GDE-066 |
AI image detection | |||||||
AI-assisted investigation | ||||||||
October 2026 | ||||||||
01
What it is
An AI image detector is a tool or workflow that tests whether a picture was created or edited by a generative AI model. The strongest approach layers provenance, watermark, classifier and reverse search checks into a verdict you can defend.
No single AI image detector settles the question, but each layer answers part of it. Provenance signals answer a narrow question with high reliability. C2PA Content Credentials are signed metadata recording how a file was made and edited, and SynthID is an invisible watermark that Google, and since May 2026 OpenAI, embed in images their models generate.
Classifier detectors answer a broader question with less certainty, returning a probability rather than a finding. Reverse image search and a close look at the content fill the gaps both leave. Journalists, fact-checkers and OSINT researchers use the layers together to decide what can be published, what needs more work and what should be set aside.
| When to use this guide
|
02
How do you check if an image is AI-generated?
Seven tools and six steps take you from provenance signals to a documented verdict, with each layer covering what the one before it cannot.
Seven tools cover the workflow. Six are free, Image Whisperer adds paid checks beyond a free daily allowance, and only Gemini needs an account.
Content Credentials Verify: Free, no login. The Content Authenticity Initiative's inspector reads any C2PA Content Credentials attached to an image and shows the signer, the creating tool and the edit history.
OpenAI Verify: Free, no login. Checks an uploaded PNG, JPG or WEBP file for C2PA metadata and SynthID watermarks associated with OpenAI tools such as ChatGPT, Codex and the API, and reports which signals it detects.
Hive Detect: Free, no login. A classifier-based AI-generated and deepfake content detector for images, video and audio that returns a probability score and, where it can, the likely generator.
TinEye: Free for non-commercial searches, no login. Reverse image search with results you can sort by oldest, useful for finding the earliest indexed copy of an image.
Google Lens: Free, no login. Visual search across Google's index, strong at surfacing near-duplicates, crops and the pages an image appears on.
Gemini: Free with a Google account. Upload an image and ask whether it was created or edited by Google AI; Gemini checks for a SynthID watermark. It recognises Google AI content only, and a rolling limit of roughly 10 image checks per 24 hours applies.
Image Whisperer: Free tier, no login. Built by Henk van Ess, it runs more than 40 checks, including AI classifiers, error level analysis and a C2PA check against the official trust list, and returns a plain-language verdict. Two checks a day are free, with paid packs beyond that. Some checks send the image to outside services, including Google and Hive.
| Before you begin Stop at the login. Six of the seven tools return a result without an account. Gemini's SynthID check needs a signed-in Google account, so use a dedicated research account rather than a personal or newsroom identity, or skip that check if one is not available. Legal considerations. Uploading an image discloses it to the provider, which may retain it, so check retention terms before submitting material from a confidential source or showing an identifiable private individual. The UK GDPR and EU GDPR apply to personal data in any image you process. |
Download the highest-resolution copy, archive the source post and note its URL and time. Record a SHA-256 hash of the file, for example with sha256sum, and run every later test on copies so each result can be repeated on identical input.
Upload a copy to Content Credentials Verify. A valid manifest names the signer and the tool that created or edited the file, and an AI generator entry is strong positive evidence. Then check the signature itself. A manifest can be valid, meaning its signature verifies and the file is unchanged since signing, without being trusted, meaning the signing certificate chains to an authority on the C2PA trust list. Anyone can make a certificate under any name, so compare the signer with the organisation that issued its certificate: a signer that issued its own certificate, a test or developer certificate, or a warning that the signer is unrecognised leaves the claimed identity unverified. A signature or hash failure means the file changed after signing. An empty result proves nothing on its own: many platforms strip metadata on upload and many generators never add it.
Run the file through OpenAI Verify and, if you have a research account, Gemini. A detected watermark means all or part of the image was created or edited by a participating model. No watermark only rules out those participating generators, since many tools, including most open-source models, add none.
Submit the copy to Hive Detect and record the score and any generator it names. Treat the score as a lead: classifiers can miss newer generators and can flag heavily edited or compressed genuine photos. For high-stakes cases, get a second reading from Image Whisperer and note any disagreement. Image Whisperer passes images to outside services, including Hive, Google and SightEngine, so the data and GDPR points under Before you begin apply to it too.
Search TinEye, sorted by oldest, and Google Lens. An earlier, higher-resolution copy credited to an identifiable photographer weighs towards authenticity, while a first appearance on an account that posts generator output points the other way. Check who uploaded it, not just where it appears.
Look for detail that does not hold together: lettering, hands, reflections, shadows and background structure. Then write one paragraph naming each layer's result and the confidence tier you assign, and say plainly when the evidence leaves the question open. An honest unresolved verdict is a sound finding.
|
03
Why an AI image detector can get it wrong
Every layer has a blind spot, and most errors come from reading one result as the whole answer.
Missing Content Credentials read as proof of authenticity: An image with no manifest looks clean, but platforms routinely strip metadata and most cameras and generators do not sign files. Verifying check: confirm authenticity through a positive trail, such as the earliest source, a named photographer or the original file, rather than the absence of a manifest.
Valid manifest signature read as trusted identity: A manifest can pass cryptographic checks while signed with a self-issued or developer certificate created under any name, so a valid signature does not establish who signed it. Verifying check: inspect the certificate issuer and confirm it chains to an authority on the C2PA trust list before treating the named author or tool as established.
No watermark read as not AI: SynthID checks recognise only generators that embed the watermark. Output from a non-participating model comes back clean, which says nothing about AI involvement. Verifying check: record which generators each tool covers and carry the image through the classifier and reverse search layers before concluding anything.
AI image detector score treated as a finding: Classifiers return a likelihood, not a determination. Upscaled, heavily compressed or retouched genuine photos can score high, and images from newer generators can score low. Verifying check: re-run the detector on the highest-quality copy you hold and require support from at least one non-classifier layer before stating a conclusion.
Genuine photo edited with AI read as fully synthetic: A real photograph retouched with generative fill can carry an AI entry in its Content Credentials or an embedded watermark, even though most of the scene was captured by a camera. Verifying check: examine the manifest's edit history to establish what was changed, and report the edit rather than labelling the whole image synthetic.
AI-enhanced copy read as a sharper original: Upscalers and "enhancers" do not recover detail, they generate it. Two runs on the same blurry photo can return two different faces. Verifying check: find the earliest, lowest-resolution copy, compare it with the enhanced version at the same size, and treat any detail that appears only in the sharper copy as invented. Never use an enhanced face to identify, describe or name anyone.
Worked example: the RAF Fairford arrest photo
In late September 2026, five men were photographed being arrested near RAF Fairford. The original image is grainy and none of their faces can be made out. Users ran it through AI tools to sharpen it, and at least two enhanced versions circulated, each giving the men noticeably different faces. Neither shows the real men. Two posts on X carrying one version reached almost 2 million views, according to France 24, and were used to make false claims about the men's religion. Lead Stories and France 24 both found a SynthID watermark pointing to OpenAI tools. Authorities identified the five as British nationals from London, aged 23 to 25, and all were released on bail.
Reverse image search leads back to the grainy original, and that copy is the evidence. Set it beside each enhanced version at the same size: any face that appears only in the sharper copy was generated, not recovered. Then run the provenance checks for SynthID and Content Credentials. A watermark hit, as here, says a lot. No hit would have proved nothing.
Chain of custody: An AI image verdict is only as strong as the record behind it. Detectors change and posts disappear, so keep enough for a colleague, editor or court to repeat each check.
Chain of custody checklist
|
04
Go deeper
A reference card and a Methods tutorial for when one image becomes a full verification case.
CARD · AIV-002 · SIGNAL TIER
AI-generated image and video detection for OSINT investigators
Hive Moderation, Optic and ExifTool in sequence, with false-positive checks built in.
METHODS · SIGNAL TIER
Detecting deepfakes in video and audio verification
Provenance inspection, classifier scoring and perceptual analysis for a defensible verdict.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.




