Apple is actively developing a system to help users prove their iPhone photos are genuine and not AI-generated deepfakes. Discovered within the iOS 27 beta 5 code by 9to5Mac, the upcoming Apple Reference Image feature embeds cryptographic provenance metadata into photographs at the exact moment of capture.
The authentication process relies heavily on Apple's Private Cloud Compute servers. According to MacRumors, users must manually tap a Reference badge on a captured photograph to initiate verification. This action sends the raw image's embedded data - including sensor signatures, the capture time frame, and unique hardware identifiers - to Apple's servers, which then return an authenticated version with a uniquely assigned ID.
Apple does not access the raw photo itself during this exchange. Instead, it uses the transmitted sensor data to block images originating from compromised hardware or to retroactively revoke prior authentications if a sensor is later found to be manipulated.
How to Enable Apple Reference Image
The feature is currently disabled by default in the iOS 27 beta, accompanied by a strict privacy disclosure. Once it officially rolls out, users can activate it through the system settings:
- Open the Settings app.
- Navigate to Camera.
- Select Reference Image.
- Toggle on Reference Mode.
After enabling the setting, users must select the new Reference option directly within the iPhone Camera app to ensure the required provenance information is embedded into the shot.
The Alternative to C2PA Standards
By developing a proprietary authentication method, Apple is notably bypassing the C2PA Content Credentials standard. While C2PA is currently supported by major camera manufacturers like Canon, Nikon, Sony, FujiFilm, and Leica - as well as Google's Pixel 10 - the standard has faced ongoing criticism regarding its overall reliability.
Apple's approach aligns with a growing industry push to label human-made works rather than solely flagging AI-generated content. This is a strategy that Instagram head Adam Mosseri recently suggested might be far more practical for online platforms to implement at scale.
The Ecosystem Lock-In of Truth
Apple's decision to build a proprietary provenance system rather than adopting the C2PA standard used by the Pixel 10 is a classic ecosystem play. By routing authentication exclusively through its Private Cloud Compute servers, Apple ensures that the cryptographic truth of an image remains tightly bound to its own hardware and privacy infrastructure.
This gives the company absolute control over the verification pipeline, allowing it to instantly revoke authentication if a specific iPhone sensor is compromised. For journalists and creators, this means the iPhone could become the de facto standard for verifiable media, but it also risks fragmenting the broader internet's attempt to create a universal, cross-platform standard for identifying real photographs.