Skip to content

How to tell if an image is AI-generated

Updated September 2026

Check the file's embedded metadata first — C2PA Content Credentials, EXIF software tags, and the PNG text chunk that diffusion tools write the prompt into. Visual inspection is unreliable in 2026 and should be the last resort, not the first.

Most advice on this question is out of date. Counting fingers, looking for garbled text in signs, hunting for asymmetric earrings — these worked against 2022-era image models and fail against current ones. Anyone relying on visual tells today is guessing, and guessing confidently is how people end up accusing the wrong person.

There is a more reliable approach, and it has nothing to do with the pixels. Most AI images carry a record of their own creation inside the file. Reading that record takes seconds and, when it is present, settles the question outright.

1. Check for Content Credentials (C2PA)

C2PA Content Credentials are a tamper-evident manifest that some tools attach to the files they produce. It records which software created the asset and what was done to it afterwards. OpenAI attaches them to DALL·E output, Adobe to Firefly, and Google to several of its image products; Leica and Sony ship cameras that sign genuine photographs the same way.

The manifest is stored differently depending on format — an APP11 segment in JPEG, a caBX chunk in PNG, a C2PA chunk in WebP — but the effect is the same: the file names its own origin. When a manifest is present and names a generator, that is the strongest evidence you will get from any method.

One caveat worth knowing, because most tools do not mention it: detecting a manifest is not the same as verifying it. Full verification means checking the cryptographic signature against a certificate chain. A tool that only reads the manifest, as most web-based checkers do, would report a hand-crafted manifest at face value. Treat it as what the file declares about itself.

2. Read the EXIF and XMP metadata

Photographs carry a distinctive trail: camera make and model, lens, aperture, shutter speed, ISO, focal length, and often GPS coordinates. Generated images almost never have any of it. That contrast is the most practical everyday signal there is.

Generators sometimes leave their own fingerprint in the same place. A `Software` or `Creator` field reading "Midjourney", "DALL·E" or "Adobe Firefly" is conclusive. So is an IPTC `DigitalSourceType` field set to `trainedAlgorithmicMedia`, which is the standards-body marker for synthetic media.

Read this evidence in one direction only. Its presence tells you a great deal; its absence tells you almost nothing, because messaging apps and social platforms strip metadata from everything you send through them.

3. Look inside PNG text chunks

This is the single most overlooked check, and on PNG files it is often decisive. Stable Diffusion, Automatic1111 and ComfyUI write the entire generation recipe into the image as a plain-text chunk: the prompt, the negative prompt, the sampler, the CFG scale, the seed and the model name.

Almost nobody removes it, because almost nobody knows it is there. If a PNG contains a `parameters` block reading something like `Steps: 30, Sampler: DPM++ 2M Karras, CFG scale: 7, Seed: 1234567890`, the question is settled — you are not detecting anything, you are reading the recipe.

This survives only in PNG. Saving as JPEG destroys it, because JPEG has no equivalent chunk.

4. Only then consider the pixels

If the file has been stripped of everything above, statistical detection is what remains — machine-learning classifiers trained to recognise the artefacts diffusion models leave behind.

Be realistic about them. They are trained on particular generators and lose accuracy sharply on newer ones, with no warning sign when they do. Published accuracy figures come from test sets resembling the training data; real-world files rarely do. A classifier that scores 95% in a paper may be near a coin-flip on an image from a model released after it was trained.

This is why a screenshot is so destructive. It discards every layer of real evidence and leaves only the weakest one. If someone sends you a screenshot of an image and asks whether it is AI, the honest answer is usually that it cannot be determined.

What about watermarks like SynthID?

Google embeds SynthID, an invisible watermark encoded into the pixels themselves, in output from its image models. Unlike metadata it survives cropping, compression and re-encoding, which makes it far more robust than anything described above.

The catch is that only Google can read it. No third-party tool can check SynthID, and any service claiming to is not doing what it says. The same applies to most proprietary watermarking schemes.

The honest conclusion

Run the checks in order: Content Credentials, then EXIF and XMP, then PNG text chunks, then — reluctantly — a classifier. Stop as soon as one gives a clear answer, because each step down the list is substantially weaker than the one above it.

And accept that for a large share of images circulating online, the correct answer is "cannot be determined". A tool that always produces a confident percentage is not more capable than one that admits uncertainty; it is just less willing to tell you when it is guessing.

Try it on a file

Runs every check described above, in that order, and shows you which one produced the answer.

Drag a file here, or

JPEG, PNG, WebP, AVIF, PDF or .txt · up to 10 MB · you can also paste a screenshot

By uploading you agree to our Terms and Privacy Policy. Your file, IP address, approximate location and device details are stored.

Frequently asked questions

Can you tell if an image is AI-generated just by looking?

Not reliably, not since 2024. The visual tells people cite — extra fingers, garbled text, asymmetric details — were artefacts of earlier models and have largely been engineered out. Current photorealistic output regularly passes human inspection, which is why metadata is the more dependable route.

Does removing metadata prove an image is AI?

No. Every major social platform strips metadata on upload, so a perfectly genuine photograph shared through WhatsApp or Instagram arrives with nothing attached. Missing metadata is extremely common and is weak evidence at best.

What is the most reliable single check?

A C2PA Content Credentials manifest naming the generating tool, or a PNG parameters chunk containing the prompt and seed. Both are the file describing its own creation rather than anyone inferring it.

Can AI detection be used as proof?

Embedded provenance is strong evidence but can be forged or stripped; classifier output is not proof under any circumstances. Neither should be the sole basis for accusing someone of anything.

Related reading