Why Authenticity Is Now a Production Problem
A few years ago, telling a synthetic image from a photograph was a party trick. Extra fingers, melted ears, text that dissolved into nonsense — the tells were obvious enough that a quick squint did the job. That era is over. Modern diffusion and video models produce skin pores, chromatic aberration, believable depth of field, and motion blur that survive casual inspection on a phone screen.
The practical consequence is not that "nobody can tell anymore." It is that verification has shifted from a glance to a process. A glance costs nothing and scales infinitely; a process costs time and has to be designed. Teams that publish, license, or archive visual media now sit on both sides of that shift. They need to verify what arrives from outside — stock submissions, user-generated clips, client-supplied reference, freelance deliverables — and they need to prove that what they publish is what they claim it is.
This guide maps out how detection actually works, where it breaks, and how to build a verification workflow that holds up when a single wrong call carries real cost. It is written for editors, producers, journalists, brand teams, and creators who work with AI-generated video and images daily — not for researchers benchmarking detectors on clean datasets.
The Forensic Signals That Give Synthetic Media Away
Detection tooling is not magic. Every method in use today leans on one of four families of evidence: pixel statistics, physical plausibility, metadata, or model fingerprints. Understanding which family a signal belongs to tells you how much to trust it.
Pixel-level and frequency artifacts
Generative models synthesize images through an iterative denoising process. That process leaves statistical traces: unusually smooth gradients in regions that should carry sensor noise, periodic patterns in the frequency domain, and subtle color channel correlations that real camera pipelines rarely produce. Classic forensic techniques — error level analysis, noise residual mapping, wavelet decomposition — were built for tamper detection and repurposed for synthesis detection.
The catch is fragility. Resize an image, re-encode it as JPEG at moderate quality, or screenshot it, and much of this signal disappears. A detector that scores 95% on pristine model output can drop to near coin-flip accuracy after a single round of social media compression.
Physics, geometry, and lighting errors
Video models have improved dramatically at temporal consistency, but they still struggle with consequences. Watch for hands interacting with objects and count fingers after the interaction, not before. Look at reflections: a mirror should show the scene behind the camera, and window reflections should match the light source direction. Check shadow direction across a scene — a single room with two contradictory shadow angles is a strong indicator.
Text is another reliable pressure point. Signs, jerseys, labels, and license plates degrade in characteristic ways. So do repeating patterns: bricks, tiles, chain-link fence, and keyboard keys tend to drift in size or spacing. None of these are proof on their own — real photos have motion blur and weird signage too — but three or more independent anomalies in one frame is a meaningful signal.
Metadata and provenance records
Container metadata is cheap to read and cheap to fake. EXIF fields tell you the camera model, lens, exposure, and timestamp if they exist and are intact. Screenshots strip them. Editors strip them. Some platforms strip them on upload. Absence of EXIF is weak evidence; contradictory EXIF is stronger evidence — a "Canon EOS R5" capture with software tags from a diffusion pipeline, or an ISO/aperture combination that the named lens cannot physically achieve.
Metadata is best treated as a routing signal. It tells you whether to escalate to a heavier verification pass, not whether the image is real.
Model-specific fingerprints
Each generative model leaves a slightly different signature, which is why some detectors are trained as classifiers against a specific family of outputs. These can be accurate — until the model updates. A new checkpoint, a new sampler, or a fine-tune shifts the distribution and the classifier's accuracy degrades quietly. Model-specific detectors are useful for triage on known sources and unreliable as a general-purpose verdict.
Where Automated Detectors Break Down
Detector accuracy numbers in vendor documentation come from curated benchmarks. Production performance is worse for predictable reasons.
False positives on real photographs
Real photos are not a clean control group. Heavy denoising, portrait-mode background blur, HDR stacking, film grain emulation, and aggressive sharpening all push an image toward the statistical profile of synthetic content. Genuine camera traps, astrophotography, and long-exposure night shots are frequent false positives. A detector that flags 2% of real photos as synthetic sounds harmless until you apply it to a newsroom's inbound queue of 50,000 images per day.
Laundering through re-encoding
Anyone motivated to hide synthetic origin has a simple toolkit: re-encode, crop, add noise, resample, screenshot, print-and-rescan, or run the output through a second generative pass. Each step degrades the forensic signal that detectors rely on. This is not an exotic attack; it is what happens naturally when content moves between apps.
The generalization gap
Detectors trained on outputs from one model family tend to underperform on another. The field is in a continuous arms race, and there is no stable equilibrium in sight. Treat any single detector's percentage as a hypothesis, not a finding.
The reproducibility problem
Many publishing and legal workflows need a verdict that can be reproduced months later. Closed detectors that return a score without an explanation make that hard. If you cannot explain why a piece of media was flagged, you cannot defend the decision under review — and you cannot learn from your own mistakes.
Provenance Beats Detection: Signing, Watermarks, and Labels
Detection tries to answer "was this made by a machine?" Provenance tries to answer a better question: "who made this, and can they prove it?" The second question has a durable answer.
How content credentials work
C2PA-style content credentials attach a cryptographically signed manifest to a media file. The manifest records the capture device or generative tool, the edit history, and the signing entity. Because it is signed, altering the manifest breaks verification. Because it can be embedded in the file and mirrored in a sidecar, it survives some pipelines better than pixel signals.
Adoption is uneven, which is the main limitation. A file without credentials is not necessarily synthetic; it may have come from an older camera, a platform that strips metadata, or a tool that never supported signing. Provenance gives you a strong positive and a weak negative.
Invisible watermarks and their limits
Some generative tools embed imperceptible watermarks in the latent or pixel space. Detection requires the matching decoder, which means verification is only available to parties the model provider cooperates with. Watermarks have been shown to degrade under cropping, compression, and regeneration. They are a useful defensive layer, not a guarantee.
The honest framing for any watermarking scheme: it raises the cost of removing provenance, it does not eliminate it.
Platform labels and disclosure rules
Disclosure labels are a social mechanism, not a technical one. They work when creators opt in honestly and platforms surface them consistently. They fail when content is re-uploaded elsewhere and the label is stripped. For your own publishing, treat disclosure as a policy commitment you control — the label may not follow your file, but the statement in your caption or description will.
A Practical Verification Workflow
The goal is not certainty. The goal is a defensible, repeatable process that produces a documented verdict with a stated confidence level. Here is a five-stage workflow that scales from a single image to a batch of a thousand.
Stage 1: Triage before you zoom
Ask three questions before opening any tool: Where did this come from? Does the source have an incentive to fabricate? Does the claim depend on the image being real? If the answer to the third question is no, the cost of a wrong call is low and you can stop at a lighter check.
Stage 2: Read the provenance layer first
Check for content credentials, EXIF, and any platform-supplied labels. Record what is present and absent. Absence is not guilt, but it tells you how much weight the rest of the process has to carry. If credentials verify and the signing entity is known, you are largely done — move to documentation.
Stage 3: Run two or more independent detectors
Use at least one detector trained across many model families and one that analyses physical or geometric plausibility. Disagreement between detectors is information: it usually means the file has been re-encoded or is an edge case. Never record a single detector's score as a verdict.
Stage 4: Do the human forensic pass
This is where most errors get caught. Zoom to 200% and walk a checklist:
- Hands, teeth, ears, and hair strands at boundaries with background.
- Text of any kind, especially small or partially occluded text.
- Reflections, shadows, and light source consistency across the frame.
- Repeating patterns: tiles, fabric weave, windows, chain-link, keyboard rows.
- For video: blink rates, lip sync drift, clothing and hair continuity between cuts, background extras that appear or vanish.
- For audio-visual: room tone consistency and whether mouth movement aligns with plosive consonants.
Stage 5: Document the verdict and the evidence
Write down what you checked, what tools you ran, what you found, and what confidence level you assign. A simple three-tier label works well: verified authentic, verified synthetic, unresolved. "Unresolved" is a legitimate and frequently correct outcome. Publishing a confident verdict you cannot support is worse than admitting ambiguity.
Keeping Your Own AI Content Trustworthy
If you produce synthetic media, detection is only half the discipline. The other half is making your work easy to verify as intentional rather than deceptive.
Disclose at the point of publication
State plainly that the scene is AI-generated. Put it in the caption, the description, and where practical on the frame itself. Audiences forgive synthetic imagery; they do not forgive being tricked.
Preserve your source chain
Keep prompts, seed values, model and version identifiers, reference images, and intermediate renders. This log is your defence if the work is later questioned, and it is genuinely useful when you need to reproduce or extend a shot six months later.
Export with provenance intact
Where your tools support signed manifests, keep them. Avoid unnecessary re-encoding before publishing, and when you must transcode, do it once from the highest-quality source. Every extra generation of compression erodes both your quality and your verifiability.
Avoid deceptive framing
Synthetic photojournalism, fabricated evidence, and fake testimonials are not creative edge cases; they are harm. Keep a short internal policy listing what your team will and will not generate, and apply it before someone has to ask.
Choosing Detection Tools: Decision Criteria
Tool selection matters less than the process around it, but the wrong tool wastes time. Weigh these criteria in order:
- Explainability. Does it show you what triggered the score — heat maps, flagged regions, frequency plots? Unexplainable verdicts cannot be defended.
- Generalization. Was it tested against multiple model families rather than one? Ask for the benchmark composition, not just the headline number.
- Robustness. How does accuracy hold after JPEG compression, resizing, and screenshotting? This is where most tools quietly collapse.
- Provenance support. Does it read signed manifests rather than relying solely on pixel statistics?
- Video handling. Frame-by-frame analysis plus temporal consistency checks is a different problem from still-image analysis. Confirm it does both.
- Batch and API access. If you process volume, manual upload interfaces will not survive contact with your queue.
- Audit logging. Can you export the checks you ran for a given asset? Legal and editorial review will ask.
A reasonable stack for a small team: one general-purpose detector with heat maps, one provenance reader, and a manual checklist. That combination catches most real-world cases without an enterprise contract.
Common Mistakes to Avoid
- Treating a score as proof. A 92% synthetic score is a hypothesis. Combine it with other evidence before acting.
- Assuming metadata absence means fabrication. Most files on the internet have been stripped by at least one platform.
- Testing only the finished, compressed file. If you have access to the original, verify that instead and note the version you checked.
- Ignoring the source's incentive structure. The most reliable signal is often who benefits from you believing the image.
- Forgetting video is not a stack of stills. Temporal consistency, audio sync, and continuity across cuts are separate checks.
- Failing to record your process. An undocumented verdict is worthless six months later when the story is contested.
Ethics, Law, and Editorial Practice
Detection work has consequences for real people. Falsely labelling someone's genuine photo as synthetic is a reputational harm, and it is the failure mode that gets least attention. Build in a review step before any public accusation, and prefer language that describes evidence rather than intent.
Legally, disclosure requirements for synthetic media are tightening in many jurisdictions, particularly around political content and advertising. Practical compliance means knowing whether your material needs a label, keeping records of what you generated and how, and being able to produce them on request. When in doubt, disclose — the cost of an unnecessary label is trivial next to the cost of being caught concealing one.
Editorially, the strongest position is a published policy. Say what you verify, how you verify it, what you will label, and what you will refuse to generate. A short, honest policy outperforms a sophisticated detector nobody on the team knows how to interpret.
Frequently Asked Questions
Can AI image detection be 100% accurate?
No. Every method in use today produces false positives and false negatives, and accuracy degrades after compression or re-generation. The right target is a documented, defensible process — not a perfect classifier.
Are invisible watermarks reliable?
They help, but they are not guarantees. Watermarks can degrade under cropping, heavy compression, and regeneration, and verification typically requires the provider's own decoder.
What is the fastest check for a suspicious image?
Look at hands, text, reflections, and shadow direction at 200% zoom. These four checks catch a large share of obvious cases in under a minute and require no tools.
How do I prove my own AI-generated video is synthetic and intentional?
Disclose it in the caption and description, keep your prompt and model records, retain signed provenance data where your tools support it, and avoid re-encoding that strips that data.
What should I do when detection is inconclusive?
Say so. Log the checks you ran, label the asset as unresolved, and avoid publishing a strong claim. Ambiguity is a legitimate finding, and admitting it protects your credibility later.
Does video need different detection than still images?
Yes. Video adds temporal consistency, audio-visual sync, and continuity across cuts. Tools that only analyse single frames miss an entire class of errors — and an entire class of evidence.
Key Takeaways
Detection is not a button. It is a workflow with four layers: provenance records, statistical and forensic analysis, human inspection, and documentation. Provenance is the strongest layer when it is available, and the most commonly missing. Detectors are useful triage tools whose reported accuracy rarely survives contact with compressed, re-uploaded, real-world media. Human inspection still catches the cases that matter most.
For creators, the more durable strategy is to make your own synthetic work trivially verifiable: disclose clearly, keep your source chain, preserve signed provenance, and avoid unnecessary re-encoding. For everyone else, the goal is not to be certain every time — it is to build a process you can explain, repeat, and stand behind when someone asks how you know.



