Apple has released the Apple Reference Image feature for the iPhone 18 Pro series. This feature hardware-signs and binds timestamps to photos via the SEPC security processor during capture, creating an unforgeable "digital negative" that ensures images originate from genuine sensors, are tamper-proof, and resist AI-generated forgeries.Article author, source: AIBase
Apple published a blog post on September 15 detailing the Apple Reference Image feature introduced on devices such as the iPhone 18 Pro and iPhone 18 Pro Max, supporting pixel-level annotation of real image data.

Pressing the shutter signs within SEP, creating a "digital negative."
Apple Reference Image is an optional reference mode that binds hardware-level proof and timestamps to photos during capture, ensuring the image originates from a real sensor, preventing tampering, and countering AI-generated forgeries—ideal for news organizations and evidence preservation scenarios.
On the technical implementation side, after the user presses the shutter button, the system signs critical metadata (such as focal length, digital zoom, etc.) within the SEP (Secure Enclave Processor) to create a tamper-proof "digital negative" record. For timestamps, the system provides lower and upper bound timestamps of the capture and embeds them into the reference image via an encrypted timestamping service, ensuring the image’s temporal accuracy and verifiability.
After signing at the sensor level, Apple complements this with a verification chain powered by Private Cloud Compute to ensure end-to-end immutability while protecting user privacy and preventing exposure of personal information.
Change from "sign after bidding" to "sign during bidding"
In use cases such as news organizations, evidence preservation, and scenarios requiring trustworthy image sources, this feature combats AI-generated content by providing an audit trail of “authentic sources.” Unlike traditional metadata-based evidence systems, which typically sign images after editing, Apple Reference Image performs hardware-level signing and timestamp binding at the moment of capture, making it theoretically more resistant to tampering and enhancing credibility.
