ChronoVerify

Is this photo AI-generated? How to actually check

A field guide from ChronoVerify, written by a veteran intelligence analyst.

The reliable signals are provenance, not "AI detectors." Real camera photos usually carry EXIF metadata (make, lens, exposure), and most major AI generators embed C2PA Content Credentials that label the image as AI-generated. Check those first. Pixel-based detectors that return a confidence score are unreliable: in a 2025 NewsGuard audit they wrongly flagged real photos as AI up to 40 percent of the time. A missing signal is never proof of fakery.

Are AI image detectors accurate?

Not reliably, and the data is blunt about it. In a June 2025 NewsGuard audit, five leading detectors (Hive, AI or Not, ZeroGPT, Sightengine, ScamAI) collectively misidentified authentic photos as AI-generated 13.33 percent of the time. ScamAI was the worst, flagging 6 of 15 real images (40 percent) as AI; ZeroGPT flagged 3 of 15 (20 percent).

They also disagreed with each other. In 35 of 45 image tests, at least one tool reached a different verdict than the rest. On heavily altered AI images, detection ranged from 100 percent (AI or Not) down to 33 percent (Sightengine, 5 of 15), a wide false-negative gap. A tool that returns "92 percent AI" is one weak signal, never a verdict. Once a photo passes through a social platform, the recompression alone can swing these scores. The same caution applies to Error Level Analysis (ELA): it reflects JPEG recompression patterns and is widely misread, so it does not prove an image was edited.

What actually helps: provenance

Provenance is the recorded history of how a file was made, and it is far more dependable than guessing from pixels. Two signals matter most:

Which AI generators label their images as AI?

Most major ones now do, which is why provenance is the practical check. The coverage as of 2026:

Camera-side provenance exists too, though it is not yet universal. The Google Pixel 10 is the first smartphone to sign every stock-camera photo with C2PA at capture, while the Samsung Galaxy S25 only embeds credentials on AI-edited images. That contrast is the reason absence of a credential proves nothing: many real cameras still do not sign at all.

Pixel AI-detectors vs provenance signals

DimensionPixel AI-detectorsProvenance signals (C2PA, EXIF)
What it inspectsThe pixels alone, guessing from visual artifactsSigned metadata and recorded edit history
ReliabilityUp to 40 percent false positives on real photos; tools disagree on most images (NewsGuard 2025)A valid C2PA credential is cryptographically signed and tamper-evident
On recompressed or screenshot imagesScores swing; results degrade furtherMetadata may be stripped, returning "unknown" rather than a false verdict
What absence meansOften misread as proof of fakeryInconclusive: a missing signal is unknown, not fake
Best useOne weak corroborating hint at mostPrimary triage signal, combined and weighed honestly

How to check if a photo is AI-generated

  1. Check for Content Credentials first. Inspect the file for C2PA credentials with a viewer, or check the photo on ChronoVerify, which detects them. A valid credential that says "AI-generated" settles the question; one that records a camera capture is a strong signal of a real photo.
  2. Read the EXIF metadata. Rich camera data (make, model, lens, exposure) leans toward a real capture. A complete absence is consistent with an AI image, a screenshot, or a stripped file, so treat absence as inconclusive.
  3. Treat any pixel-detector score as one weak signal. If you run a detector, weight its percentage lightly. These tools false-accuse real photos and miss edited AI images, so never present a score as proof.
  4. Weigh the signals honestly. Combine what you found. When no signal is present, the truthful answer is "not enough data to tell," and missing signals stay "unknown."

The honest limits

No single check is decisive, and pretending otherwise is how real photos get falsely accused. C2PA is tamper-evident, not tamper-proof: a screenshot or re-encode can strip it entirely from a genuine AI image or a real one. SynthID survives common compression, cropping, and screenshots but carries almost no standalone information, and heavy edits like style transfer can degrade it. The two are complementary because they fail differently.

ChronoVerify is built on that principle: it reports the C2PA manifest, EXIF, and pixel-forensics signals it finds, flags possible editing for review, and never treats a weak pixel score as proof. You can read exactly how the pipeline weighs each check, and where it stops short, on the method page.

ChronoVerify is tuned in the opposite direction from pixel-only detectors. On its measured real-photo corpus, no authentic capture was wrongly flagged and no known edit was cleared as authentic; a manipulation flag requires two corroborating signals, never one. The benchmark and calibration report documents the method and its limits.

Check a photo for Content Credentials and camera metadata in seconds.

Check a photo now

Moderating AI content at scale? Platforms and newsrooms can run the same deterministic C2PA, EXIF, and forensics checks programmatically through the ChronoVerify API, with flat per-image pricing and no operation multipliers. Get an API key and pay per image, no waitlist.

Common questions

Are AI image detectors accurate?

Not reliably. In a June 2025 NewsGuard audit, five leading detectors misidentified authentic photos as AI-generated 13.33 percent of the time, with one tool flagging 40 percent of real images as fake. The tools also disagreed with each other on most images, so a single pixel score is not proof.

What is C2PA and how does it work?

C2PA is an open standard for recording the origin and edit history of digital content. Its implementation, Content Credentials, acts like a nutrition label that is cryptographically signed and tamper-evident. Steering committee members include Adobe, Amazon, BBC, Google, Meta, Microsoft, OpenAI, Sony, and Truepic.

Which AI generators label their images as AI?

OpenAI attaches C2PA credentials to ChatGPT and API images. Adobe applies Content Credentials to Firefly output. Google embeds C2PA and SynthID in Gemini, Imagen, and Nano Banana images. Meta reads these credentials to label content across Facebook, Instagram, and Threads.

Does a photo with no metadata mean it is AI-generated?

No. A missing signal is not evidence of fakery. Screenshots, recompression, and most social platforms routinely strip EXIF and C2PA data from genuine photos. Absence of credentials is inconclusive, not proof either way.

What is the difference between C2PA and SynthID?

They fail differently. C2PA carries rich, signed provenance but can be stripped by a screenshot or re-encode. SynthID is embedded in the pixels and survives common compression, cropping, and screenshots but carries almost no standalone information. SynthID is Google-specific, so it does not appear on every generator.

Can AI image metadata or watermarks be removed or faked?

C2PA is tamper-evident, not tamper-proof: altering recorded data breaks the cryptographic signature, but the whole credential can be fully stripped by re-encoding or screenshotting. SynthID survives common transformations but heavy edits like style transfer or content-aware fill can degrade it.

Is ChronoVerify C2PA conformant?

Yes. ChronoVerify is a C2PA Conformant Validator on the C2PA Conforming Products List, record 019f8a20-6452-7a43-b11b-59d0b0e4a84a, covering validation of JPEG, PNG, WebP and AVIF under C2PA specification 2.2. The list is public, so you can check the record yourself. It covers validation rather than generation: ChronoVerify reads and validates Content Credentials, it does not sign them.

Sources and further reading: NewsGuard, AI image-detection audit (June 2025); Coalition for Content Provenance and Authenticity (C2PA); Google, identifying AI-generated media; Google DeepMind, SynthID; Meta, labeling AI-generated images; Adobe, Content Credentials overview; CIPA DC-008 (EXIF) standard.