Why the AI label on your video rarely reaches the viewer
The signed metadata that marks a video as AI-generated survives to the audience roughly a third of the time, and the EU now puts the disclosure duty on whoever publishes.

Key takeaways
- An audit of 516 posts of AI-generated images and videos found only 169, just over 30%, received a correct AI label on Instagram, LinkedIn, Pinterest, TikTok or YouTube.
- The C2PA standard signs a file at creation with a tamper-evident record of origin, tools and edits, but Cloudflare Polish, Cloudinary and the sharp library strip that metadata by default lower down the pipeline.
- Since 2 August 2026, the EU AI Act's deployer duty makes whoever publishes realistic AI imagery responsible for disclosure, with maximum penalties of 15 million euros or 3% of worldwide annual turnover.
- The C2PA's answer is durable credentials, invisible watermarks or fingerprints that let a stripped file be matched back to its manifest, but adoption is early.
A video arrives on your feed stamped as AI-generated by the tool that made it. More often than not, the stamp is gone before you see it.
The mechanism is C2PA, the Coalition for Content Provenance and Authenticity, and its Content Credentials. A generator signs a record into the file at creation: who made it, which model, what was edited, with a cryptographic signature that makes later tampering detectable. The record travels inside the file. Then the file travels through an internet that strips it.
The plan, on paper
The design is a relay. OpenAI, Adobe, Google and others embed C2PA manifests or the lighter IPTC metadata tag when they generate a file. Platforms read the signal at upload and label the post: Meta announced in February 2024 that Facebook, Instagram and Threads read the "AI generated" information in the C2PA and IPTC standards; TikTok became the first video platform to implement Content Credentials in May 2024; LinkedIn added a "CR" icon the same month; YouTube added a "Captured with a camera" disclosure in October 2024 for video with intact C2PA provenance. A label appears, and the advertiser or the publisher inherits its disclosure from the pipeline.
Then someone measured it
In October 2025 the verification publication Indicator uploaded 516 posts carrying C2PA or IPTC provenance signals to Instagram, LinkedIn, Pinterest, TikTok and YouTube. Only 169 of them, just over 30%, received a correct AI label. Pinterest performed best, at 55%.
The March 2026 follow-up that the International Press Telecommunications Council reported found a revealing asymmetry. Content from OpenAI, which carries full C2PA signatures, was correctly labelled by LinkedIn, Pinterest and YouTube. Content from Meta's own AI, marked only with the lighter IPTC tag in XMP metadata, went unrecognised by LinkedIn, TikTok and YouTube. Pinterest missed Google Gemini content entirely. The IPTC's conclusion was blunt: "Tech platforms have the talent to implement C2PA tomorrow; they simply need the will to prioritize it."
Where the label actually dies
Read the quoted sentence carefully: the platforms have the talent to read the signal. That is not the same as the signal arriving.
Every hop between generation and upload tends to remove it. Cloudflare's Polish strips metadata as part of image optimization. Cloudinary discards embedded EXIF, IPTC and XMP on transformed images by default. The sharp library, which sits inside countless upload and build pipelines, outputs metadata-free images unless a developer explicitly asks otherwise. Those defaults predate C2PA and treat provenance as dead weight to shave off.
The platforms finish the job on the delivered copy. The IPTC's own investigation of Facebook found all XMP metadata removed and Facebook's tracking fields injected in its place. Hands-on tests in 2025 and 2026 reported Instagram, Facebook, X and Threads stripping embedded metadata from the files they serve, and Mastodon strips manifests too. The label, where it exists, often lives in the platform's database rather than in the image. A screenshot, the internet's favourite way to redistribute a picture, carries nothing at all.
A forensic teardown of a Sora 2 video makes the failure concrete. OpenAI's implementation was exemplary by any internal measure: ECDSA P-256 signing, the Truepic Lens toolchain, an IPTC tag marking the file as trained algorithmic media, and a signed generation timestamp. Five common video pipelines, including a plain ffmpeg remux that does not even re-encode the streams, each destroyed the manifest.
What the standard is doing about it
None of this surprises the C2PA. Its own specification explainer describes "durable" Content Credentials: soft bindings, in the form of invisible watermarks or content fingerprints, that let a stripped file be matched back to its manifest in a recovery database. A conformance program now certifies implementations at defined assurance levels, and the current specification, version 2.4 from April 2026, added explicit assertions for AI-generated media. The direction is right; the adoption at both ends of the pipe is what the testing above measures, and it is early.
Why it is now your problem
On 2 August 2026, the EU AI Act's transparency obligations took effect. Article 50 puts the disclosure duty on the deployer, which means the person or company publishing a realistic AI image or video, not only the lab that made the model. Maximum penalties reach 15 million euros or 3% of worldwide annual turnover. A signed metadata field that survives roughly a third of the time is not a safe place to keep a legal obligation, and the Act's code of practice expects two machine-readable marking layers, one of them signed.
What to do this week
- Treat embedded provenance as fragile. Assume your CDN, your image optimizer and every social platform will strip it from the delivered file.
- Where disclosure is required, put it in the visible creative or in the caption. Metadata alone will not reliably reach the audience.
- Verify the final exported asset, not the file your model produced. Read the Content Credentials on the file you are actually about to upload, because a scan of the export is the only checkpoint you control.
- Keep your own record of prompts, seeds and model versions outside the file. That is the provenance you can always produce.
- If your platform mix includes LinkedIn, Pinterest or YouTube, know that full C2PA signatures are read far more reliably today than the lighter IPTC tag.
- Watch the durable credentials work. Watermark plus fingerprint recovery is the standard's answer to stripping, and it is the layer worth tracking.
Read the credentials on your next export before you publish it; if the field is empty, the label was already lost.
Sources
- chekr.io - the 516-post audit figure and the pipeline evidence
- indicator.media - the original October 2025 platform test
- iptc.org - the IPTC's March 2026 follow-up findings
- filexray.orygn.tech - forensic teardown of a Sora 2 file and the pipeline tests that destroyed its manifest
- ppc.land - C2PA version history and the EU AI Act Article 50 dates
- spec.c2pa.org - the C2PA specification explainer