A photo that can be proven to have been taken exactly as it appears: That's what Apple promises with the new reference mode of the iPhone 18 Pro. Now the company has revealed how this verification is technically achieved – from the key generated by the camera sensor at the factory to the retraction of fake photos. However, there's a catch at launch in Germany and Austria.
Apple Reference Image, internationally known as the Apple Reference Image, is one of the camera features Apple introduced with the iPhone 18 Pro and iPhone 18 Pro Max on September 9th. According to the German press release, a new sensor in the main camera signatures the captured pixels, and Private Cloud Compute uses this signature to create an unchanging reference image. This reference image is displayed alongside the actual photo in the Photos app, allowing for easy comparison.
On September 16, Apple provided further details in a post on its Security Research blog, authored by the security department in collaboration with the camera and photography team. The trail goes back even further: clues to a method for verifying the origin of photos taken with the iPhone camera were already present in the code of the fifth beta of iOS 27, which was released on August 10. The iPhone 18 Pro will be available in stores starting Friday, September 18.
Key Facts at a Glance
- The main camera's sensor signs the pixel data directly during capture, even before the operating system processes it.
- The reference image is developed in Private Cloud Compute, whose software is publicly auditable.
- Each image is captured between two cryptographic timestamps; fake images and entire sensors can be revoked.
- Those who take photos remain anonymous, and Apple does not see the image content.
- In the EU, it is not possible to take a reference image at the start, but it is possible to develop and view it.
Signature in the sensor instead of at the end of processing
Apple justifies this approach by citing weaknesses in previous methods. According to Apple, systems based on the C2PA standard only append the source information after the image has been captured and document the processing steps from that point onward – meaning that a viewer cannot detect any manipulation anywhere in this chain. Other solutions only sign the image at the end of the processing, meaning that a compromised operating system could alter the photo beforehand.
For the reference image, the sensor therefore starts in its own, secure reference mode. It signs the pixel data immediately after capture, and its firmware is then prohibited from modifying it. The key for this is generated by the sensor during its initial factory setup; the private part never leaves the sensor. This mode is optional and only available for the main camera.
Information not originating from the sensor, such as zoom level and focal length, is signed by the Secure Enclave with its own key. Both keys are linked in the device manifest, allowing verification later on to determine whether the sensor and Secure Enclave came from the same iPhone. A removed sensor in a different device will therefore be detected.
The result is a digital negative, stored as a DNG file on the iPhone and linked to the normally processed photo. It can remain there indefinitely and can even be shared undeveloped – a process Apple believes professional photographers might find useful.
Development takes place in Private Cloud Compute
Only when a reference image is to be created does the iPhone upload the negative. Private Cloud Compute verifies all signatures up to the manufacturing certification authorities and only proceeds if the sensor and Secure Enclave are assigned to the same device. The following steps then transform the raw data into a viewable image: color reconstruction, tonal adjustment, and compression into a JPEG file.
Experts should be able to verify for themselves that nothing is falsified. Every production software version of Private Cloud Compute is documented in a tamper-proof transparency protocol, the program files are publicly accessible, and the iPhone only sends data to servers that verify a version listed there. These are the same assurances Apple uses to secure the processing of Apple Intelligence queries.
The finished reference image is signed by Apple's signature service using a combination of classical and quantum-safe methods. This means that an image deemed authentic in 2026 should still be verifiable decades from now. To Apple's knowledge, no other system for verifying the origin of photographs offers such protection.
After development, the negative is automatically moved to the deleted photos. Anyone who wants to keep it can restore it; otherwise, it is permanently deleted after 30 days.
Time window and cancellation
The iPhone doesn't use its own clock to determine when a photo was taken, but rather two timestamps from an Apple service. The first is continuously retrieved in the background, on average about every 15 minutes worldwide, and the most recent one is embedded in the photo. The second is requested immediately after the photo is taken; without a network connection, it is retrieved later. Apple guarantees that the photo was taken between these two times.
If the verification of the first stamp fails, Private Cloud Compute sets March 31, 2026, as the lower limit, because the function did not exist before then. If the second stamp is missing, the date of development is considered the upper limit. An image developed today, September 16, would therefore have a time window of 169 days in the worst-case scenario.
In the event that forgeries occur despite all security measures, Apple has built in a revocation mechanism. A neural network in Private Cloud Compute evaluates with each development whether the image exhibits the physical properties of genuine raw data from Apple's sensors, and a companion service continuously records this value for each sensor. Individual photos, as well as all images from a single sensor, can be revoked—Private Cloud Compute will no longer sign anything for a locked sensor.
Those taking the photos remain anonymous. Other solutions require a person or institution to authenticate an image using their own login credentials, which Apple considers a risk for photographers in conflict zones, for example. With the reference image, Apple signs the image, and it's impossible to tell from the outside whether two reference images were taken by the same device.
According to Apple, the image content remains hidden even from the company itself. The opt-out service only stores identifiers of the photo and sensor, not pixels, and does not make its list public. Requests to the timestamp service are processed in such a way that the service does not learn the iPhone's IP address, and because the opt-out check takes place on the device itself, no one knows which image is currently being viewed.
Entry into the EU blocked at launch
In a footnote to the press release, Apple mentions two regional limitations. In China, Apple's reference image is not available at launch due to legal regulations. In the EU, the image is missing for the iPhone 18 Pro models at launch – however, reference images can already be developed and displayed with iOS 27, iPadOS 27, and macOS 27.
In Germany and Austria, it will not be possible to create reference images with the iPhone 18 Pro at launch. Switzerland is not affected: Apple explicitly states that the restriction applies to the EU, and the same wording is used in the Swiss version of the announcement. This adds another camera function to the list of Apple features that are, at least partially, unavailable in the EU.
| Region | Shot on iPhone 18 Pro | Develop and display |
|---|---|---|
| Germany, Austria (EU) | Not available at launch | with iOS 27, iPadOS 27 and macOS 27 |
| Switzerland | without restriction | without restriction |
| China | Not available at launch | Not available at launch |
First, a tool for editorial teams
Technically, Apple is on the right track. A verification method that only kicks in at the end of image processing merely proves that nothing has been altered since then – the signature in the sensor closes precisely this gap. One limitation remains: A reference image shows what the sensor has captured, not whether the scene is staged or taken out of context. Furthermore, it only helps against deepfakes and other AI-generated forgeries where someone has deliberately activated the mode.
In German-speaking EU countries, this feature is therefore primarily for recipients. Newsrooms, photo agencies, and fact-checkers can verify reference images taken outside the EU, and third-party apps can also display them via the interfaces in iOS, iPadOS, and macOS 27. However, if you want to use the iPhone 18 Pro to prove the authenticity of your own photos, you won't be able to do so in Germany and Austria at launch.
Would you trust a photo online more if a reference image was available – or does it ultimately still depend on who shares it? Tell us in the comments what criteria you use to determine if a photo is genuine.



