Key takeaways
- No single test reliably shows whether content was made with AI; Content Credentials, watermarks, and detectors can each miss.
- Content Credentials record how a file was made and edited, but they can be stripped, so a file without them proves nothing either way.
- Watermark checks find only marks from tools that add them, and AI detectors make errors, especially on short text and writing by non-native English speakers.
On this page
- Why there is no single test
- What Content Credentials record
- How to inspect a file, and why credentials vanish
- Invisible watermarks such as SynthID
- Why text is harder
- What AI detectors can and cannot do
- A checklist for readers
- Worked example: a photo from a reader
- What you can do next
- Check your understanding
There is no single reliable test for whether an image, video, audio clip, or text was made with AI. Three kinds of evidence exist. Content Credentials are signed records, built on an open standard from the C2PA coalition, that a tool attaches to a file to say how it was made and edited, including whether AI was used. Invisible watermarks, such as Google DeepMind's SynthID, are hidden in the content itself by the tool that generated it. Detectors examine the content and estimate whether it is synthetic. A valid credential or a detected watermark is real evidence about a file's origin, but credentials can be stripped, watermarks come only from tools that add them, and detectors make mistakes, so finding nothing proves nothing. Weigh these checks alongside where the content first appeared and who shared it.
Why there is no single test
NIST's report Reducing Risks Posed by Synthetic Content (external site: nvlpubs.nist.gov) (NIST AI 100-4, published November 20, 2024) surveys these techniques. It groups them into provenance data tracking, which records where content came from using watermarks or metadata, and synthetic content detection, which classifies whether content is synthetic. It says none of these techniques offers a comprehensive solution on its own. It also warns that transparency can create a false sense of trust, for example when genuine content is taken out of context, and that content may be only partly synthetic, such as a photo with one object removed and the gap filled in by AI. OpenAI's ChatGPT Images 2.5 system card (external site: deploymentsafety.openai.com) likewise says "there is no single solution to provenance."
What Content Credentials record
The Coalition for Content Provenance and Authenticity (C2PA) publishes the Content Credentials specification (external site: spec.c2pa.org), now at version 2.4, dated April 2026. According to C2PA's explainer (external site: spec.c2pa.org), a Content Credential (technically a C2PA manifest) is a set of statements about a file, such as its origin, what edits were made with which tools, and whether AI was used. It includes a cryptographic hash, a short code computed from the content that changes if the content changes, and a digital signature, so changing either the file or the record breaks the match. The explainer calls this tamper-evident.
In the specification's own example, a video generated by an AI model from a text prompt has a record that starts with a c2pa.created action whose digital source type is trainedAlgorithmicMedia. Version 2.4 also added an AI disclosure assertion for machine-readable information about AI use. OpenAI's Images 2.5 system card lists a continued commitment to C2PA metadata as part of its provenance tooling.
The explainer is plain about limits. Provenance alone cannot tell you whether content is true, accurate, or factual; Content Credentials show whether the record is intact and whether its signer is on a known trust list. Provenance can also be incomplete: a crop made in a tool that does not support the standard may go unrecorded.
How to inspect a file, and why credentials vanish
C2PA's deployment guidance (external site: c2pa.org) (July 8, 2026) points to the free Verify tool (external site: verify.contentauthenticity.org): you upload a file and see whether Content Credentials are present, who signed them, when, with what tool, and whether AI generation or editing was flagged. It describes three results:
- Valid: the credential and the content are intact, but the signer may not be on the C2PA Trust List.
- Trusted: intact, and the signer is on the Trust List.
- No Content Credentials found: the file was not made with a conforming tool, or its credentials were stripped.
Stripping is common. Asked whether provenance metadata can be removed, C2PA's explainer answers: "Yes it can." NIST adds that metadata is often stripped when files are shared, for example on social media, either to deceive or for benign reasons such as privacy. C2PA's response is "durable" credentials, which pair the signed record with a watermark or fingerprint so the record can be found in online storage after it has been removed from the file. Because adding credentials is optional, the explainer answers "Maybe" to whether you should distrust media without them. The deployment guidance says to treat content with missing or invalid credentials "cautiously."
Invisible watermarks such as SynthID
A watermark hides a signal in the pixels, sound, or words themselves rather than in attached metadata. Google DeepMind's SynthID page (external site: deepmind.google) says SynthID embeds imperceptible watermarks in AI-generated images, audio, text, and video, and that image and video watermarks are designed to withstand cropping, filters, frame-rate changes, and lossy compression. A Gemini help page (external site: support.google.com) describes SynthID as marking content generated by Google's AI models, and OpenAI's Images 2.5 system card says that, for Images 2.5, OpenAI also adds SynthID watermarks through ChatGPT, Codex, and the OpenAI API.
A watermark check finds only marks from tools that add them. The same help page says Gemini's check currently recognizes only content made by Google AI tools; that a missing watermark means the file was not made or edited by Google AI but could have come from other AI systems; and that after many alterations a watermark may not be detected. The SynthID page says a separate portal, SynthID Detector, checks for content from Google and partners including OpenAI, NVIDIA, and Kakao. NIST notes that watermark detection always carries some probability of error.
Why text is harder
Text is harder to label: NIST says metadata generally cannot travel with raw text copied between documents or apps. Text watermarks work differently. A language model writes one token (a word or piece of a word) at a time, choosing by probability, and SynthID adjusts those probabilities in a pattern a detector can score; Google says it does this for text from the Gemini app and web experience. Google's SynthID Text documentation (external site: ai.google.dev) says the method is open source, available in Hugging Face Transformers from version 4.46.0, and that detection is probabilistic, returning watermarked, not watermarked, or uncertain. Its stated limits: the watermark is less effective on factual answers, detector confidence can drop sharply after thorough rewriting or translation, and it "is not designed to directly stop motivated adversaries."
What AI detectors can and cannot do
Detectors that do not rely on a watermark look for traces a generator leaves, such as regularities in pixels. NIST AI 100-4 calls this "a constant cat-and-mouse game" and says detectors are often tied to, and may only perform well on, specific generators. For text, it reports studies finding detectors little better than chance on short passages, notes that most detectors were built for English, and says they label English text by non-native writers as AI-generated more often. It adds that someone with a model's weights can fine-tune it to evade a given detector, and warns that in many contexts false positives, judging human work to be AI-made, "can be extremely damaging." Human judgment varies: NIST cites a study in which experienced chatbot users classified some text well, and others in which people performed near chance.
A checklist for readers
- Get the original file. Screenshots and re-uploads often lose metadata.
- Check for Content Credentials with a tool that supports the standard, such as Verify, and note who signed them.
- Check for watermarks with each developer's own tool, remembering that each finds only its own marks or its partners'.
- Treat a detector score as one clue, especially for short text or writing by non-native English speakers.
- Trace the source and context: who posted it first, when, and where. Google's help page suggests reverse image search.
- Say what you checked and what you could not.
Worked example: a photo from a reader
Lee is a fictional reader invented for this page. Lee edits a neighborhood newsletter and receives a dramatic photo of flooding on Main Street from a subscriber.
- Lee asks for the original file rather than a screenshot.
- Verify reports "No Content Credentials found." Lee notes that this shows only that no credential is attached.
- Gemini's check finds no SynthID watermark. Lee reads this as "not made by Google AI, as far as the check can tell," leaving other generators possible.
- Two free online detectors disagree. Lee sets them aside.
- Lee asks the subscriber when and where the photo was taken, compares the storefronts with the street, and finds a neighbor's photo of the same scene from another angle, posted the same morning.
Lee runs the photo with a credit and a line saying how it was checked. Without the second photo and the sender's account, Lee would have held it.
What you can do next
- Open SynthID Bio, a Google DeepMind project that watermarks AI-generated biological sequences and structures, and the Google DeepMind and NIST profiles.
- Read how language models work to see the token probabilities that text watermarks adjust, and tokens and context windows for what a token is.
- Read how AI developers test models for safety for what developers publish about their models before release, and browse the AI safety, security, and trust hub.
- Look up weights, open weight, and tokenizer in the glossary.
Sources
All read on October 8, 2026.
- C2PA: Content Credentials: C2PA Technical Specification, version 2.4 (external site: spec.c2pa.org); C2PA and Content Credentials Explainer, 2.2 (external site: spec.c2pa.org); Content Credentials Deployment Guidance 1.0 (external site: c2pa.org) (July 8, 2026); Verify tool (external site: verify.contentauthenticity.org), linked from contentcredentials.org (external site: contentcredentials.org)
- Google DeepMind: SynthID (external site: deepmind.google); SynthID Bio README (external site: github.com)
- Google: SynthID Text documentation (external site: ai.google.dev) (last updated April 9, 2025); Verify AI-generated images, videos, and audio (external site: support.google.com) (Gemini Apps Help)
- OpenAI: ChatGPT Images 2.5 System Card, Image Provenance (external site: deploymentsafety.openai.com) (published September 8, 2026)
- NIST: Reducing Risks Posed by Synthetic Content (NIST AI 100-4) (external site: nvlpubs.nist.gov) and its publication page (external site: nist.gov) (published November 20, 2024)
Check your understanding
Three quick questions, answered from this page. Nothing you choose is saved or sent anywhere.
0 of 3 answered.