
Apple Reference Image digitally signs original RAW data at capture, creating a durable record of what an iPhone sensor observed. According to appinn, that record can establish iPhone capture without carrying personal identity or device information. That is useful provenance, but it is not a permission slip for people who may appear in the result. It also does not clear the use of recorded voices or depicted assets.
sspai separates file modification from a trustworthy capture and processing workflow. It also distinguishes both from the reality of the object before the lens. Digital signatures and secure hardware address the first two questions, its author argues; a certified image could still show a high-resolution screen or printed paper rather than the real item. Provenance therefore needs two revocable records: an immutable capture baseline and a distinct consent record. They answer different questions, and neither turns "verified" into proof of truth or permission.
A signed capture is not proof of the subject
Apple Reference Image makes a limited claim about the capture path, not the world in front of the lens. According to appinn, the camera sensor digitally signs the original RAW image data at capture. ifanr describes Reference mode as signing pixel data before firmware changes the image, then saving a DNG digital negative linked to the conventionally processed main photo.
- September 1, 2025China's AI-generated-content labeling Measures take effect
- JuneSpatial Reframing becomes available in beta
- September 15, 2026Apple releases Apple Reference Image
- September 18, 2026iPhone 18 Pro and iPhone 18 Pro Max officially go on sale
That protects a record of what the sensor received.
It does not establish that the sensor faced the genuine physical subject. The sspai author separates photo authenticity into three questions: file modification, trust in capture and processing, and the reality of the object before the lens. Digital signatures and secure hardware address the first two. They cannot by themselves determine whether the lens saw an original object, a replica, a miniature, a printout, or a high-resolution screen.
A certified image can therefore be authentic as a capture while still being misleading as evidence of a subject. sspai specifically notes that an ARI-certified photo could show an item displayed on paper or a screen rather than the item itself. This distinction matters wherever a photograph is asked to prove more than its own technical history.
Depth information might make some substitutions harder. Yet sspai argues that it cannot provide absolute authenticity: it may fail with distant objects and may miss subtle surface changes on a very thin badge. Apple has not clearly stated whether ARI authentication includes depth data. appinn also says an Apple Reference Image does not contain personal identity or device information, so its value is a protected capture record rather than a complete account of what, or whom, was photographed.
Keep the source capture beside the working image
An immutable source capture should travel beside any consequential working image, rather than being treated as a badge attached to the final export. Apple's Reference Mode makes that separation tangible: only images captured in the mode create signed reference-image data, while a standard photo is kept at the same time, according to appinn. Apple compares ARI to a digital negative, sspai reports. The useful record is the sensor-adjacent baseline, not merely the file someone later chooses to circulate.
That distinction becomes practical after routine editing. appinn says signed data is saved first, then the Photos app creates a Reference Image through an internet connection and Private Cloud Compute. ifanr describes auditable demosaicing, tone mapping, and compression before a viewable Apple-signed image emerges. Cropping and color work can produce legitimate derivatives. Compositing or export can do so as well, but such derivatives should remain explicitly paired with the retained capture. For 12MP or 24MP photos, appinn puts additional unsigned data at about 8-10 MB before generation and about 3 MB afterward.
The need is sharper for generative reframing. Spatial Reframing in iOS 27 can crop an image and drag it to simulate a different viewing position, according to ifanr. ifanr reports examples that included an unfamiliar man behind a horse, plus windows and ledges absent from source scenes. Keeping source and working versions together makes the divergence inspectable.
Consent cannot be inferred from provenance
An Apple Reference Image can show that a photo was captured by an iPhone, according to appinn. It carries neither personal identity information nor device information. Even signatures on photos from the same iPhone model cannot establish that the images came from the same physical device.
That is a capture claim, not a permission claim.
A real photograph or recording therefore needs a separate authorization record when an identifiable face or voice is used. A generated asset needs one as well. Article 1019 of China's Civil Code bars unauthorized making of a portrait. It also bars unauthorized use or publication, except where law provides otherwise; it prohibits portrait-right infringement through information-technology forgery. Article 1023 extends relevant protection to a natural person's voice.
The record should show the scope of permitted use rather than treating provenance as a blanket release. Commercial advertising deserves distinct handling, as woshipm's author recommends focusing an initial withdrawal system on real faces and voices used in advertising. A lawful use permitted without consent is a different category: its basis is the applicable legal exception, not an inference from a signed image.
AI labels answer another question. They tell viewers that material was generated with AI, but, as woshipm's author argues, they do not show that the depicted person authorized use of their face. YouTube's experimental likeness-detection feature gives eligible adult creators who complete identity and selfie-video verification a way to locate suspected AI face uses and seek removal through its privacy-complaint process. Voice-related capabilities remain in expansion.
Consent must be recorded separately from capture integrity. Its scope and evaluation must also remain separate.
Revocation needs a visible evidentiary trail
Apple Reference Image's revocation list addresses a narrow technical failure: a sensor's private key may be compromised, or its signatures may no longer be trusted. According to appinn, Apple's servers maintain that list, while verification happens locally on the device. Devices periodically retrieve updates and can check a viewed photo without sending that photo to Apple. The result is an evidentiary record that a signing source has lost trust, not a ruling on who may reuse a depicted person.
Permission withdrawal needs a separate record, with a separate trigger.
The unresolved questions include who can authorize withdrawal. They also include what evidence meets the standard and how narrowly a decision applies. A person may claim a face or voice was used without permission; a platform must then distinguish that claim from a compromised capture device. The applicable evidence concerns identity. It also concerns authorization and use, rather than the validity of a sensor signature.
According to woshipm, the Measures for the Labeling of Artificial Intelligence-Generated and Synthetic Content require generation providers to place generation attributes in metadata. The metadata must also include provider identification and content numbers. Publishing platforms must examine that metadata and user declarations. They must also examine identifiable generation traces, then provide public notices for generated or synthetic material. Those records can support a visible decision trail when distribution is restricted or removed.
They cannot retrieve every shared file. The woshipm author argues that a portrait-withdrawal system cannot erase copies on private devices or in closed group chats. It also cannot erase offline files, but can seek timely control over public dissemination inside participating systems. The author recommends beginning with real faces and voices used in commercial advertising. The author argues that platforms handling portrait-right violations should stop recommendation and restrict distribution. They should delete material and block variants. A revocation record therefore needs to state what system acted. It must also state what evidence it relied on and where its reach ends.
Separate capture provenance from permission to use a likeness
- You need evidence that an image originated in a camera capture process rather than from an AI generator. Use a capture-provenance record such as Apple Reference Image, which has the camera sensor sign original RAW image data at capture. Treat it as evidence about the capture workflow, not as proof of every claim made by the image.
- You need to decide whether a signed or "verified" photo proves that the subject depicted is real. Do not make that inference. Secure hardware and digital signatures address file modification and workflow trustworthiness, but a certified photo could still show an image displayed on a high-resolution screen or printed on paper.
- A sensor key is compromised or a previously trusted signing source must no longer be accepted. Use a provenance system with revocation. Apple Reference Image includes sensor revocation, maintained by Apple's servers; devices periodically retrieve the revocation list and can check it locally without uploading the viewed photo to Apple.
- An AI-generated image or voice includes an identifiable person and you need to establish whether its use was permitted. Maintain a separate authorization record rather than relying on AI labels or capture provenance. Chinese rules require labels for generated or synthetic content, but labels inform viewers about generation and do not establish consent from the person whose face or voice was used.
- A rights holder withdraws permission for a face or voice used in commercial advertising. Build for public-distribution control rather than promising universal deletion. A withdrawal system may support stopping recommendation, restricting distribution, deleting content, and blocking variants within participating systems, but cannot erase copies on private devices, in closed group chats, or in offline files.
Apple's chain still has interoperability and privacy gaps
Apple Reference Image has a strong device-bound starting point, but its practical reach is narrower than a general provenance system. It debuted on the iPhone 18 Pro and iPhone 18 Pro Max. The phones went on sale on September 18, 2026. The feature works only with their main cameras after manual activation. It was unavailable in mainland China at launch. European Union iPhones could not capture it then, although existing files could be generated and viewed on iOS 27, iPadOS 27, and macOS 27.
That makes verification dependent on where a capture occurred and which Apple environment can interpret it.
The signature design also does not settle every implementation question. According to appinn, the signing private key remains inside the camera sensor, never reaching iOS or leaving the device. The system uses hybrid RSA-3072 and ML-DSA-87 signatures; ML-DSA-87 is post-quantum. Those are concrete security properties, not proof that every claimed sensor-stage step has been publicly established.
ifanr describes a unique sensor identity bound to the Secure Enclave. It says Private Cloud Compute checks the sensor, then the phone and timestamp. sspai's author instead frames sensor-stage signing and Private Cloud Compute generation as speculation, including the possibility that original photos and metadata are sent to Private Cloud Compute. These accounts should be treated as evidentiary claims with different weight, rather than merged into a settled account of the pipeline.
Cloud processing creates a privacy boundary that a capture signature cannot answer. If image material or metadata reaches Private Cloud Compute, practitioners need to know what leaves the handset, what is retained, and which later verification environments can read the result. Apple files may coexist with provenance approaches from Google Pixel, Samsung, Sony, Leica, and Qualcomm-backed Truepic, according to appinn, but coexistence is not interoperability. A verifier outside Apple's stack may be unable to establish the same chain or expose its limits clearly.
Capture provenance, authenticity checks, and consent controls
| Apple Reference Image | TAPCam | China AI-content labels and portrait-right protections | |
|---|---|---|---|
| Primary record | Camera sensor digitally signs original RAW image data at capture | Secure Enclave-protected credential signs image and depth data | Generated or synthetic content carries explicit and implicit labels |
| What it can establish | A photo was captured by an iPhone | Server can check whether the Secure Enclave signature is valid | Generation attributes, provider name or code, and content numbers in metadata |
| Real-world truth | Does not establish whether the object before the lens is real | Depth data is signed; not covered whether it establishes real-world truth | Labels do not establish whether a depicted face was used with consent |
| Identity and device linkage | Includes no personal identity information or device information; two photos from the same iPhone model cannot be linked to the same device | Not covered | Portrait and voice protections apply to natural persons |
| Consent or authorization | Not covered | Not covered | A portrait may not be made, used, or made public without consent except as otherwise provided by law |
| Revocation or response mechanism | Sensor revocation mechanism for compromised keys or signatures that are no longer trusted | Not covered | Eligible YouTube creators can find suspected AI face uses and request removal; voices capabilities are still expanding |
| Verification and processing | Verification is local; devices retrieve revocation lists and can check without uploading the viewed photo to Apple | Server checks the signature; other processing occurs in the user's browser to reduce uploads and central processing | Publishing platforms verify metadata, user declarations, and identifiable generation traces |
| Availability and access | Main cameras of iPhone 18 Pro and iPhone 18 Pro Max; manually enabled; unavailable in mainland China at launch | Designed for iPhones running iOS 18.6 or later; code and design are open source; app is free with no in-app purchases | China's Measures for the Labeling of Artificial Intelligence-Generated and Synthetic Content |
Treat an AI label as a disclosure, not a consent record. According to woshipm, it can tell viewers that AI was involved without showing that an identifiable face was authorized for use.
For commercial advertising, keep a separate authorization record for each real face or voice, and make withdrawal possible when permission changes. Start with uses that create the clearest portrait-right risk. YouTube's experimental likeness-detection process offers an example of a downstream remedy for eligible adult creators who complete identity and selfie-video verification, but voice capabilities are still expanding, according to woshipm. Build for removal requests before publication: stop recommendation, restrict distribution, delete the material, and block variants where participating systems can act. Do not promise total erasure from private devices, closed group chats, or offline files.
For readers outside China
- Availability: Apple Reference Image debuted on the iPhone 18 Pro and iPhone 18 Pro Max, and supports only their main cameras when users manually enable Reference Mode. It was unavailable in mainland China at launch. In the European Union, iPhones could not capture Reference Images at launch, although existing Reference Images could be generated and viewed on iOS 27, iPadOS 27, and macOS 27. TAPCam is designed for iPhones running iOS 18.6 or later; its official version had been submitted for review.
- Pricing: Apple Reference Image pricing is not disclosed in sources. TAPCam is free with no in-app purchases.
- Closest Western equivalents: C2PA-based provenance systems, which seek to establish verifiable provenance and modification records for digital content.; Truepic, a Qualcomm-backed provenance approach using C2PA, digital signatures, or hardware security mechanisms.; YouTube's experimental likeness-detection feature, which lets eligible creators find suspected AI videos using their faces and request removal through its privacy-complaint process.
- Data residency: Apple Reference Image verification is performed locally, and a device can check the revocation list without uploading the photo being viewed to Apple. However, generating a Reference Image in Photos requires an internet connection and Private Cloud Compute. The source material does not say where Private Cloud Compute data is processed or retained. TAPCam performs other data processing in the user's browser to reduce the need to upload and centrally process user data.
Sources
- appinn AI 图片真假难辨,我们怎么证明「一张照片真的是相机拍出来的」? https://appinn.com/apple-reference-image-photo-authenticity
- woshipm 一张脸被AI复制以后,为什么没有"撤回"按钮? https://woshipm.com/ai/6449389.html
- sspai 新 iPhone 相机如何记录照片真实性?开发者视角的猜想和尝试 https://sspai.com/post/114453
- ifanr iPhone 18 Pro 系列正式开售,新 AI 功能「自相矛盾」 https://ifanr.com/1680844
The evidence: 47 facts from 4 Chinese articles
Each line below was extracted from the article it sits under, in Chinese, before any of this was written. The writing is done from these and never from the source prose - that separation is structural, not a promise. How we work.
appinnAI 图片真假难辨,我们怎么证明「一张照片真的是相机拍出来的」?
- Apple released Apple Reference Image on September 15, 2026, as a digital-signature technology intended to prove that photos were captured rather than AI-generated.
- Apple Reference Image has the camera sensor digitally sign the original RAW image data when a photo is captured.
- The private key used for the signature is stored inside the camera sensor and is not provided to iOS or exported.
- Apple Reference Image includes a revocation mechanism for sensors whose private keys are compromised or whose signatures are no longer trusted.
- Apple's servers maintain the Apple Reference Image revocation mechanism, while verification is performed locally on the device.
- Devices periodically retrieve the latest revocation list and can check it locally without uploading the photo being viewed to Apple.
- Apple Reference Image uses a hybrid RSA-3072 and ML-DSA-87 digital signature.
- ML-DSA-87 is a post-quantum cryptographic algorithm.
- An Apple Reference Image can prove that a photo was captured by an iPhone, but it does not include personal identity information or device information.
- Signatures on two photos captured by the same iPhone model cannot be used to determine that they came from the same device.
- Apple Reference Image debuted with the iPhone 18 Pro and iPhone 18 Pro Max, which officially went on sale on September 18, 2026.
- Apple Reference Image supports only the main cameras of the iPhone 18 Pro and iPhone 18 Pro Max, and users must enable it manually.
- Apple Reference Image was unavailable in mainland China at launch.
- In the European Union, iPhones could not capture Reference Images at launch, but existing Reference Images could be generated and viewed on iOS 27, iPadOS 27, and macOS 27.
- Only photos captured in Reference Mode generate signed reference-image data, and a standard photo is retained at the same time.
- After capture, signed reference-image data is saved first, and a Reference Image is subsequently generated in the Photos app using an internet connection and Private Cloud Compute.
- For 12MP or 24MP photos, unsigned reference-image data uses about 8-10 MB of additional storage before generation and about 3 MB after generation.
- For 48MP photos, unsigned reference-image data uses about 35-40 MB of additional storage before generation and about 7-8 MB after generation.
- Reference Mode supports Live Photos, Portrait photos, and Photographic Styles, while some features such as Night mode are unavailable.
ifanriPhone 18 Pro 系列正式开售,新 AI 功能「自相矛盾」
- Apple's iPhone 18 Pro series officially went on sale at 8 a.m. today.
- The iPhone 18 Pro and iPhone 18 Pro Max went on sale today.
- iOS 27 received its official release three days before the iPhone 18 Pro series went on sale.
- Spatial Reframing is a generative photo-editing feature added in iOS 27.
- Spatial Reframing had been available in beta since June.
- Spatial Reframing allows users to crop photos and drag an image to simulate a change in the photographer's viewing position.
sspai新 iPhone 相机如何记录照片真实性?开发者视角的猜想和尝试
- Apple recently introduced Apple Reference Image (ARI).
- The sspai author developed a camera app called TAPCam to add evidence of photo authenticity.
- Apple compares ARI to a digital negative.
- Apple has not clearly stated whether ARI includes depth data in its authentication process.
- TAPCam uses Apple's App Attest API and a Secure Enclave-protected credential to sign image and depth data.
- When verifying a TAPCam photo, the server checks whether the Secure Enclave signature is valid.
- TAPCam performs other data processing in the user's browser to reduce the need to upload and centrally process user data.
- TAPCam does not rely on new hardware sensors and is designed for iPhones running iOS 18.6 or later.
- TAPCam's code and design are open source, the app is free with no in-app purchases, and its official version has been submitted for review.
- The sspai author received a $75 prize for the project at a small hackathon.
woshipm一张脸被AI复制以后,为什么没有“撤回”按钮?
- China's Measures for the Labeling of Artificial Intelligence-Generated and Synthetic Content officially took effect on September 1, 2025.
- Under the Measures for the Labeling of Artificial Intelligence-Generated and Synthetic Content, generated or synthetic text, images, audio, video and virtual scenes must carry explicit and implicit labels.
- The Measures for the Labeling of Artificial Intelligence-Generated and Synthetic Content require generation service providers to include generation attributes, the service provider's name or code, and content numbers in file metadata.
- Content publishing platforms are required to verify metadata, user declarations and identifiable generation traces, and provide public notices about generated or synthetic content.
- Article 1019 of China's Civil Code prohibits organizations and individuals from infringing portrait rights by means such as forgery using information technology.
- Article 1019 of China's Civil Code provides that, except as otherwise provided by law, a portrait holder's portrait may not be made, used or made public without that person's consent.
- Article 1023 of China's Civil Code applies relevant portrait-right protections by reference to the protection of a natural person's voice.
- Chinese courts have found that making another person's portrait into an AI face-swapping template without permission infringes portrait rights.
- In a case involving AI deepfake obscene images and the spread of rumors, the perpetrator was convicted of defamation.
- In a case involving online dating fraud using deep face-swapping and voice synthesis, the perpetrator was sentenced for fraud.
- YouTube has launched an experimental likeness-detection feature that allows eligible creators who complete identity and selfie-video verification to find AI videos suspected of using their faces and request removal through its privacy-complaint process.
- YouTube's experimental likeness-detection feature mainly serves adult creators enrolled in the program, while capabilities concerning voices are still expanding.