Field notes / AI provenance
AI images · provenance

Was this image made by ChatGPT?

In 2026, the useful answer is no longer “look for weird fingers.” Start with provenance signals: C2PA Content Credentials, SynthID, and the metadata actually present in the file.

Published September 15, 2026 · CreatorPrivacyKit Research

Strong signal

A trusted OpenAI C2PA manifest or supported OpenAI SynthID signal can indicate that a file was generated by, or exported from, OpenAI tools.

Useful clue

Ordinary EXIF, XMP, PNG text chunks, software fields, filenames, and dimensions can add context, but they are easier to remove or rewrite.

Not proof

No detected provenance signal does not prove that an image is human-made. Signals can be absent, unsupported, or lost during editing and sharing.

Start with the file, not the visual vibe

Visual AI detectors can be useful for triage, but a polished photograph, illustration, product render, or screenshot can fool both people and classifiers. Provenance is a different question: does the file carry machine-readable evidence about where it came from or how it was edited?

That is why C2PA and watermarking matter. C2PA Content Credentials can carry signed provenance assertions. OpenAI also uses SynthID as a more durable watermarking signal for supported generated content. The two approaches solve different problems: metadata can carry richer context, while a watermark may survive some transformations that discard metadata.

Check these four layers

  1. C2PA / Content Credentials. Look for a valid manifest and the signer. A manifest is more meaningful than a random text field that simply says “AI.”
  2. Supported watermark signals. OpenAI’s verifier can check supported files for OpenAI provenance signals including SynthID. This is not the same as reading EXIF.
  3. Conventional metadata. EXIF, XMP, IPTC, PNG text chunks, software names, timestamps, and editing fields can provide supporting context.
  4. File history. Ask whether the image was screenshot, resized, recompressed, copied through a social network, or exported by another app. Every step can change what survives.

What if the metadata was stripped?

This is the point where many “AI detector” articles become too confident. A screenshot can remove the original container metadata. A messaging app can rewrite an image. A photo editor can create a fresh JPEG. Even a simple conversion from PNG to JPEG can destroy fields that were present in the source.

That does not automatically erase every possible provenance signal. Watermarking systems are specifically designed to be more durable than ordinary metadata. But durability is not immortality. Cropping, heavy editing, format changes, filters, screenshots, or unsupported generation paths can produce a file where no supported signal is detected.

The safe interpretation is asymmetric: a trusted positive signal can be meaningful; a negative result is usually inconclusive.

Can you identify the exact generator?

Sometimes, but only when the evidence supports it. A trusted C2PA chain can name a product or signer. A vendor-specific watermark verifier may identify its own signal. A software field can hint at an editing application. None of that gives you permission to guess “ChatGPT” from texture alone.

If a detector reports a percentage such as “93% AI,” treat that as a classifier score, not provenance evidence. It may still be useful, but it answers a different question.

A practical verification workflow

ResultReasonable interpretationDo not claim
Trusted OpenAI C2PA or supported OpenAI SynthID detectedThe file contains a supported OpenAI provenance signal.Who prompted it, whether every pixel is untouched, or whether the claim is legally owned.
C2PA from another signerThe file has signed provenance information from that ecosystem.That OpenAI created it.
Only ordinary metadata cluesThe fields may describe software or workflow.That the fields are authentic or impossible to edit.
No signal foundNo supported signal was found in this file.“This image is definitely real.”

Why this matters for creators

Creators increasingly receive images from clients, collaborators, marketplaces, AI tools, and social platforms. Knowing whether a file carries provenance data can matter for disclosure, licensing conversations, moderation disputes, newsroom workflows, or simply understanding what information you are about to publish.

It also matters for privacy. Provenance and ordinary metadata are not the same thing, but both can reveal information about a file’s history. Inspect first; sanitize only when you understand what you are removing.

Important: removing metadata is not the same as removing an invisible watermark, and it should not be used to make false claims about a file’s origin.

Inspect the file before you trust the label

CreatorPrivacyKit can inspect supported metadata and C2PA information locally in your browser. Your file does not need to be uploaded just to see what the container is carrying.

Open Metadata Cleaner →