A little clarity for every image

How to Check if an Image Is AI-Generated

Learn what image metadata, Content Credentials, OpenAI signals and AI detector scores can tell you, and why a missing signal cannot prove a photo is real.

Start with the original file and its source history. Read provenance records, check supported source-specific signals and treat model scores as predictions with limitations. No missing tag or single detector score proves that an image is a genuine photograph.

AI Photo Checker result showing the completed public sample evidence report and analysis sections.
AI Photo Checker result showing the completed public sample evidence report and analysis sections.

A practical order of checks

First obtain the closest available original and record where it came from. Inspect local metadata and Content Credentials. Then use a source-specific verification service where appropriate. Add a pixel-based model only if its coverage helps answer your question and you accept sending the image to that provider.

Keep the file and the context together: publication URL, date obtained, available original, any known edits and the exact version checked. A screenshot or compressed copy can have different metadata and model behaviour. Do not inspect private images without authority to handle them, and review the data-transfer notice before an online check.

A readable credential is not the whole validation

Content Credentials can carry signed statements about an asset’s creation or editing history. Validation needs to distinguish whether the record exists, whether its signature and asset binding pass, and whether the signer is trusted under the verifier’s policy. Those are separate questions.

A claim that says AI was used is useful source evidence when interpreted with its validation state. A credential describing an ordinary edit does not imply the whole image was generated. Equally, a file without a credential is not automatically a camera original. A complete report should show what was checked and where validation was unavailable rather than replacing these distinctions with one confidence percentage.

Read ordinary metadata cautiously

XMP source fields, AIGC labels and generation-workflow records can explain how a file claims to have been made. Many such fields can be copied, edited or removed. Treat them as stored records with source context, not as a verified identity just because the text names an application.

Automatic1111 parameters and ComfyUI workflows can contain prompts and technical settings. Avoid publishing those details without reviewing them for private information. Camera EXIF is also editable and can remain in a composite. A model name in a comment, an unused workflow node or a familiar camera make should not become a stronger conclusion than the evidence supports.

Source-specific verification has limited coverage

OpenAI’s provenance check returns applicable C2PA and SynthID results for images. Its documentation states that a not-detected outcome does not rule out OpenAI generation: supported signals may be missing or degraded, and some older content or other generators fall outside coverage. An unavailable request is not a negative result.

In a separate CheckImageDPI test on September 15, 2026, one newly generated original PNG returned detected SynthID and trusted C2PA from the official service. That observation establishes a positive result for that file. It does not establish that every generated image, transformed copy or open-source library will produce the same outcome.

Case 1: a real-photo score changed after compression

In our September 15, 2026 integration sample batch, sample 06 was the NASA astronaut image distributed through scikit-image. Hive returned an AI score of 0.531209 for the original. Sample 07, a reduced JPEG Q50 derivative, returned 0.001501. These are provider scores on particular files, not calibrated probabilities created by CheckImageDPI.

The case shows why a universal 0.5 cutoff or a generator-name guess can mislead. It does not prove that compression always lowers scores or that one provider is generally better. Preserve the transform history and inspect the original source before making a claim about a person or publication.

Case 2: valid and trusted are different

Sample 04 was the Content Authenticity Initiative’s Firefly tabby-cat example. The OpenAI response reported an Adobe issuer and a valid C2PA state, while its OpenAI-specific detection outcome remained not detected. A separate local validation run classified the available credential as valid but untrusted under that run’s trust configuration.

Those statements describe different layers. An Adobe credential is not proof of OpenAI generation, and structural validity does not by itself identify a signer as trusted. When reporting the result, name the verifier, date and validation state instead of collapsing them into “verified AI” or treating the issuer string as a successful trust check.

Case 3: an original and a stripped copy differed

Sample 01 was the CAI ChatGPT example. In that batch, the OpenAI response included issuer OpenAI with an invalid C2PA state and a not-detected outcome. Sample 02 was a metadata-stripped derivative of the same source; it reported not_present for C2PA. The later newly generated positive example above was a different file.

This demonstrates why “not detected” and “no credential” cannot be substituted for each other. The sample set contained ten files, including derivatives from the same originals, and was designed to test integration rather than estimate accuracy. It is not a representative benchmark or evidence of a guaranteed detection rate.

Use scores to guide review, not settle disputes

A pixel model estimates patterns from its training and supported image types. Keep the provider’s score meaning, model version when available and completed/failed status. Do not average two incompatible scores into an invented certainty. Deepfake face-replacement analysis is also different from whole-image generation detection.

If evidence conflicts, return to the publication history, request an original or seek additional corroboration. If a check fails, report the failure and retry only when appropriate; do not replace it with zero percent. For high-impact decisions, a detector should be one input to a documented review, not the sole basis for an accusation. Visual oddities can suggest questions, but fingers, reflections and text are not a dependable standalone test.

Sources and method

Reviewed on September 15, 2026. Numerical examples are worked calculations, not measurements of your image. Linked product documentation describes the cited application or standard; CheckImageDPI examples and test observations are identified separately.

Frequently asked questions

Does a zero or low score prove a photo is real?

No. It means the model returned a low score for its supported task on that file. It is not an authenticity certificate.

Does missing metadata prove someone hid AI use?

No. Many ordinary workflows remove metadata. Absence alone does not explain why it is missing.

Can I combine two scores into one probability?

Not without a validated calibration method. This tool keeps providers and their meanings separate.