Camera makers now embed cryptographic signatures proving a photo is real

Camera makers now embed cryptographic signatures proving a photo is real

Getty Images walked away from a $3.7 billion merger with Shutterstock in July 2026 rather than accept a regulator’s order to sell off its editorial photography business. The collapse, arriving the same week the European Union’s AI content-labelling law took effect, shows that verified, camera-captured images have become a distinct and defended market — one that generative AI has made harder to replace, not easier.

Getty Images ended a $3.7 billion merger with Shutterstock rather than sell off its editorial photography business. On June 30, 2026, the company’s board voted not to accept a UK regulator’s order to divest three wire services — Rex Features, Backgrid, and Splash News — that supply verified, camera-captured images of real events to British newsrooms. Getty confirmed the deal was dead on July 7. The Competition and Markets Authority’s objection was not about stock photography in general. Its final report found the merger posed no threat to the broader creative content market, where AI-generated imagery now competes freely alongside traditional stock. The concern was narrower: editorial photography, the kind that has to show something that actually happened, would end up under the control of one company in one part of the world. That distinction, between images a machine can approximate and images a regulator will not let a single company monopolize, is the clearest evidence yet that authentic photography has become a market of its own. Camera manufacturers are now wiring cryptographic proof of capture into their hardware. Consumer surveys show rising demand to know when an image was made by software rather than a person. A European transparency law took effect this week. Each development points to the same place: the easier AI makes it to fake a photograph, the more a photograph people can verify turns out to be worth.

The regulator drew a line inside one merger

Getty Images and Shutterstock announced their merger of equals in January 2025, a deal meant to combine the two largest stock photography libraries into a single company under the Getty Images name. Shutterstock’s shareholders approved the transaction in June 2025, and the US Department of Justice cleared it without conditions in February 2026. The UK’s Competition and Markets Authority took a different view. In October 2025, its Phase 1 review found the merger could substantially lessen competition in supplying editorial content, and the case moved to a Phase 2 investigation the following month.

The distinction the CMA drew mattered more than its headline outcome. Its interim report in April 2026 and final report in May 2026 both cleared the deal for the broader “creative” stock market — the pool of generic lifestyle, business, and concept images increasingly filled by AI-generated alternatives — while finding a separate problem in editorial supply: real photographs of real news events, licensed to British newspapers and broadcasters, where Getty and Shutterstock’s Rex Features, Backgrid, and Splash News brands were each other’s closest substitute. The CMA’s proposed fix was a straightforward divestiture. Getty and Shutterstock could keep their combined creative library intact if they sold off the editorial titles the authority considered too concentrated.

Shutterstock’s own disclosures put the scale of that editorial business at $32.7 million in global revenue for 2025, with $10.6 million of it earned in the UK specifically — a modest sum next to a $3.7 billion transaction, and smaller still next to either company’s overall revenue. Getty’s board rejected the trade anyway, choosing to lose the entire merger rather than give up a photography segment worth a small fraction of the deal’s value. That choice is itself a measure of how much strategic weight verified, real-world photography now carries, independent of what it earns on its own.

The CMA’s process took nearly two years from the merger’s announcement to its collapse, moving through a Phase 1 inquiry in August 2025, a Phase 2 referral in November, an interim remedies report in April 2026, and a final report the following month. Getty and Shutterstock spent that period offering successive rounds of undertakings, none of which satisfied the authority’s concern about editorial supply specifically. A deal that both companies’ shareholders had already approved, and that US antitrust regulators had cleared outright, still failed on a single, narrow point that had nothing to do with the technology reshaping the rest of the industry.

Photography split into two markets years before regulators noticed

The CMA’s finding formalized something the photography business had already been living through. Generative models can now produce a competent lifestyle photo, product shot, or stock illustration in seconds, and stock libraries have adapted by selling AI-generated content alongside traditional photography rather than trying to compete with it directly. Adobe’s Firefly image generator produced billions of images within months of its 2023 launch, a volume that dwarfs the accumulated archives of most traditional photo libraries combined. Getty and Shutterstock each built or licensed their own generative tools, and Shutterstock’s data-licensing agreement with OpenAI was reported to be worth as much as $250 million by 2027 — a sum that treats the company’s archive as raw material for training AI rather than as a product competing against it.

None of that touched editorial photography the same way. A picture of a specific protest, a specific court hearing, or a specific disaster has to show that the event happened and that a photographer was there; a generated approximation of “a protest” or “a disaster” cannot substitute for it in a news context, however convincing it looks on a screen. That functional gap is why the creative and editorial segments of the same two companies have diverged so sharply in how regulators, and increasingly buyers, treat them.

One segment is being commoditized by the technology that makes images cheap to produce at any volume. The other is being treated as infrastructure for verifying that something real occurred, and infrastructure of that kind draws a different category of scrutiny — from courts weighing copyright claims, from newsroom standards desks writing new sourcing rules, and now from a competition authority weighing what happens when two of the last major suppliers of it try to merge.

The split shows up in how the companies report their own business, not only in how regulators categorize it. Getty has acknowledged that the creative side of its business, the part most exposed to generative competition, declined by nearly 5% year-on-year in 2024, offset by gains in editorial licensing and new AI data-licensing deals. A market that behaved as a single, undifferentiated pool of stock photography a decade ago now behaves as two markets wearing one brand, and the merger review simply made that split legally explicit for the first time.

An industry coalition built a standard for proving capture

Adobe co-founded the Content Authenticity Initiative in 2019, alongside Twitter and the New York Times, to build a shared technical answer to a specific question: how does a piece of digital media prove where it came from? The result, formalized through the Coalition for Content Provenance and Authenticity, is a specification called Content Credentials — described by its backers as a nutrition label for digital media, attaching a cryptographically signed record of who or what produced a file, when, and what happened to it afterward.

The coalition’s membership spans camera manufacturers, software companies, and news organizations that would otherwise have little reason to cooperate on a shared standard: Adobe, Amazon, Google, Meta, Microsoft, OpenAI, and Sony sit alongside the BBC, Agence France-Presse, the Associated Press, Reuters, and the Wall Street Journal. That mix reflects the two jobs the standard has to do. Producers — cameras, phones, and generative AI tools alike — sign what they output. Publishers read those signatures and decide what to surface, whether that means a “captured with a camera” label on YouTube or an “AI-generated” tag on a TikTok video.

The specification itself has kept moving. Its current version, 2.4, was released in April 2026, four years after the first public draft circulated in 2021. What the standard cannot do is settle the underlying argument by itself. A signature only proves what its signer attests to, and the credibility of the whole system depends on which signers a verifier chooses to trust — a detail that becomes far more consequential once cameras, and not only software, start signing images at the point of capture, before any editing has occurred.

Camera makers are wiring that standard into hardware

Camera manufacturers began treating that signature as a selling point once it became clear which segment of photography the market intended to reward. Leica went first. The M11-P, announced in October 2023 at a US list price of $9,195, was the first commercially available camera to sign images with Content Credentials at the point of capture, using a dedicated security chip built into the body. Sony, Nikon, and Google followed with their own approaches, though “followed” understates how differently each company implemented the same underlying idea, as the comparison below shows.

Hardware Content Credentials signing, selected devices

DeviceFirst shippedHow it signsWhat happened next
Leica M11-POctober 2023Dedicated security chip signs every JPEG and DNG by defaultExtended to the M11, Q3, and SL3 via firmware
Sony Camera VerifyJune 2025Opt-in, aimed at accredited news organizations via Sony’s Creators’ CloudLimited at launch to still images and selected agencies
Nikon Z6 IIIAugust 2025Firmware update added signing at captureSuspended within two weeks after a signing flaw was found
Google Pixel 10September 2025Signs every photo by default using hardware-backed keysFirst mainstream smartphone to sign by default, not only AI edits

The four approaches differ in what they actually guarantee, from a self-contained chip that needs no network connection to a cloud-registered service built for accredited newsrooms rather than the general public.

Leica’s chip-based signing and Google’s hardware-backed keys both bind the signature to physical hardware that is difficult to swap or spoof. Sony’s system depends on a cloud registration step and an invitation-only, accredited-organization model designed around news agencies rather than consumer buyers. Nikon’s implementation, added to the Z6 III by firmware in August 2025, turned out to have a signing flaw that let a manipulated image pass verification, and the company suspended the feature within two weeks of shipping it. The practical lesson is that a camera advertising Content Credentials support is not selling one uniform standard; it is selling one company’s implementation of that standard, with that company’s own failure modes attached. A photographer or a newsroom relying on hardware signing has to know which implementation it is trusting, not only whether a logo is present on the box.

Consumers say they want to know what made an image

Survey data from two independent sources point in the same direction. Getty Images’ own 2024 “Building Trust in the Age of AI” research, drawn from more than 30,000 adults across 25 countries, found that 87% of respondents consider it important for an image to be authentic, and close to 90% want to know when an image has been created using AI. Seventy-six percent agreed with the statement that it is getting to the point where they cannot tell if an image is real, a discomfort that predates most of the current camera and legislative response and helps explain why that response arrived at all.

Gartner’s more recent numbers, drawn from a survey of 1,539 US consumers in October 2025, sharpen the picture. Half of respondents said they would rather give their business to brands that do not use generative AI in consumer-facing marketing at all. Sixty-one percent said they frequently question whether the information they rely on for everyday decisions is reliable, and 68% said they frequently wonder whether the content they see is real. Gartner’s own analysts frame this as a trust decision rather than a technology decision — brands that fail to disclose AI use are not simply making a stylistic choice, they are taking on reputational risk with an audience that is actively trying to verify what it sees. Only 27% of consumers, by the end of 2025, said they judge whether information is true mostly by intuition, down from a clear majority in earlier years — a shift toward active verification behavior that gives camera-level signing and regulatory labeling an audience that is already looking for the signal, rather than one that has to be persuaded to care about it in the first place.

Neither survey claims that consumers can reliably tell a real photograph from a generated one on sight; both point in the opposite direction, toward growing uncertainty about what is in front of them. That uncertainty is precisely what turns disclosure into a competitive advantage rather than a compliance burden. A brand or publisher that can point to a hardware-signed image, or a caption verified through a documented editorial process, is offering a specific, falsifiable answer to a question audiences say they are already asking themselves. A brand that cannot make that claim is not automatically penalized, but it is competing without an answer to a question its own customers say matters to them.

A fashion campaign showed how fast the backlash can move

H&M gave the abstract survey numbers a concrete test case in March 2025, when it announced plans to build AI-generated “digital twins” of about 30 of its human models for use in marketing and social media. The company built in safeguards its executives clearly hoped would defuse criticism: models would retain rights to their own digital twin, get paid whenever it was used, and could even license it to competing brands. The reaction split along predictable lines anyway. Sara Ziff, a labor advocate who runs the Model Alliance, raised concerns about consent and long-term compensation once a likeness exists independently of the person who owns it. Paul Fleming, general secretary of the UK entertainment union Equity, welcomed the payment pledge but said it needed binding legislation behind it, not a company promise, noting that few legal protections of that kind yet exist anywhere.

H&M was not acting in isolation. Mango, Levi’s, and Inditex-owned Zara had each explored AI-generated or AI-assisted model imagery around the same period, and Amazon has built generative tools directly into its advertising platform for sellers who want the same effect without a fashion house’s production budget. What made the H&M case instructive was the gap between the company’s own account and outside coverage of it: H&M framed the rollout as a model-friendly alternative to unauthorized deepfakes, while labor groups treated it as a preview of how quickly a supporting cast around a photoshoot — stylists, makeup artists, assistant photographers — becomes unnecessary once the subject herself can be replicated digitally. Both readings can be true at once, which is exactly why the episode became a reference point rather than a one-off controversy.

Later coverage of the rollout captured that same split within a single project. Vanessa Moody, one of the models whose likeness became a digital twin, described the process to trade press as collaborative and transparent, framing it as a template other brands could follow responsibly. Model Alliance and Equity’s objections were not about that particular company’s execution so much as about a structural risk that no individual company’s good conduct can fully resolve: once a likeness exists as reusable data, the terms of its reuse depend on contracts and legislation that, in most jurisdictions, do not yet exist.

Signing a photograph is not the same as verifying it

Nikon’s experience with the Z6 III is the clearest available case study in what camera-level signing can and cannot guarantee. The company added Content Credentials support through a firmware update released on August 27, 2025, allowing the camera to sign images at the moment of capture. Within about a week, a researcher demonstrated that the camera’s multiple-exposure mode could be used to blend a manipulated composite into a single file that still carried a valid signature — because the camera was faithfully attesting to what its own sensor and firmware had produced, not to whether that output depicted a real, unaltered scene. Nikon suspended its Authenticity Service, revoked every certificate it had issued, and had not restored the feature as of mid-2026.

The lesson generalizes beyond one camera model. A cryptographic signature answers a narrow question: did this specific device produce this specific file? It does not answer the broader question a reader actually cares about, which is whether the scene in front of the lens was real and unstaged. A signed file is not the same claim as a true one. Provenance systems face a second, more mundane limitation as well: most social platforms strip embedded metadata, including Content Credentials manifests, during upload and re-encoding, which is why the coalition behind the standard has started developing invisible watermarking meant to survive that process by embedding a recoverable identifier directly in the pixels rather than in metadata that a server can simply discard. Until that layer matures, a hardware signature protects a file only for as long as it stays in a chain of custody that nobody has broken.

A European law turns disclosure into a legal duty this week

The transparency obligations in Article 50 of the EU’s AI Act took effect on August 2, 2026, the day before this article was written. The rule requires two distinct things. Providers of AI systems that interact directly with people must design them so users know they are dealing with a machine. Providers of generative AI systems must apply a machine-readable mark to synthetic audio, image, video, or text output so that it can be detected as artificial, with narrow exceptions for systems that perform only minor assistive edits, such as grammar correction, that do not change a file’s substance. Deepfakes and AI-generated text published on matters of public interest carry an added disclosure duty regardless of the underlying marking.

The law reaches further than its “EU” label suggests, applying to any provider or deployer serving people inside the bloc regardless of where the company is based, and penalties can run as high as €15 million or 3% of a company’s worldwide turnover. The European Commission softened one part of the timeline in May 2026, when the Council and Parliament agreed to delay the marking obligation specifically for generative systems already on the market before August 2, 2026, pushing that piece to December 2, 2026. Content generated before the original deadline does not need retroactive labeling, though the Commission has encouraged voluntary disclosure anyway. For marketers and publishers, the practical effect is that disclosure is no longer a brand-safety choice — it is a compliance requirement with a specific date, a specific penalty ceiling, and a growing body of guidance from Brussels on exactly which use cases it covers.

Enforcement sits with national market-surveillance authorities rather than with a single EU body, which means the practical strictness of Article 50 will vary somewhat by member state in its first years, in much the same way that early GDPR enforcement varied before a common baseline emerged. The European Commission’s draft Code of Practice on Transparency of AI-Generated Content, first published in December 2025, is meant to narrow that variation by giving providers a voluntary but closely watched template for compliance, one that regulators are likely to treat as the de facto standard even though adopting it remains optional in name.

The premium on real photography depends on enforcement holding

Every strand of evidence here points the same way: a UK regulator willing to let a merger collapse over an editorial photography unit, camera makers building signing hardware, consumers telling researchers they want disclosure, and a European law that now requires it. Together they support the premise this article set out to test — that interest in authentic, verifiable photography has grown alongside, not despite, the flood of AI-generated imagery. What the evidence does not support is a simpler, more comfortable version of that story, in which “real” photography is safely insulated from synthetic competition and only has to wait for the market to notice its value.

Three conditions will determine whether the current premium holds. The first is enforcement: Article 50 carries large penalties on paper, but its marking obligation for existing generative systems does not bind until December 2026, and national market-surveillance authorities, not Brussels, will decide how aggressively to police it in practice. The second is technical durability — whether watermarking that survives social-platform re-encoding matures faster than the next Nikon-style vulnerability appears in a different manufacturer’s signing chain. The third is a paradox photographers themselves have started naming: once “authentic” becomes a marketing claim that clients pay for, some of what gets sold as authentic is itself staged to look that way, which risks teaching audiences to distrust the label as thoroughly as they learned to distrust airbrushed perfection. A verified photograph is only worth more than a generated one for as long as verification means something, and that condition is still being built, one camera firmware update and one regulatory filing at a time, rather than settled.

Common questions about photography authenticity in 2026

Why did Getty Images end its merger with Shutterstock?

Getty’s board chose not to accept a condition set by the UK Competition and Markets Authority, which had conditionally cleared the merger only if the combined company sold off Shutterstock’s editorial photography brands: Rex Features, Backgrid, and Splash News. Getty terminated the agreement on July 7, 2026, rather than divest that business.

What is the difference between editorial and creative stock photography?

Creative stock photography covers generic images — lifestyle scenes, business concepts, product mockups — that illustrate an idea rather than document a specific event, and AI generation now competes directly in that category. Editorial photography documents a specific real event, person, or moment and is licensed mainly to news organizations, a category regulators treat as functionally distinct.

What are Content Credentials?

Content Credentials are a technical specification, maintained by the Coalition for Content Provenance and Authenticity, that attaches a cryptographically signed record to a piece of digital media showing who or what produced it, when, and what edits were made afterward.

Which cameras currently sign photos with Content Credentials?

Leica’s M11-P, M11, Q3, and SL3 sign by default through a dedicated security chip. Sony offers an opt-in system for accredited news organizations. Google’s Pixel 10 signs every photo by default using hardware-backed keys. Nikon added support to the Z6 III in 2025 but suspended it after a security flaw was discovered.

Does a Content Credentials signature prove a photo has not been manipulated?

No. It proves that a specific signer, such as a particular camera or piece of software, produced or touched the file. It does not independently verify that the scene depicted is real or unstaged, which is why Nikon’s Z6 III could sign a manipulated composite image without the signature itself being forged.

What does the EU AI Act require starting in August 2026?

Article 50 of the AI Act requires generative AI systems to mark synthetic image, audio, video, and text output as artificially generated, and requires disclosure when people interact with an AI system directly or are shown a deepfake. The obligations took effect on August 2, 2026, with a delay until December 2, 2026 for the marking duty on systems already on the market.

Why did World Press Photo tighten its rules on AI-generated images?

The foundation’s contest rules define a photograph as a record of light captured by a sensor or film, and disqualify any entry that uses AI generation or generative fill in post-production, requiring photographers whose work reaches the later rounds to submit original camera files for independent verification.

Why did H&M’s AI model campaign cause controversy?

H&M announced plans to build AI-generated “digital twins” of around 30 human models for marketing use, offering the models payment and ownership rights over their own likeness. Labor advocates and a UK entertainment union welcomed the compensation pledge but argued it needed to be backed by legislation, since job displacement for photographers, stylists, and support crews was a real concern regardless of the models’ own consent.

Does authentic photography actually cost more than AI-generated imagery?

Survey data shows consumers say they value and want disclosure of authentic imagery, and some photographers report clients paying for documentary-style, unposed coverage rather than polished studio work. Direct, controlled data on pricing across the wider market is limited, so this remains a documented preference rather than a fully proven pricing premium.

Will social media platforms preserve Content Credentials when images are uploaded?

Not reliably today. Most platforms strip embedded metadata, including Content Credentials manifests, during upload and re-encoding. The coalition behind the standard is developing invisible watermarking designed to survive that process, but it has not yet been widely deployed across major platforms.

Author:
Jan Bielik
CEO & Founder of Webiano Digital & Marketing Agency

Camera makers now embed cryptographic signatures proving a photo is real
Camera makers now embed cryptographic signatures proving a photo is real

This article is an original analysis supported by the sources cited below

Competition and Markets Authority investigation into Shutterstock’s acquisition of Getty Images
Timeline of the UK regulatory review, from the 2025 Phase 1 inquiry through the July 2026 termination of the merger agreement.

Getty Images Holdings, Inc. — Form 425 SEC filing
Getty’s own disclosure of its board’s June 30, 2026 decision not to divest Shutterstock’s editorial business and to terminate the merger agreement.

Getty Images and Shutterstock Receive Unconditional Antitrust Clearance from the DOJ
Getty’s press release confirming US Department of Justice clearance of the merger without conditions in February 2026.

Content Credentials
Overview of the C2PA specification’s history, membership, and adoption by Google, Nikon, Sony, and other manufacturers, with sourced references to primary announcements.

Nikon Suspends C2PA Functionality on the Z6 III Due to Authentication Issue
Reporting on the signing vulnerability discovered in the Z6 III days after its Content Credentials firmware update shipped.

New: Leica M11-P
Leica’s own announcement of the M11-P as the first commercially available camera with built-in Content Credentials signing.

Gartner Marketing Survey Finds 50% of Consumers Prefer Brands That Avoid Using GenAI in Consumer-Facing Content
Gartner’s October 2025 survey data on consumer skepticism toward AI-generated brand content and verification behavior.

Nearly 90% of Consumers Want Transparency on AI Images finds Getty Images Report
Getty Images’ 2024 VisualGPS consumer research on authenticity and AI-image disclosure across 25 countries.

Entry rules
World Press Photo’s 2026 contest rules defining a photograph as camera-captured and disqualifying AI-generated or generative-fill entries.

Verification process
World Press Photo’s description of how finalist entries are checked against original camera files for manipulation.

World Press Photo Defines What Counts as a Photograph
Analysis of the 2026 World Press Photo of the Year award and the foundation’s tightened verification standards.

Fashion giant H&M plans to use AI clones of its human models. Not everyone is happy
CNN’s original reporting on H&M’s digital-twin model program and the labor and consent concerns it raised.

H&M Uses Digital Twins of Professional Models to Showcase Denim Designs
Sourcing Journal reporting on the rollout of H&M’s digital-twin campaign and model reaction to the finished images.

Quick Facts: Transparency rules for AI systems
The European Commission’s summary of Article 50 obligations, effective dates, and enforcement structure.

Transparency obligations under Article 50 of the AI Act
The Commission’s FAQ on labeling requirements, retroactivity, and enforcement responsibility for Article 50.

EU AI Act Transparency Obligations: Preparing for Compliance by 2 August 2026
Legal analysis of the Article 50 compliance timeline, including the 2026 delay to the marking obligation for existing systems.

Why Authenticity Became Photography’s Market Shift
Industry analysis of client-driven demand for authentic, documentary-style photography and the risk of “authenticity” becoming its own performance.

Can Getty and Shutterstock Survive Generative AI?
Analysis of Getty’s disclosed 2024 decline in creative-stock revenue and its offsetting gains in editorial licensing and AI data-licensing deals.

Citing this article? Brief excerpts are welcome. Please credit Webiano.digital, name the author where stated, and include a link to https://webiano.digital and to this original article. Full or substantial republication requires prior written permission. Read our Copyright and Content Use Policy.

This article was prepared with the assistance of artificial intelligence tools. The content underwent expert human review, and Webiano Digital & Marketing Agency assumes editorial responsibility for its final version and publication.