Strictly speaking, properly checking C2PA metadata requires network requests in the general case, because you need to check if the signing certificate has been revoked or not via OCSP.
But in anthropic's use case they can probably get away with just pinning their own certs in the verification webpage.