Policy

Apple tests Reference Image tool to verify iPhone photos

Code in the iOS 27 beta 5 reveals Apple is developing a 'Reference Image' system to embed provenance metadata in photos, helping users prove their iPhone pictures are not AI-generated fakes.

The Verge AI19 hrs agoPolicy
Image: The Verge AI

Apple is working on a new iOS feature designed to verify the authenticity of photographs taken on its devices. Discovered in the iOS 27 beta 5, the upcoming 'Apple Reference Image' system embeds secure provenance metadata directly into images at the moment of capture. This metadata will allow users to prove that their photos are genuine and have not been altered or generated by artificial intelligence.

The feature will be turned off by default, but users can activate it by navigating to Settings, then Camera, Reference Image, and finally Reference Mode. To use it, photographers must select a new Reference option within the iPhone Camera app. To authenticate a photo, a user taps a Reference badge on the image, which transmits the raw file and its embedded provenance data to Apple's Private Cloud Compute servers. This data includes sensor signatures, the capture time frame, and unique hardware identifiers. The servers verify the details and return an authenticated version with a unique ID, all without Apple accessing the raw photo itself.

This server-side verification allows Apple to monitor sensor data. If a camera sensor is compromised, Apple can block future authentications or retroactively revoke credentials for affected images. Authenticated files can then be viewed across iPhone, iPad, and Mac devices. The system functions similarly to the C2PA Content Credentials standard used by competitors like the Google Pixel 10 and camera manufacturers such as Canon, Nikon, Sony, FujiFilm, and Leica. However, Apple has chosen to build its own proprietary pipeline rather than adopting the industry-wide C2PA standard.

For photojournalists, creators, and editors, this tool provides a robust defense against the rising tide of deepfakes and generative AI skepticism. By establishing a secure, hardware-linked chain of custody, practitioners can easily verify the integrity of their work to publishers and audiences. This shift supports a growing industry preference for labeling human-made content directly at the source, offering a more reliable alternative to trying to detect AI-generated media after it has already spread online.

This is our own summary of reporting by The Verge AI

More in Policy