Is This Photo AI-Generated? How to Check an Image Before You Use It as Evidence
Last reviewed September 29, 2026 · 7 min read · By the PEA team (Lumina Spark)
Short answer: No single check can tell you for certain that a photo is genuine: official checks can confirm some AI-made images, but a clean result proves little. Work through Content Credentials, the official watermark checks, the file's metadata and a careful visual review, treat any detector score as just one input, and write down exactly what you did and found.
Start with the right question
"Is this AI?" is really two questions: where did this file come from, and has it been changed? Provenance tools try to answer the first by reading information attached to or embedded in the file. Detectors try to infer an answer from the pixels. Both have gaps. In its 2024 report on synthetic content (NIST AI 100-4), the US National Institute of Standards and Technology concluded that none of these techniques is a complete solution on its own, and that the value of each depends on the use case.
Before you check anything, get the best copy you can: the original file from the person who took it, not a screenshot or a version forwarded through a messaging app. Save it unchanged, note where, when and from whom you got it, and work on copies. Record a hash (such as SHA-256) of the original so you can show later that it didn't change.
Step 1: Check for Content Credentials (C2PA)
Content Credentials are based on an open standard from the Coalition for Content Provenance and Authenticity (C2PA). A camera, phone, editing app or AI generator can attach a signed record of how a file was created and edited, including whether AI was used, and a verifier can show who signed that record.
How to check:
- The Content Authenticity Initiative's Verify tool (contentcredentials.org/verify): drop in a file to inspect any credentials and the history they record. It accepts common formats such as JPEG, PNG, HEIC and WebP.
- The Gemini app: Google says Content Credentials checks are available at gemini.google.com and in the Android app, with iOS to follow.
How to read the result:
- Credentials present: useful context about origin and edits. Some devices now sign at the point of capture; Google says the Pixel 10 was the first phone to do this in its built-in camera app. Note who signed the record and what history it shows.
- No credentials: this tells you very little. Most images still don't carry them (the Verify tool itself notes they are still rolling out), and the information can be lost through uploads, downloads, format changes, resizing or screenshots.
Step 2: Run the official watermark checks
Some AI companies embed invisible watermarks in what their tools produce and offer free public checks:
- Google (SynthID): in the Gemini app, you can upload an image, video or audio file and ask whether it was created or edited with Google AI. You need to be signed in, and there are limits, such as one file at a time and 100 MB per file. Google says a detected watermark means all or part of the content was created or edited by its AI models, and that content without one could still come from other AI systems. In May 2026, Google announced it was bringing this check to Search and Chrome.
- OpenAI: OpenAI's public Verify page checks an uploaded image or audio file for provenance signals associated with its tools, including C2PA metadata and SynthID watermarks. It is designed for content made with ChatGPT, the OpenAI API or Codex. If nothing is found, OpenAI says the content could still be from its tools (for example, if metadata was stripped or the file predates these signals) or from another company's model, which the tool doesn't detect.
In California, generative AI providers with over 1,000,000 monthly visitors or users have been required since August 2, 2026 to offer a free public tool that checks whether image, video or audio content was created or altered by their own system. That points to the main limit of all these checks: each one recognizes only its own company's tools. A positive result is meaningful; a negative one is not a clean bill of health. A positive result can also reflect an AI edit to a real photo rather than a wholly invented scene.
Before uploading sensitive evidence to any online tool, read its privacy terms. OpenAI, for example, says files uploaded to Verify are not stored unless legally required and are not used to train its models.
Step 3: Read the metadata, knowing its limits
If you have the original file, its EXIF data may show a camera model, date, time and settings, and sometimes traces of editing software. Record it, but keep its limits in mind:
- It can be changed. NIST notes that anyone copying or editing a file can alter or falsify its metadata.
- It's often stripped. Many platforms remove at least some metadata on upload to protect privacy, and files that have passed through social networks or messaging apps often arrive with little or none of it.
- Missing metadata proves nothing either way.
Treat metadata as consistent or inconsistent with the account you've been given, not as proof.
Step 4: Look closely, but don't rely on your eyes alone
Visual clues can prompt good questions: garbled text, odd hands or teeth, inconsistent shadows and lighting, unnatural repeated patterns, backgrounds that don't make physical sense. A reverse image search may turn up an earlier original, or show that a supposedly new photo has been online for years.
But people are not reliable judges on their own. In a Microsoft AI for Good Lab study of about 287,000 image judgments by more than 12,500 participants, people told real and AI-generated images apart correctly 62% of the time, only modestly better than chance. Generators keep improving, so clues that worked last year may not work now.
Automated detectors are one input, not a verdict
Detectors that score an image without relying on a watermark can help with triage, but treat their output with care:
- They may not generalize. NIST notes that detectors often perform best on content from the generators they were trained on.
- False positives do harm. NIST warns that wrongly labeling authentic content as AI-generated can be extremely damaging.
- Advertised accuracy may not hold. In 2025, the US Federal Trade Commission finalized an order against Workado, which had marketed its AI Content Detector as 98% accurate; the FTC alleged that independent testing showed just 53% accuracy on general-purpose content. That tool analyzed text, but the lesson carries over to images.
If a detector result matters to your case, ask what the tool was tested on and whether that resembles your image, and consider an independent forensic examiner.
How to document what you checked
A simple record made at the time makes your checks useful to a lawyer, a court, an insurer or a platform. For each image, note:
- The file: name, size, format, SHA-256 hash, and where, when and from whom you received it.
- Each check: the tool, the date and time, what you uploaded, and the result in the tool's own words. Save a screenshot or export of each result.
- What you couldn't check, and why (for example, "only a forwarded copy available").
- Your conclusion, worded carefully. "No Content Credentials found; no Google or OpenAI watermark detected; no metadata" is accurate. "Proved genuine" is not.
Keep the original untouched and store the log with it.
What PEA can and can't do
PEA (Professional Evidence Authenticator), from Lumina Spark in Japan, runs several independent analyses on an uploaded image and shows its findings, separating confirmed facts from concerns, with a grade from 1 to 10. It checks Content Credentials (C2PA) and, where available, some official watermark checks. When there isn't enough to go on (a frame from a video, a photo of a screen or printout, or no usable material), it says "Not assessed (Grade –)" instead of guessing, and suggests a human review. Its certificate fixes the file with a SHA-256 hash and seals it with an Ed25519 digital signature and an RFC 3161 timestamp from a third-party time-stamping authority, which anyone can verify by certificate number on PEA's public verification page. It does not prove when or by whom a photo was taken. Staff see an image only if you request a human review and consent, and free results are deleted after 7 days.
PEA runs in Japanese today and the English version is in early access. If it sounds useful, you're welcome to join the early-access list at our early-access page.
This article is general information, not legal advice.
Sources
- NIST AI 100-4, Reducing Risks Posed by Synthetic Content (November 2024), publication page: https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content
- NIST AI 100-4, full report (PDF): https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-4.pdf
- C2PA (Coalition for Content Provenance and Authenticity): https://c2pa.org/
- Content Authenticity Initiative, Verify tool (contentcredentials.org/verify redirects here): https://verify.contentauthenticity.org/
- Gemini Apps Help, "Verify AI-generated images, videos, and audio": https://support.google.com/gemini/answer/16722517
- Google, "Making it easier to understand how content was created and edited" (May 19, 2026): https://blog.google/innovation-and-ai/products/identifying-ai-generated-media-online/
- OpenAI, "Advancing content provenance for a safer, more transparent AI ecosystem" (May 19, 2026, updated July 31, 2026): https://openai.com/index/advancing-content-provenance/
- OpenAI, "Verify OpenAI-generated content": https://openai.com/research/verify/
- California Business and Professions Code § 22757.1 (definitions): https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=22757.1
- California Business and Professions Code § 22757.2 (AI detection tool): https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=22757.2
- Roca et al., "How good are humans at detecting AI-generated images? Learnings from an experiment" (Microsoft AI for Good Lab, 2025): https://arxiv.org/abs/2507.18640
- FTC, "FTC Order Requires Workado to Back Up Artificial Intelligence Detection Claims" (April 28, 2025): https://www.ftc.gov/news-events/news/press-releases/2025/04/ftc-order-requires-workado-back-artificial-intelligence-detection-claims
- FTC, "FTC Approves Final Order against Workado, LLC" (August 28, 2025): https://www.ftc.gov/news-events/news/press-releases/2025/08/ftc-approves-final-order-against-workado-llc-which-misrepresented-accuracy-its-artificial