If you’ve noticed a small badge appearing on some images and videos on LinkedIn recently, that’s Content Credentials, a feature LinkedIn is rolling out based on the C2PA standard. Clicking the badge shows viewers where a piece of content came from, whether AI was used to generate or edit it, and who created it.
That’s useful for spotting misinformation, but some sources say the same metadata that makes content traceable also raises real privacy questions, particularly around who gets identified and how that information can be used once it’s attached to a public post.

• Content Credentials, based on the C2PA standard, attach cryptographically signed metadata to images and videos, covering whether AI was used, the device or app used to create the content, and who created and issued the credential.
• That metadata is publicly readable by anyone who views the content, with no built-in encryption or access control, which privacy researchers have flagged as a genuine risk for photographers, journalists, and anyone who doesn’t want their identity or device details tied to a specific image.
• This sits alongside the EU AI Act’s Article 50 transparency rules, which require AI-generated and manipulated content to carry a detectable, machine-readable marking, making provenance standards like C2PA increasingly relevant for any organisation posting AI-assisted content.
Content Credentials are LinkedIn’s implementation of the C2PA standard, developed by the Coalition for Content Provenance and Authenticity, a group of technology and media companies working to verify the origin of digital content. When an image or video carries C2PA data, LinkedIn displays a small icon. Clicking that icon shows the content’s provenance information, including whether AI was used to generate or edit any part of it, the app or device used, who created it, who issued the credential, and when it was signed.
LinkedIn says it’s rolling this out gradually, so not every account or piece of content has access to it yet, and it can’t currently identify or label all AI-generated content on the platform.
A Content Credential can include several distinct pieces of information tied to a single image or video:
• Assertion about the media: whether AI generated or edited any part of the content, asserted by whoever created and signed the credential.
• App or device used: the origin of the content, including the specific camera model or AI tool involved.
• Created by: the individual who generated the content.
• Issued by: the entity that created and signed the credential, which could be an individual, an organisation, or a trust authority.
• Issued on: the date and time the credential was created and signed.
Depending on how a piece of content was captured and signed, this can include camera serial numbers and, in some implementations, GPS location data.
The privacy issue comes down to how that provenance information is stored and exposed. C2PA metadata is cryptographically signed but not encrypted, so anyone who receives the media file can read the embedded assertions with freely available tools, with no access-control layer limiting who can see what.
The World Privacy Forum’s 2025 technical review of C2PA found real gaps between the standard’s provenance goals and its handling of identity and privacy. Researchers have pointed specifically to the risk that embedded creator identity, device details, and location data could expose journalists working in authoritarian contexts, whistleblowers, activists, and domestic violence survivors, since a credential that identifies a photographer, a camera serial number, and a GPS location can compromise a source or reveal information that was never meant to be public.
For a business posting on LinkedIn, the practical version of this risk is smaller but still real: metadata attached to marketing images or videos, such as internal tool names, employee identity, or device information, becomes permanently attached and independently verifiable by anyone who views the post, whether or not that was the intention.
The EU AI Act’s Article 50 transparency rules require providers of generative AI systems to mark their outputs, text, images, audio, and video, in a way that’s machine-readable and detectable as artificially generated or manipulated. Those obligations became enforceable on 2 August 2026, and deepfakes must be disclosed as such. The Commission hasn’t endorsed one single technical method for compliance; instead, it expects a multi-layered approach combining metadata, watermarking, and provenance tools, which is exactly the kind of technical infrastructure C2PA and Content Credentials are built to provide.
That means platforms adopting C2PA-based labelling, like LinkedIn, are moving in the same direction the AI Act is pushing generative AI providers, even where the platform’s own rollout isn’t itself an AI Act obligation. For businesses using AI tools to generate or edit content, the two threads (a platform showing provenance data publicly, and a regulation requiring AI-generated content to be marked) are converging on the same practical question: what does this content reveal about how it was made, and is your organisation comfortable with that being visible to anyone who clicks on it?
Before posting an image or video that might carry a Content Credential, it’s worth checking what metadata is actually attached to it, particularly for content involving contributors who have a reason to stay unidentified, or content generated using internal AI tools whose names you’d rather not have permanently, publicly disclosed. If a platform lets you review or strip that metadata before publishing, use it. Where it doesn’t, treat any C2PA-enabled post as something that discloses more about its own origin than a typical image would.
Content Credentials make a real trade-off visible: more transparency about where content comes from, in exchange for metadata that’s public, permanent, and readable by anyone. That trade-off is reasonable for much everyday content, but it’s worth understanding before you post anything where the creator’s identity, device, or location shouldn’t be part of the public record. With the EU AI Act’s transparency rules now pushing platforms and AI providers toward exactly this kind of labelling, provenance metadata is quickly becoming a standard part of what gets attached to content.
C2PA stands for the Coalition for Content Provenance and Authenticity, a group of technology and media organisations that developed a technical standard for attaching verifiable information about a piece of content’s origin and edit history, including whether AI was used to create or modify it.
Yes, if the credential includes that information. Clicking the C2PA icon on a labelled image or video shows available metadata, which can include who created the content, what device or app was used, and who issued and signed the credential.
No. C2PA metadata is cryptographically signed to verify it hasn’t been tampered with, but it isn’t encrypted, so anyone who has access to the media file can read the embedded information.
No. The AI Act’s Article 50 requires AI-generated content to carry a detectable, machine-readable marking, but it doesn’t mandate a specific technical standard. C2PA and Content Credentials are among the leading approaches being used to meet that kind of requirement, alongside watermarking and other provenance tools.
Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It is not a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.