Two different questions hiding in one
When someone sends us a picture and asks if it was made by AI, they are usually asking two things at once. The first one is what the pixels look like, and the programs that guess at that get it wrong in both directions a lot of the time, and more so once the picture has been edited or compressed or is just a little unusual. The second question is what your file has to say about where it came from, and that one you can answer properly, since there is now a standard for writing the file’s history into the file and signing it. So that is the one we answer. Drop your PNG or your JPEG on the file tab and we read the C2PA Content Credentials inside it, test the signature, and show you who or what made your file, with which tool, when, and what was done to it afterwards.
What Content Credentials are
A Content Credential is a little signed record inside your file that says where the file came from and what edits were made to it along the way. The group behind the standard is a broad one, which is part of why it has lasted: camera makers like Leica and Sony, Adobe on the creative software side, Microsoft and Google as platforms, and OpenAI among the AI labs. A camera that supports it can sign your photo the moment you take it, the pictures that come out of DALL·E carry a record saying they were made by AI, and Photoshop can add each edit to the chain as you work. The record is signed, so if someone goes in and changes it you can tell, and that is what turns it from a bit of trivia in the file’s metadata into something you could put in front of another person and have them take it seriously.
The three things you can get back, and what we would make of each one
- A record from an AI generator. The record says an AI model made your picture, and how much weight it carries turns on one further question, which is whether the certificate that signed the record traces back to an authority we recognise. When it does, we say the credentials verified, and that is the strongest reading anything on this site produces, since a signature either checks out or it does not and there is no guessing in that part of it. When it does not, we tell you that too, in the result itself: the file has not been changed since it was signed, and who signed it is unverified, since anybody can make a certificate and sign a file with it. In that second case the record is a claim somebody attached to the picture rather than something we have checked out for you.
- A valid capture or editing chain. Here the record says a camera took your picture, or it lays out a chain of edits that hangs together. That tells you a lot about how the file came to be, though what it tells you about is the file’s history, and a real camera can take a real photo of a staged scene.
- Nothing at all, which is what you will see most often. When there is nothing there we say “no provenance data,” and we label that as unknown every time, never as “probably real.” Most real photos have no record in them, and the ones that had one lose it to a screenshot, a messaging app, or a platform that strips the metadata out. So an empty result does not prove anything about your picture, and it is only when the record is there that you have learned something.
Documents work in a similar way, only the evidence is a lot weaker. If you upload a DOCX or a PDF we read the metadata, which is the fingerprint the software typed in when the file was saved, and anybody could have changed that in a few seconds with a text editor, so we label it as the weak signal that it is.
Why you will see more of these records over the next year
The law has started to point in this direction. On August 2, 2026 the obligations in Article 50 of the EU AI Act became enforceable, and a company that provides a system which generates synthetic images, audio or video has to mark the output in a way a machine can read, with a grace period to December 2, 2026 for systems that were already running. Every time the conversation about how to do that marking comes up, C2PA is the standard it lands on. So we expect these records to get steadily more common over the next year, and a picture with nothing in it to become, very slowly, a little more meaningful than it is today, though we would not count on that yet. Who is bound, what the penalties are, and what the US and China have done is on the AI content law page, in plain language and not as legal advice.
Does ChatGPT watermark its text?
Almost every person who asks us about pictures asks this right afterwards, and no, it does not. There is nothing like C2PA for a piece of text that you paste into a box. OpenAI built a text watermark as a prototype and never shipped it, and the invisible Unicode characters people sometimes find in ChatGPT’s output are left over from copying and pasting rather than put there on purpose. The text marks that do exist are hidden in which words got picked, and only the company that holds the key can read them, so neither we nor you can. The page on how text watermarks work goes through the mechanism, and who watermarks text today keeps track of where each of the big companies has got to. For text, what you can have today is a statistical test with a published error rate behind it, and that is what the other tab on the front page does.
What Cobalynx can and cannot do here
We tell you what is signed into your file. We do not look at the pixels and guess, and we are not going to add a pixel classifier whose error rate we could not put on the evidence page with a straight face. A record from an AI generator whose signature traces back to an authority we recognise is strong evidence about where your picture came from, and one that traces back to nobody is a claim rather than a check, and we show you which of the two you have. A screenshot or a re-save strips the record out, so when we say “no credentials” we mean unknown, and if you were about to accuse someone on the strength of an empty result we would ask you not to. What every verdict state means across the site is on the methodology page.
Common questions
What are C2PA Content Credentials?
They are a small signed record that lives inside the file, and what it says is who or what made the file and who edited it afterwards. C2PA is an open standard, and the people who put it together were the camera makers, Adobe, Microsoft, OpenAI and Google, and when the EU AI Act talks about marking synthetic media in a way a machine can read, this is the mechanism it keeps coming back to. We would call it evidence since the record is signed, and so if someone has been in there and changed it, you can tell.
The image has no credentials. Is it real, then?
We do not know, and we will always say unknown when that is the situation. Most real photos have no record in them at all, and the ones that did have one tend to lose it when someone takes a screenshot, sends the picture through a messaging app or saves it again. So an empty result does not tell you the picture is real and it does not tell you it is fake, and it is only when a valid record is there that you have learned something definite about the file’s history.
Does screenshotting or re-saving remove Content Credentials?
Yes, it does, and that catches a lot of people out. A screenshot is a brand new file, and it has none of the history that the original was carrying, and on top of that a lot of apps and platforms strip the embedded metadata out of a picture when you upload it. That is the reason that “no credentials” is such weak evidence, and it is why we report it as unknown and do not let you think a picture with no record in it is suspect in some way, because most of the time it is just a picture that has been through a phone.
Does ChatGPT watermark its text the same way?
No, it does not. There is nothing like C2PA for text you paste into a box, because OpenAI built a text watermark as a prototype and never shipped it, and the stray invisible Unicode characters people sometimes find in ChatGPT’s output are left over from copying and pasting and are not a watermark. What you can do with text today is score it statistically, the way we do, and the pages on how text watermarks work and who really watermarks text go through the whole picture if you want it.
Why don't you offer a pixel-based AI image detector?
Because we are not willing to give you a verdict that we could not put an error rate behind. The programs that guess from the pixels are wrong in both directions a lot of the time, and they get worse once a picture has been edited or compressed again, while a signed record either checks out or it does not. We would sooner tell you “unknown” than give you a guess, and that is the same thinking behind every Cobalynx verdict, which is written up on the methodology page.