Back to blog
AI

How to Tell If an Image Is AI Generated Without a Label

How to tell if an image is AI generated when the new EU marking rules leave no visible label. The checks that work, the ones that do not, and why.

Ronkay ArslanRonkay ArslanFounder, Tase10 min read

There is no single test that proves an image was generated. What works is a sequence, and it runs in the opposite order to most people instincts. Check the provenance data attached to the file first, check the source and context second, and study the pixels last. Visual tells are the weakest step, because they are the part image models improve every few months. From August 2, 2026, some generated images also carry a built in mark under European law, but you will not see it, and that is by design.

That ordering matters because the reliable signals live outside the picture. A generated image can be flawless and still announce itself through its metadata, through the account that posted it, or through the simple fact that no earlier version of it exists anywhere. Meanwhile a photograph of a real hand can look wrong enough to fail every artifact checklist on the internet. Starting with the pixels means starting with the least dependable evidence you have.

What changed on August 2, 2026, and what did not

The transparency rules in the European Union AI Act apply from August 2, 2026, and one of them was written for exactly this problem. Providers of generative systems have to mark synthetic images, audio, video and text in a machine readable format, so the output stays detectable as artificially generated or manipulated after it leaves the tool that made it.

Machine readable is the part that catches people out. The mark can be metadata, an invisible watermark, a cryptographic provenance record or a fingerprint. None of those is a caption printed across the picture. The requirement is that the information travels with the file, not that your eyes ever meet it. The European Commission set out its own reading of these duties in its FAQ on Article 50 transparency obligations, which is the primary text rather than a summary of it.

Visible disclosure is required in a much narrower case. Someone publishing a deepfake of a real person has to disclose it in a way an ordinary person can perceive without any special tool, and even there a carve out exists for work that is evidently artistic, creative or satirical. So the labels you will actually meet are the ones attached to manipulated footage of real people, not to every generated landscape in a feed.

Two more limits are worth holding on to. Systems already on the market before August 2 have until December 2, 2026 to meet the marking duty, and nothing generated before August 2 has to be labelled retroactively. Most of what is circulating right now was made before the rule existed. If you want the wider picture of what the Act does and does not cover, we walked through it in what the EU AI Act actually means for you.

And this is European law. Its scope follows the European market rather than where you happen to live, which cuts both ways. A company anywhere is covered once its system is placed on that market, and plenty of what reaches you was still made entirely outside its reach.

Start with the file, not the picture

The standard doing most of the work here is Content Credentials, built by the Coalition for Content Provenance and Authenticity. The idea is a signed record travelling inside the file that says which tool produced the image, what edited it afterwards, and when. Its steering committee includes Adobe, Google, Meta, Microsoft, OpenAI, Sony, the BBC and TikTok, which is a reasonable signal that this is infrastructure rather than a side experiment.

  1. 1

    Get the original file

    Download the image rather than capturing what is on your screen. A screenshot is a brand new file and carries none of the history of the one you were looking at.
  2. 2

    Open it in a credential viewer

    Public verification pages and a growing number of platform viewers will read the manifest and show you what it holds. Some apps now display a small credential indicator directly on images that carry one.
  3. 3

    Read the history, not just the verdict

    A useful manifest names the tool that generated or edited the image and the steps applied to it. That chain tells you far more than a single generated or not generated answer ever will.
  4. 4

    Treat a blank result as unknown

    No credential means no information. It does not mean the image is a photograph, and it does not mean it is synthetic. It means this particular question came back empty and you move to the next one.

An empty result is not an answer

The absence of a mark tells you almost nothing about the image. Usually it tells you the file has been copied, compressed or screenshotted since it was made, which is what happens to nearly everything you see.

Why the mark goes missing so often

Content Credentials attach through what the specification calls a hard binding, a cryptographic hash of the content stored inside the file itself. It is precise, and it is fragile on purpose. Modify the content substantially and the binding breaks, which is correct behaviour for a tamper record and awkward behaviour for everyday sharing. The C2PA technical specification is unusually candid about this, and about how much the standard does not promise.

In practice the credential disappears long before anyone is trying to hide anything. A screenshot produces a new file with no manifest at all. Editors that are not credential aware drop the metadata when they resave. Messaging apps and social platforms re-encode images on upload, and an embedded record does not reliably survive that trip.

The answer built into the standard is a second, weaker layer called a soft binding: an invisible watermark or a fingerprint computed from the content, which can be used to find the original credential in a repository even after the embedded copy is gone. It is a real improvement and it is not a guarantee. The specification states plainly that a soft binding must not be used in place of a hard binding, and this remains an area of active work rather than a solved problem.

How the image reached youEmbedded credentialWhat you can still check
Downloaded as the original fileUsually intactThe full manifest, if the maker attached one
Screenshotted from a screenGoneNothing in the file. Only source and context
Forwarded through a messaging appOften stripped on re-encodeSometimes recoverable through a watermark
Saved from a social feedDepends entirely on the platformAny label the platform applies itself
Cropped or edited and resavedThe hard binding breaksHistory up to that edit, if the editor was credential aware
Why most images arrive with nothing attached, without anyone acting in bad faith.

The visual tells worth keeping, and the ones to retire

Only once the file and the source have come back empty is it worth studying the image itself. The honest framing for this step is that you are hunting for mistakes a model happened to make, not for a signature it always leaves behind.

  • Text and signage. Lettering on packaging, shopfronts, documents and street signs is still where generators fail most visibly, because text has to be correct rather than merely plausible.
  • Light that does not agree with itself. Shadows falling in several directions at once, a reflection that does not match what stands in front of it, or a bright surface with no light source in the scene to account for it.
  • Geometry that will not close. Railings, window frames, tiled floors and staircases that change rhythm halfway across the frame, or edges meeting at an angle the rest of the room rules out.
  • Repeated texture. Crowds, foliage, brickwork and fabric where the same small detail recurs at a suspiciously even interval.
  • The edges of the frame. Backgrounds get less of the attention faces do, so continuity errors gather where nobody was expected to look.

Three habits are worth dropping. Counting fingers stopped being decisive some time ago. So did the idea that skin which looks too smooth means a machine made it, in an era where every phone camera and most filters smooth skin by default. And the uncanny feeling in your gut is not evidence, it is a reaction that fires just as readily at heavy retouching, unusual lighting or an unfamiliar face.

Keep one caveat over the whole list. Every item on it describes a bug that somebody is currently being paid to fix. Visual analysis is evidence with an expiry date, which is precisely why it belongs at the end of the sequence rather than the start.

A thirty second routine for a suspicious image

Most of the time you are not writing a forensic report. You are deciding whether to believe something for long enough to share it. This is the version that fits in the gap before you do.

  1. 1

    Try to reach the original file

    If the image is downloadable, take the file rather than a screenshot. This is the only step that can produce hard evidence, so it is worth the extra few seconds when it is available.
  2. 2

    Read the credentials if any exist

    Check for a manifest or a platform credential indicator. A result here settles the question. An empty result moves you along without telling you anything.
  3. 3

    Find where it first appeared

    A reverse image search that surfaces one recent post and nothing else is a strong signal. Real photographs of newsworthy events tend to exist in several places, from several angles, taken by several people.
  4. 4

    Look at the account, not only the picture

    How old is it, what else has it posted, and does it have any history unrelated to this one claim. Fabricated images usually arrive attached to thin accounts.
  5. 5

    Only now, look at the image

    Run the visual list above, and hold the result loosely. If the first four steps came back empty, unproven is the correct place to stop.

The question underneath the question

Is this generated is usually standing in for a better question: is the claim this image supports actually true. A real photograph can be captioned into a lie, cropped into one, or moved five years and two countries from where it was taken. A generated image of a place that does not exist is harmless as a wallpaper and dishonest in a property listing. Provenance data tells you where a file came from. It does not tell you whether the thing it is being used to say is true, and the specification is careful to make no claim of that kind.

The same instinct is worth pointing at the tools you use every day. Software that will show you where a piece of information came from is easier to trust than software that presents everything with identical confidence, which is the thread running through our list of AI assistant privacy questions and the decision covered in whether to let an assistant read your messages. Marking and disclosure rules raise the floor. They do not do the thinking for you.

Are AI image detector websites accurate?+

Treat their output as one weak signal, never as a verdict. Detectors that guess from pixels alone produce false positives on ordinary photographs and false negatives on recent generators, and they degrade as image models change. A provenance check is different in kind, because it reads a record that was deliberately attached to the file rather than guessing from what the file looks like.

Does taking a screenshot remove Content Credentials?+

Yes. A screenshot creates a new image file that contains none of the provenance record belonging to the original. If you intend to check an image, save or download the original file instead of capturing what is on your screen.

Will every AI generated image carry a visible label now?+

No. The duty that started on August 2, 2026 is for a machine readable mark, which can be metadata, a watermark, a cryptographic provenance record or a fingerprint. Clear visible disclosure is required in the narrower case of deepfakes depicting real people, and an exemption applies to evidently artistic or satirical work.

Does the rule cover images made outside Europe?+

The obligations follow the European market rather than the location of the company, so a provider anywhere is covered once its system is placed on that market or its output is used there. Even so, a great deal reaches you from outside that scope, and anything generated before August 2, 2026 does not have to be marked at all.

What is the single fastest check I can do?+

Find where the image first appeared. A reverse image search that turns up one recent post and nothing earlier is a stronger signal than any artifact you will find by zooming in, and it takes about ten seconds.

An assistant that shows its work

Tase keeps what it remembers about you in one place you can read, edit and delete, so you are never taking its word for where something came from.

Try it free

Related guides

aiprivacyregulationtrust