A depth map from the apple camera (again, signed) would show that the entire image had the same distance from the camera.
This is a pretty standard application of trusted computing and can be done entirely on the iPhone. A server would only possibly be needed for anonymization (while retaining key revocation capabilities if a key does end up leaking), but there are serverless ways to do even that (TPMs have supported these for a while now).
I think a big part of validation for things like these are just "could it have been modified since Z event happened", because Z was not something people paid attention to before.
It may not be in reach for you and I - but within reach of anyone with the budget to run a 'bot farm'
Proof of captured image with hardware-based-attestation can be increased by adding extra information besides the RGB channels, like depth mapping (which a projected screen wouldn't be able to fake), and eventually light field recording (plenoptic imaging, e.g. Lytro).
things like color rendering, sharpness, screen door/morie, motion blur, and yup even good ole depth queues in the lens system all show up as artifacts.
case in point, outside of a few specific niche cases like the mandalorian, that virtual production video wall thing is not actually being used all that much because of the amount of post shoot cleanup required to fix all those issues, it wasnt actually that much cheaper and its not really better either. especially when you factor in how hard it is to shoot that way.
Pre-AI fake videos sidestep this sort of issue by lowering the video quality.
Add some motion blur, some camera shake, some poor lighting, the camera being slightly out of focus, and make the video 720p instead of 4k.
I suspect it’s significantly less than millions.
It helps but doesn't solve credibility issue.
Then we might move to an age where photos which were not signed by someone will be treated as fake.
What we need is almost something like the classic "press C+A+D to log in" or the idea of "above the browser pane"... something an image cannot show you unless it's legit. Perhaps a personal thumbprint icon that is different for each viewer, so you know its your device telling you that something is real and not just some mock fake thing?
Will this also work with third-party camera apps like ProCam?
Congrats to Apple achieving nation-wide tracking, embedding some kind of yellow dots[1], but this time this time this is based on strong cryptography and non-removable, targeting people who don't use AI under the slogan "we are fighting AI fakes", but people still "love the feature".
It's still distinct from actual AI generation imo.
The problem is real, but this solution seems to not really solve it in any practical sense.
So, 90% of photojournalism outside of the major cities, then.
We really need Apple to open up true depth APIs to make forgery non trivial.
1) I see a photo online and doubt it's provenance
2) I contact the photographer and ask to see their cloud image (???!)
2a) I borrow someone's mac to download the image (.jpg?) and it can be verified on that?
We really need it for journalism. Otherwise we will not know what is real and what fabricated with ai.
On the other hand if this becomes mandated by law I can see it become treacherous for endusers.
Security is never a binary property, however, and can usually be better expressed in terms of how expensive it would be to subvert a given mechanism. "This image is either authentic or would have cost at least $x to fake" is already much more useful than nothing at all even without $x trending to infinity.
I wonder what the common thread is.
Regulation.
For China I would assume like other services, if there's some cloud involved, it should be on Chinese soil and accessible to China.
For EU harder to guess, but again the lock-in with "Private Cloud Computing" feels related.
It’s likely DMA — Apple would be required to provide APIs for signing for 3rd party apps too.
https://c2paviewer.com/articles/samsung-galaxy-s25-c2pa
https://security.googleblog.com/2025/09/pixel-android-truste...
On the other hand, ignoring standards altogether is the wrong way to go because the ecosystem after capture won't be there.