Treadstone Associates
Article · 8 min read

How to tell if an image is AI-generated

There is no single reliable test for whether an image was AI-generated. The realistic approach combines a provenance check — does the file carry a recorded history — a watermark check, and ordinary source skepticism, because none of the three works alone.

Treadstone Associates · Updated 2026

Key takeaways

  • • A Content Credentials “pin” reveals a file’s own recorded history, but only where the platform hosting the image supports it and the record was never stripped.
  • • Google’s SynthID can only be checked through Google’s own tools, and only ever detects Google’s own watermark.
  • • Content Credentials’ own site names the core limitation: authenticity tools prove what a good actor did, not that every bad actor’s fake is caught.
  • • Because no general-purpose, source-agnostic detector is documented anywhere fetched for this piece, the mechanism matters more than any single tool’s output.

Check one: look for a Content Credentials pin

The C2PA coalition’s Content Credentials standard is designed to be visible at a glance: “The Content Credentials pin signals that the content contains information about its provenance.” Clicking through it is meant to “determine the method of creation and see a record of editing history.” (contentcredentials.org) The standard is not a niche experiment — its own page describes “a collaboration with hundreds of companies led by Microsoft, Adobe, Intel, BBC, Truepic, Sony, Publicis Groupe, OpenAI, Google, Meta, and Amazon” — but adoption by the companies behind a model is only half the chain; the platform displaying the image also has to preserve and surface the pin, which not every platform does.

Check two: ask a model to check its own watermark

Google’s SynthID can be checked directly through Gemini: “Simply upload the image, video or audio clip to your chat, and ask if it’s been created or altered by Google AI. Gemini will check for a SynthID watermark, and let you know if it finds one.” (deepmind.google) Google also describes a separate SynthID Detector, a dedicated verification portal, but frames it as new: the company says it is “currently collaborating with journalists and media professionals to test the portal and collect their feedback” — language that describes an early access programme, not a finished, generally available product.

Why neither check is conclusive on its own

Each check has a narrow, specific blind spot rather than a general unreliability. A Content Credentials pin is only as durable as the platform preserving it — screenshotting or re-encoding an image can strip the record entirely without anyone intending to remove it, a mechanism the companion piece on metadata stripping covers in detail. SynthID’s blind spot is different: Google’s own description covers watermarks “embedded across Google’s generative AI consumer products” specifically, so an image from a different company’s model returns no signal either way — not a “no,” just an absence of information.

Check three: apply the same discipline the Cyber Centre recommends for text

Canada’s Centre for Cyber Security gives essentially the same advice for any AI output, image or text: “Review the generated content and take the time to fact check it against credible sources,” and be cautious about content “not clearly identified as being AI-generated,” because that is exactly the condition that “can result in the spread of misinformation, disinformation and confusion.” (cyber.gc.ca) Applied to an image with no pin and no known model, that guidance is the whole answer: corroborate the image against an independent, credible source rather than relying on the image alone, because neither of the technical checks above has anything to offer here.

What’s left when neither signal is present

No accuracy rate for any general-purpose AI-image detector — Canadian or otherwise — was found in any source fetched for this piece, and none is stated here. Where a Content Credentials pin is absent and the origin model is unknown, the honest fallback is the verification discipline that predates generative AI entirely: checking the original source, corroborating with other reporting, and treating an unverified image as unverified rather than running it through a tool whose accuracy nobody here can vouch for.

Running the checks in order, not in isolation

The three checks are cheapest to run in a specific order, because each one only costs time once the previous one comes up empty. Look for a Content Credentials pin first — it costs nothing but a click, and if it is present it answers the question directly with a dated, attributable record rather than an inference. If there is no pin, ask whether the image plausibly came from a Google product and, if so, run the Gemini watermark check — a fast, free confirmation or a genuine absence-of-information result. Only once both come back empty does the ordinary sourcing-and-corroboration discipline become the whole of the answer, and at that point it is worth being explicit, in whatever the image is used for, that the file’s origin is unconfirmed rather than presenting a guess as a finding.

A worked example

A newsroom receives a submitted photo with no visible Content Credentials pin and no indication of which tool, if any, produced it. Neither the provenance check nor the watermark check applies — there is nothing to click through and no vendor to ask. The honest answer is that no tool checked here confirms or rules out AI generation for this specific file, and the fallback is the same process used long before generative AI existed: source the photo back to whoever took it, look for independent corroboration, and treat the image as unverified rather than assign it a false level of confidence either way. Publishing it captioned as “unverified” is a defensible editorial choice here; publishing it as confirmed authentic, on the strength of an absent pin and an absent watermark, is not — absence of a signal was never evidence of anything.

The stakes are higher once a business, rather than a newsroom, is the one publishing the image. Under the Competition Act, a business that presents an AI-generated image as a genuine, unaltered photograph in its own advertising risks the same reviewable conduct as any other false claim: it is reviewable conduct for a person promoting a product or business interest to make “a representation to the public that is false or misleading in a material respect.” (laws-lois.justice.gc.ca, Competition Act s.74.01(1)(a)) A court can order a corporation found to have engaged in that conduct to pay an administrative monetary penalty of up to $10,000,000 for a first order and $15,000,000 for a subsequent one, or three times the value of the benefit derived from the conduct, or 3% of the corporation’s annual worldwide gross revenue where that benefit cannot be determined. (laws-lois.justice.gc.ca, s.74.1(1)(c)) Treadstone Law’s own explainer on misleading advertising sets out how that track works and what a business needs on file before an ad claim is published. (treadstonelaw.ca)

Related: the mechanism behind the watermark check, why pattern-based detection tools fail in both directions, why recording origin at creation beats guessing afterward

Common questions

Is there a free tool that reliably tells me if an image is AI-generated?

None documented here publishes a reliability rate worth relying on. Google’s own SynthID Detector is still in a limited testing phase, and it only ever covers Google’s own products — it is not a general-purpose answer.

If an image has no watermark, does that mean it’s real?

No. Absence of a detectable watermark only means either the image was not made by a system whose watermark you checked for, or a real watermark was present but not detected — it is not evidence the image is unaltered.

Does a Content Credentials pin guarantee an image is authentic or synthetic?

It reports what the file’s own attached record says, when that record survives to the copy you’re viewing. Content Credentials’ own site is explicit that its goal is to let good actors demonstrate authenticity, not to catch every attempt to fake or strip that record.

What should a business do if none of these checks apply and the image matters?

Fall back on the same discipline Canada’s Centre for Cyber Security recommends for any AI content: fact-check it against an independent, credible source rather than accept it on its own terms, and treat the absence of a provenance or watermark signal as unresolved rather than as proof either way.

Verifying content authenticity matters wherever AI touches customer-facing material.

The same checks that verify a submitted image apply to anything a brand publishes or receives from a customer.