Deep Dive

How to Detect an AI Image: C2PA, SynthID and Metadata in 2026

A photo in the news, a portrait on social media, a "snapshot" of an event that never happened — telling real from generated keeps getting harder. But images in 2026 now carry a "passport": a digital provenance signature and an invisible watermark. Let's unpack how it works, how to check an image yourself, and why this is about to become a legal requirement.

A smartphone showing a stream of code and a person's silhouette — verifying the authenticity of data
In 2026 you don't check an image with your eyes — you check the digital trail inside the file. Photo: Pexels

Why "eyeballing it" no longer works

A couple of years ago AI gave itself away with six-fingered hands and garbled text on signs. By 2026 the models have improved so much that telling a generation from a photograph by artifacts alone has become nearly impossible. Scrutinizing hands, the reflections in eyes, patterns on clothing and text in the background is still useful — but it is no longer a reliable method, more of an early warning.

So the industry took a different route: instead of catching AI after the fact, the image is marked at the moment of creation. Two complementary methods have emerged — signed metadata and an invisible watermark. Let's look at both.

In short

The most reliable move isn't to "stare harder" but to check the file for two things: is there a C2PA signature (a provenance passport) and a SynthID watermark (a mark in the pixels)? If so, it is almost certainly AI or an edited shot.

C2PA Content Credentials: the digital passport

C2PA (Coalition for Content Provenance and Authenticity) is an open "passport" standard for media. Technically it appears as Content Credentials: a signed record (a little tamper-proof file) attached to the image, listing which device or model created it, what edits were applied at each step, and who cryptographically vouched for it. In 2025 the standard became an ISO standard (ISO/IEC 22144).

The key point for us: in 2026 the major generators embed this manifest by default. OpenAI signs every DALL·E image, Google signs Imagen images, and Adobe Firefly and Midjourney do the same. Cameras have also started signing photos at the moment of capture — building an unbroken chain of trust from shutter to publication.

The face of an android with glowing eyes — a symbol of detecting and verifying AI
A C2PA signature is a cryptographic chain: who created it, with what, and what they changed. Photo: Pexels

The signature's weak spot

The C2PA manifest lives in the file's metadata, and metadata is easily lost: a screenshot, a re-save into another format, or a pass through a third-party editor often strips the signature. So the absence of Content Credentials does NOT prove an image is genuine.

SynthID: a watermark in the pixels themselves

To make the mark survive screenshots and re-saving, a second layer was invented — an invisible watermark. The best known is SynthID from Google. It isn't written into the metadata; instead it subtly alters the pixel values themselves using a neural network: the eye notices nothing, but a dedicated classifier-detector reads it.

The crucial difference from metadata: because the signal sits in the pixels, ordinary operations — a screenshot, a re-upload, light editing — do not destroy it the way they strip a C2PA signature. Google marks its Imagen, Veo and other models with SynthID, and in May 2026 OpenAI joined the approach by adding watermarks to its images.

Aug 22026 — EU rules take effect
2layers: C2PA + SynthID
ISOstatus of the C2PA standard

Metadata versus watermark

They aren't rivals but partners: together they cover each other's weak spots.

PropertyC2PA (metadata)SynthID (watermark)
Where it livesIn file metadataIn the pixels
Survives a screenshotUsually noYes
What it showsWho, with what, what changedThe fact "this is AI"
Visible to a humanNoNo
How to verifyContent Credentials viewerSynthID detector

How to check an image yourself

Not everyone has a full detector, but a basic check is doable without special skills.

1

Check Content Credentials

Upload the file to a public Content Credentials viewer (for example at contentcredentials.org). If a C2PA manifest is present, you'll see which model created the shot and what edits were made.

2

Look at the EXIF metadata

Open the file properties or any EXIF viewer. Camera, generation-model or software fields hint at the origin.

3

Use the SynthID detector

For Google and partner images there's a dedicated watermark detector — it will tell you whether the shot is marked.

4

Apply common sense

Check the source, the date, the context. Technical marks help, but the final judgment is still yours.

An important format nuance

Remember: the C2PA signature lives in the metadata. When you convert a file from one format to another, that data may not carry over. If you need to preserve an image's "passport," keep the original PNG that the network signed untouched (more in what format AI images use).

EU AI Act: labeling as law

Why did all this suddenly matter so much? Because of the law. From August 2, 2026, Article 50 of the European Union's AI Act requires providers and deployers to mark or disclose AI-generated and manipulated content. For the industry that meant a technical standard was needed — and it converged on exactly that two-layer scheme: signed C2PA metadata plus an invisible watermark such as SynthID.

Put simply: labeling AI images stops being a developer's goodwill gesture and becomes a requirement. That's precisely why generators embed signatures by default — so their users comply with the rules automatically.

Working with images? Start with the right format

To keep provenance metadata from getting lost, it pays to handle formats correctly. FormatZ converts images right in your browser — no install, no sign-up.

Open all converters

Want a deeper understanding of how the formats themselves work and where metadata lives? See what is PNG and the comparison PNG vs JPG.

The future isn't about "spotting AI by counting fingers" — it's about every image carrying an honest passport of where it came from.
They are a signed "passport" for an image — metadata in a secure manifest that records which device or model created the file, what edits were applied, and who cryptographically vouched for it. C2PA became an ISO standard (ISO/IEC 22144). In 2026 Adobe Firefly, Google Imagen, OpenAI DALL·E and Midjourney embed such a manifest by default.
SynthID is an invisible watermark woven directly into the image's pixels by a neural network. The eye cannot see it, but a dedicated classifier can. Its key advantage: the mark survives screenshots, re-saving and social sharing — exactly where metadata is usually lost.
No. The absence of a signature or watermark does not prove an image is real. Most AI tools in 2026 do not add marks, so their output is not detectable automatically. Signatures and SynthID are a "yes, this is AI" signal, not a guarantee of the opposite.
Upload the file to a Content Credentials viewer (for example at contentcredentials.org) — it shows the C2PA manifest if there is one. For SynthID you need Google's detector. Also inspect the file's hidden info (the EXIF data that cameras and apps tuck inside photos) and look at the image itself: hands, text, reflections and jewelry are often where AI slips up.
From August 2, 2026, Article 50 of the EU AI Act requires providers and deployers to mark or disclose AI-generated and manipulated content in the European Union. The industry converged on a two-layer approach: signed C2PA metadata plus an invisible watermark such as SynthID.