Apple finally joins the provenance push. What it signals, what changes, and how to prepare for a messy transition.
Apple’s move
Yesterday, September 9, was Apple's 'Surprise and Shine' event. After years of watching competitors run ahead with a technology, Apple finally showed up, convinced it could arrive late and do it better than everyone else.
I'm not talking about the iPhone Duo, their new foldable.
I'm talking about Apple's new proprietary answer to proving whether a photo is real: Reference Image.
From Apple’s release:
Users can now prove the authenticity of a photo taken on iPhone 18 Pro models with Apple Reference Image, powered by the new sensor in the Main camera that can sign every pixel it sees. When a photo is taken in the new Reference mode, the camera captures signed sensor data that Private Cloud Compute develops into an unalterable reference image.

Keep in mind, this implementation is very narrow.
- It is only available on the iPhone 18 Pro and Pro Max.
- It is opt-in. A user has to turn it on, and most won't.
- Capture is not available at launch in China or the EU. EU users can view and develop reference images, they just can't make them.
Worse, while nearly every other major player built around C2PA, Apple did the very Apple thing. Silence on the open standard. A proprietary solution inside its walled garden, verified on Apple's servers, viewable through Apple's APIs. The two answer different questions. C2PA says "here is the history of this file." Reference Image says "here is what the sensor saw, compare for yourself." They could eventually complement each other, but nothing Apple said on stage suggests that is the plan.
If C2PA is new to you: it's the open standard for content credentials, a nutrition label attached to a file that records where it came from and what was done to it. I wrote about it in a previous newsletter, and the IPTC has a good FAQ.
But let's not undersell this. The company that made cameras in our pockets ubiquitous is now actively working on proving what that camera saw. Apple also mentioned SynthID support before the end of the year. And there is enough legal pressure from the EU AI Act and California's AI Transparency Act (CAITA) that Apple will likely make its system interoperable with C2PA, the leading open standard. We've seen that already with USB-C ports. California's rules for platforms and capture devices both require provenance data that complies with "widely adopted specifications adopted by an established standards-setting body." That standard exists, and Apple isn't using it... yet.
Anthropic’s move
Apple's move is about proving something is real at capture. Last month Anthropic moved on the other end, marking what is synthetic at generation. To comply with the EU AI Act, Anthropic began watermarking Claude's text output. (Files are a different story. Images and other files generated by Claude now carry C2PA signed metadata, the same open standard Apple skipped.) The text watermark launched globally, proving once again that effective tech legislation in one jurisdiction can change the trajectory of global tech.
The reception was rough. Critics argued it would create false positives and degrade the writing itself. Given how quickly Claude watermark removers showed up on GitHub, I suspect some users didn't want anyone to know their emails or homework were written by a Claude agent. But for writers who use AI as part of their workflow, there is a strong case that this is a step in the right direction.
My own approach: I write the first draft alone, then use Claude to find gaps and structural problems and to help with a polishing pass. Claude's watermark might flag that text without saying how much human thinking went into the prose and the argument before Claude touched it. I'm still looking for better ways to make that balance visible.
Provenance tech alone will never be enough to build trust. You also need a clear editorial policy, a way of explaining how you use AI, and a workflow that can survive an audit or an external challenge if someone claims your editorial work was made by a machine and not a human.
The EU has already written this into law. Under the AI Act, AI-assisted text published on matters of public interest must either carry a label or sit under documented human editorial control, with a named person or organization holding editorial responsibility. That second option is the one most newsrooms will want, but it only works if you can show your process.
Synthetic content now exists on a spectrum, and for trusted brands and individuals it is becoming essential to:
- Explain what was direct human craft.
- Record what was an AI tool guided by a human.
- Track what was an agent acting on its own to carry out a human's directive.

What changes
There has never been a better time to start laying this groundwork in your own practice or organization. The legislative roadmaps for the EU AI Act, California's CAITA and other regulations show how the Internet we've grown used to is about to shift over the next two years as we adapt to generated content and agentic AI.
The big dates for visual journalists and content producers:
December 2, 2026: The EU's grace period ends for generative AI systems that were already on the market in August. (California's equivalent rules took effect August 2 with no grace period.) Expect every frontier AI company to have a marking scheme in place by year end. Most already use a mix of C2PA and SynthID.
January 1, 2027: CAITA requires large online platforms to preserve provenance data and display it in their own interface. Expect the biggest social platforms to start showing you where content came from. LinkedIn and TikTok already do if the metadata exists.
January 1, 2028: CAITA's capture-device requirements kick in. The list of cameras and phones that sign content at capture is still limited. With Apple in, every major phone and camera maker is now working toward it.
In short, expect platforms to show provenance data in 2027 and your cameras to produce it by 2028. That is both the start and the end of a full provenance chain, what the industry calls "glass to glass."
The messy transition
The middle is where it gets messy. Keeping that chain intact through your own tools and workflows is a different problem for every organization.
There are real incentives to start now and get it right. We are moving from an Internet where most content was stripped of its metadata to one where metadata permanence is the standard. That is a fundamental shift in our relationship with content, and in what is possible for media practitioners and audiences.
Given the trajectory we are on, in a couple of years nearly every new camera will capture provenance data, most platforms will display it, and more and more content will be fetched, served or synthesized by AI agents on behalf of humans. It is not a leap to think the most valuable media will be content that can cryptographically prove its authenticity to both machines and humans. Proof that the work is signal amongst the noise.
If you're trying to sort out what that middle section looks like inside your own organization, reply and tell me about it. This is the part I enjoy figuring out with people.