The era of declaring an image AI-generated because the skin looks too smooth or a hand looks strange is over. Generators improve quickly, while ordinary photographs acquire unnatural artifacts through editing, compression, compositing, and screenshots. A synthetic image can look photographic, and a real photograph can look synthetic. The useful question is no longer “Does it look like AI?” but Where did it come from, what transformations did it pass through, and can those records be verified?
This guide reflects the C2PA 2.4 specification, OpenAI's image verification tool, Google DeepMind SynthID, Adobe Content Authenticity Inspect, and NIST guidance available on July 30, 2026. The practical conclusion is simple: do not rely on one detector. Combine signed provenance, provider-specific watermarks, the original file, publication context, and independent evidence.
Why visual clues and one AI detector are not enough
Pixel-based detectors probabilistically classify compression artifacts, textures, frequencies, or patterns associated with known generators. New models, cropping, filters, screenshots, and recompression change that distribution. A heavily edited camera photo can trigger a false positive, while post-processing can weaken signals in generated media.
NIST separates digital content transparency into two broad families: provenance data tracking and synthetic-content detection. Provenance records creation and editing history. Detection estimates whether observed signals resemble synthetic content. They answer different questions and should support, not replace, each other.

| Evidence layer | What it checks | Main strength | Common mistake |
|---|---|---|---|
| C2PA Content Credentials | Who signed claims about creation and edits | Cryptographically verifies integrity and history links | Treating absence as proof of human creation |
| Watermarks such as SynthID | Whether a supported provider embedded a hidden signal | Designed to survive some crops, filters, and compression | Assuming it detects every model |
| Pixel-based AI detector | Whether visual statistics resemble learned generator patterns | Can assist when provenance is unavailable | Ignoring model drift and false positives |
| Source and context research | Whether first publication, date, and other evidence agree | Needed to assess factual claims in the image | Requires time and human judgment |
C2PA is a history receipt, not a truth stamp
C2PA Content Credentials are an open standard for attaching declarations about origin and editing history to media. Digital signatures and content bindings help determine whether the declarations belong to the asset and remained intact. C2PA 2.4 extends the ecosystem with JSON-based credentials, additional asset support, and external-reference mechanisms.
When credentials appear, examine more than the badge:
- the signer and signature trust state;
- the recorded capture, generation, or editing tool;
- declared actions such as cropping, color adjustment, or generative editing;
- ingredients and links to prior versions;
- validation errors or changes after signing.
C2PA explicitly warns that valid provenance does not prove an image's claims are true, and missing credentials do not make an image untrustworthy. A faithfully signed synthetic scene can still be used deceptively. A real photograph from an older camera or unsupported editor may have no credential.
Why evidence disappears during sharing
Messaging and social platforms may resize and re-encode files. A screenshot does not inherit the original file's embedded metadata. An incompatible editor may drop a C2PA manifest. Soft bindings and external provenance stores can sometimes reconnect separated records, but they are not implemented everywhere.

Therefore, “no Content Credentials” or “watermark not detected” should be recorded only as no supported signal found. It must not become “verified human-made.” Conversely, a detected provider watermark is strong evidence of generation or editing in that provider's ecosystem, not proof that the depicted event happened.
A practical five-step provenance check
Step 1: Preserve the original file and publication context
Obtain the original file rather than a messaging preview or screenshot whenever possible. Record the filename, download URL, account, publication time, and surrounding description. Before uploading to a verification service, check for private information, location data, or confidential material. Sensitive files should stay inside an approved local workflow.
Step 2: Inspect Content Credentials
Use a verifier such as Adobe Content Authenticity Inspect on the file or a supported screenshot. Read the signer, creation and edit actions, ingredients, and validation errors. A signature establishes that a declaration is associated with a signer and has not silently changed; it does not guarantee every claim made by that signer.
OpenAI's image verification tool checks supported OpenAI-generated images for C2PA metadata and SynthID signals. It is not a universal classifier for every provider, so preserve the scope of its result.
Step 3: Check provider-specific watermarks
Google says users can upload an image, video, or audio clip to Gemini and ask whether a Google AI SynthID watermark is present. SynthID is inserted at generation time and designed to remain detectable after some cropping, filtering, and lossy compression. A negative result means the supported Google signal was not found; it does not identify another generator or establish human authorship.
Step 4: Corroborate the source and scene independently
Find the earliest publication and compare earlier versions, alternate angles, the creator's account, and reliable reporting. Check whether landmarks, weather, shadows, time, and event dates agree, but never treat one visual anomaly as decisive. For journalism, commerce, hiring, identity, or safety decisions, request originals, burst sequences, or additional evidence.
Step 5: Record an evidence level, not a binary verdict
Use calibrated labels:
- Source confirmed: trusted provenance and independent context agree.
- AI-generation signal detected: a supported credential or watermark was found.
- Change or conflict detected: validation errors or provenance-context mismatch.
- No supported signal found: the tested tools returned no supported evidence.
- Unresolved: the original, context, or independent evidence is insufficient.

Decision table for interpreting results
| Observation | What you may conclude | What you must not conclude | Next action |
|---|---|---|---|
| Trusted C2PA record matches context | Recorded history is connected to the file | Every depicted claim is factual | Verify signer and original source |
| SynthID or provider signal detected | Supported provider generation or editing is likely | Every pixel is AI-generated | Record the detector's exact scope |
| Credential validation error | The file-record relationship has a problem | Malicious manipulation is proven | Obtain the original and compare versions |
| No signal detected | Tested tools found no supported signal | Human-made or a real-world event | Investigate source and external evidence |
| Signals conflict with external facts | Additional review is required | One signal settles the case | Pause high-impact use and escalate |

A ten-minute checklist
- [ ] Obtain the original rather than only a screenshot.
- [ ] Record the earliest URL, account, and publication time.
- [ ] Inspect the C2PA signer, actions, ingredients, and error state.
- [ ] Use a watermark verifier supported by the relevant provider.
- [ ] Never interpret no detection as proof of human authorship.
- [ ] Search for earlier versions and independent sources.
- [ ] Verify the depicted claim separately from provenance.
- [ ] Do not delegate high-impact decisions to one detector score.
- [ ] Label the result as confirmed, detected, conflicting, unsupported, or unresolved.
Conclusion: ask for provenance and evidence, not a visual hunch
The biggest risk in AI-image verification is not merely an imperfect tool. It is turning an incomplete result into a definitive judgment. C2PA verifies recorded history, SynthID searches for signals from a particular ecosystem, and pixel detectors provide probabilistic assistance. Factual truth still requires the original source, timeline, and corroborating evidence.
Preserve the original, inspect signed records and provider watermarks, corroborate context, and state confidence honestly. It is slower than searching for a magical AI detector, but it is more accurate, auditable, and fair.
Primary sources
- C2PA 2.4 Content Credentials specification
- C2PA 2.4 Harms Modelling guidance
- OpenAI image verification tool
- Google DeepMind SynthID
- Adobe Content Authenticity Inspect
- NIST AI 100-4 on synthetic-content transparency
Supported models, file formats, and privacy terms can change. Check each official service before uploading media.