How to Check If an Image Is AI-Generated: SynthID and C2PA
Check an image with SynthID Detector, OpenAI's verifier and Content Credentials tools, plus our test of which everyday edits strip C2PA labels.
- Published
- Reading time
- 8 min
- Category
- AI Tools
You can't prove an image is AI-generated by looking at it, but you can check for the labels many AI companies embed in their images. Upload the file to Google's SynthID Detector (opens in a new tab) to look for an invisible SynthID watermark, and to a Content Credentials viewer such as Adobe's Inspect (opens in a new tab) to read any C2PA label. If both come back empty, that doesn't mean the image is real: in our test, a plain screenshot and seven other everyday edits erased Content Credentials completely.
This guide covers the checks anyone can do, what Google's and OpenAI's tools can and can't tell you, and the results of our hands-on test of which edits strip Content Credentials.
How to check if an image is AI-generated
Work through these steps in order.
- Get the original file. Save the image itself instead of taking a screenshot, and use the highest-quality copy you can find. In our test, screenshots and re-saved copies lost their Content Credentials entirely.
- Check for Content Credentials. Upload the file to Inspect (opens in a new tab), Adobe's Content Credentials viewer (in beta), or to the Content Authenticity Initiative's Verify (opens in a new tab) tool. According to the Inspect documentation (opens in a new tab), it reads JPEG, PNG, WebP, HEIC, AVIF and other common formats, and shows No Content Credential when the file has none.
- Check for a SynthID watermark. Upload the same file to SynthID Detector (opens in a new tab). It looks for the invisible watermark that Google and several partner companies add to AI-generated images, video and audio. Google also lets you upload an image to the Gemini app and ask whether it was made with Google AI (Gemini Help (opens in a new tab)).
- If it might come from ChatGPT or another OpenAI tool, try OpenAI's verification tool (opens in a new tab). It looks for the two signals OpenAI uses for its images: C2PA Content Credentials and a SynthID watermark.
- Find where the image came from. Run a reverse image search (Google Lens and TinEye both do this) and look for the earliest copy. An image that first appeared on an AI art account, or that has no history before a viral post, deserves more doubt.
- Then look closely. Garbled text, warped hands or jewelry, shadows that fall in different directions, and backgrounds that melt into patterns are common signs of AI generation. Don't rely on these clues alone: a clean-looking image is unproven, not real.
How to read the results
| What the checker shows | What it means |
|---|---|
| SynthID watermark detected | Google says the file was likely made or edited with a model that uses SynthID |
| Valid Content Credentials that say AI created it | The signer recorded that the image is AI-generated, and the file hasn't changed since it was signed |
| Content Credentials present but invalid or flagged | The file changed after it was signed. The change may be harmless, such as a re-save |
| No watermark and no Content Credentials | Unknown. The image may be real, made by a tool that adds no labels, or stripped |
What SynthID Detector can and can't tell you
SynthID is an invisible watermark from Google DeepMind. It sits in the content itself rather than in a separate label attached to the file. In early October 2026, Google opened SynthID Detector to everyone (opens in a new tab), available globally in English, after testing it with journalists and media professionals. According to Google, it checks images, video and audio for watermarks from Google's own AI and from partners including OpenAI, NVIDIA and Kakao.
Two limits matter:
- It isn't a general AI detector. The SynthID Detector page (opens in a new tab) says it can only detect media from companies that use SynthID. An image from a generator that doesn't add the watermark will come back negative.
- A negative result doesn't rule out AI. Google says this on the same page. Watermarks are designed to hold up better than metadata. The Content Authenticity Initiative (CAI) describes watermarking (opens in a new tab) as surviving cropping, rotation and screen capture. Still, OpenAI's developer documentation (opens in a new tab) lists a degraded watermark as one reason a check can miss content its own models made.
We did not run SynthID Detector for this guide. This section is based on Google's published material as of October 2026.
What Content Credentials (C2PA) are, and how OpenAI uses them
Content Credentials are a signed record of where a file came from and how it was edited. They follow an open standard from the Coalition for Content Provenance and Authenticity (C2PA), and the record usually lives inside the image file. An AI tool that supports the standard marks its output as created by generative AI (trainedAlgorithmicMedia in the technical data, per the CAI documentation (opens in a new tab)). Because the record is cryptographically signed, a checker can show who signed it and tell whether the file changed afterward.
According to OpenAI, images made with its tools can carry both signals. OpenAI's developer API returns a separate result for each signal: C2PA, with a status of trusted, valid, invalid or not present, and SynthID. The API documentation (opens in a new tab) is direct about the limits. A "not detected" result can still be OpenAI content if "the metadata was stripped or has evidence of tampering, the watermark was degraded, it comes from a legacy generation model, or it was created before provenance signals were available." The tool also doesn't detect AI images from other companies.
The CAI's FAQ (opens in a new tab) puts it plainly: Content Credentials give a positive signal about an image's origin, not a negative signal about its authenticity. Because they are metadata, they are easy to lose. We measured how easy.
What we tested: which everyday edits strip Content Credentials
We took two C2PA-signed JPEG images, applied 12 edits to each, and checked every result with two C2PA tools.
Test images. We did not use a real ChatGPT or Gemini image. Both files were signed with test certificates that are published for developers:
- Our own synthetic 1600×1067 image, signed with the test certificate that ships with c2patool and labeled
trainedAlgorithmicMedia, the label the CAI documentation specifies for generative AI output. C.jpg, a signed sample from the c2pa-rs test files (opens in a new tab).
Environment. Ubuntu 24.04.5 LTS (x86_64), October 11, 2026. Python 3.13.16, c2pa-python (opens in a new tab) 0.38.0 (C2PA SDK 0.91.0), c2patool (opens in a new tab) 0.27.22, Pillow 12.3.0, ImageMagick 6.9.12-98, and headless Chromium 141 for the screenshot. We set both checkers to trust the C2PA test root in place of the trust list a real checker uses, so both untouched originals validated as Trusted.
Results. Both images gave the same result unless noted, and c2patool and c2pa-python agreed on every file.
| Edit (tool we used) | Credentials still in the file? | Still valid? |
|---|---|---|
| None (control) | Yes | Yes |
| Re-save as JPEG, quality 85 (Pillow) | No | No credentials to check |
| Resize to 50% (Pillow) | No | No credentials to check |
| Crop to the center 80% (Pillow) | No | No credentials to check |
| Rotate 90 degrees (Pillow) | No | No credentials to check |
| Convert to PNG (Pillow) | No | No credentials to check |
| Convert to WebP (Pillow) | No | No credentials to check |
Strip metadata (ImageMagick -strip) | No | No credentials to check |
| Screenshot (headless Chromium, PNG) | No | No credentials to check |
| Re-save as JPEG without stripping (ImageMagick) | Yes | No: hash mismatch |
| Remove only the EXIF data, pixels untouched (our image only) | Yes | No: hash mismatch |
| Edit pixels but copy all metadata over (simulated editor) | Yes | No: hash mismatch |
| Resize in a C2PA-aware tool (c2patool, original as parent) | Yes | Yes |
C.jpg has no EXIF data, so the EXIF-only edit didn't apply to it.
What stood out:
- 8 of the 11 ordinary edits removed the credentials completely. The checkers found no C2PA data at all, the same result you'd get from an image that was never labeled.
- The screenshot was pixel-for-pixel identical to the original, and its credentials were still gone. We compared the pixels to confirm. A screenshot captures what's on screen, not the file's embedded data.
- When credentials survived a tool that doesn't support them, they broke. ImageMagick copied the C2PA block into its re-saved JPEG, but the new image data no longer matched the signed hash, so both checkers marked the file Invalid (
assertion.dataHash.mismatch). Deleting only the EXIF fields, without changing a single pixel, had the same effect. The AI label was still readable in the raw data, which is why "invalid" means "changed since signing," not "fake." - Only the C2PA-aware edit kept a valid record. When c2patool signed the resized copy with the original attached as its parent, the new file validated as Trusted and still carried the original's AI label in its history.
We tested a Python imaging library, ImageMagick and a browser. We did not test phone gallery apps, Photoshop or social media uploads, which may handle credentials differently, and we did not test SynthID watermarks.
FAQ
Does taking a screenshot remove AI labels from an image?
It removes Content Credentials. In our test, a screenshot that matched the original pixel for pixel had no C2PA data left, and the CAI FAQ (opens in a new tab) says the same. An invisible watermark such as SynthID is part of the image itself, so it is designed to survive more edits. We didn't test that.
Can SynthID Detector tell whether any image is AI-generated?
No. According to Google (opens in a new tab), it only detects content from Google and partner companies that add SynthID watermarks. A negative result doesn't mean a person made the image.
If an image has no Content Credentials, is it real?
Not necessarily. An image may never have been labeled, for example if it was made before provenance labels existed or with a tool that doesn't add them. And in our test, 8 of 11 everyday edits deleted the credentials. A missing label tells you nothing either way.
Can Content Credentials be faked?
Anyone with a certificate can sign a file. We signed our test image with a public test certificate in a few lines of code. That's why checkers show who signed a file and whether they recognize the signer. For example, the CAI documentation (opens in a new tab) says Inspect shows "The Content Credential issuer couldn't be recognized" for test certificates like ours. Changing a signed file without the checker noticing is harder: in our test, every edited file that still carried its credentials was flagged as a hash mismatch, unless a C2PA-aware tool re-signed it.
Do social media sites keep Content Credentials?
It depends on the site, and we didn't test any. The CAI documentation (opens in a new tab) notes that platforms might remove C2PA data if their software doesn't support the standard yet. If a site re-encodes uploads the way our tools did, expect the credentials to be gone, and check the original file when you can.
