Microsoft's Content Provenance Detection: what you can check on a file

Foundry has a detection website and API for provenance. What the page says it checks, its limits, and how to use it on an AI clip or image from any generator.

4 min readSume
All posts

If you want to know whether a file carries provenance data, Microsoft offers a check. The Foundry provenance page, read on 2026-10-05, says there is a detection website and an API under the name Content Provenance Detection, tied to the C2PA Content Credentials and invisible watermarks that Foundry's supported models add.

I could read the page's description of the feature. I could not read the detection tool's own documentation, so this post sticks to what the page says and does not describe the tool's inputs, size limits or output format.

What the check can and cannot settle

What a provenance check means, per the Foundry page (read 2026-10-05)
ResultWhat it tells youWhat it does not tell you
Provenance foundThe file carries Foundry-style provenanceThat the content is trustworthy or who authored it
Nothing foundNo provenance was detectedThat the file was not made by AI
Edited fileWhatever survivedEdits like cropping or compression may remove marks

Using it on a file from another generator

Microsoft's page ties the check to its own models and marks. A file from a different API may carry other credentials or none, so a negative result there is weak evidence. A positive result is stronger, but only for the signal Microsoft knows how to read.

For an image from the Sume image API, which lists models such as black-forest-labs/flux.2-pro, Sume's docs say nothing about provenance. Run the detection on the delivered file, not on the provider's example, and write down what it returned and when.

What to write in your own records

Microsoft says customers remain responsible for their own transparency obligations, so a clean check is not a disclosure. If you are labelling an ad or a social clip, use the platform's AI setting regardless. Sume's docs describe a metadata field on video, image and music jobs that Sume stores on the job and does not send to the provider. I found nothing in the docs about Sume adding, keeping or removing C2PA credentials, watermarks or platform labels, so treat that as undocumented and check the delivered file.

  • The Sume job id, model id and the date you ran the check.
  • The result in plain words: found, not found, or not checked.
  • The exact file you checked, by name and size, because a re-export changes the result.
  • Your disclosure decision, separate from the check result.

Sources

Related posts

More in Media tools

All Media tools posts

Written by Sume