Image credit: Suzanne Kantra/Techlicious generated by ChatGPT
Apple has built a way for the iPhone 18 Pro and Pro Max to prove that a photo came straight out of the camera, untouched by AI or editing software. The feature, called Reference Image, is a response to a world where a growing share of images online are AI-generated or altered, and where a real photo increasingly needs its own proof of authenticity to be trusted at all.
Turning on Reference Image switches the camera into a dedicated capture mode. The moment a photo is taken, the sensor itself cryptographically signs the raw pixel data along with a timestamp and information identifying the specific device. Apple calls the result a secure digital "negative": a sealed record of exactly what the sensor captured, before any processing takes place on the device.
That negative isn't a finished photo yet. To turn it into one, the phone sends it to Apple's Private Cloud Compute, the same private server infrastructure Apple uses for other tasks not handled on-device. There, publicly verifiable code "develops" the image (adjusting color and detail the way any camera normally would) and calculates a confidence score for how likely it is that the photo is genuine. The finished image gets a signature Apple claims will hold up even against future quantum computers. Apple can revoke trust in an individual photo, or in an entire iPhone's sensor, if it later turns out to have been compromised.
Reference Image is opt-in and must be switched on before taking a photo. Photographers who want the option, for a court case, an insurance claim, or an investigative story, get cryptographic backing that a specific photo is what their camera actually saw. However, there is a practical limit: without an internet connection at the moment of capture, the negative can't get an upper-bound timestamp proving it couldn't have been created after a certain moment, because that requires reaching Apple's servers. It can only get a lower one, proving a photo couldn't have been created before a certain moment.
Apple isn't the first phone maker to tackle this problem, but its approach differs from the industry's existing answer. Google and other Android phone makers back the Content Credentials standard (C2PA), an open specification that multiple companies contribute to and that attaches metadata to a photo after the image is processed. Apple's system instead signs the sensor's raw data before any processing happens, which makes Reference Image proprietary to Apple's own hardware and cloud rather than an open standard other companies can adopt. And, a secure digital negative also doesn't stick around by default: Apple says it moves to the Recently Deleted album after 30 days unless you manually save it.
Read more: 4 iOS 27 settings you should change the day you install it