2026-06-19 · JPEG · 1 sample

Adobe Firefly

Valid C2PA Content Credentials with digitalSourceType=trainedAlgorithmicMedia; the signature is cryptographically valid while the signing certificate is untrusted in the browser trust list.

Answer

What did this experiment find?

Valid C2PA Content Credentials with digitalSourceType=trainedAlgorithmicMedia; the signature is cryptographically valid while the signing certificate is untrusted in the browser trust list.

This result applies to the 1 documented sample tested on with aicheck 0.2.0 (c2pa-rs 0.82, wasm). It should not be generalized to every file exported by Adobe Firefly.

Experiment Summary

PlatformAdobe Firefly
Tested at2026-06-19
Research page updated2026-07-10
Sample count1
File formatJPEG
Parser versionaicheck 0.2.0 (c2pa-rs 0.82, wasm)
Browser/systemBrowser-local WASM parser in Chromium/Playwright local preview; aicheck 0.2.0; c2pa-rs 0.82.
Source/licenseMIT via contentauth/example-assets

Provenance of this research record

Source, license, and authorship

Fixture source
Open the upstream fixture repository ↗
Declared license
MIT via contentauth/example-assets
Research operator
AICheck365, an organization; no individual author is claimed.
Environment
Browser-local WASM parser in Chromium/Playwright local preview; aicheck 0.2.0; c2pa-rs 0.82.

Expected Signals

  • C2PA manifest present
  • digitalSourceType=trainedAlgorithmicMedia
  • Cryptographic signature validates

Actual Signals

  • C2PA state: valid
  • Manifest reports trainedAlgorithmicMedia
  • Signing certificate is not trusted by this browser-local trust list

Misses

  • The browser trust list does not upgrade this sample to trusted.

Limitations

  • Valid means the signature is cryptographically valid, not that the signer is a configured trust root.
  • The sample is a public fixture, not a fresh production export from every Adobe Firefly workflow.

Reproducible Steps

Run the test locally with C2PA Validator. The file remains in the browser.

  1. Open the C2PA Validator.
  2. Upload /samples/verified-ai-credentials.jpg.
  3. Confirm the status summary and raw manifest JSON.
  4. Compare validation_status with the expected signal list.

Sample Provenance

Adobe Firefly image with valid Content Credentials

Source
Content Authenticity Initiative example assets (contentauth/example-assets, MIT)
Format
JPEG
Test date

Open the tested sample file →

  • digitalSourceType = trainedAlgorithmicMedia and the signature is cryptographically valid.
  • The signing certificate is not in this engine's trust list (untrusted), so the result is reported as 'valid' rather than 'trusted'.

Related Tools and Platform Guides

References

Sources

  1. Upstream fixture repository ↗ — MIT via contentauth/example-assets.
  2. Adobe Firefly image with valid Content Credentials — Content Authenticity Initiative example assets (contentauth/example-assets, MIT).
  3. AICheck365 experiment registry (JSON) — record ID firefly-jpeg-2026-06, tested 2026-06-19.