Provenance, not pixel-guessing
“Is this image AI?” hides two very different questions. One is what do the pixels look like — answered by classifiers that guess from visual patterns and are routinely wrong in both directions once an image is edited, compressed, or simply unusual. The other is what does the file itself record — answered by reading the provenance data standards now embed in files. We answer the second, because it can be answered deterministically: drop a PNG or JPEG on the file check and we verify its C2PA Content Credentials cryptographically, then show you who or what created the file, with which tool, when, and through which edits.
What Content Credentials are
C2PA Content Credentials are a signed manifest embedded in a file — a tamper-evident record of its origin and edit chain, backed by an industry coalition spanning camera makers (Leica, Sony), creative software (Adobe), platforms (Microsoft, Google), and AI labs (OpenAI). Cameras can sign photos at capture; DALL·E images ship with manifests recording their AI origin; editors like Photoshop can append each edit to the chain. Because the manifest is cryptographically signed, altering it is detectable — which is what elevates reading it from metadata trivia to actual evidence.
The three outcomes — and what each honestly means
- An AI-generator manifest. The credentials record creation by an AI model. This is near-conclusive: the generator itself signed the file as synthetic. It is the strongest verdict this site ever issues, and it comes from arithmetic, not judgment.
- A valid capture-or-edit chain. The credentials record a camera capture or a coherent editing history. That is strong provenance for how the file came to be — bearing in mind that provenance describes the file's history, not the honesty of what the picture shows.
- No credentials at all — the common case. We report “no provenance data,” and we will always label it unknown, never “probably real.” Most authentic photos have no credentials, and credentials that existed are stripped by screenshots, messaging apps, and platform re-uploads. Absence proves nothing; only presence tells you something definite.
Documents travel a parallel, weaker path: DOCX and PDF uploads get a metadata reading — tool fingerprints typed by software and trivially editable — always labeled as the weak signal metadata is, never dressed up as verification.
Why adoption is accelerating: the law now points here
The EU AI Act's Article 50 obligations became enforceable on August 2, 2026: providers of systems that generate synthetic images, audio, and video must mark their outputs machine-readably, with a grace period for pre-existing systems running to December 2, 2026 — and C2PA is the standard the marking conversation keeps landing on. That means image credentials will get steadily more common, and their absence will very slowly become more meaningful. The legal picture — who is bound, penalties, the US and China rules — is on the AI content law page. (Plain language, not legal advice.)
“Does ChatGPT watermark its text?” — the sibling question
People asking about image credentials usually ask this next, so: no. There is no C2PA equivalent for pasted text. OpenAI prototyped a text watermark and never shipped it; occasional invisible Unicode characters in outputs are copy-paste artifacts, not a marking scheme. Text watermarks that do exist live in word-choice statistics and can only be verified by the provider holding the key — how text watermarks work explains the mechanism, and who watermarks text today tracks each provider's actual status. For text, calibrated statistical detection is what is honestly available — that is the other tab of the checker.
What Cobalynx can and can't do here
We report what is cryptographically in the file — we don't guess from pixels, and we won't bolt on a pixel classifier whose error rate we couldn't honestly publish. Credentials can be stripped by screenshots and re-saves, so “no credentials” means unknown, and we will always label it that way: a signed AI-generator manifest is near-conclusive evidence of AI origin, while an empty result is not evidence of anything. What each verdict state means across the whole site is documented on the methodology page.
Common questions
What are C2PA Content Credentials?
A cryptographically signed manifest embedded in a file that records who or what created and edited it — an open standard (C2PA) backed by camera makers, Adobe, Microsoft, OpenAI, and Google, and the mechanism the EU AI Act points to for machine-readable marking of synthetic media. Because the manifest is signed, tampering with it is detectable — which is what makes reading it evidence rather than guesswork.
The image has no credentials. Is it real, then?
Unknown — and we will always label it that way. Most authentic photos carry no credentials at all, and credentials that did exist are stripped by screenshots, messaging apps, and re-saves. Absence proves nothing in either direction; only the presence of a valid manifest tells you something definite about a file's history.
Does screenshotting or re-saving remove Content Credentials?
Yes — a screenshot is a brand-new file with none of the original's provenance, and many apps and platforms strip embedded metadata on upload. That is exactly why “no credentials” is such weak evidence, and why we report it as unknown rather than implying an image without credentials is suspect.
Does ChatGPT watermark its text the same way?
No. There is no C2PA equivalent for pasted text: OpenAI prototyped text watermarking but never shipped it, and stray invisible Unicode characters in outputs are artifacts, not a watermark. Text today is checked statistically instead — how text watermarks work and who actually watermarks text cover the full picture.
Why don't you offer a pixel-based AI image detector?
Because we will not publish a verdict we cannot put an honest error rate behind. Pixel classifiers guess from visual patterns and are routinely wrong in both directions on edited or re-compressed images; a signed manifest is deterministic evidence. We would rather tell you “unknown” than sell you a coin flip — the same principle behind every Cobalynx verdict on the methodology page.