// HOW-TO · AI CONTENT

How to detect AI-generated images (2026): provenance signals, visual tells, and detector limits

Detect AI-generated images in 2026: check C2PA Content Credentials and SynthID, run reverse image search, read the visual tells, and why detectors miss.

Last verified · 2026-09-20 · by Moe Ameen

Telling whether an image was made by AI got harder in 2026, not easier. The broken hands and melted faces that gave the first generation away have mostly been trained out, and the strongest current models produce photos that fool trained professionals in isolation. So the reliable method is no longer "spot the weird thing" — it is a layered check that starts with cryptographic provenance, falls back to origin tracing, and only then reads the image itself.

This guide walks that order deliberately: provenance signals first (they are the closest thing to proof), then reverse image search to find where a picture actually came from, then the visual tells that still leak on today's models, and finally the detector tools — which you use last and trust least, because their accuracy against modern generators is far worse than the marketing suggests. No single check is a verdict. The judgment is cumulative, and the honest answer is often "probably," not "definitely."

The steps

  1. Check for provenance signals first (C2PA and SynthID). The strongest evidence lives in the file, not the pixels. C2PA Content Credentials are cryptographically signed metadata recording which tool made or edited an image; SynthID is Google DeepMind's invisible watermark embedded in the pixels themselves. Verify both: drop the file into a Content Credentials viewer, ask Google Search or the Gemini app "Is this made with AI?" (SynthID and C2PA verification rolled out in the Gemini app on May 19, 2026 and are expanding to Search and Chrome), and use openai.com/verify for OpenAI-made media. A confirmed credential is the closest thing to proof you will get.
  2. Know why the absence of a credential proves nothing. Provenance is strong when present and useless when absent. C2PA metadata is stripped by screenshots, resizing, format conversion, and most social uploads — so a real photo can arrive with no credential, and an AI image can be laundered clean by one screenshot. SynthID is more durable (it survives a screenshot that strips C2PA) but not universal: it only marks media from tools that embed it. Treat "no signal found" as "unknown," never as "confirmed real."
  3. Reverse image search to find the origin. Before you scrutinize a single pixel, find out where the image actually came from. Run it through Google Lens, TinEye, or Bing Visual Search. A first appearance on a stock or news site with a photographer credit points to real; a first appearance on an AI-art board or a brand-new account with no other provenance points the other way. Origin tracing also catches the common case that detectors can't — a real photo that has been edited or miscaptioned rather than fully generated.
  4. Read the visual tells that still leak in 2026. Modern models fixed hands, gross anatomy, and obvious lighting errors, so the durable tells moved to the edges. Text is the most frequent flaw — deformed letters, invented brands, and unreadable signs still break on strong models. Look also at fine repeated structures: watch hands and dials, jewelry that melts into skin, teeth and ear detail, and background objects that dissolve into mush or repeat in impossible patterns. Physics-of-light errors — shadows falling the wrong way, reflections that don't match — remain a reliable signal.
  5. Zoom to 100% and inspect the transitions. A lot of AI tells only appear at full resolution. View the image at 100% and scan the boundaries where two things meet: hairlines against a background, fingers against an object, the seam where a subject meets a shadow. AI often produces an unnaturally smooth "airbrushed" skin texture, over-symmetrical faces, and edges that blur or fuse where a real lens would keep them crisp. Compression and downscaling hide these, which is exactly why viral thumbnails are so hard to judge.
  6. Run a detector last — and treat it as one weak vote. AI image detectors output a probability, not a verdict, and their accuracy against current models is poor. A published benchmark of 16 detection methods found mean accuracy declining from roughly 79% on 2020–2021 generators to about 38% on 2024 models, and as low as 18–30% against modern commercial generators like Midjourney v7. No tool claims 100% accuracy, and hybrid or lightly edited images defeat most of them. Use a detector to add weight to a conclusion you already reached from provenance, origin, and the tells — never as the deciding factor.
  7. Weigh the signals together and state your confidence honestly. Combine what you found: a confirmed C2PA or SynthID signal is near-conclusive; absent that, stack origin, the visual tells, and the detector score into a judgment. Two or three independent signals pointing the same way is a strong call; a single tell or a lone detector flag is not. When the evidence is mixed, say "likely AI" or "unverified" rather than asserting a certainty the checks don't support — over-claiming is how real photos get wrongly branded fake.

Common gotchas

  • No credential does not mean "real." C2PA is stripped by screenshots, resizing, and most uploads, so a genuine photo often arrives with no provenance at all.
  • The visual tells age with every model release. Hands and faces are largely fixed; text, fine repeated structures, and light physics are the durable ones — but assume any specific tell is on borrowed time.
  • Detectors are far weaker than they advertise. Accuracy collapses on recent generators and on edited or hybrid images, and false positives brand real photos as fake.
  • Compression hides evidence. Judging a heavily downscaled thumbnail or a re-shared screenshot is close to guessing — find the highest-resolution copy you can before deciding.
  • A "real" verdict on the pixels can still miss a manipulated or miscaptioned genuine photo. Detection of generation is not the same as verification of truth.
Legal note

An AI image detector produces a probabilistic score, not proof. Publicly accusing a person, publication, or brand of faking an image on the strength of a detector flag alone is reputationally and legally risky, given documented false-positive rates and rapidly falling accuracy against current models. Lead with verifiable evidence — provenance signals and origin tracing — and describe your confidence honestly rather than asserting certainty a detector cannot support.

Where Kompozy fits

Two readers land on a page like this: one vetting an image someone else made, and one who makes AI images and wants to handle them responsibly. [Kompozy](/) is squarely on the making side, and understanding how detection actually works is what makes that side better. It is an AI content generation and multi-platform publishing engine, and images are a whole family of its output — Photo Posts, Infographic Photo, Persona Photos, Persona Infographic, Quote Graphics, and Persona Tweets — so the two things this guide judges a maker on, how the image looks and how it is disclosed, are both things Kompozy is built to control.

Start with the look. The tells in step 4 are the fingerprints of raw, default diffusion output — the "almost right" face, the garbled headline, the generic scene. Kompozy's images do not come out of a bare model. Persona Photos and Persona Infographic use Gemini face-lock so the same influencer face stays consistent across every post instead of drifting into the uncanny-valley tell, and Quote Graphics and Persona Tweets render their words as a real server-side text layer composited over the artwork via [HyperFrames](/glossary/hyperframes) — so the type is correct by construction, not painted as pseudo-letters that break under a zoom. A [Persona Brief](/glossary/persona-brief) holds voice and style steady across the set. The output reads as a designed, on-brand asset rather than AI slop, which is exactly the gap audiences and detectors react to.

Then disclosure — the part knowing-how-detection-works should push you toward, not away from. Every Kompozy generation lands in a per-post review queue before it fans across the eight social platforms plus blog and email, and that gate is where you apply each platform's AI-content label and write honest disclosure copy before [Autopilot](/glossary/autopilot) schedules and ships it. Because Kompozy also generates net-new formats beyond static images — [Persona Shorts](/glossary/persona-shorts) and avatar video, Carousels, Text Posts, Newsletters — you are not leaning on one raw image type that a detector or an audience clocks fastest; you are publishing a diversified, disclosed, on-brand mix. For deeper background, see the guide on [AI content detection](/guides/ai-content-detection) and the how-to on [handling visible AI watermarks](/how-to/handle-visible-ai-watermarks). Creator ($49/mo for 2,500 credits) fits a solo creator publishing a few branded images a week; Pro ($299/mo for 18,000 credits) suits a team fanning disclosed, on-brand visuals across every platform on autopilot; Enterprise is custom. The detector is the last, weakest check on an image; Kompozy is how you make one that is honest and unmistakably yours before it ever gets tested.

Frequently asked questions

What is the most reliable way to detect an AI-generated image?

Provenance, not eyeballing. Check for C2PA Content Credentials and a SynthID watermark first — a confirmed signal is the closest thing to proof. When no credential is present, combine reverse image search, the visual tells (text, fine repeated structures, light physics), and a detector score into a cumulative judgment, since any single check can be wrong.

Are AI image detectors accurate in 2026?

Not against current models. A benchmark of 16 detection methods found accuracy declining from roughly 79% on 2020–2021 generators to only about 38% on 2024 models, and as low as 18–30% on modern commercial generators. No tool claims 100% accuracy, and lightly edited or hybrid images defeat most of them, so a detector should be your last and weakest signal.

What are the visual signs of an AI image now that hands are fixed?

The tells moved to the edges. Garbled text, invented brand names, and unreadable signs are the most frequent flaws; look also at watch dials, jewelry, teeth, and ears, at backgrounds that dissolve or repeat, and at lighting and reflections that break physics. Zoom to 100% — most of these only appear at full resolution.

Does a screenshot remove proof that an image is AI?

It removes some, not all. A screenshot strips C2PA metadata, so the "made with AI" credential disappears — but Google's SynthID watermark is embedded in the pixels and typically survives, so a SynthID check can still flag a screenshotted AI image. Metadata alone is fragile; that is why provenance is only one layer of the check.

Related tutorials

← All how-to guides · Get Started