Skip to content
AI AND PROVENANCE

How to check if an image is AI-generated from its metadata

What an image's metadata can tell you about AI generation: Content Credentials, IPTC digital source types and generator prompts, and the limits of each.

· 6 min read

There is no single test that proves whether an image was made by AI. But an image file can say a lot about its own origin, if you know where to look. This guide covers the three kinds of evidence metadata can hold, how strong each one is, and how to read them in seconds.

1. Content Credentials (C2PA)

Signed Content Credentials are the strongest evidence. If an AI tool signed a manifest saying it created the image, and the signature is valid, you know which tool made it and that the file has not been changed since. Read more in what Content Credentials are.

2. The IPTC digital source type

The IPTC, the standards body for news media, defines terms that say how an image was made. Several generators write them into the XMP metadata:

TermMeaning
trainedAlgorithmicMediaCreated by a model trained on sampled content (most AI image generators)
compositeWithTrainedAlgorithmicMediaA composite that includes AI-generated elements, such as generative fill
algorithmicMediaCreated purely by an algorithm, without sampled training data
digitalCaptureCaptured by a camera

Unlike a signed manifest, this label is plain text. It can be added, changed or removed by anyone, so treat it as a claim rather than proof.

3. Generator settings and software names

Local image generators often save their settings in the file. Stable Diffusion web interfaces write a parameters text chunk with the prompt, seed and sampler; ComfyUI saves its whole prompt and workflow. Some tools also name themselves in the Software or Creator Tool field. See why AI images can contain your prompt.

Check an image in seconds

  1. Open Exifo Check and drop the image. Nothing is uploaded.
  2. Read the verdict: Marked as AI-generated, Marked as AI-edited, Has Content Credentials, no AI marker, or No provenance data found.
  3. Look at the details: the generating tool, who signed it and when, the recorded actions, whether the signature is valid, and any prompt found.

The limits of metadata

  • Screenshots, many apps and most social networks remove metadata, so its absence means nothing.
  • Unsigned labels can be faked in either direction.
  • Invisible watermarks such as Google's SynthID live in the pixels, not the metadata, and can only be detected with the maker's own tools. Exifo does not look for them.
  • AI-detection classifiers estimate probabilities and can be wrong; Exifo does not use one.
A valid signed manifest is the only strong evidence. Everything else is a clue to weigh alongside the source of the image, its context, and a reverse image search.

Related guides