Here is the single thing you need to know: if an image was produced by a provider that embeds provenance signals, a verifier supplied by that provider can reveal those signals. Some companies now write cryptographic C2PA records or invisible SynthID-style watermarks into images. A positive verification is strong evidence the image came from that system. Absence of a signal isn't proof an image is genuine. If you find non-consensual intimate images or child sexual abuse material, preserve the original file where possible and report it to An Garda Síochána and to hotline.ie.
1. The short answer and what matters for you
Here is the single thing you need to know: if an image comes from ChatGPT, Codex or the OpenAI API and it has provenance signals, OpenAI Verify will tell you. If OpenAI Verify finds a signed C2PA record or a SynthID watermark, that's strong evidence the image was produced in those OpenAI systems. But many other generators and older models don't yet embed those signals. Absence of a signal isn't proof the image is authentic.
I will tell you straight, for everyday use you rely on a combination of quick on-screen checks and targeted verification. Follow the six steps below. They work for casual fact checking and for saving time before you escalate to a forensic lab or to the authorities.
2. Step 1 and 2: Quick visual scan and metadata checks
First, make a fast visual assessment on-screen. Zoom the image to between 200 and 400 percent and look for a cluster of common AI artifacts. Look for uniformly smooth skin and missing pores, hair strands that merge or disappear, repeating tiles of fabric or background texture, impossible geometry in the background, melting or smudged edges, odd symmetry in faces or objects, jewellery that mismatches, or shadows and reflections that don't align with a single light source. Any combination of these errors increases the probability the image was generated or heavily manipulated, but no single quirk proves it.
Second, examine file metadata. Open an EXIF viewer or the file properties panel and look for camera fields such as camera make and model, lens, aperture, shutter speed, ISO and GPS coordinates. Many AI-generated images omit authentic EXIF or contain generic software tags naming an editing tool. Remember two cautions. One, a genuine photograph can lose EXIF when it's exported, compressed or re-saved. Two, some editing workflows intentionally strip or change metadata. If EXIF shows a plausible camera make and exposure settings that match the scene, that supports authenticity.
If EXIF is absent or lists tool- or model-related software tags, that supports the hypothesis the image was generated or edited with an AI tool.
Worked example: you receive a portrait that looks plausible at first glance. You zoom and see hair that blurs into the background and a necklace that changes shape between the chest and the reflection. The EXIF shows no camera make and a software tag instead. Treat this as suspicious and proceed to the provenance checks below.
3. Step 3: Provenance signals and OpenAI Verify
OpenAI announced on 19 May 2026 that images produced by ChatGPT, Codex and the OpenAI API will include two technical provenance signals. The first is C2PA, a cryptographic provenance standard developed by the Coalition for Content Provenance and Authenticity that can record the creator, editing history and other provenance data inside a file. The second is SynthID, an invisible watermarking technique that embeds a machine-readable signal inside image pixels.
OpenAI also launched OpenAI Verify, a free public web tool, to inspect whether those signals are present in images. If OpenAI Verify returns a positive C2PA signature or detects a SynthID watermark that's strong evidence the image came from those OpenAI products. Cryptographic signatures are tamper-evident, and SynthID is embedded at the pixel level rather than relying on file metadata.
Two important limits. One, the adoption announced on 19 May 2026 applies only to ChatGPT, Codex and the OpenAI API. It doesn't cover generators outside OpenAI unless those providers adopt the same standards. Two, absence of a C2PA record or SynthID doesn't mean an image is genuine, because many other AI tools currently don't write these signals. Treat OpenAI Verify as a high-confidence test where it applies. As one piece of evidence otherwise.
Worked example: a meme circulating with a politician's face can be run through OpenAI Verify. A positive SynthID detection means it likely originated in the OpenAI ecosystem. A negative result doesn't clear the image; proceed to forensic methods if .
4. Step 4 and 5: Forensic escalation and documenting provenance
If you need higher assurance for editorial use, competitions, legal claims or safety incidents, escalate to specialist forensic analysis. Advanced workflows combine metadata analysis with noise and compression fingerprinting and pixel-level tampering detection. Cryptographic provenance, when present and signed, offers a clearer chain than heuristic forensic signals. Forensic tools are still essential when provenance markers are absent or contested.
If you don't have direct access to forensic software, seek a trusted third-party forensic lab or a platform that provides verification services. Preserve the original file where possible rather than saving a screenshot, because a screen capture destroys many forensic traces. For images found on social media preserve URLs, post IDs and timestamps and use the platform's reporting tools. Document the chain of where you found the image and who uploaded it.
Point is, worked example: a news desk receives an image that might be evidence in a complaint. Step one is to preserve the original file and the post URL. Step two is to ask a forensic lab to run metadata, noise analysis and pixel-level checks, and to look for any signed provenance records.
The Irish legal and regulatory context treats distribution of non-consensual intimate images and child sexual abuse material as illegal whether or not AI generated them. A spokesman for the Department of Communications said, "The sharing of non-consensual intimate images is illegal. The generation of child sexual abuse material is illegal." John Evans, digital services commissioner at Coimisiún na Meán, said "it doesn't matter if such material was generated by AI or by people, it's still illegal to share," and he urged people concerned about images of themselves online to contact hotline.ie and An Garda Síochána. The minister of state with responsibility for artificial intelligence, Niamh Smyth, said Irish and EU law had been broken in relation to AI-generated child abuse images and has sought engagement with platforms.
Government officials and the Office of the Attorney General have been reported to be examining whether existing laws are enoughly robust and are engaging with platform operators. If you encounter sexualised or child sexual content preserve evidence, don't redistribute it, and report it to An Garda Síochána and to hotline.ie. Use the platform's reporting tools and provide the original file or the post ID where possible.
Worked example: you find an image of someone you know on a social site that appears to be an AI manipulation of an intimate photograph. Don't download or share. Preserve the original link, copy the post ID, keep the file if you have it. Report to hotline.ie and to An Garda Síochána as instructed by Coimisiún na Meán.
Provenance signals reduce uncertainty when present but coverage will be partial for the foreseeable future. OpenAI's May 19, 2026 adoption covers ChatGPT, Codex and the OpenAI API only. Other commercial generators and older models may not write C2PA metadata or SynthID, and legitimate workflows can strip or falsify metadata. Visual and forensic checks are probabilistic and can be defeated by high quality manipulation.
Irish regulators have framed enforcement through EU law. Officials cited the enforcement provisions of the EU Artificial Intelligence Act as the mechanism to regulate harmful AI systems used by platforms. Those enforcement provisions are scheduled to begin operating in August 2026. Until then, tools such as OpenAI Verify improve transparency for one slice of the problem but they don't create universal coverage or instantaneous legal remedies.
Worked example: a platform policy team might use C2PA signatures to remove known AI content created with covered systems without a separate forensic analysis. For content from other generators the team will need different detection methods and may have to open legal or regulatory investigations.
For everyday checks, return to the six practical steps below. They will save time and will separate probable fakes from files that need a deeper forensic read.
Related Articles
- 3 upgrades to make a Weber or Kamado Joe smart
- USCG medical certificate: 4 clear steps
- AI Trading Bots 2026: 10-Step Beginner's Guide
Check official guidance for the timetable and enforcement details of the EU Artificial Intelligence Act. Until then, preserve the original file where possible, run the visual, metadata and provenance checks above. Escalate to forensic analysis if you need higher assurance. Report illegal sexualised or child sexual material to An Garda Síochána and to hotline.ie.
This article was created with AI assistance.