Every asset carries a C2PA 2.1 manifest recording the model, seed, parameters and references used to make it, plus AI-generated labelling.
Without a signing certificate the manifest is unsigned, and it is marked unsigned. An unsigned manifest still carries the provenance data and is still useful; presenting it as signed would be a false authenticity claim, which is precisely the thing C2PA exists to prevent.
To sign, provide an X.509 certificate. Everything else already works.