Treadstone Associates
Guide

How to verify a suspicious image or video

None of the tools built for this problem — provenance labels, invisible watermarks, AI detectors — can prove a piece of media is genuine on their own. What they can do, used in the right order, is narrow down how much confidence you actually have. This guide is that order.

Treadstone Associates · Updated 2026

Key takeaways

  • • Content Credentials, the C2PA standard’s output, describes itself candidly: it helps “good actors” demonstrate authenticity — it does not stop a bad actor from producing a fake with no credentials at all.
  • • Google’s SynthID watermarks AI-generated content across Google’s own consumer products specifically; its absence says nothing about content made with a different tool.
  • • No Canadian law requires AI content to carry a label. ISED’s Voluntary Code asks signatories to work toward it; it is voluntary and binds only 46 named organisations.
  • • The cheapest, most decisive checks — the source and its history — usually come before any technical tool, not after.

STEP 01 OF 12

Check the source before you check the file

Before opening any technical tool, ask who posted this, when, and whether that account has a track record. A suspicious image from an account created yesterday with no other posts carries a different weight than the same image from an outlet with a long, checkable publishing history. This step costs nothing and resolves a meaningful share of cases on its own.

This is not a technical check and it is not infallible — a compromised or impersonated account can post through a trusted-looking source — but it is the cheapest filter available and belongs first, not last.

STEP 02 OF 12

Look for a Content Credentials pin

The Coalition for Content Provenance and Authenticity (C2PA) publishes an open technical standard called Content Credentials, described on its own site this way: “Content Credentials function like a nutrition label for digital content, giving a peek at the content’s history” — see c2pa.org. Where present, a visible pin “signals that the content contains information about its provenance,” and: “Determine the method of creation and see a record of editing history” — from contentcredentials.org, backed by a group that includes Microsoft, Adobe, Intel, BBC, Truepic, Sony, Publicis Groupe, OpenAI, Google, Meta, and Amazon.

A pin, when present, is genuinely useful evidence. Its absence is not: adoption is voluntary and far from universal, so most images and video you encounter will simply have no pin either way, which tells you nothing on its own.

STEP 03 OF 12

Check for a SynthID watermark, but only within its actual scope

If the content plausibly came from Google’s own tools, SynthID embeds an invisible digital watermark into AI-generated images, video, audio, and text, detectable through Google’s own tools. Google DeepMind’s own description: “The watermarks are embedded across Google’s generative AI consumer products, and are imperceptible to humans — but can be detected by SynthID’s technology” — see Google DeepMind’s SynthID page.

This only covers Google’s own products. A negative result — no SynthID watermark detected — says nothing about content generated by a different company’s tools; it is not a general-purpose AI detector, whatever the marketing framing around it implies.

STEP 04 OF 12

Reverse image search for an earlier or original version

Search for the image itself, not just related keywords, to find whether it appeared somewhere earlier, in a different context, or attached to a different claim. A genuine photo that has circulated before with a different caption is a very different finding from an image with no prior history anywhere — and this check does not depend on any AI-specific tool at all.

This step and Step 1 together resolve more cases, faster, than any of the AI-specific tools in this guide — they are worth exhausting before reaching for anything more specialised.

STEP 05 OF 12

Check the metadata, and understand why it is often already gone

Original file metadata — camera details, timestamps, edit history — can support or undermine a claim about an image’s origin, where it survives. But most social platforms strip this data automatically on upload, for entirely ordinary reasons unrelated to deception — see why image metadata gets stripped.

Missing metadata is therefore a weak signal on its own — it is the default state for almost anything shared through a mainstream platform, genuine or not, and should not be read as suspicious by itself.

STEP 06 OF 12

Use an AI detector, if at all, as one weak input among several

Dedicated AI-detection tools exist and are sometimes useful directionally, but see why AI detectors get it wrong before treating any single tool’s verdict as decisive. Even C2PA’s own materials are candid about the underlying limit: “there will continue to be bad actors who seek to label synthetic content as authentic” — provenance and detection tools are built to help good actors demonstrate what they did, not to catch every deliberate fake.

Treat a detector’s output the same way this hub recommends treating any single AI-generated claim: a lead worth weighing against the other checks in this sequence, not a conclusion on its own.

STEP 07 OF 12

Weigh provenance and detection against each other, not in isolation

A pin present and consistent, a plausible original source, and no contradicting metadata together build real confidence. Any one of these alone is weaker than it looks: a missing pin is common and meaningless by itself; a detector flag without a corroborating provenance signal is one opinion, not a verdict; an old, well-documented source outweighs a technical signal either way.

The goal of this sequence is not certainty — genuine certainty is often unavailable — it is an honest, defensible level of confidence you can actually justify if someone asks how you reached your conclusion.

STEP 08 OF 12

Match how hard you check to what happens if you are wrong

A questionable image shared privately among colleagues for amusement deserves less scrutiny than one you are about to cite in a client-facing document or repeat as fact to someone else. Before repeating a claim about an image’s authenticity, apply the same proportionality this hub recommends for AI answers generally — see how to sanity-check an answer from AI for the underlying logic, here applied to media instead of text.

If the content is heading into something you publish, a further, more specific set of checks applies — see how to check AI content before publishing.

STEP 09 OF 12

Write down what you checked and what you concluded

Where the stakes are real, keep a short, dated note of which checks you ran and what each one showed — the source history, whether a pin or watermark was present, what a reverse search found. This is the same discipline this hub recommends for AI-assisted decisions generally: a specific, checkable record beats a general assertion that something was “verified.”

This record is also what protects you later if the conclusion is challenged — you can show the actual reasoning, not just the outcome.

STEP 10 OF 12

Check whether the platform itself has already added a label

Some platforms now attach their own AI-generated or altered-media labels automatically, independent of anything embedded in the file by the creator. Where present, treat this the same way as a Content Credentials pin in Step 2 — a useful positive signal, not a guarantee, since platform labelling systems have their own error rates and cover only content processed through that specific platform.

A platform label and a Content Credentials pin can agree, disagree, or one can be present without the other. None of these signals is authoritative on its own; each narrows the range of plausible conclusions a little further, which is the same logic running through this entire sequence.

STEP 11 OF 12

Consider who benefits from the image or video being believed, one way or the other

This is a judgment check, not a technical one, and it belongs alongside the source check in Step 1 rather than replacing any of the technical steps. Content that would meaningfully benefit someone if believed — financially, reputationally, or otherwise — deserves more scrutiny before repeating it than content with no obvious motive behind its spread.

This does not mean assuming bad faith by default. It means weighting the effort you put into the rest of this sequence according to what is actually at stake if you get it wrong, which is the same proportionality principle this hub applies to checking any AI-produced answer.

STEP 12 OF 12

Accept “unverified” as a legitimate final answer

Sometimes none of the checks above resolve the question either way — no pin, no watermark match, no earlier version found, no clear metadata. “Unverified” is a complete, honest conclusion in that situation, not a failure to check hard enough. Treating an unresolved case as if it must be genuine, simply because nothing proved it fake, is the mistake this whole sequence is built to avoid.

No Canadian law currently requires AI content to be labelled — ISED’s Voluntary Code asks its 46 signatories to work toward labelling and detection tools, and binds no one else. Build your own confidence from the checks above; do not assume a missing label means anything either way.

Common mistakes

Treating a missing Content Credentials pin as suspicious. Adoption of the standard is voluntary and far from universal. Most genuine content you encounter has no pin either, simply because the tool that made it does not support the standard.

Treating a SynthID check as a general AI detector. It only covers content generated through Google’s own products. A negative result says nothing about content made with a different company’s tools.

Treating an AI detector’s output as a verdict. Detectors carry real error rates in both directions, covered in a companion piece on this hub. Weigh a detector’s flag alongside source and provenance checks, never in isolation.

Forcing a genuine or fake conclusion when the checks do not support one. “Unverified” is a legitimate, stable answer. Presenting an unresolved case as settled either way is a bigger error than admitting the checks did not resolve it.

Skipping the cheap checks because a technical tool is available. Source history and a reverse image search, both free and fast, resolve more cases than any provenance or watermark check — run them first, not as an afterthought once a technical check comes back inconclusive.

The order, in one place

  • • 1. Source and account history (Step 1).
  • • 2. Content Credentials pin, if present (Step 2).
  • • 3. SynthID, only for plausibly Google-made content (Step 3).
  • • 4. Reverse image search for an earlier version (Step 4).
  • • 5. Metadata, weighed lightly given how often it is stripped by default (Step 5).
  • • 6. An AI detector, as one weak input, never a verdict (Step 6).

Run the cheap checks first. Most cases resolve, or fail to resolve honestly, well before the more specialised tools are needed at all.

Frequently asked

Does the absence of a Content Credentials pin mean an image is fake?

No. The standard is voluntary and adoption is still limited — most content, genuine or not, currently has no pin. Treat its presence as a positive signal and its absence as no signal at all.

Can I rely on an AI detector tool to give a definitive answer?

No single detector should be treated as definitive. See why AI detectors get it wrong for the specific failure modes, and weigh a detector’s output alongside the source and provenance checks in this guide, not instead of them.

Is there a Canadian law requiring AI-generated content to be labelled?

No. ISED’s Voluntary Code asks its signatories to work toward detection and labelling methods, but it is voluntary and binds only the organisations that signed it — there is no general Canadian labelling requirement.

Verifying one piece of content is different from setting a standard for everything you publish.

A consistent publishing check is a policy question, not a one-off judgment call.