Back to overview

The Detection Engine. Unveiled.

For CTOs, IT lawyers, and anyone who wants to understand what lies beneath the surface. We disclose every layer — including our honest limitations. This is precisely the level of transparency we expect you to provide to your users.

View Trust-Badge

Detection Stack

Ten layers, one verdict.

No single layer is flawless. Stacked, they deliver the most comprehensive AI inventory on the EU market. Our fingerprint database improves with every scan — this is the compounding moat.

Fingerprint database · Live

Loading …

Live

C2PA JUMBF Manifest

Cryptographic signatures embedded directly in image data — Adobe, OpenAI, Microsoft, Google. We scan the bytes themselves, not just XMP strings.

Confidence

0.97

Weight

1.00

Cost

free

Live

EXIF · XMP · IPTC

22 generator patterns in Software, CreatorTool, and Description fields. Effective even for generators without C2PA (Stable Diffusion, Midjourney v6).

Confidence

0.90

Weight

0.85

Cost

free

Live

Perceptual Hash DB

DCT-based pHash for every image. Lookup against our fingerprint database — improves with every scan. Detects re-uploads and crops in under 50ms.

Confidence

0.85+

Weight

0.95

Cost

free

Live

URL · Filename Heuristics

Fast first-pass detection via asset URL and filename. Low weight, extremely low cost — catches obvious cases.

Confidence

0.45

Weight

0.35

Cost

free

API-key ready

Hive Moderation ML

Pixel-level forensics for unsigned generators. ~85% recall on JPEG roundtrip. Active from Starter tier via HIVE_API_KEY.

Confidence

0.40–0.95

Weight

0.90

Cost

$0.01

API-key ready

Sightengine Ensemble

Second ML opinion as ensemble partner. In case of disagreement with Hive → human review queue. SIGHTENGINE_USER + SECRET.

Confidence

0.40–0.95

Weight

0.85

Cost

$0.008

Live

Text Heuristics (local)

Vocabulary, em-dash frequency, transition word density, sentence length uniformity — detects ChatGPT/Claude/Gemini output without API.

Confidence

0.40–0.85

Weight

0.55

Cost

free

API-key ready

GPTZero · Originality

External text detection API. Invoked only if local heuristics have already triggered (cost optimisation). GPTZERO_API_KEY.

Confidence

0.30–0.97

Weight

0.90

Cost

$0.02

Phase 3

Audio Forensics

ElevenLabs detection API + spectral analysis for AI voice. Sora/Veo frame forensics for AI video. Phase 3.

Confidence

Weight

0.85

Cost

Phase 3

Human-in-the-Loop

If two ML models disagree → a human decides within 5–10 seconds. Enterprise tier opt-in for “Verified Accuracy”.

Confidence

0.99

Weight

1.00

Cost

$0.10

You will see actual confidence values and hit rates per layer after each scan under “Detection Layer Breakdown” in the report.

Asset Types

Four media classes, one pipeline.

We scan everything that can be embedded in HTML — images, text, video, audio. Each class passes through the detection layers relevant to its format.

Images

Product photos, hero visuals, blog illustrations from Midjourney, DALL·E, Firefly, Stable Diffusion, Flux.

C2PA · EXIF · pHash · ML

Text

Blog articles, product descriptions, about pages — generated with ChatGPT, Claude, Gemini.

Heuristics · GPTZero

Video

Hero loops, explainer videos, animations from Runway, Sora, Veo, Kling, Pika.

URL · Frame sampling (Phase 3)

Audio

Voice-overs, podcast voices, AI voices from ElevenLabs, OpenAI Voice, Resemble.

Spectral forensics (Phase 3)

The EU AI Act in 60 seconds

Four key dates. Three sanction levels.

A factual summary of the transparency obligations under Article 50 EU AI Act and the sanctions framework from Article 99. Source-based. Not legal advice.

Status

In force

Article 50 (transparency obligations) has applied since 2 August 2026. Sanctions from 2 August 2027.

  1. 13 June 2024

    Adopted

    Published

    Regulation (EU) 2024/1689 adopted by the European Parliament and Council. Enters into force as directly applicable EU law.

  2. 2 Aug 2026

    Transparency active

    In force

    Article 50 becomes applicable. Deepfakes and AI-generated texts on public topics must be labelled. Chatbots must disclose themselves.

  3. 2 Dec 2026

    Watermark spec

    In force

    Providers of GenAI systems (OpenAI, Adobe, Google) must embed machine-readable markers. Specific technical standards via delegated act.

  4. 2 Aug 2027

    Full sanctions

    Sanction risk

    Fines may be imposed — up to a maximum of EUR 15 million or 3% of global group annual turnover (Art. 99). Warnings under unfair competition law (UWG) may be possible from the date of applicability.

Fine framework

What the sanctions catalogue contains.

Article 99 EU AI Act defines three levels. The higher of the two values always applies: fixed amount or percentage of global group annual turnover.

Art. 99 (3)

Prohibited practices

Highest level — prohibited practices under Art. 5 (social scoring, biometric real-time surveillance).

€35 million

7%

Not relevant for transparency violations.

Art. 99 (4)

Deployer obligations

Breaches of deployer obligations — including Art. 50.4 (deepfake labelling) and Art. 50.1 (chatbot disclosure).

€15 million

3%

Directly relevant for you as a website operator.

Art. 99 (5)

False information

False or incomplete information provided to market surveillance authorities upon request.

€7.5 million

1%

Avoidable through proper documentation.

Important

Maximum ≠ likelihood.

Authorities determine fines on a case-by-case basis — considering severity, intent, turnover, and demonstrated diligence. SMEs are generally sanctioned well below the maximum thresholds.

We state upper limits because they are public and you should assess risk realistically — not to predict a specific penalty. Anyone who does so is being misleading.

Assessment factors (Art. 99(7))

Severity

Type and duration, intent vs. negligence.

History

Repeat offence vs. first-time occurrence.

Economic advantage

Did the breach measurably increase conversion or reach?

Duty of care

Were technical measures taken? This is precisely where Provifai documents.

Sources: Regulation (EU) 2024/1689 (AI Act), Articles 50 and 99. Sanctions are enforced nationally by market surveillance authorities — in Germany, expected to be BNetzA + BSI. Not legal advice.

The Result

You see immediately what matters.

Your content, clearly categorised: What is AI, what is authentic, what awaits your decision. Technical evidence is provided for every finding — but it appears in the second line, not the first.

example-shop.com

Checked today · 12 subpages · 18 seconds

37
checked
13
AI detected
6
pending
  • Product image “Summer Campaign”

    Created with AI — evidenced within the image itself

    Labelled
  • Blog cover image

    Very likely AI — not yet labelled

    Pending
  • Text “About Us”

    Likely written with AI

    Pending
  • Retail store, entrance area

    Authentic photo — camera data present

    Authentic
  • Video testimonial

    Face artificially generated — labelling required

    Deepfake

You can confirm or dispute each finding with a single click — your input is decisive, not our estimate.

Demo with sample data. All visuals AI-generated and declared in our certificate .

Ready?

Enough theory. Discover what’s running on your domain.

Article 50 has applied since 2 August. The audit takes less than a minute.