Kerry Wan/ZDNETZDNET’s key takeaways
- Apple’s new image provenance feature, Reference Image, can verify a photo’s origin.
- Still, it lacks elements that raise concerns for open-source builders.
- Content provenance still isn’t a widespread priority in tech.
In something of a surprise to longtime viewers like ZDNET senior contributing editor Kerry Wan, Apple’s annual hardware event on Wednesday opened with the reveal of the iPhone 18 Pro and Pro Max. New CEO John Ternus immediately focused on Apple Intelligence, emphasizing how central it is to the new devices — especially when it comes to your photos.
Reference Image, a new feature for the forthcoming iPhone 18 models, lets users prove they took a photo and that it isn’t AI-generated or altered. The feature is “powered by the new sensor in the Main camera that can sign every pixel it sees,” Apple said in the release, essentially creating a digital copy of a photo using that sensor data. Users can see reference images and main images side by side in the Photos app to identify any edits or changes between them.
Also: How to spot an AI image: 6 telltale signs it’s fake – and my go-to free detectors
Apple added that support for Google’s SynthID is “upcoming” and can “help users identify images generated or edited with AI.” A footnote clarified that this means “SynthID will be available in a software update later this year and will be included for most edited images, depending on the edits applied.”
Both are decisive next steps in image verification, especially for a potentially widely used smartphone. But Reference Image isn’t a systemwide upgrade or priority yet, and it’s not a silver bullet for AI-generated or altered images. I spoke with a content provenance expert to gain some context.
How it works
Reference Image is opt-in; photos must be taken in Reference mode for this to work. The feature will appear as a camera setting, like Portrait mode, for users who have enabled it in their settings. In that mode, Apple’s new sensor will turn on, collecting the additional data needed to create the reference photo. Viewers can then compare it side by side with any altered versions of the image.
Ari Abelson is co-founder of OpenOrigins, which builds cryptographic proofing systems for content and identity. In March, the company launched Source, a free image verification tool for iOS and Android.
“This technology is all very similar to Source, on the surface,” he said. “We had a very strong point of view on why we should use cryptographic hashes and sensor attestation at a hardware level. Apple seems to have picked up on those notes and developed that into [its] system.”
Unlike watermarking, which OpenAI and SynthID use, Source works by verifying an image or video from the moment it’s taken on your device. When you download the Source app, it verifies that it’s running on a physical phone or laptop, as opposed to a simulation of a device being run on a server. Source then authenticates the camera by checking outputs from your device’s sensor, again confirming it’s not being simulated.
Also: How to avoid Claude watermarking your content
To vet images, Source uses metadata and cryptographic signatures to verify where and when an image came from. Abelson told ZDNET he thinks Reference Image draws on similar technology by authenticating pixels.
On the privacy front, an Apple representative confirmed to ZDNET that the company only stores hashes, rather than the reference photos themselves, which means your photos stay on-device or in Private Cloud Compute, as many users have come to expect from Apple’s approach to data.
Possible limitations
So why make a feature like this opt-in? Apple explained in a briefing that the digital negatives Reference Image relies on are quite large in terms of file size due to the additional sensor data that makes them irrefutable. While making it the default camera setting might guarantee an image verification method for iPhone 18 users, it would also eat up a lot of storage on your device. That’s not ideal for users who don’t frequently need to verify the origins of their photos.
The feature also won’t be available just yet in China due to regulatory requirements, according to Apple. For EU-based users, the feature won’t be available on the iPhone 18 models it seems designed for, but iOS 27, iPadOS 27, and MacOS 27 will allow users to view reference images. For now, API access and viewing capabilities in the 27 software class won’t let users actually take photos in Reference Image mode, though Apple said it’s aiming to expand capture capabilities next year. For now, if you don’t have an iPhone 18 Pro or Pro Max, you’ll just be able to practice your image comparison skills.
Apple’s flashy new Duo foldable, which closed the show, also won’t have Reference Image. That’s because the capability is tied to Apple’s Fusion Main camera system, which Duo lacks.
Currently, reference images only appear on other Apple devices — so if you wanted to verify that someone’s iPhone photo was real, you’d only be able to use Reference Image for that with another iPhone, Mac, or iPad. Apple said it’s working on expanding to third-party camera systems next year.
Opaque boundaries
Apple Reference Image isn’t open source, though, which left Abelson with questions.
“It’s very hard to figure out how Apple’s doing things and why,” he said. “They say they’re doing cryptographic hashes. That’s great – what kind of cryptographic hashes? What do those look like? How are they doing device attestation? How does the sensor work? These are all things that are not exposed yet or public and may never be.”
Also: A low-tech solution from the past may be your best defense against AI deepfakes
For Abelson, that makes it hard to know where possible security vulnerabilities may crop up. He added that OpenOrigins plans to open-source its entire tech stack in the next month, “mostly because we want to understand the potential security vulnerabilities.”
“Apple has an amazing security record, but closed-sourcing as a concept is complicated in a cybersecurity world,” he added.
For Apple, though, its reputation validates keeping this info proprietary. An Apple representative said the company would “stake the Apple brand” on the fact that Reference Image is a reliable source of truth about images.
3D depth capture
Abelson also noted that Apple isn’t currently focused on 3D depth capture, which helps differentiate between a real-life scene and a photo of a photo. I tested this feature in the Source app: It creates a 3D depth map of whatever you capture, taking multiple photos from different angles and stitching them together. You can then view the depth map of an image at various levels of definition.
When I tried this by taking a photo of a photo, the image lacked the above depth; it was clear Source couldn’t read variation in the pixels.
“Because of the depth map, we are able to distinguish between the curvature of a human face versus the flatness of a screen,” OpenOrigins co-founder Dr. Manny Ahmed told ZDNET in March.
Abelson noted that picture-of-a-picture attacks have been a common issue in provenance for years and are an issue for other standards like C2PA.
So why wouldn’t a company that pours so much into its camera manufacturing — and is ostensibly taking the issue of provenance seriously — opt for 3D mapping at the start? When asked, an Apple representative told ZDNET that without the use of an additional camera, 3D mapping is often software-based and therefore spoofable — not adequately secure by Apple standards. To ensure Reference Image is a reliable photo fact-checker, the company chose to focus on a hardware-based approach, which it believes is more airtight.
“We don’t think this is breakable,” an Apple representative told ZDNET.
Still, Abelson thinks another factor is simply demand and market uncertainty.
“Apple has created limitations in this, I think, intentionally, that are just relatively interesting,” Abelson said. “I think it’s partly because they don’t want to over-invest in the robustness of technology that’s unproven in the market. I imagine over iterations of years, Apple is going to focus more on how we create more robust standards for this, as we see exploitations.”
As with any first-generation technology, many users trying Reference Image will reveal any gaps Apple needs to address.
Unclear permissions and isolated control
Abelson argued that because the Reference Image feature is governed by Apple, the company reserves the right to retroactively remove reference images and their data. Apple told ZDNET it would only do so under very specific conditions, as a “backstop.” For example, if a reference image sets off flags by not following the laws of physics or matching the class of sensor on the corresponding device, Apple would take note and invalidate that sensor. Basically, Apple doesn’t see it happening often, but the decision would be at the company’s discretion. We may get more details on this next week when Apple is set to publish additional information on the feature.
Still, Abelson’s point remains that it’s a possibility worth considering when open-source alternatives to provenance exist.
“We don’t have a framework to explain or make decisions as to why Apple may do this, which is complicated in the age of trust,” he said.
OpenOrigins Source, by contrast, is decentralized and records verified images on the blockchain. Abelson said that it was an explicit choice to avoid the security vulnerability associated with a single controller.
A single trust standard
We’re still far from provenance being a mass public concern (just labeling AI-generated videos seems slow to take, let alone understanding whether people care if what they’re seeing is real). For Abelson, any provenance tool needs to be universally accepted and trusted by journalists, investigators, and others capturing evidence to really matter — not knowing who is allowed to remove proofs or why undermines that.
“It becomes just a small layer of vulnerability – if you’re a person who wants to deny that a photo in fact existed, you could make an argument that Apple was out to get you,” he said. “We designed our blockchain in a way that we believe is the most efficient design to allow for mass photo capture. Everybody who has a node is part of maintaining that network of proofs.”
If Apple sees value in Reference Image, Abelson thinks the company has the opportunity to set the bar for content provenance, but taking over for open-source alternatives may be tricky without significant investment in security.
“I think that any system that creates universality, including Apple’s, will one day need to consider how to decentralize these networks effectively and ensure that there’s a level of trust that is shared among users,” he said.

