How to Tell If a Photo or Video Was Made by AI
How to tell if a photo or video was made by AI: check Content Credentials, ask Gemini about SynthID, reverse image search, and why AI detectors come last.

In February, a video of JD Vance being booed at the Winter Olympics opening ceremony passed four million views on X before anyone checked. It was a deepfake, built from a single still photo. The firm that debunked it, Sensity AI, reproduced a similar clip for about 12 euros.
That's the state of things. The old tells, six fingers, gibberish text, warped backgrounds, are mostly gone from current image models, and video has caught up fast. Looking harder at the pixels is no longer the first move.
There is now a proper order of operations, and the first two steps take under a minute. This guide walks through them, then what to look for when the quick checks come back empty, and why "AI detector" websites should be your last resort.
The short answer
- Check provenance first. Many generators attach Content Credentials, a signed record of where an image came from. Drop the file into a verify tool and read it.
- Ask Gemini. Upload the image or video and ask whether it was made by Google AI. It reads Google's SynthID watermark and other companies' Content Credentials.
- Reverse image search. Google Lens or "About this image" shows where the picture has appeared before. A "breaking" photo from 2023 answers itself.
- Then look properly. Skin, physics, backgrounds, blinking, audio. The tells have moved, not vanished.
- Detector sites are a second opinion, never a verdict. In a May 2026 test, one flagged 40% of real news photos as fake.
- Absence of a watermark proves nothing. A screenshot strips everything. Silence from every tool means "unknown", not "real".
Step 1: Check for Content Credentials
Content Credentials are the closest thing to a nutrition label for images: a signed metadata record, built on a standard called C2PA, saying which tool made or edited the file. OpenAI, Adobe, Google, Meta and Microsoft are all members, and OpenAI became a certified C2PA generator in May 2026.
To read them, go to the Content Credentials verify tool, which redirects to Adobe's hosted checker, and drop the file in or paste its URL. If credentials are present you'll see the issuer, date, app and whether AI was involved. Adobe says Firefly attaches them automatically to anything where every pixel was generated.
OpenAI runs its own checker at openai.com/verify. Upload a single image and it reports whether it finds OpenAI's C2PA record or its SynthID watermark, and says "content likely originated from OpenAI tools" if so. It only knows OpenAI's own output. It won't recognise a Midjourney image, and Midjourney reportedly doesn't embed Content Credentials at all, though I couldn't confirm that first-hand.
The catch is in OpenAI's own help page: the metadata can be "stripped during upload, download, editing, conversion, or sharing". A screenshot is a new file with no history. Most of what you see on social media has been through at least one of those.
Step 2: Ask Gemini whether Google made it
Google's approach is different. Instead of relying on metadata that gets stripped, it stamps a watermark called SynthID into the pixels of everything its models produce, designed to survive cropping, filters and compression. Google says it has watermarked more than ten billion images and video frames this way.
The way to check it is the Gemini app. Open gemini.google.com or the mobile app, attach the file, and ask "Was this image created or edited by Google AI?" Google's help page lists the limits: files up to 100 MB, video under 90 seconds, roughly ten checks per content type per day. It also reads other companies' Content Credentials on web and Android.
Google announced in May that the same check was rolling out to Search and a right-click option in Chrome. I couldn't confirm the Chrome version had reached everyone at the time of writing, so treat the Gemini app as the reliable route.
The limit mirrors OpenAI's tool: Gemini "can currently only recognise content created by Google AI tools". A clean result means "not Google's", not "real". OpenAI has adopted SynthID for its images too, but that's still two companies out of dozens.
Step 3: Find out where the image has been
This is the check that catches most fakes that matter, because most fakes that matter are old images with new captions.
On Android, long-press the home button, circle the image, and swipe up to the "About this image" tab. In the Google app on either platform, open Lens, select the image and swipe up. You'll see where else the image appears online, the earliest date Google has for it, what fact-checkers have said, and any AI-related metadata Google can read, including SynthID.
TinEye does the same job from a desktop browser: upload or paste a URL and sort results by oldest. I didn't use it for this piece, but the principle hasn't changed in a decade.
When the Iran conflict produced a flood of fakes in March, the most-shared "missile strike on Tel Aviv" video turned out to be a 2023 football celebration in Algiers, and a five-million-view "US F-15 strike" was footage from the game Arma 3. Neither needed a detector. Both needed someone to search.
Step 4: Look at it properly
If the file has no credentials, no watermark and no history, you're down to your eyes. The classic giveaways are mostly fixed in the current generation, so update your checklist.
For photos:
- Skin and surfaces that are too smooth, too symmetrical or slightly plastic, especially across a whole crowd.
- Backgrounds where lines don't quite meet, walls shift angle, or patterns repeat.
- Lighting and shadows that disagree with each other, or reflections in glasses and windows that show something the scene doesn't contain.
- Text now usually renders correctly, so legible signage is no longer proof of a real photo. Text that's plausible but wrong, a shop name that doesn't exist, is a better tell.
- Teeth and eyes at close range, which still distort more often than the rest of the face.
For video:
- Blinking that's absent, uneven or too regular.
- Physics: cloth, water and hair that move too smoothly, or objects that vanish between frames.
- Mouth and audio drifting out of sync, and audio that's too clean, with no room noise.
- Length and cuts. Many generated clips are under ten seconds with no edits, because that's the tools' limit. A "leaked" phone video that's exactly eight seconds and perfectly steady deserves a second look.
- Watermark scars. Sora's cloud logo can be scrubbed in seconds by removal sites, often leaving a soft, blocky patch. CCTV grain and bodycam overlays, meanwhile, are now generated on purpose to look raw.
Play the video at double speed. Inconsistencies that pass at normal speed jump out when compressed.
Step 5: If you must use a detector, know its numbers
Dozens of websites promise to tell you "AI or not" with a percentage. They are not the oracle they look like.
NewsGuard tested five of them in May 2026 on 45 images: real news photos, lightly edited real photos, and heavily altered ones. Hive and Sightengine flagged 0% of real photos as fake, which is what you want. ScamAI flagged 40% of them, ZeroGPT 20%. But the cautious tools missed a lot: Sightengine caught only a third of the heavily altered images, Hive about three-quarters. And lightly edited real photos, a brightness change or a bit of blur, were called "AI" by three of the five tools at least 80% of the time.
That matches the wider research. A CSIRO study of 16 deepfake detectors in 2025 found none could reliably identify real-world deepfakes, because they fail on anything unlike their training data. Columbia Journalism Review put the best models at "about two-thirds of the time".
My judgement: if you use one, use Hive or Sightengine, because a tool that never calls a real photo fake is more useful than one that catches more fakes but cries wolf. Treat "AI detected" as a reason to go back to Steps 1 to 4, and "no AI detected" as no information at all. Never repost a verdict from one of these as evidence.
Where it goes wrong
Trusting the absence of a signal. This is the big one. No watermark, no credentials and no detector hit adds up to "we don't know". OpenAI's help page says outright that content with no signal "could still have been generated or exported by OpenAI".
Screenshots. The moment someone screenshots an image, its Content Credentials are gone, and platform labels that depend on that metadata won't appear either. Meta's "AI info" label and YouTube's disclosure both lean on metadata surviving upload. A screenshotted fake gets no label.
Calling edited real photos fake. The NewsGuard test showed detectors are worst on real photos that have been lightly retouched, which describes most news photography. A confident "92% AI" on a wire-agency photo is more likely a false positive than a scoop.
Assuming Sora and Veo output is always watermarked. The consumer apps add visible marks. Videos made through the developer tools may not carry one, and removal sites handle the rest.
Stopping at the platform label. Instagram, YouTube and TikTok label some AI content, partly from metadata and partly from creators ticking a box. A label is evidence that something is AI. Its absence is not evidence of anything.
Frequently asked questions
Is there a law that says AI images have to be labelled? Increasingly. The EU AI Act's transparency rules took effect on 2 August 2026, requiring machine-readable marking of AI output and visible labels on deepfakes, with some deadlines for existing systems pushed into late 2026 and early 2027. California's AI Transparency Act became operative the same day, and China has required labels since September 2025. The UK has no general labelling rule, though creating sexual deepfakes without consent became a criminal offence in February 2026.
Can a watermark be removed? Metadata, yes, trivially. Pixel-level watermarks like SynthID are designed to survive ordinary edits, and Google's claims have not been independently tested at scale as far as I could find. Assume a determined person can defeat any of them, and that a casual one won't bother.
What about AI voices and phone calls? Different problem, same principle: verify through a second channel rather than trusting the signal itself. There's a separate guide on protecting your family from AI voice scams with the safe-word method that works.
How good are the image generators now, really? Good enough that cinematic output is routinely indistinguishable from photography at phone-screen size. To calibrate your eye, look at what eight current image models produce from the same prompts and notice how few of the old tells appear.
Build the habit, not the checklist
The order matters more than any individual trick. Provenance first, because it's a signed answer when it exists. Reverse search second, because most fakes are recycled. Eyes third. Detectors last, and lightly.
Next time something outrageous crosses your feed, give it 60 seconds before sharing: drop it into the verify tool, then into Lens. Most of the time you'll have your answer, and when you don't, you'll at least know that you don't.