Intacta
Legal Center

Content Credentials

How Intacta marks AI-generated images · Last updated 31 July 2026

Everything Intacta produces is generated by AI. Every image we generate today carries machine-readable signals that say so — and if those signals cannot be validated, we fail the shoot rather than deliver the image. Images generated before our provenance-preserving release do not carry them; that exception is set out in section 6. This page explains what the signals are, and how anyone — a customer, a journalist, a regulator, or a member of the public — can check them independently, without asking us.

1. What Intacta marks

Intacta generates images using OpenAI’s GPT Image 2 model. Every image we deliver from that pipeline carries two independent machine-readable markings, applied by the model at generation:

  • C2PA Content Credentials — cryptographically signed provenance metadata embedded in the file, following the open C2PA standard. The manifest records that the image was created by a generative model, using the IPTC digital source type trainedAlgorithmicMedia.
  • An invisible watermark — embedded in the image pixels themselves rather than in metadata, so it is designed to survive common transformations such as cropping, filters and lossy compression. The manifest records that a watermark is present, and OpenAI documents that the watermark used is SynthID.

Intacta validates the C2PA manifest on every image at the moment it is generated, before the file is stored. We check the cryptographic signature, the certificate chain against the official C2PA conformance trust lists, the revocation status and the timestamp, and we require the manifest to actually assert AI generation.

An image that fails any of those checks is not delivered. In production we refuse the image and refund it to the customer’s allowance rather than hand over a file we cannot show to be marked. We do not label anything as carrying credentials unless a validator actually confirmed it on those exact bytes.

2. How to verify an image

You do not need Intacta’s cooperation, an account, or any special software to check an image we produced. Both tools below are free, public and operated independently of us:

  • OpenAI Verify — checks both the C2PA credentials and the SynthID watermark. This is the more complete check, because it can still detect the watermark when metadata has been removed. It is currently offered as a research preview.
  • Content Credentials Verify — checks the C2PA manifest and shows its full contents, including who signed it and when.

Upload the image file and the tool reports what it finds. Because C2PA is an open standard, any conformant reader works — you are not limited to these two.

Use the original file. Verification is most reliable on the file exactly as Intacta delivered it. Screenshots, re-exports and some social platforms strip metadata; in those cases the C2PA manifest may be gone even though the image really was AI-generated.

3. What the signals mean — and what they do not

A detected signal tells you how the file was made: that it was generated by an AI model rather than captured by a camera. That is all it establishes.

It does not tell you that an image is accurate, that it fairly represents a product, that it is used with permission, or that it is presented in an honest context. Equally, the absence of a signal does not prove an image is not AI-generated — metadata can be stripped and watermarks can be degraded.

4. Why we deliver originals only

Re-encoding an image — resizing it, converting it to another format, or re-saving it — destroys the C2PA manifest. There is no way to resize a file and keep a signature that was computed over the original pixels.

So Intacta delivers the byte-exact file the model produced, and nothing else. We do not offer resized or converted copies, we do not re-encode files on the way out, and we do not shrink an image because an account’s plan changed after it was generated.

Every download is therefore the stored file exactly as we received it from the model. For images generated after our provenance-preserving release that file is the marked original. For older images it is the file as it was stored at the time, which was re-encoded and carries no credentials — see section 6.

5. If you publish images made with Intacta

Under the EU AI Act, the marking obligation for AI-generated content sits with Intacta as the provider of the system. Separate obligations may sit with you as the organisation deciding to publish the content.

In particular, if published content qualifies as a “deep fake” under the AI Act, the organisation publishing it must add a disclosure that a person can actually see — a visible label. Machine-readable credentials do not satisfy that requirement, because a viewer cannot perceive them.

European Commission guidance indicates that a real product shown against an AI-generated background or environment is generally not a deep fake, provided the advertisement does not mislead about the product’s actual appearance, characteristics or use. Conversely, an AI-generated product image that makes the product look different from, or better than, the real thing may well be. Intacta is built to preserve the real package, label, colours and proportions for exactly this reason, but the assessment depends on the image and the context, and it is yours to make.

This page is an explanation, not legal advice. Your obligations depend on where you publish, what you publish and who sees it.

6. Limits and known gaps

We would rather state these plainly than overclaim:

  • The marking is applied by OpenAI at generation. Intacta validates it and preserves it byte-for-byte, but does not add a third, independent signal of its own.
  • Verification of the watermark currently depends on OpenAI’s tool, which is offered as a research preview. Intacta cannot detect the watermark itself — we rely on the manifest’s assertion that one is present and on OpenAI’s documentation of it. The C2PA layer, by contrast, can be verified with any conformant reader, independently of both OpenAI and Intacta.
  • Images generated before our provenance-preserving production release were stored in a re-encoded form and carry no credentials. They are not re-marked retroactively, Intacta never presents them as carrying credentials, and the app reports their status as unverified. If you need to know whether a specific older image is affected, ask us.
  • Once a file leaves Intacta, we cannot control what happens to it. Editing software and publishing platforms may remove metadata.

7. Researchers, media and authorities

If you are a market surveillance or other competent authority, a regulator, a fact-checker, a journalist, an independent researcher or a civil-society organisation and you need to verify content, understand our implementation, or ask about a specific image, contact legal@intacta.io. We will respond substantively and without charge.

8. Contact

Questions about Content Credentials, or reports of an Intacta image that unexpectedly lacks them, should go to legal@intacta.io. Related terms are set out in section 10 of our Terms of Service, and our handling of provenance data is described in our Privacy Policy.