Skip to content
ToolProof

How to Check If an Image Is AI-Generated: SynthID and C2PA

Check an image with SynthID Detector, OpenAI's verifier and Content Credentials tools, plus our test of which everyday edits strip C2PA labels.

Published
Reading time
8 min
Category
AI Tools

You can't prove an image is AI-generated by looking at it, but you can check for the labels many AI companies embed in their images. Upload the file to Google's SynthID Detector (opens in a new tab) to look for an invisible SynthID watermark, and to a Content Credentials viewer such as Adobe's Inspect (opens in a new tab) to read any C2PA label. If both come back empty, that doesn't mean the image is real: in our test, a plain screenshot and seven other everyday edits erased Content Credentials completely.

This guide covers the checks anyone can do, what Google's and OpenAI's tools can and can't tell you, and the results of our hands-on test of which edits strip Content Credentials.

How to check if an image is AI-generated

Work through these steps in order.

  1. Get the original file. Save the image itself instead of taking a screenshot, and use the highest-quality copy you can find. In our test, screenshots and re-saved copies lost their Content Credentials entirely.
  2. Check for Content Credentials. Upload the file to Inspect (opens in a new tab), Adobe's Content Credentials viewer (in beta), or to the Content Authenticity Initiative's Verify (opens in a new tab) tool. According to the Inspect documentation (opens in a new tab), it reads JPEG, PNG, WebP, HEIC, AVIF and other common formats, and shows No Content Credential when the file has none.
  3. Check for a SynthID watermark. Upload the same file to SynthID Detector (opens in a new tab). It looks for the invisible watermark that Google and several partner companies add to AI-generated images, video and audio. Google also lets you upload an image to the Gemini app and ask whether it was made with Google AI (Gemini Help (opens in a new tab)).
  4. If it might come from ChatGPT or another OpenAI tool, try OpenAI's verification tool (opens in a new tab). It looks for the two signals OpenAI uses for its images: C2PA Content Credentials and a SynthID watermark.
  5. Find where the image came from. Run a reverse image search (Google Lens and TinEye both do this) and look for the earliest copy. An image that first appeared on an AI art account, or that has no history before a viral post, deserves more doubt.
  6. Then look closely. Garbled text, warped hands or jewelry, shadows that fall in different directions, and backgrounds that melt into patterns are common signs of AI generation. Don't rely on these clues alone: a clean-looking image is unproven, not real.

How to read the results

What the checker showsWhat it means
SynthID watermark detectedGoogle says the file was likely made or edited with a model that uses SynthID
Valid Content Credentials that say AI created itThe signer recorded that the image is AI-generated, and the file hasn't changed since it was signed
Content Credentials present but invalid or flaggedThe file changed after it was signed. The change may be harmless, such as a re-save
No watermark and no Content CredentialsUnknown. The image may be real, made by a tool that adds no labels, or stripped

What SynthID Detector can and can't tell you

SynthID is an invisible watermark from Google DeepMind. It sits in the content itself rather than in a separate label attached to the file. In early October 2026, Google opened SynthID Detector to everyone (opens in a new tab), available globally in English, after testing it with journalists and media professionals. According to Google, it checks images, video and audio for watermarks from Google's own AI and from partners including OpenAI, NVIDIA and Kakao.

Two limits matter:

We did not run SynthID Detector for this guide. This section is based on Google's published material as of October 2026.

What Content Credentials (C2PA) are, and how OpenAI uses them

Content Credentials are a signed record of where a file came from and how it was edited. They follow an open standard from the Coalition for Content Provenance and Authenticity (C2PA), and the record usually lives inside the image file. An AI tool that supports the standard marks its output as created by generative AI (trainedAlgorithmicMedia in the technical data, per the CAI documentation (opens in a new tab)). Because the record is cryptographically signed, a checker can show who signed it and tell whether the file changed afterward.

According to OpenAI, images made with its tools can carry both signals. OpenAI's developer API returns a separate result for each signal: C2PA, with a status of trusted, valid, invalid or not present, and SynthID. The API documentation (opens in a new tab) is direct about the limits. A "not detected" result can still be OpenAI content if "the metadata was stripped or has evidence of tampering, the watermark was degraded, it comes from a legacy generation model, or it was created before provenance signals were available." The tool also doesn't detect AI images from other companies.

The CAI's FAQ (opens in a new tab) puts it plainly: Content Credentials give a positive signal about an image's origin, not a negative signal about its authenticity. Because they are metadata, they are easy to lose. We measured how easy.

What we tested: which everyday edits strip Content Credentials

We took two C2PA-signed JPEG images, applied 12 edits to each, and checked every result with two C2PA tools.

Test images. We did not use a real ChatGPT or Gemini image. Both files were signed with test certificates that are published for developers:

  • Our own synthetic 1600×1067 image, signed with the test certificate that ships with c2patool and labeled trainedAlgorithmicMedia, the label the CAI documentation specifies for generative AI output.
  • C.jpg, a signed sample from the c2pa-rs test files (opens in a new tab).

Environment. Ubuntu 24.04.5 LTS (x86_64), October 11, 2026. Python 3.13.16, c2pa-python (opens in a new tab) 0.38.0 (C2PA SDK 0.91.0), c2patool (opens in a new tab) 0.27.22, Pillow 12.3.0, ImageMagick 6.9.12-98, and headless Chromium 141 for the screenshot. We set both checkers to trust the C2PA test root in place of the trust list a real checker uses, so both untouched originals validated as Trusted.

Results. Both images gave the same result unless noted, and c2patool and c2pa-python agreed on every file.

Edit (tool we used)Credentials still in the file?Still valid?
None (control)YesYes
Re-save as JPEG, quality 85 (Pillow)NoNo credentials to check
Resize to 50% (Pillow)NoNo credentials to check
Crop to the center 80% (Pillow)NoNo credentials to check
Rotate 90 degrees (Pillow)NoNo credentials to check
Convert to PNG (Pillow)NoNo credentials to check
Convert to WebP (Pillow)NoNo credentials to check
Strip metadata (ImageMagick -strip)NoNo credentials to check
Screenshot (headless Chromium, PNG)NoNo credentials to check
Re-save as JPEG without stripping (ImageMagick)YesNo: hash mismatch
Remove only the EXIF data, pixels untouched (our image only)YesNo: hash mismatch
Edit pixels but copy all metadata over (simulated editor)YesNo: hash mismatch
Resize in a C2PA-aware tool (c2patool, original as parent)YesYes

C.jpg has no EXIF data, so the EXIF-only edit didn't apply to it.

What stood out:

  • 8 of the 11 ordinary edits removed the credentials completely. The checkers found no C2PA data at all, the same result you'd get from an image that was never labeled.
  • The screenshot was pixel-for-pixel identical to the original, and its credentials were still gone. We compared the pixels to confirm. A screenshot captures what's on screen, not the file's embedded data.
  • When credentials survived a tool that doesn't support them, they broke. ImageMagick copied the C2PA block into its re-saved JPEG, but the new image data no longer matched the signed hash, so both checkers marked the file Invalid (assertion.dataHash.mismatch). Deleting only the EXIF fields, without changing a single pixel, had the same effect. The AI label was still readable in the raw data, which is why "invalid" means "changed since signing," not "fake."
  • Only the C2PA-aware edit kept a valid record. When c2patool signed the resized copy with the original attached as its parent, the new file validated as Trusted and still carried the original's AI label in its history.

We tested a Python imaging library, ImageMagick and a browser. We did not test phone gallery apps, Photoshop or social media uploads, which may handle credentials differently, and we did not test SynthID watermarks.

FAQ

Does taking a screenshot remove AI labels from an image?

It removes Content Credentials. In our test, a screenshot that matched the original pixel for pixel had no C2PA data left, and the CAI FAQ (opens in a new tab) says the same. An invisible watermark such as SynthID is part of the image itself, so it is designed to survive more edits. We didn't test that.

Can SynthID Detector tell whether any image is AI-generated?

No. According to Google (opens in a new tab), it only detects content from Google and partner companies that add SynthID watermarks. A negative result doesn't mean a person made the image.

If an image has no Content Credentials, is it real?

Not necessarily. An image may never have been labeled, for example if it was made before provenance labels existed or with a tool that doesn't add them. And in our test, 8 of 11 everyday edits deleted the credentials. A missing label tells you nothing either way.

Can Content Credentials be faked?

Anyone with a certificate can sign a file. We signed our test image with a public test certificate in a few lines of code. That's why checkers show who signed a file and whether they recognize the signer. For example, the CAI documentation (opens in a new tab) says Inspect shows "The Content Credential issuer couldn't be recognized" for test certificates like ours. Changing a signed file without the checker noticing is harder: in our test, every edited file that still carried its credentials was flagged as a hash mismatch, unless a C2PA-aware tool re-signed it.

Do social media sites keep Content Credentials?

It depends on the site, and we didn't test any. The CAI documentation (opens in a new tab) notes that platforms might remove C2PA data if their software doesn't support the standard yet. If a site re-encodes uploads the way our tools did, expect the credentials to be gone, and check the original file when you can.

  • #AI images
  • #SynthID
  • #Content Credentials
  • #C2PA
  • #Google
  • #OpenAI