Claim evidence

Can you tell if a damage photo was generated by AI?

15 September 2026 · 4 minute read

Sometimes you can, though not the way the detection vendors advertise and not often enough to build a refund policy on. There is a narrow set of things you can actually prove, and that set got wider this year.

Start with what the vendors claim. Several sell AI image detection with accuracy figures in the high nineties. Those numbers come from lab conditions, where the test image goes straight from the generator to the classifier. Detectors that clear ninety five percent on those test sets have been measured under sixty percent once the file has been screenshotted or squeezed through a messaging app. Independent testing also puts the rate at which consumer detectors label real photographs as AI somewhere around five to fifteen percent.

Take the kind end of that range: one honest customer in twenty wrongly flagged. No refund policy survives being wrong that often.

What actually changed in 2026

In May, OpenAI said that images generated through ChatGPT and its API now carry a C2PA manifest alongside Google DeepMind's SynthID watermark, and it opened a public tool at openai.com/research/verify that reports whether either signal is present. Google says SynthID has now marked more than a hundred billion images and videos. Article 50 of the EU AI Act took effect on 2 August and requires generated output to be marked in a machine readable form, which pushes every large generator the same way. Systems already on the market have until 2 December to comply, so coverage this autumn is still patchy.

That matters for a dull reason. Someone filing a doubtful claim is unlikely to be running an open model on their own hardware. The realistic path is a free app on a phone, and those apps now sign their output.

The three tiers

Tier one: provable, and safe to write down

A valid C2PA manifest is a cryptographic signature from an issuer you can check against a trust list. It is not a probability score. If a file carries one from OpenAI or Adobe, that is a fact you can put in writing.

Alongside it, two metadata fields do similar work. The EXIF software field sometimes names the generator outright. The IPTC digital source type field can be set to trainedAlgorithmicMedia, the tag generators use to mark their own output. Neither field is signed, so both can be stripped or faked. Describe them for what they are, which is the file declaring its own origin.

Tier two: comparative, and still safe

Absence of metadata proves nothing. Most platforms strip it. A photo taken on a real phone and sent through WhatsApp arrives just as bare as a generated one.

What carries weight is inconsistency inside a single claim. If a customer sends four photos and three carry iPhone capture data while the fourth carries nothing, that is worth asking about. Asking is not accusing.

Tier three: keep it internal

Classifier scores and error level analysis live in this tier. They help you decide where to look. They have no place in a message to a customer, because you cannot explain a score in one sentence or defend it when it turns out to be wrong.

The check that beats all of this

The strongest signal has nothing to do with whether an image was generated. It is whether you have seen it before.

Fingerprint every image that arrives with a claim and compare it against every image the store has already received. A reused photo is not a probability. Either the file matches an earlier claim or it does not, and when it matches you have an order number and a date to put in front of the customer.

The same goes for your own product photography. The easiest picture to send is the one already on your listing, and that match is exact rather than statistical.

How to word it

Never write that an image was generated by AI. You will eventually be wrong, and the one time you are wrong costs more than every claim you caught.

Hi Sam,

One thing before I process this. The photo attached to your claim matches a photo we received with an order back in March. Could you send a fresh picture with the damage and the shipping label in the same frame? I will get this sorted as soon as it comes through.

That message makes no claim about the customer. It states a fact about a file and asks for something anyone holding a damaged product can produce in a minute.

Where this leaves you

You cannot reliably detect AI generated images, and anyone selling that certainty is selling something they do not have. You can read what a file says about its own origin and check it against everything you have already received. When those disagree, ask one good question.

That is the whole job. Send your last 100 claims and we will send back a written report saying, order by order, what the evidence actually supports. Where it settles nothing the report says so, which is the most common outcome. We do not charge for it.

Your file stays in your own folder and we delete our copies once your report is done. We never ask for customer email addresses or payment details.

Request the audit