# Detection Taxonomy v1.0: How Tools Identify AI Images · Easy AI Act Image Labels

> Four method classes for identifying AI images: a marker in the original (evidence), heuristics, a probability detector (hint), and provider confirmation.

URL: https://easyaiactlabels.com/en/taxonomy/

Reference

# Detection Taxonomy v1.0: How Tools Identify AI Images

Last updated: 16 September 2026

Version 1.0, as of 2026-09-14.

> Public, versioned document. It describes methods; providers appear only as measured examples with a date. Every number on this website carries its class.

## What are the four classes?

If you want to know whether an image came out of an AI tool, there are four fundamentally different ways to find out. They do not differ in effort. They differ in what a result means in the end.

Class

Method

What the result means

1

Marker in the original (C2PA/Content Credentials, IPTC `DigitalSourceType`, XMP)

Evidence

2

Heuristic (file name, alt text, metadata fragments)

Weak signal

3

Probability detector

Hint

4

Provider confirmation (watermark)

Confirmation that only the provider itself can read

Two rules apply across all classes: a result is never reinterpreted as a higher class, and numbers from different classes are never combined.

## What is a marker in the original (class 1, evidence)?

A marker is a machine-readable provenance statement that the generator writes into the image file when it saves the image: a signed C2PA manifest (Content Credentials), the IPTC value `DigitalSourceType` (for example `trainedAlgorithmicMedia` for fully AI-generated images or `compositeWithTrainedAlgorithmicMedia` for AI-modified ones), or the corresponding XMP fields.

A marker that is found establishes AI provenance with a high degree of confidence. It is not a measurement taken on the image, though. It is a signed statement by the creator. The IPTC puts it this way in its FAQ dated July 8, 2026: C2PA does not detect AI content; it only extracts what the creator put there. How much weight the statement carries therefore depends on the signer. For most of the tools measured on lakör’s test bench on September 1, 2026, a named organization signs, among them OpenAI, Google, Adobe, Black Forest Labs, and Ideogram. In the same run, Grok images carried a complete manifest with a self-signed chain and no verifiable trust anchor; a validator can see that someone made a claim there, but not who.

**A missing marker establishes nothing.** The image may be a real photo, an AI image from a tool that writes no marker, or an AI image whose marker was lost along the way. Three reasons, each measured on lakör’s test bench (September 1, 2026, with a follow-up on September 10, 2026):

-   **Many tools write no marker.** Of 47 image models measured through the Magnific API, 34 wrote a signed C2PA manifest and 13 wrote nothing. In the same run, Shopify’s image editor (“Generate background”) did not write a single metadata block.
-   **The export path destroys markers.** A screenshot never contains provenance data; the control test, a screenshot of a marked file, produced a JPEG without any provenance statement at all. A format conversion on download has the same effect: Recraft V4.1 delivered a PNG with a C2PA manifest through the API, while the same generation as a JPEG from the web interface carried nothing.
-   **The Shopify CDN serves re-encoded copies.** Through the storefront URLs, 5 of 34 markers survived on September 1, 2026; through the stored original (`originalSource` in the Admin API), 34 of 34 did. A follow-up measurement on September 10, 2026 confirmed this: three product images with a C2PA marker in the original showed 0 of 3 markers through their CDN URL. A quarterly re-test is planned. Scanning the storefront measures Shopify’s image pipeline, not the image’s provenance.

A marker can therefore only be checked against the stored original. In Shopify, that is the file under Content › Files, which the Admin API exposes as `originalSource`. Images without such a file, for example collection images uploaded directly to a collection, have no readable original and cannot be verified (measured September 10, 2026). The way to make them verifiable: upload the image under Content › Files and select it from there in the collection (measured September 7, 2026).

**What the marker is in legal terms.** The marker is the machine-readable marking that Article 50(2) of the AI Act imposes on the provider of the generator. The visible disclosure under Article 50(4) is owed by the deployer (Betreiber), in this case the store; a marker does not replace it, because for the viewer it is neither clear nor distinguishable (Commission guidelines C(2026) 5054, para. 117, as of 2026-08-31). Providers of generators placed on the market before August 2, 2026 only have to comply with Article 50(2) from December 2, 2026 (Article 111(4) of the AI Act as amended by Regulation (EU) 2026/1744). A gap in the marker inventory in the fall of 2026 is therefore normal and no indication of a real photo.

## What are file names and alt text worth (class 2, weak signal)?

File names like “midjourney\_…” or “ChatGPT\_Image\_…”, alt text, remnants of metadata without a signature. Traces like these are easy to add, easy to remove, and easy to fake. Shopify may append its own suffix to file names on upload, and alt text changes with every SEO edit. A heuristic can point toward an AI image and is useful as a search aid for pre-sorting images before a manual review. It establishes nothing, in either direction. A number based on heuristics is reported as a weak signal and is never listed as evidence or as a hint.

## How reliable is a probability detector (class 3, hint)?

A detector model estimates from image patterns whether an image is AI-generated. It delivers a probability, not a fact. False positives on real product photos are possible with this method, as are missed AI images. On this website, results like these are called a hint, never evidence. A false-positive rate is only stated once it has been measured, and then with provider, sample, and date; as long as no measurement exists, there is no number. Hints about other people’s stores are not published; a detailed report with hints goes only to the owner of the store in question.

## What does a provider watermark tell you (class 4)?

Some providers embed an invisible watermark in the image pixels that only their own detector can read. Example from the measurement on September 1, 2026: images from Google’s Gemini models declare the action “Applied imperceptible SynthID watermark” verbatim in the C2PA manifest; images from gpt-image 2.0 (OpenAI) and MAI Image (Microsoft) list the action `watermarked`. These are provider statements in the manifest; the test bench did not read the watermark itself.

When a provider’s detector reports its own watermark, that is a provider confirmation: a form of marking under Article 50(2) of the AI Act (as of 2026-08-31), but not a marker in the original that third parties could verify. A negative result is not a statement, because it only says that this one provider did not recognize a watermark of its own. This level is kept separate, with provider name and date, and is never combined with the marker rate.

## How do you tell which class a number belongs to?

Every number on this website carries three pieces of information: the class, the measurement date, and the basis, meaning the sample or the source. “34 of 47 image models write a marker (class 1, September 1, 2026, lakör test bench)” is a complete statement. A number without a class is an error, not a matter of interpretation. Third-party statements, such as a provider’s explanation of its own watermark, are marked as such. Evidence and hints sit in separate columns and are never added up.

## What does this mean for your store?

-   Anyone who promises to find every AI image is confusing class 3 with class 1: a detector estimates, a marker establishes. No tool finds an AI image whose creator wrote nothing into it and that shows no conspicuous patterns.
-   Whether an image must be labeled is governed by Article 50(4) of the AI Act (applicable since August 2, 2026) and by the question of whether it looks deceptively real, not by the result of a check. The classes only tell you how solid the technical basis for your decision is. For an AI image without a marker, labeling remains your job. Contested cases, such as a fully AI-generated but true-to-life product image, are not settled in the Commission guidelines (as of 2026-08-31).
-   Images whose origin you know do not need to be checked. Class 1 helps with the inventory you no longer have an overview of; the decision about the label stays with you in every case.
-   An audit trail like the one kept by the Easy AI Act Image Labels app records what was checked, what was found and not found, and what you decided. It documents marker findings, the visibility of the labels, and your decisions. It does not document that images without markers are not AI images.

## How is this document versioned?

Changes to this document increase the version number; older versions remain available. New measurements are added with a date and do not silently replace older ones. This version 1.0 has been in effect since 2026-09-14.

## Related questions

### What is the difference between evidence and a hint?

Evidence is a marker that the generator wrote into the original file (C2PA/Content Credentials, IPTC DigitalSourceType). A hint is the result of a probability detector, which can be wrong. The two are kept separate and never combined.

### What does it mean when no marker is found?

Nothing. The image may be a real photo, an AI image without a marker, or an AI image whose marker was lost on export. Of 47 image models measured on lakör’s test bench on September 1, 2026, 13 wrote no marker.

### Does a marker that is found replace the label in the store?

No. The marker is the provider’s machine-readable marking under Article 50(2) of the AI Act. The visible disclosure under Article 50(4) is owed by the deployer (Betreiber), in this case the store; according to para. 117 of the Commission guidelines, metadata does not replace it (as of 2026-08-31).

### Why can images from the Shopify storefront not be verified?

The CDN serves re-encoded copies without provenance metadata: on September 1, 2026, 5 of 34 markers survived, and in the follow-up measurement on September 10, 2026, 0 of 3. What can be verified is the stored original, which Shopify keeps separately under Content › Files.

### Is a provider watermark like SynthID evidence?

No. Only the provider’s own detector can read its watermark; third parties cannot. It therefore counts as a provider confirmation with provider name and date, and a negative result is not a statement.

### Why are markers missing from many AI images in the fall of 2026?

Providers of generators placed on the market before August 2, 2026 only have to set the machine-readable marking from December 2, 2026 (Article 111(4) of the AI Act as amended by Regulation (EU) 2026/1744). For the store as deployer, Article 50(4) has applied since August 2, 2026 with no transition period.
