
Apple is developing a feature called Apple Reference Image in iOS 27 that lets iPhone users embed and verify photo provenance metadata—proving when a photo was taken and that it isn't a deepfake.
Users who enable the feature can tap a Reference badge on a photo to send it to Apple's servers for authentication using sensor signatures, capture time, and hardware identifiers.
The system is designed to compete with the C2PA Content Credentials standard that other camera makers already support, and reflects Apple's belief that labeling authentic human-made content is a more practical approach than identifying AI-generated images.
What happened
Apple is developing an iOS feature called Apple Reference Image that embeds provenance metadata into iPhone photographs at the point of capture, allowing users to verify when and where a photo was taken and prove it wasn't AI-generated. The feature appears in iOS 27 beta 5 code and will be off by default; when enabled, users can tap a Reference badge to send the raw image and embedded provenance data—including sensor signatures, capture time, and hardware identifiers—to Apple's Private Cloud Compute servers for verification.
Why it matters
The feature addresses growing concern about deepfakes and AI-manipulated images by giving iPhone users a way to authenticate their own photos. Unlike the C2PA Content Credentials standard that Canon, Nikon, Sony, FujiFilm, Leica, and Google's Pixel 10 already support, Apple's proprietary system may offer what Apple believes is a more robust solution. Instagram head Adam Mosseri has suggested that labeling human-made works may be easier to achieve than identifying AI-generated content, and Apple's move signals support for that approach.
What to watch
The feature is not yet live and requires users to manually enable it via Settings > Camera > Reference Image > Reference Mode. Only photographs taken using a new "Reference" option in the iPhone Camera app will include the provenance information needed for authentication. Authenticated photos can be viewed across iPhone, iPad, and Mac.
Apple is working on a feature called Apple Reference Image that aims to solve the problem of deepfakes and AI-manipulated images by letting iPhone users cryptographically prove their photos are authentic. According to code discovered in iOS 27 beta 5, the feature embeds provenance metadata directly into photographs at the moment they are captured using the iPhone camera, creating a digital record of when and how the photo was taken.
When enabled—via Settings > Camera > Reference Image > Reference Mode—the feature only works with photos taken using a new "Reference" option in the iPhone Camera app. These special Reference images carry embedded provenance information including sensor signatures, the precise capture time frame, and unique hardware identifiers that act as a fingerprint for the device that took the photo. To verify a photo, users tap a Reference badge on the image, which triggers Apple's authentication process. That process sends the raw image and its embedded provenance data to Apple's Private Cloud Compute servers, where the data is checked against Apple's records. The servers then return an authenticated version of the photo with a uniquely assigned ID, which can be displayed on iPhone, iPad, or Mac.
Apple's authentication system does not require the company to access the raw photo itself during verification—a privacy-focused design choice. However, the company may receive sensor data in a way that allows it to prevent images from compromised sensors from being authenticated, or to retroactively revoke authentication on images associated with a sensor that has been flagged.
The feature is not yet live and will be off by default when it eventually rolls out. Apple's approach differs notably from the C2PA Content Credentials standard, which major camera manufacturers—Canon, Nikon, Sony, FujiFilm, and Leica—have been gradually integrating into their hardware. Google's Pixel 10 phone cameras also support C2PA. Despite the industry convergence around C2PA, Apple has opted to build its own proprietary system, apparently believing it will be more robust. C2PA itself has not earned a strong reputation for reliability, which may have influenced Apple's decision to develop an alternative. According to reporting, Apple's focus on labeling and authenticating human-made content aligns with thinking from Instagram head Adam Mosseri, who has suggested that proving authenticity of human work may be more practical than identifying and labeling AI-generated content.
Apple's move to develop its own photo provenance system reflects a strategic choice to diverge from the C2PA Content Credentials standard, which has been gradually adopted by major camera manufacturers and Google. While the industry has coalesced around C2PA as a common way to trace image provenance and detect AI manipulation, Apple's internal assessment—that its proprietary system will be more robust—suggests confidence in its engineering approach. The feature's default-off status and manual authentication requirement indicate Apple is prioritizing user choice and privacy, particularly in how sensor data is handled during the verification process.
Apple's emphasis on authenticating human-made content aligns with a broader industry shift in thinking about AI and authenticity online. Rather than focusing solely on labeling AI-generated content (which is technically harder to implement at scale), Adam Mosseri's observation that labeling authentic works may be more practical suggests a pivot toward verifiable provenance for human creators. By embedding metadata at the point of capture and requiring explicit user action to authenticate, Apple creates a system where photographers maintain control over when and how their images are verified—fitting the company's public privacy positioning while offering a tool for those who want proof of authenticity.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Security researchers led by Alexander Panfilov discovered a vulnerability in the APIs of all major AI provider…

Researchers at A Security discovered a major vulnerability in Zoom's annotation feature that allowed attackers…

Meta CEO Mark Zuckerberg published a 6,500-word essay Monday outlining his vision for artificial intelligence…

ServiceNow has announced AI-powered agents designed to operate within security operations centers (SOCs), auto…

CrowdStrike and Palo Alto Networks jumped more than 5% to new highs on Monday following the Black Hat cyber co…

Rep. Greg Casar (D-Texas) and 18 other House Democrats sent a letter to Speaker Mike Johnson calling for open…

The AI news that matters, in one minute each morning.
Sign up free