Edit

Content provenance for Foundry models

As advances in generative AI accelerate the creation and distribution of highly realistic digital content, the ability to understand where information comes from and how it was created becomes increasingly important.

For years, Microsoft has helped advance technologies and standards that promote trust, transparency, and authenticity online. As a co-founder of the Coalition for Content Provenance and Authenticity (C2PA), Microsoft has worked alongside industry partners to establish open standards that help people understand how digital content was created and modified.

Building on this foundation, Microsoft continues to advance content provenance in partnership with governments, standards bodies, and technology companies. As interest in content transparency grows across the ecosystem, policymakers, industry groups, and technology leaders are advancing common approaches through efforts such as the EU AI Act's Code of Practice on Transparency of AI-Generated Content, the California AI Transparency Act, and C2PA standards. Microsoft is contributing to this evolution by making provenance technologies available across Microsoft AI systems, including those available through Microsoft Foundry. Microsoft’s goal is to not only extend provenance signals across content generated by Microsoft products, but to also support content provenance signals in the applications and experiences built by customers on Foundry.

What is content provenance and why is it important?

Content provenance is information that helps identify where digital content came from, how it was created, and whether it was modified. For example, provenance information can indicate:

  • Which application generated a piece of content.
  • Which AI model was used.
  • When the content was created.
  • Whether the content was edited after creation.
  • Whether the content contains supported authenticity signals.

What is Microsoft committed to doing?

Building content provenance into Microsoft AI experiences

Microsoft is committed to making content provenance more broadly available across its products, services, and platforms. As capabilities become available, Microsoft AI systems that generate supported image, audio, video, and text content include provenance information to help communicate the origin and history of AI-generated content.

Making provenance capabilities available to customers

For supported Foundry Models sold by Azure, customers can leverage available content provenance capabilities to help provide transparency about AI-generated content and support their own transparency objectives.

Partnering with model providers to expand text provenance support

For text-generating models, Microsoft works closely with model providers to increase the availability of text provenance capabilities across supported models as the underlying technologies mature and become available.

How Microsoft marks AI-generated content in Microsoft Foundry

Microsoft uses state-of-the-art technologies to provide content provenance for supported Microsoft Foundry models and Microsoft AI systems, including:

  • Content Credentials (C2PA), which attach cryptographically signed metadata to content.
  • Invisible watermarks, which embed provenance signals directly into generated content.

These technologies help provide information about how content was generated and support transparency workflows across different platforms and ecosystems.

1. Content Credentials (C2PA)

Content Credentials are based on the Coalition for Content Provenance and Authenticity (C2PA) open standard.

When you generate supported content, Microsoft Foundry can attach cryptographically signed metadata that records information about the content's origin and generation history. Depending on the scenario, this information might include details such as:

  • That the content was generated or modified by using AI.
  • The service or application involved in content creation.
  • The time the content was created or processed.
  • Other provenance information supported by the C2PA standard.

Because this information is cryptographically signed, recipients can verify that the metadata isn't altered after creation.

2. Invisible watermarks

Invisible watermarks are also used to support content provenance signals.

Watermarks embed machine-readable provenance signals directly into the content while remaining imperceptible during normal use. Unlike metadata-based approaches, watermark signals might remain available even when metadata is removed or unavailable. Watermarks are designed to support content provenance and transparency scenarios and might require specialized tools or services for verification.

How can I detect and interpret provenance information?

Microsoft provides free tools to verify and inspect provenance information.

  • Detection website: Use the Content Provenance Detection website to upload and analyze image, audio, and video files for supported provenance signals, including C2PA Content Credentials and Microsoft watermarking technologies.
  • API: Use the Content Provenance Detection API to programmatically verify and process provenance information at scale.

What is currently covered?

Content provenance capabilities are currently available for selected Microsoft Foundry models and Microsoft AI systems. Support varies by modality, model family, deployment type, and output modality.

The following table lists the current availability of provenance capabilities.

Image and audio

Modality Model family Models
Image Azure OpenAI GPT Image gpt-image-1-mini
gpt-image-1.5
gpt-image-2
Image Microsoft AI Image MAI-Image-2.5
MAI-Image-2.5-Flash
MAI-Image-2e
MAI-Image-2.5-Pro
Image Black Forest Labs Flux Flux-1.1-Pro
Flux.1-Kontext-pro
Flux.2-flex
Flux.2-Pro
Audio¹ Azure OpenAI GPT Audio gpt-audio
gpt-audio-mini
gpt-audio-1.5
Audio¹ Microsoft AI Audio MAI-Voice-1
MAI-Voice-2
Audio¹ Azure AI Speech²

Note

¹ We support the most commonly used audio formats, including MP3 and WAV, and continue to expand support for additional formats and configurations.

² Azure AI Speech supports content provenance for both streaming and non-streaming text to speech APIs. Availability varies by configuration, output format, sample rate, and deployment environment.

Text

Text provenance support varies by model. Where available, the underlying model provides invisible watermarking and surfaces it through Microsoft Foundry. Microsoft partners closely with model providers and shares the latest updates on supported models as they become available.

What are the limitations?

Content provenance technologies can improve transparency around AI-generated content, but it's important to understand their limitations.

Provenance doesn't determine trustworthiness

Content provenance provides information about content origin and generation history. It doesn't determine whether content is accurate, truthful, harmful, misleading, or trustworthy. For example, provenance information might indicate that an image was generated by a specific Microsoft Foundry model at a specific time. However, provenance information doesn't determine whether the image depicts a real event, contains accurate information, or should be trusted.

Provenance doesn't prove authorship

Provenance signals might not indicate that a particular model, service, or workflow generated or processed content. Don't interpret them as proof of ownership, authorship, intent, or endorsement. For example, provenance information might indicate that an image was generated using Microsoft Foundry. However, it might not identify who prompted the model, who owns the content, or who is responsible for publishing or distributing it.

Provenance information might not survive all transformations Some content workflows might alter or remove provenance information. Examples include:

  • Editing or re-saving content in applications that don't preserve provenance metadata
  • Cropping, resizing, or applying filters
  • Format conversion, transcoding, or compression

What support does Microsoft provide to customers subject to AI transparency obligations?

Customers are responsible for evaluating and meeting any transparency obligations that apply to their products and services. To support these efforts, Microsoft is making provenance technologies available in select Microsoft Foundry models and will continue to publish guidance on available provenance and detection capabilities.