Llama · Meta · C2PA

The weights are not the watermark. Meta’s key stays with Meta.

Meta signed the Code of Practice. Instagram is adding Content Credentials. That is a file. Llama is also a set of weights you can run yourself. A local completion does not arrive pre-stamped. A reply from a Meta-hosted product might.

Reviewed by · Published

or type below, or drop a file

Inspected in your browser. A plan is required to finish.

No text? Try one of these:

Choose the surface, then the tool

SurfaceGifi actionWhat can be verified
Ordinary wordsRewrite the proseThe words changed; no private detector certificate
C2PA, EXIF, XMP, propertiesStrip named metadataAction list plus an independent reinspection
Pixels, audio, or videoNot supportedNo removal claim

A download is not a signature

The weights do not include Meta’s detector key. If you sample Llama on your own machine, those tokens are yours unless you added a mark. Hosted Meta serving the EU is under Article 50. That output may be marked. Meta has not published the text method.

The public part is a note in the file

Instagram Content Credentials are a signed note. We can strip the local label. Soft binding can survive. A statistical trail in hosted text, if it exists, needs a rewrite.

What this cannot promise

  • A rewrite does not prove the text was never AI-assisted.
  • No one outside the lab can certify their detector. The key is private.
  • Pixel watermarks, audio and video are out of scope.

Questions this usually raises

Does every Llama reply have a watermark?
No. Local weights do not. Hosted Meta might, and they have not said how.
What about Instagram or Meta AI images?
Those can carry C2PA. Pixels are out of scope.
Can I delete a Llama watermark like EXIF?
Only if it sits in the file. Word choice has nothing to delete.

Llama

Statistical signal? Rewrite the prose.

A Llama mark, if it is in the words, needs different words. Hidden characters and C2PA need the file cleaner.