nor the related standard mechanisms. A Content Credential records provenance; it does not encode a rights reservation, and it is not a licence. If a training opt-out matters to you, it has to come from somewhere else, such as a platform's own setting or a robots-style directive where one applies.
Does removing a Content Credential make my file look human-made?
It makes the file unverifiable, which is not the same thing. Stripping or re-encoding away a manifest does not alter the pixels or the audio, and it does not change what produced them — it deletes the chain of custody that would let anyone confirm the origin either way. You end up in the same undifferentiated pile as every file that never had a manifest, having given up the one thing that could have worked in your favor later.
The gap between the two announcements is the whole story: one side is signing its output, the other side has not said whether it reads the signature. Until that changes, the only provenance you can rely on is the one you keep yourself.
