I'd always thought the usefulness of C2PA was limited to verified devices in custody by trusted actors.
Like a security camera with a tamper evident enclosure, or an organisation being able to attest that they recorded the imagery.
The idea that it could be used to attest the authenticity of any random person or device surely wasn't a thing serious people expected was it?