How to verify AI-generated content you receive from an agency
If you commission AI creative, you carry the disclosure obligation. Here is how to check what you receive - read the Content Credentials, confirm the certificate, and match the fingerprint - in a couple of minutes, before it runs.
When an agency hands you a polished AI-generated campaign, you inherit a question you can't answer from the file alone: how was this made, and can you prove it? Because under most AI disclosure rules the obligation lands on whoever publishes the content - the brand - "the agency said it's fine" is not a record you can produce when someone asks. This is a practical checklist for verifying AI content you receive, before it goes live.
For the contract and procurement side of this, see commissioning AI content without inheriting the risk. This post is the hands-on verification workflow.
Why the brand has to check
The disclosure duty follows the deployer - the organization putting content in front of an audience. That's usually you, not the production shop. So the practical test isn't "does the agency seem competent," it's "if a regulator, platform, or client asks me to show how this AI content was handled, can I?" If the answer lives only in the agency's inbox, you don't have a record. The fuller argument is in who is liable for AI creative work.
The good news: when the provenance is real, checking it takes minutes.
Step 1 - read the Content Credentials
Open the delivered file in a viewer that reads C2PA content credentials and confirm three things: a manifest is present, it's signed, and it actually describes the asset in front of you. A public option is verify.contentauthenticity.org; if the work came through Archibal, you can drop the file into the labeling checker and get a plain "labeled / partially labeled / not labeled" verdict without an account.
What you're looking for: valid, present, and consistent. A manifest that's missing, unsigned, or describes a different asset is a red flag, not a formality.
Step 2 - confirm the compliance certificate
A credential in the file tells you the asset is marked. A signed compliance certificate tells you the delivery was handled: which models produced it, the approval chain with timestamps, the jurisdictions it was assessed against, and content hashes tying each file to the record. Confirm the certificate covers every delivered asset - a record that covers five of seven files is not a record - and that the hashes match what you actually received.
If the delivery came through Archibal, every certificate has a public verification page at /verify/[token] - no login - so you (or your legal team, or a platform) can confirm it independently. That page is also where the agency can hand you a shareable link instead of a PDF buried in an email.
Step 3 - match the fingerprint
Platforms strip metadata. So the question "will this still be verifiable after it's published?" matters. A perceptual fingerprint (a content-derived hash) computed at delivery lets a stripped or re-encoded copy be matched back to the original signed record later. If you're receiving assets through a registry, this is automatic; if you're not, ask the agency how they handle re-verification after stripping. Here's why fingerprinting is the layer that survives.
Step 4 - keep it where you can find it
Verifying once at delivery isn't the finish line. Investigations and audits arrive long after a campaign ends, often from a different team than the one that ran it. Keep the certificates and provenance in one durable archive across every agency you work with - not scattered across vendor portals - so you can produce the proof on demand. That cross-vendor archive is the core of the client side of Archibal.
What to require so verification is even possible
You can only verify what the agency provides. Make provenance a deliverable in the brief, the same as the final files: C2PA credentials in each asset, a signed certificate covering every delivered file, explicit disclosure of any AI likenesses, and confirmation the work was assessed for the territories you're actually publishing to. If an agency can't produce these, that's worth knowing before the campaign runs, not after.
Frequently asked questions
How do I verify AI-generated content from an agency? Read the file's C2PA content credentials (present, signed, consistent), confirm a compliance certificate that covers every delivered asset with matching content hashes, and check that a perceptual fingerprint exists so stripped copies can be re-matched later.
How do I check if an image or video has C2PA provenance? Open it in a Content-Credentials-aware viewer, or drop it into a labeling checker that reports whether a signed manifest is present and valid.
The agency says it's compliant - isn't that enough? No. As the publisher you carry the disclosure obligation, and "they told us" is not evidence. You need the machine-readable marking and a signed record you can produce yourself.
What if the platform strips the provenance after we publish? Embedded credentials can be lost on upload, but a perceptual fingerprint survives re-encoding, so the published asset can still be matched back to its original signed record in the registry.
How long should we keep the provenance records? Plan for the statute of limitations in your publishing markets - commonly several years. Keep the certificates and provenance in a durable archive so the record is there when a question arrives after the campaign has ended.
The bottom line
Verifying AI content you receive is three quick checks - credentials, certificate, fingerprint - plus keeping the result somewhere you can find it later. Do it at delivery, require the provenance in the brief, and you turn "trust me" into something you can actually show. That receive-and-verify workflow is exactly what Archibal is built for.