Language
Search

Was This Image Made by AI — Watermarks, Credentials and Detectors

어둠 속 필름 스트립과 빛망울 사진

·

Views 9
Can you tell an AI-generated image apart?
By eye, mostly not any more. Clues like the number of fingers or garbled text are already gone. Two methods are in use now: an invisible watermark embedded in the pixels at generation time, and provenance information that travels with the file (content credentials). Together they are strong, but a screenshot or a re-save can break them.

Only a few years ago you could spot an AI image by counting fingers. Not now. Judging by eye has stopped being a practical method.

So the industry and the regulators went in a different direction: leaving a mark at the moment of creation.

Three approaches

Method Where it lives Strength Weakness
Visible label Visibly on the image Anyone knows immediately Crop it and it is gone
Invisible watermark In the pixel values themselves Survives cropping and compression to a degree Needs a dedicated detector to read
Content credentials As a signed history in the file metadata Records when and with what it was made, and how it was edited Easily broken by screenshots or re-saving

The three are not competitors but layers you stack. The design assumes one will break and another will remain.

Invisible watermarks

Google DeepMind’s SynthID is the representative case. It embeds a signal by adjusting pixel values just below the threshold of human vision. It is designed so the detector can still read it after common transformations such as cropping, filters and compression.

The change worth noting is that competitors have begun adopting the same approach. OpenAI introduced measures applying SynthID watermarks to its own image output. Labelling technology is moving from company-by-company schemes toward shared infrastructure.

The limits are clear too. Watermarks come with research into removing them running alongside. Heavy transformation or a regeneration pass can weaken the signal, and plenty of generators embed no watermark at all in the first place.

Content credentials (C2PA)

C2PA is an open standard that attaches a content item’s origin and edit history to the file in signed form. Adobe, Google, Microsoft, the BBC and Reuters are among the participants.

  • What tool it was created with
  • What edits followed
  • Whose signature vouches for each step

That history travels with the file. It is also used in the other direction, to prove that a photograph taken on a camera is genuine.

The problem is that it breaks easily. Take a screenshot, upload to a platform that strips metadata, or re-save in another format, and the history is gone. So the absence of credentials on its own cannot tell you something is AI-generated.

The deadlines regulation has set

The EU AI Act requires machine-readable marking of AI-generated content. The published schedule runs like this.

  • Applies to generative AI systems placed on the market after 2 August 2026
  • Systems already on the market before then must meet the requirements by 2 December 2026
  • Non-compliance carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher

Reality is not there yet. A 2025 survey found that of 50 AI image generators, only 19 embedded a watermark and only 9 offered a visible label. The gap between the regulatory deadline and actual implementation is wide.

A practical order for checking

If you have to verify where an image came from, this order is the realistic one.

  1. Get the original file. Images received over a messenger are usually recompressed with the metadata stripped. Ask for the original
  2. Check the content credentials. Look for a history in a viewer or verification site that supports them
  3. Run a watermark detector. Some services provide their own
  4. Do a reverse image search. See whether an original source or an earlier posting turns up
  5. Look at context. Whether photos of the same event from other angles exist, and what the history of the account that posted it first looks like

The important thing is not to conclude from one detector’s score. Services that claim to detect AI have a fair number of false positives, and misclassifying a real photograph as AI is common. In matters where a person’s reputation is at stake in particular, a single detector’s result must not be used as evidence.

What to observe on the creating side

  • Label it. Whether AI-generated material is disclosed in commercial output is already a policy matter on several platforms
  • Do not distribute with the credentials stripped. Check for the option in your editing tool that preserves metadata
  • Be especially careful with human likenesses. Output resembling a real person leads to likeness and defamation problems

In summary

  1. Judging by eye is effectively finished. The method now is marking at generation time
  2. There are three layers: the visible label, the invisible watermark (the SynthID family) and content credentials (C2PA)
  3. Watermarks are robust to transformation but removal research runs alongside them, and credentials break on screenshots and re-saving
  4. The EU AI Act applies to systems placed on the market after 2 August 2026, and existing systems must comply by 2 December. Actual implementation still lags
  5. Verify in the order get the original → credentials → watermark → reverse image search → context, and never conclude from a single detector score

Frequently asked questions

If there are no credentials, is it an AI image?

No. Take a screenshot or pass it through a platform that strips metadata and the history disappears. Credentials let you confirm the source when present; their absence merely means you cannot confirm it, and is not grounds for a judgement.

Are AI detection sites trustworthy?

Usable as a reference, insufficient as sole evidence. Both false positives and false negatives are reported, and heavily edited or retouched real photographs are sometimes classified as AI. The principle is to read several signals together.

If the watermark is removed, is it undetectable?

Research into removal exists and some of it reports success. Removal often damages image quality, though, and the watermark is only one of several defences. Credentials, posting history and reverse image search remain alongside it.

Do individuals have to label the AI images they make?

The primary target of the legal obligation is the system provider. That said, platform policies increasingly require uploaders to disclose, and separate rules may apply depending on the use — advertising, journalism and so on. Checking the policy of the platform you are publishing to is the safe move.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *