How to Detect AI-Generated Content — and Why No Single Detector Is Sufficient
C2PA, metadata, watermarks, ML classifiers: an honest overview of the methods for detecting AI-generated images and texts — including their weaknesses.
“Is this image AI-generated?” — the question sounds simple, but it is not. There is no method that can reliably answer it for every piece of content. What does exist are several independent approaches, each with very different strengths. Understanding these makes it clear why a thorough review always consists of multiple layers.
1. Cryptographic Provenance (C2PA)
The strongest form of evidence does not come from analysing the image, but from the image itself. The C2PA standard — supported by Adobe, Microsoft, Google, OpenAI and several camera manufacturers — embeds a cryptographically signed provenance statement directly in the file. This records which tool created or edited the content.
The major advantage: this is not a probability, but a verifiable statement. The drawback: metadata does not always survive every processing step. If an image is recompressed, passed through a CMS, or shared via social networks, the signature often disappears. Missing credentials are therefore not proof of human authorship — they simply mean there is no information.
The Overlooked Benefit
Provenance works both ways. An image signed by a Leica, Sony, Nikon or Canon camera proves that it was genuinely photographed. In a world of growing doubt, this is often more valuable than proving the opposite.
2. Metadata and Embedded Traces
Alongside C2PA, there are simpler but surprisingly rich sources. The IPTC standard includes a field for the “digital source type”, which can explicitly mark a file as algorithmically generated — this very marker is referenced in the EU code of conduct for labelling. EXIF and XMP fields often reveal the tool used to create the content. And with PNG files from popular image generators, the full prompt and settings are stored in the file header — a clear-cut piece of evidence.
3. Invisible Watermarks
Some providers embed a pattern into the pixels that is invisible to humans. The advantage over metadata: it can survive compression and cropping. The catch: such watermarks can usually only be read by the party who created them. In practice, this means you are reliant on the cooperation of the providers.
4. Statistical Classifiers
If all other traces are missing, the content itself can be analysed. Modern classifiers achieve high accuracy rates for images and can often even identify the generating model. For texts, the situation is more delicate: good detectors are often correct, but every one of them produces false positives and false negatives. Carefully written human texts can be wrongly classified as machine-generated, while edited AI texts can slip through undetected.
A detector provides a probability, not a truth. Mistaking this for a fact is to confuse statistics with evidence.
Why Layers Alone Are Not Enough
Combining these methods makes the result significantly more robust: a cryptographic proof outweighs any estimate, an embedded prompt is hard evidence, and a classifier covers cases where all traces have been removed. Nevertheless, some uncertainty always remains — and this is not a weakness of the technology, but a feature of the problem itself.
That is why at Provifai we take a deliberately different approach: our assessment provides the evidence, but the final statement is made by the operator. For each finding, you see which method triggered and how reliable it is — and you confirm or reject it. This protects against the worst consequence of automated detection: that someone is accused of content they actually created themselves.
Practical Rule
Treat detection results as indications, not verdicts. First review cases with hard evidence — metadata, signatures, embedded prompts — and make a conscious decision on the rest.
Free audit
What is actually on your website?
Enter your domain, wait less than a minute — you will see which content shows traces of AI generation. No registration required.
Read more
Art. 50 EU AI Act: Who Must Label AI Content — and What This Means in Practice
The practical guide to labelling obligations: affected content, the operator’s role, and the most common misconceptions.
EU AI Act: The 10-Point Checklist for Your Website
From inventory to monitoring: the ten questions every website operator should now be able to answer.
Labelling AI Images: What Is Mandatory, What Is Sensible — and How to Do It Properly
The honest answer to the most common question — and three design rules to ensure your labelling doesn’t look like a warning sign.
Deepfakes on Your Own Website: Why the Operator Is Liable — Not the Creator
The law’s most powerful lever does not target AI providers, but you — and deepfakes arise more quickly than most people realise.
C2PA, Metadata, Watermarks: How Machine-Readable AI Labelling Really Works
A look inside the file rather than at the image: the standards that make origin verifiable — clearly explained.
Stock Photos and AI: Why Almost Every Website Contains Unlabelled AI Content
You have never knowingly used AI? Your website probably has — in ways no one expects.