Apple's iOS 27 could prove iPhone photos aren't deepfakes

Share
Apple's iOS 27 could prove iPhone photos aren't deepfakes

Trust is the theme of this brief: Apple is building hardware-backed proof that a photo came from a real iPhone camera, and a Rocky Linux founder is trying to make AI training data as auditable as source code.

Apple is quietly working on a photo-authentication system that would let iPhone users prove a picture was really captured by their camera — not conjured or edited by AI. Code and a privacy disclosure buried in the iOS 27 beta point to a feature called Apple Reference Image, first reported by 9to5Mac and since corroborated by MacRumors, Engadget and The Verge. Photos taken with an opt-in Reference mode would carry embedded provenance data — sensor signatures, capture time, unique hardware identifiers — and verifying a shot means tapping a Reference badge so Apple's Private Cloud Compute can check the raw image against that data, then return an authenticated copy with a unique ID. Apple says it won't see the raw photo itself, though it may receive sensor data to block, or retroactively revoke, authentication for compromised cameras.

That puts Apple in the same race as the C2PA Content Credentials standard that Canon, Nikon, Sony, Fujifilm and Leica have adopted, and that Google's Pixel 10 supports — a standard Apple has conspicuously skipped in favor of its own hardware-anchored approach. Why it matters: in an era when "shot on iPhone" is becoming a credibility claim anyone can fake, a provenance system baked into the world's most popular camera would be one of the largest real-world deployments of authenticity tech yet — if it ships. It's still beta code, and Apple could cut it before iOS 27 lands this fall.


OpenWALDO, a new open-source project from Rocky Linux and CentOS founder Gregory Kurtzer, launched today to build a community-owned corpus of AI training data. Sponsored by Ctrl IQ, the project proposes an "AI Bill of Materials": open weights plus the full training data, licenses and provenance needed to rebuild a model from scratch, with every assertion attributed and correctable in public. The pitch — "know before you train" — targets the copyright and licensing risk hanging over models trained on scraped data: if every ingredient is visible, reviewers can spot tainted or copyleft content before it propagates downstream. It's a foundation rather than a finished product, but Kurtzer has a track record of turning shared infrastructure into industry standards, so this one is worth watching for anyone betting on the open-source AI commons.

What to watch: whether Apple's authentication system interoperates with C2PA — or kicks off a provenance format war.

If your phone could cryptographically prove a photo is real, should platforms be required to honor that proof? Tell us in the comments.

Sources: The Verge · 9to5Mac · MacRumors · Engadget · SiliconANGLE · OpenWALDO