Back to BlogAI Image Detection & Provenance · Pillar guide
    ·16 min read

    AI Image Detection in 2026: How Detectors, Watermarks and Metadata Really Work

    A photograph being scanned by a forensic analysis grid with metadata fields floating around it

    Key takeaways

    • AI image detection runs on three completely separate layers: embedded metadata (C2PA, EXIF, XMP), invisible pixel watermarks (SynthID and similar), and statistical classifiers that guess from the pixels alone.
    • Metadata is the layer that actually gets you labelled today. It is a deterministic, machine-readable confession attached to the file — and it is the one layer you can verify and strip yourself.
    • Statistical classifiers are probabilistic, not proof. Published false-positive rates mean real photographs get flagged and real AI images slip through.
    • Re-encoding, resizing and screenshotting destroy metadata but do not reliably destroy a robust invisible watermark — anyone claiming a 100% guarantee is selling you something.
    • You can inspect every provenance signal in your own images, strip them, and see a before/after detection-likelihood score in your browser, free, with nothing uploaded.

    You uploaded a photograph you took yourself. The platform stamped it "AI info". Or you generated an image legitimately for your own project, licensed and paid for, and now every crawler, marketplace and social feed treats it like a forgery.

    Both situations feel the same from the outside — an invisible verdict you did not get to see, with no explanation of what triggered it. And almost every article you can find on the subject is either a vague listicle of "AI detector" links or a scammy landing page promising to make anything undetectable.

    This guide is the honest version. It explains exactly what the three layers of AI image detection are, which one is actually flagging your files today, what you can verify yourself, and what nobody can truthfully promise you. Everything described here you can inspect in your own browser, on your own images, without uploading a single file to anyone.

    The three layers of AI image detection

    The single biggest misconception about this topic is that "AI detection" is one thing. It is three independent systems that happen to answer the same question. They fail in completely different ways, and they respond to completely different remedies.

    LayerWhat it readsReliabilitySurvives re-encoding?Can you inspect it?
    Provenance metadata — C2PA, EXIF, XMP, IPTC, PNG text chunksStructured fields written into the file containerDeterministic — it is a signed or literal declarationNo. Re-encoding from raw pixels drops itYes, completely
    Invisible pixel watermark — SynthID and similarA statistical pattern embedded in the pixel valuesHigh when intact, by designRobust designs are built to survive itNo — detection is proprietary
    Statistical classifier — "AI detector" websitesTexture, frequency, noise and artefact patternsProbabilistic, with real error rates in both directionsYes, the pixels are the evidenceOnly by proxy, via heuristics

    Read that table again, because it contains the whole strategy. Layer one is a confession. Layer two is a fingerprint. Layer three is a guess.

    Layer 1: metadata is the confession in the file

    Every image file is a container, and the picture is only part of what is inside it. Around the pixels sit blocks of structured data: EXIF from cameras, XMP from editors, IPTC from newsrooms, ICC colour profiles, PNG text chunks, and increasingly a C2PA manifest — a cryptographically signed record of what created the image and what happened to it afterwards.

    When an AI model generates an image, that record can include the model name, the generating software, a creation timestamp, an action list describing the generation event, and a signature from the issuing organisation. When an AI-assisted editing step touches a real photograph, it can append its own entry to the same chain.

    This is the layer that gets you labelled, and it works whether the picture shows a mountain, a face or a spreadsheet. It requires no cleverness at all — just a parser.

    What actually lives in your files

    • C2PA / Content Credentials — the signed provenance manifest. The strongest possible declaration, and the one social platforms read first.
    • EXIF `Software`, `ProcessingSoftware` and maker notes — often carry a generator or model string verbatim.
    • XMP packetsxmp:CreatorTool, digital-source-type fields and vendor namespaces, frequently naming the model outright.
    • PNG `tEXt` / `iTXt` chunks — a favourite for prompt text, seeds and workflow JSON from local generation tools.
    • IPTC digital source type — a standardised field whose value can literally say the content was synthetically generated.

    The unnerving part is how much of that you never asked to include. A prompt you typed privately can ride along inside a PNG chunk to anyone who downloads the file.

    Read the deep dive: AI image metadata explained — EXIF, XMP, C2PA and generator tags →

    Why re-encoding removes it

    Metadata is not part of the picture. It sits alongside the compressed pixel data in the container. When an image is decoded to raw pixels and re-encoded from scratch, everything outside those pixels is simply not carried over — there is no mechanism by which it could be.

    That is why our Remove AI Metadata tool works the way it does: it decodes your image in the browser, throws away the container entirely, and writes a brand-new file from the pixel buffer. Nothing to parse, nothing to strip selectively, nothing left behind by accident.

    Layer 2: invisible watermarks are a fingerprint in the pixels

    An invisible watermark is a deliberate, imperceptible pattern woven into the pixel values themselves at generation time. Google's SynthID is the best-known example. Because it lives in the pixels rather than the container, it does not care about your file format, your metadata, or how many times you have re-saved the image.

    Robust watermarking schemes are explicitly designed to survive the things people do to images: JPEG compression, resizing, cropping, colour adjustment, screenshots. That is the entire engineering goal. Fragile schemes — and plenty of watermarking is fragile — degrade quickly under the same treatment.

    Honest framing: no browser-based tool, ours included, can guarantee removal of a watermark that was designed to survive re-compression and resampling. Anything that claims otherwise is either mistaken or lying to you.

    What pixel-domain processing *can* do is disrupt fragile embeddings, at a real cost in image fidelity. Aggressive resampling, requantisation and dithering all perturb exactly the low-level statistics a watermark hides in. Sometimes that is enough. Sometimes it is not, and you cannot tell from the outside which case you are in.

    Read the deep dive: what SynthID is and whether it can be removed →

    Layer 3: statistical classifiers are guessing, confidently

    This is the layer people mean when they type "ai image detector" into Google. You paste an image, a website prints "94% likely AI" and you are expected to treat that as a fact.

    It is not a fact. It is a model's opinion, formed from patterns like these:

    • Frequency-domain signatures — generative upsampling leaves characteristic periodic structure that photographic optics do not produce.
    • Noise floor coherence — real sensors produce spatially varying noise; synthetic images are often unnaturally clean or uniformly noisy.
    • Local texture regularity — hair, foliage, fabric weave and skin pores are hard for models to keep statistically consistent at every scale.
    • Edge and gradient smoothness — a suspiciously perfect absence of chromatic aberration, sensor imperfection and lens falloff.
    • Compression history — genuine camera output usually carries a plausible JPEG history; freshly generated PNGs do not.

    Every one of those is a correlation, not a proof, and every one of them is destroyed or introduced by ordinary editing. Heavily post-processed real photographs — beauty retouching, denoise, upscaling, aggressive compression for the web — can trip the same wires. That is why responsible platforms treat classifier output as one weak signal among many, and why you should be deeply sceptical of any single-number verdict.

    Read the deep dive: how AI image detectors work and how accurate they really are →

    Why this hits legitimate creators hardest

    The people most damaged by AI detection are rarely the bad actors it was designed to catch.

    • Photographers whose editing suite ran an AI denoise or generative-fill step, so their genuine shot arrives pre-labelled as AI.
    • Designers and agencies using properly licensed generative assets in client work, where a stray "AI info" badge derails an approval.
    • Small e-commerce sellers whose product visuals get demoted by marketplace ranking rules that penalise flagged media.
    • Marketers whose paid creative underperforms because platform distribution quietly discounts labelled images.
    • Anyone with privacy needs, since the same metadata block that names a model also carries GPS coordinates, device serials and timestamps.

    None of that is fraud. It is the collateral damage of a signalling system that was bolted onto image files faster than anyone built tools for ordinary people to see it.

    How to inspect an image yourself, in four steps

    You do not need to trust a black-box verdict about your own files. You can read the provenance layer directly and see exactly what a platform would see.

    1. 1Open the image in a tool that reads the container, not just the picture. Our Remove AI Metadata tool enumerates C2PA manifests, EXIF, XMP, IPTC, ICC profiles and PNG text chunks locally in your browser.
    2. 2Read the findings list before you change anything. This is the important step people skip. It tells you whether you have a signed C2PA manifest, a bare generator string, or nothing at all.
    3. 3Strip the container by re-encoding from raw pixels. Everything outside the pixel data is discarded — deterministically, not heuristically.
    4. 4Compare the before/after report. The tool scores detection likelihood on both versions using local heuristics, so you can see which signals disappeared and which pixel-level characteristics are unchanged.

    Read the deep dive: how to read your before-and-after AI detection report →

    What each remedy can and cannot do

    Setting expectations properly is the most useful thing this article can give you.

    What you doMetadata layerInvisible watermarkStatistical classifier
    Re-encode from raw pixelsRemovedUnaffected if robustLargely unchanged
    Crop or trim a visible badgeUnaffectedUnaffectedSlightly changed
    Aggressive resample + requantiseRemovedBest-effort disruption onlyChanged, sometimes for the worse
    Screenshot the imageRemovedRobust designs surviveAdds a screen-capture signature
    Heavy re-compressionRemovedRobust designs surviveCan increase suspicion

    Notice the pattern: the metadata column is honest and absolute. The other two are qualified. Any tool that presents all three columns as solved has stopped describing reality.

    Removing a visible AI badge is a separate job

    Provenance metadata is invisible. The little coloured strip or logo that Gemini, DALL·E and other models stamp onto the bottom edge of an image is not — it is pixels in the picture, and no metadata operation touches it.

    That is a cropping and patching problem, handled by our Remove AI Watermark tool, which trims or blends the badge region with preset strip heights per model. For a clean result you usually want both operations: remove the visible badge, then strip the container.

    Read the guide: remove AI watermarks from Gemini and DALL·E images →

    The ethical line, stated plainly

    We build these tools because ordinary people deserve to see and control what their own files say about them. That belief comes with a boundary.

    Cleaning provenance data from images you own — for privacy, for file size, for a client deliverable, for a platform that mislabels your photograph — is legitimate, and it is what every social network already does to your uploads automatically. Using the same operation to pass synthetic media off as documentary evidence, authentic journalism, or proof of a real event is not, and in a growing number of jurisdictions and platform policies it is explicitly prohibited.

    Disclose AI use when it matters. Clean your files when it does not. The tooling is the same; the honesty is on you.

    Where to go next

    Each spoke below goes deep on one layer of the stack. If you only have time for one, pick by what you actually need: understanding a verdict, understanding a watermark, or cleaning a file.

    Frequently Asked Questions

    What is AI image detection?

    AI image detection is the process of deciding whether an image was generated or edited by an AI model. It combines three approaches: reading embedded provenance metadata such as C2PA Content Credentials, checking for an invisible pixel-level watermark such as Google's SynthID, and running a statistical classifier that estimates AI likelihood from the pixels alone.

    How accurate are AI image detectors?

    It depends entirely on the layer. Metadata and watermark checks are near-deterministic when the signal is intact — if the file says it was made by an AI model, it was. Statistical classifiers are far less reliable: independent testing routinely shows both false positives on genuine photographs and misses on AI images that have been compressed, cropped or re-encoded, which is why serious platforms treat a classifier score as a signal, not a verdict.

    Can you tell if an image is AI-generated just by looking at it?

    Less and less. The classic tells — malformed hands, garbled text in signage, impossible reflections, repeating background texture, over-smooth skin with no pore detail — still appear in cheap output, but current top-tier models produce images most people cannot classify by eye. That is exactly why the industry moved to embedded provenance signals instead of visual inspection.

    Does removing metadata make an image undetectable?

    No, and any tool that promises this is lying. Stripping metadata removes the deterministic layer — the C2PA manifest, EXIF generator tags and XMP fields that state outright which model made the image. It does nothing to a robust invisible watermark and nothing to a statistical classifier, both of which read the pixels themselves.

    Why do platforms label my own edited photo as AI?

    Usually because an AI-assisted editing step wrote a provenance record into the file. Generative fill, AI denoise, AI upscaling and some phone camera modes can all attach C2PA Content Credentials or a generator tag, so a photograph you actually took gets labelled the moment the platform reads that metadata.

    Is it legal to remove AI metadata from images I own?

    Removing metadata from your own files is a normal, everyday operation — every social platform, CMS and messaging app already strips metadata on upload for privacy and bandwidth reasons. What matters is intent and context: some jurisdictions and platform policies require AI-generated media to be disclosed, and stripping a signal to pass AI output off as documentary evidence or authentic journalism can breach those rules. Clean files freely; disclose honestly.

    Can an invisible AI watermark be removed?

    Fragile watermarks are often destroyed by ordinary processing — heavy re-compression, resampling, crops and screenshots. Watermarks designed to be robust, like SynthID, are built to survive exactly those operations, and no browser tool can guarantee their removal. Treat pixel-domain disruption as best-effort and never as a guarantee.

    AI Image Detection & Provenance: complete guide series