Updated on 18 August 2026
Detecting AI images: what SynthID, C2PA and watermarks really reveal
Last updated: August 18, 2026
"How do I tell whether an image came from an AI?" is the most common question on the subject, and the answer is uncomfortable: reliably only if somebody put a marking in beforehand. Everything else is guesswork. This article shows the three traces that exist, what Google's SynthID actually covers, why C2PA so often gets lost on the way through Instagram and WhatsApp, and how to check a file yourself in two minutes instead of trusting a detector.
In brief
- Evidence sits in the file, not in the impression. There are three dependable traces: IPTC/XMP metadata, a C2PA provenance chain, and an invisible watermark.
- SynthID only marks Google. Images from Midjourney, DALL·E or Firefly carry no SynthID. Since May 2026 Google and OpenAI have combined watermarking with C2PA, because metadata alone does not hold up.
- Metadata often does not survive the upload. Estimates for the share of distributed images that still carry their provenance sit around 30 to 50 percent; screenshots, resizing and format changes remove it reliably.
- AI detectors guess. An image without a marking cannot be proven to be AI generated. That is why the EU AI Act requires labeling at the source rather than detection after the fact.
- What this means for you: check what is there, and label your own material properly. That is exactly what the two modes of this tool do.
Contents
- Why "detecting" is the wrong question
- Trace 1: metadata under IPTC and XMP
- Trace 2: C2PA and Content Credentials
- Trace 3: invisible watermarks and SynthID
- Why the traces disappear
- What AI detectors can and cannot do
- Checking a file in two minutes
- Frequently asked questions
Why "detecting" is the wrong question
The EU AI Act approaches the problem from the other end. It does not oblige the audience to detect, it obliges the parties involved to label: providers must mark their AI outputs in machine-readable form (Article 50(2)), deployers must visibly disclose certain content (paragraph 4). Both have applied since August 2, 2026. The legislator thereby acknowledged what holds technically: a finished rendered image carries no reliable signature of its origin unless somebody writes one into it.
So anyone asking "is this image AI?" is really asking: "did somebody leave a marking here, and is it still present?" That question can be answered. The other one cannot.
Trace 1: metadata under IPTC and XMP
The simplest and most widespread marking is an entry in the file's metadata. The IPTC field digitalSourceType has a dedicated value for this, trainedAlgorithmicMedia, which states exactly one thing: this content was produced by a trained algorithm. Alongside it sit values for partly edited and for purely composed content.
Advantages: the entry is openly documented, any imaging software can read it, and it costs neither a certificate nor infrastructure. Disadvantage: it is not signed. Anyone editing the file can set, change or remove it. As evidence of your own diligence it is still the starting point, and for the obligation under paragraph 2 it is the accepted minimum.
How to set this entry yourself is covered in Machine-readable AI labeling with C2PA, IPTC and watermarks.
Trace 2: C2PA and Content Credentials
C2PA is the attempt to turn the note into proof. Instead of a plain field, a signed manifest is attached to the file: who created it, with which tool, which editing steps followed. It is signed with a certificate, so the manifest cannot be altered unnoticed.
The initiative has matured. In early 2026 it counted more than 6,000 members and affiliates, among them Google, Meta, OpenAI, Sony, Nikon and Leica. Content Credentials are produced today by DALL·E 3, Sora, Adobe Firefly, Microsoft Copilot, Meta AI and cameras, among others. Instagram displays existing credentials and recognizes shots taken natively on Pixel devices.
Two limitations remain. First, C2PA is tied to a certificate: signing your own content requires your own trusted signature, and a self-signed one is rejected by the verification tools. Second, the manifest is only as durable as the file it hangs on. Which brings us to the heart of the problem.
Trace 3: invisible watermarks and SynthID
An invisible watermark does not place the information beside the pixels but inside them: as tiny patterns in the image structure that the eye cannot notice. The advantage is obvious, it survives the removal of metadata because it is not metadata.
SynthID by Google DeepMind is the best known of these methods. Google states it has already marked more than 100 billion images and videos. Three things are worth knowing:
- SynthID only sits in content from Google's own models. An image from Midjourney, DALL·E or Firefly carries no SynthID, so the absence of SynthID says nothing about whether an image is AI generated.
- It is not unbreakable. In April 2026 a publicly available tool became known that removes SynthID from images.
- Google itself no longer relies on it alone. Since May 2026 Google and OpenAI have combined watermarking with C2PA metadata into a two-layer model, explicitly because metadata alone does not hold up.
Our tool brings its own invisible watermark (DCT/QIM), which likewise survives the removal of metadata. The honest limit applies here too: it does not survive scaling or cropping, because it lacks the synchronization patterns commercial systems use for that. It is an additional layer, not a replacement for the visible label.
Why the traces disappear
The most common reason a check finds nothing is not malice but the perfectly normal path a file takes through the internet:
- Platform upload. Social networks recompress images and routinely discard metadata in the process.
- Screenshot. A screen capture creates a new file without any history. It is the surest way to lose every marking.
- Resizing and recompression. A thumbnail, a WhatsApp message, a format change from PNG to JPEG: each of these steps can cost metadata and weak watermarks.
- Editing. Cropping, filters, collages. Any change that rewrites the image can break the chain.
Estimates of the share of distributed images whose provenance survives the journey sit around 30 to 50 percent. That is not a footnote, it is the reason a single technique is not enough.
What AI detectors can and cannot do
There are services that analyze an uploaded image and return a probability that it is AI generated. They look for statistical anomalies in noise, edges and frequencies. That works for a while against fresh model generations, then it stops, because the models improve and the detectors' training data ages.
Treat such results as an indication, never as proof. A detector that flags a genuine photo as AI causes real damage, and the error rate in both directions is considerable. For a legal dispute, a probability figure without an embedded marking is worthless.
Our verify mode therefore does something deliberately different: it reads out what is in the file. It does not judge whether content really came from an AI, and it does not claim to.
Checking a file in two minutes
- Get the original file. Not the screenshot, not the preview from a chat. Only the original file can carry a marking.
- Check the file. Upload it in verify mode. You get back whether a machine-readable marking is present, which
digitalSourceTypeis recorded and whether a watermark was found. - Read the result correctly. A marking found is positive proof. No marking found is not proof of the opposite, it may have been lost along the way.
- For third-party content: ask the source. For your own content the question does not arise, because you label at creation time.
Frequently asked questions
Does SynthID replace labeling under the EU AI Act?
No. At best SynthID can cover the machine-readable provider marking from Article 50(2), and only for content from Google's models. It does not replace the visible labeling you owe as a deployer under paragraph 4. Anyone publishing images from other generators has no SynthID in the file to begin with.
Can I read SynthID myself?
For text and for content within its own ecosystem Google offers verification, for example in Gemini. There is no open, generally available verification interface for arbitrary images. So do not rely on it for your own compliance, rely on markings you set yourself and can verify yourself.
An image has no marking. May I treat it as genuine?
No. A missing marking only means: no information. It may never have been set, or it may have been lost on the way. If provenance matters legally, get it from the source, not from the file.
What is the difference between C2PA and a watermark?
C2PA is a signed provenance chain beside the pixels; it proves a lot but only lasts as long as the metadata survives. A watermark sits inside the pixels, survives metadata loss, but carries less information and can be destroyed by heavy editing. That is why the major providers have combined both since 2026.
What good is the visible EU icon when metadata gets lost?
That is precisely its advantage. The visible label is rendered into the image and survives screenshots, re-uploads and format changes because it is part of the pixels. For your obligation as a deployer it is the decisive part anyway, and it is the only layer still present when everything else has been stripped away.
What now?
Checking is one half, labeling is the other and the more important one. Put the visible EU icon and the machine-readable marking on your own AI content and you become independent of what any given generator ships. Both in one step works directly in the tool, free of charge, without an account, and your files are not stored.
Read on: The complete guide to AI labeling obligations · Machine-readable labeling in detail · Labeling images from Midjourney and DALL·E