Evidence or Hint: How Do You Recognize AI Images?

Last updated: Responsible: Martin Jäger 9 min read
Short answer

AI images can be recognized in four ways that differ in how much weight they carry. Only a provenance marker in the original (C2PA, IPTC) is evidence; a probability detector gives a hint, a file name a weak signal, and a provider watermark confirms only that provider's own output. In no class does a negative result establish that an image is not an AI image, and the check has to run on the unchanged original, because the Shopify CDN delivers re-encoded copies that mostly no longer carry the marker (measurements of September 1 and 10, 2026).

Whether an image came out of an AI tool is getting harder to tell by eye. The ways to find out differ a lot in how much weight they carry. The detection taxonomy v1.0 (as of September 14, 2026) sorts them into four classes. Knowing them tells you when a result is evidence, when it is only a hint, and why an empty report is not an all-clear.

What are the four ways to recognize an AI image?

ClassWhat is checkedWhat a hit meansWhat no hit meansTerm
1 Marker in the originalProvenance data written by the generator (C2PA/Content Credentials, IPTC DigitalSourceType, XMP)AI origin establishedno conclusionevidence
2 HeuristicsFile name, alt text, metadata fragmentsmay point to AIno conclusionweak signal
3 Probability detectorA model estimates from image patternsa probability, not a factno conclusionhint
4 Provider confirmationA provider’s detector recognizes its own invisible watermarkthe provider confirms its own outputno conclusionconfirmation, not evidence

The right-hand column applies to all four classes: a negative result never establishes that an image is not an AI image.

What are C2PA, Content Credentials, and IPTC markers?

Many generators write a machine-readable provenance record into the file when saving. Two forms are common:

  • C2PA / Content Credentials: a cryptographically signed manifest. It names the signer (for example the organization behind the model), often the tool, and the actions performed.
  • IPTC DigitalSourceType: a field with the value trainedAlgorithmicMedia (fully AI-generated) or compositeWithTrainedAlgorithmicMedia (real image with an AI component).

A marker that is found establishes that the creator declared the image as AI output. That is evidence. A measurement series of September 1, 2026 on the lakör test bench shows how common such markers are: of 47 image models from the catalog of one aggregator (Magnific/Freepik, retrieved through its API), 34 set a signed C2PA manifest with trainedAlgorithmicMedia, 13 set nothing. For two of the 34 (Grok), the manifest is only self-signed and cannot be traced back to an issuer. Shopify’s built-in image editor (“Generate background”) wrote no metadata at all on a test image the same day. A retest after December 2, 2026 is planned.

The legal side: the machine-readable marking is the obligation of the provider of the generator under Article 50(2) of the AI Act (Regulation (EU) 2024/1689). For systems placed on the market before August 2, 2026, that obligation applies only from December 2, 2026 (Article 111(4) as amended by Regulation (EU) 2026/1744). Gaps in marker coverage in fall 2026 are therefore to be expected. The merchant has a different obligation, in force since August 2, 2026: the visible disclosure under Article 50(4) for AI images that can appear real (deep fake under Article 3(60)). A marker in the file does not replace it; the Commission guidelines C(2026) 5054 final of July 20, 2026 state in paragraph 117 that deployers may not rely on the provider’s machine-readable marking. For the image types this covers, see the guides overview.

Why does a missing marker tell you nothing?

A marker can be missing for at least three reasons, and from the outside a reviewer cannot tell them apart:

  1. The tool does not write one. 13 of 47 models did not in the measurement of September 1, 2026.
  2. The export path destroyed it. A screenshot never contains provenance data; in the control test of September 1, 2026, 144 bytes of EXIF and 54 bytes of IPTC remained, without any provenance value. A format conversion on download is enough, too: the same model (Recraft V4.1) delivered a native PNG with a 3,174-byte C2PA manifest through the API, but nothing at all as a JPEG from the web interface (measured September 1, 2026).
  3. Delivery re-encoded it. See the section on the original below.

C2PA and IPTC are also not a detector. They carry a claim made by the creator and measure nothing in the image. The IPTC FAQ (as of July 8, 2026) puts it this way: “Does C2PA detect deepfakes or AI-generated content? No. […] They simply extract the data that was put there by its creator or publisher.”

Hence the asymmetry: a found marker is evidence, because the creator declared the image as AI output. A missing marker supports no conclusion; the file may be a real photo, an AI image without a marker, or one whose marker was lost on the way.

How useful is a probability detector?

A class 3 detector is a trained model that estimates from image patterns whether an image was generated artificially and outputs a probability. It helps when no marker exists, with two limitations. It delivers an estimate, not a fact. And false alarms on real product photos happen, while AI images whose patterns it does not know can slip past it. Measurements of the false-alarm rate on product photos from the lakör test bench were not available as of September 14, 2026.

The taxonomy therefore calls such a result a hint, never evidence. A hint is a reason to look at an image more closely, not a basis for judging someone else’s image. It can set the review order for your own catalog; the label decision stays with you.

What about file names and alt texts?

A file name like midjourney_product_03.png or an alt text with the note “AI generated” is a weak signal. It can point to an AI image, but it is easy to fake and easy to lose: a rename on upload or an SEO app that overwrites alt texts deletes it silently. The heuristic works as a search aid in your own inventory; as evidence it does not.

Is an invisible watermark like SynthID evidence?

No. Some providers embed an invisible watermark in the pixels and offer their own detector that recognizes it. An example from the measurement of September 1, 2026: the C2PA manifest of a Google Gemini image literally declares the action “Applied imperceptible SynthID watermark”.

That is the provider’s marking under Article 50(2), not a marker in the original that an independent reader could check. A positive result confirms the output of one specific provider. A negative result says only that this one provider does not find its watermark, nothing about other tools. That is why this class is kept separate, with provider name and date, and never counted toward a marker rate.

Why does the check have to run on the original?

For Shopify stores this is the decisive technical point. Shopify keeps the uploaded file unchanged and exposes it through the Admin API as originalSource. What the store visitor sees is a different file: the content delivery network (CDN) re-encodes the image for the requested width and format, and most of the metadata is lost in the process.

Measurements from the lakör test bench, each dated:

MeasurementAccess pathResult
September 1, 2026, 47 images from nine signature chains uploaded as product mediaoriginalSource47 of 47 file sizes byte-equal to the local file, 34 of 34 markers preserved
September 1, 2026, the same imagesCDN delivery5 of 34 markers preserved
September 10, 2026, three product images with a C2PA marker known to be presentCDN image.url0 of 3 markers preserved

The CDN finding is dated and can change; it describes delivery, not storage. For the question “is this image AI-generated,” the storefront is the wrong place to look: the same image can carry a marker at one width and not at another. A storefront scan measures the image pipeline, not the image origin. The app Easy AI Act Image Labels therefore reads the original through originalSource and nothing else.

One limitation remains: collection images without a file in the Files library (for example from older or imported inventory) have no originalSource and cannot be checked (measurements of September 7 and 10, 2026). Such an image becomes checkable once you upload it under Content > Files and select it from there in the collection.

For your own workflow: download generator output through the official download button in the native format, never as a screenshot, never through an offered format conversion, and do not run the file through a compressor on the way.

What does a check log establish, and what does it not?

The Commission guidelines expect deployers that have not joined the code of practice to be able to explain to the market surveillance authority how their measures implement the obligations (paragraph 148). That takes documentation.

A check log is a sensible tool for it, as long as its scope is clear: it records marker finds, the visibility of the labels, and your decisions. It does not establish that images without a marker are not AI images. A usable log records:

  • which images were checked when, and with which method,
  • which markers were found (tool, signer, date),
  • which images remained without a marker, noted as “no conclusion”,
  • which images you classified and labeled as AI images yourself,
  • whether and where the label was visible in the store.

What it does not replace: the decision whether an image needs a label. That depends not on the technology but on whether the image misleads about the real product (guidelines paragraphs 113 to 116). And it does not cure a misleading image: an AI image that shows a product differently from what is delivered remains misleading, labeled or not (for Germany, Section 5 of the German Act against Unfair Competition (§ 5 UWG), as of August 31, 2026).

What does this mean for your store?

  1. Know your tools. You know which images came from a generator. That knowledge is a reliable source that needs no marker.
  2. Read results by their class. Marker in the original: evidence. Detector result: hint. File name: weak signal. Watermark: confirmation of one provider.
  3. Treat “nothing found” as “nothing found.” Not as an all-clear.
  4. Check the original, not the delivery. And keep originals checkable: native download, upload through the Files library.
  5. Document what you checked and decided. With date, method, and a note on what the log does not establish.

Article 50 of the AI Act is still new in practice; as of August 31, 2026, no court decisions on AI image labeling were known in Germany, Austria, or Switzerland.

Frequently asked questions

What is the difference between evidence and a hint?

Evidence is a machine-readable provenance marker in the original (C2PA/Content Credentials, IPTC DigitalSourceType) that the generator itself wrote. A hint is the result of a probability detector that estimates from image patterns and can be wrong. Only evidence establishes AI origin.

My scan found no marker. Does that mean the image is not an AI image?

No. A missing marker supports no conclusion: of 47 image models measured on September 1, 2026, 13 wrote none at all, and screenshots or format conversions delete existing markers. Images you know came from a generator you classify yourself, regardless of the scan result: under Article 50(4) of the AI Act they need a label if they can appear real (guidelines paragraphs 113 to 116 of July 20, 2026), and for photorealistic images the answer, when in doubt, is yes.

Why is it not enough to check the images in the store, the way customers see them?

The Shopify CDN delivers re-encoded copies that mostly no longer carry metadata: on September 1, 2026, 5 of 34 markers made it through the CDN, and on September 10, 2026, none of three control images did. Shopify keeps the unchanged original separately and exposes it through the Admin API as originalSource; there, all 34 markers were preserved.

Is an invisible watermark like SynthID evidence?

No. Only the provider itself can read a watermark with its own detector; it is the provider's marking under Article 50(2) of the AI Act, not a checkable marker in the original. A positive result confirms the output of that one provider, and a negative result says nothing about other tools.

Is a C2PA marker in the file enough as the merchant's label?

No. The machine-readable marking is the provider's job (Article 50(2)); as the deployer, you have been responsible for the visible disclosure under Article 50(4) since August 2, 2026 for images that can appear real. The Commission guidelines of July 20, 2026 state in paragraph 117 that deployers may not rely on the provider's marking; something visible on the image is needed.

Sources

  1. Regulation (EU) 2024/1689 (AI Act), Article 3(4) and 3(60), Article 50, Article 111. eur-lex.europa.eu (accessed 31 August 2026)
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Article 1(39)(b) (Article 111(4) AI Act). eur-lex.europa.eu (accessed 31 August 2026)
  3. European Commission, Guidelines on the implementation of the transparency obligations under Article 50, annex to C(2026) 5054 final of July 20, 2026 (paragraphs 113-117, 142-148). ec.europa.eu (accessed 31 August 2026)
  4. European Commission, landing page of the guidelines on Article 50 AI Act. digital-strategy.ec.europa.eu (accessed 31 August 2026)
  5. European Commission, EU icons for labelling AI-generated content (page as of August 10, 2026). digital-strategy.ec.europa.eu (accessed 31 August 2026)
  6. IPTC NewsCodes, Digital Source Type trainedAlgorithmicMedia. cv.iptc.org (accessed 31 August 2026)
This article is general information, not legal advice. Whether an image needs a label is your decision; for your specific case, please ask a lawyer.
I find the AI evidence. You confirm with one click.
Coming soon to the Shopify App Store