2026-06-19 · PNG · 1 sample

OpenAI (ChatGPT / DALL·E)

A C2PA claim (trainedAlgorithmicMedia) is present, but the signing certificate is expired, so validation returns Invalid: the provenance claim cannot be verified.

Answer

What did this experiment find?

A C2PA claim (trainedAlgorithmicMedia) is present, but the signing certificate is expired, so validation returns Invalid: the provenance claim cannot be verified.

This result applies to the 1 documented sample tested on with aicheck 0.2.0 (c2pa-rs 0.82, wasm). It should not be generalized to every file exported by OpenAI (ChatGPT / DALL·E).

Experiment Summary

PlatformOpenAI (ChatGPT / DALL·E)
Tested at2026-06-19
Research page updated2026-07-10
Sample count1
File formatPNG
Parser versionaicheck 0.2.0 (c2pa-rs 0.82, wasm)
Browser/systemBrowser-local WASM parser in Chromium/Playwright local preview; aicheck 0.2.0; c2pa-rs 0.82.
Source/licenseMIT via contentauth/example-assets

Provenance of this research record

Source, license, and authorship

Fixture source
Open the upstream fixture repository ↗
Declared license
MIT via contentauth/example-assets
Research operator
AICheck365, an organization; no individual author is claimed.
Environment
Browser-local WASM parser in Chromium/Playwright local preview; aicheck 0.2.0; c2pa-rs 0.82.

Expected Signals

  • C2PA manifest present
  • digitalSourceType=trainedAlgorithmicMedia
  • Expired signing credential is reported as invalid

Actual Signals

  • C2PA state: invalid
  • Manifest is present
  • Validation status includes an expired or untrusted credential problem

Misses

  • No trusted provenance state is produced because the signing credential is expired.

Limitations

  • The failure is about provenance verification, not a visual authenticity judgement.
  • Certificate status can change across parser/trust-store versions.

Reproducible Steps

Run the test locally with C2PA Validator. The file remains in the browser.

  1. Open the C2PA Validator.
  2. Upload /samples/expired-credentials.png.
  3. Confirm that manifest presence is found but signature validity is invalid.
  4. Review validation issues for the expired credential.

Sample Provenance

OpenAI image whose C2PA certificate has expired

Source
Content Authenticity Initiative example assets (contentauth/example-assets, MIT)
Format
PNG
Test date

Open the tested sample file →

  • A C2PA claim marked trainedAlgorithmicMedia is present, but the signing certificate is expired and untrusted.
  • Validation therefore fails: the provenance claim exists but cannot be verified (evidence state D).

Related Tools and Platform Guides

References

Sources

  1. Upstream fixture repository ↗ — MIT via contentauth/example-assets.
  2. OpenAI image whose C2PA certificate has expired — Content Authenticity Initiative example assets (contentauth/example-assets, MIT).
  3. AICheck365 experiment registry (JSON) — record ID openai-png-2026-06, tested 2026-06-19.