(Non-)AI Images: Labeling and Recognition – Content Credentials, SynthID & EU AI Icons

How should (or must) you label AI-generated (or AI-modified) content?

How can a layperson tell if a image is AI-generated, or if it is an authentic photograph?

At first glance, a layperson can hardly recognise AI assets at all, especially as image and video generators are becoming increasingly sophisticated. Even for professionals, it is becoming difficult, and we are only thinking of fraud caused by AI-manipulated photos and videos.

What exists: There are technologies that ensure transparency, on a voluntary basis and via EU AI Act regulations.

This brings us to the topic: „As a company, we mark our (non-)AI images (somewhat) voluntarily because our brand stands for transparency and fairness.“

This article covers three approaches:

  • Visible „baked-in“ overlays, such as the EU AI Icons, which are simply icons or text integrated clearly into images and videos. This low-tech approach is pragmatic and sensible because only this type of marking is not easily removable (except by cropping).
  • Information embedded in the asset such as „cr“ (see the article image), known as „Content Credentials“, which can then be read by display software and shown as an overlay. „cr“ data can be overwritten by third-party software, which is not always even intentional.
  • SynthID by Google (which is open source), acting as a hidden watermark, although this does not function robustly.

Want to advertise in the EU?

For you UK, US, Swiss or any other non-EU folks: If you are planning to run advertising campaigns within the European Union, it is essential to stay compliant with evolving (and partly kafkaesque) regulations like the EU AI Act.

Stefan Golling

About the Author

Stefan Golling, Cologne, Germany. Worked since 1998 as a Copywriter and Creative Director in (Network) Agencies and freelances since 2011 as German Freelance Copywriter, Marketing Freelancer, Creative Consultant etc., e.g., in international projects.

The EU AI Icons

The EU favours a simple and therefore robust solution: „burning in“ icons.

You can find the „official“ EU AI icons (PNG & SVG) with instructions here: https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content

The base element is „AI“ as one of four variants, shown as white text in a black circle. This is clever because this variant „stands out“ on almost any background.

You do not have to use the official EU icons; you can also design your own. Using the „AI“ abbreviation keeps you safe. It is conceivable that „KI“ might not be objected to in German-speaking regions or „IA“ in French-speaking regions, but no one can guarantee that.

The base element is not enough, however! You might / must supplement it with:

  • „generated“, i.e., „AI generated„, if the entire asset was AI-generated
  • „modified“, i.e., „AI modified„, if a part was changed, such as a face swap (which could also be done with Photoshop) or an AI background
  • „{element} generated by AI“ to label deepfakes, for example, „Voice generated by AI“
  • Remember: Also include the AI label in the ALT text or Aria-Labels!
  • Applying the icon does not exempt you from (other) legal obligations.

(Minor) exceptions for the labelling obligation also exist, for example, for satirical content where the fake is so extreme that it is obviously fake. However, this is a vague rule, which creates legal uncertainty.

Content Credentials: Complex

With „cr“, you can mark AI images, non-AI images, and composites from both. Since the labelling can be „lost“, it is currently only partially suitable.

The „cr“ logo does not say where the medium comes from. It only says that you can click on the logo to view the metadata.
Confusing:
On LinkedIn, „cr“ is mostly seen on AI-generated images.
Meta, however, will soon roll out a feature on Instagram where the cr-logo will mark „real photos“ (e.g., those taken with a Google Pixel 10. Other providers will have to follow suit immediately).

What is „cr“ actually? „cr“ is data that is encrypted and embedded in media. Some (few) cameras build cr-data into images, including Nikon, Leica, and Google Pixel. After editing an image, the data can disappear, which is why the image must be „re-signed“ after editing; Photoshop can do this, and with some coding, every app can (though this requires a paid certificate).
SynthID, on the other hand, is a type of „watermark“ that is so robust it supposedly survives resizing or screenshots. Google uses SynthID in addition to „cr“ to invisibly tag AI-generated images (or videos, speech, or even text). OpenAI and others will likely use it soon. For detection, Google offers an „AI Content Detection API“.

tl;dr:

  • „cr“ can be used by camera and software manufacturers, as a medium, and by users to, for example:
    • Sign „real“ photos to make them identifiable
    • Sign AI-generated media to make it identifiable
    • Trace editing steps and image components, such as a composite from a real photo with an AI background (including information on the creators)
    • Disadvantage: „cr“ data is usually deletable; they can be „stripped“ like other metadata if they are only embedded in the file.
  • SynthID can be used to permanently tag AI images as such invisibly. Only serious providers will do this, of course. However, it does not function perfectly robustly.
  • Perspective: If images (or videos) have NO cr-data and NO watermark, platforms (Google, Meta, LinkedIn, news sites…) will have doubts about the origin of the images (or videos). These doubts can lead to content being suspected of being AI-generated.

Want to talk?

[hubspot portal=“6963721″ id=“801761dc-4aea-42b7-a3a1-9e84892bb766″ version=““ type=“form“]

This is cr

„cr“ is a labelling for visual content. contentcredentials.org, provided by the „Content Authenticity“ initiative, offers this, and for example, the AI image generation tool Bria uses it, as does OpenAI (ChatGPT), or Adobe Firefly (and even when you use „Generate Image“ via Firefly within Photoshop).
Adobe participates with all tools; among camera manufacturers, Leica (M11-P) and Nikon (Z9) are involved, along with Google Pixel (10).

More on SynthID later.

The Technology Behind cr

With cr, cryptographically hashed/signed information or metadata is embedded in the image file (or uploaded to the [Adobe-] cloud [including a URL – this is integrated into the file] or attached as a .c2pa sidecar file):
With this information, one can recognise if the image comes from an AI (or was edited with AI), or if it is an authentic photo with one (or more) identifiable creator(s) – or both.

In the world of the Content Authenticity Initiative, these metadata are called „Manifests“, which are collected in the media file (or in an external file) and stored in a „Manifest Store“.

The concept is somewhat similar to the well-known EXIF data found in digital photos, but massively expanded.

  • EXIF data is easily viewable and manipulable
  • Content Credentials, on the other hand, are cryptographically encrypted and not as easily readable
  • cr does not replace the good old EXIF data; cr is additional data with little data overlap.

The biggest problem with cr – and the simple solution:

  • The support by image display software providers or platforms is poor outside of the Adobe world
  • cr data is often deleted during image editing, for example, if you upload an AI image into Canva and export it, or save it with an image viewer, or if a web CMS (or a social media provider) converts an uploaded PNG into webp. This will guaranteed change in the future, but old software will never master it. Technically, the image must basically be „re-signed“, more on that later.
  • The most banal method remains, for now: photoshopping the image author’s name hard into the image. Example: Look at the Aldi leaflet, where you can find some images with „AI-generated“ labels. Or you can use the EU Icons.
  • Additionally, it is recommended to archive AI-generated „original images“. If anyone ever asks what is going on with the image, you can pull out the original and have the (meta)data ready.
    Think also of future legal and/or technological changes. If tools and platforms consistently pass on cr-data, it might be necessary to re-upload your assets. This is, of course, a horror scenario that doesn’t have to happen.

Verifying Images with cr

Verification of an image is simple, either via the website or via an appendix to the URL, as in this example – after source= comes the URL of the verifying medium.

https://contentcredentials.org/verify?source=https://www.testwebsite.com/test.jpg 

Adobe offers a (Chromium-) plugin for the Chrome browser: Adobe Content Authenticity

What a cr verification result looks like:

How it works:

  • The AI image generator (or the camera or the image editing software) builds
    a) a signed code snippet into the image file (or uploads it to a cloud) (or both) (or attaches it). In the special case of video, start and end frames are additionally defined.
    b) a clickable button into the image – if the display program supports it – which you see above (and you may have already seen on LinkedIn posts): This is the „cr“ signet („Content Credentials pin„). It „belongs“ to the Coalition for Content Provenance and Authenticity (C2PA).
  • The image format is „relatively“ irrelevant: Bria and ChatGPT build the cr into PNG files, Adobe Lightroom can only integrate it into JPGs. Photoshop handles both PNG and JPG. Adobe Premiere Pro offers cr for audio and video files (e.g., MP3, MP4, MOV, AVI), and additionally for TIFFs. The file format is therefore not an indicator for now.
  • Clicking on the pin opens the website contentcredentials.org. However, the website must support the display of the pin (it gets thin there; for example, LinkedIn – I have seen it myself – and Behance can already do it; many more websites will surely follow).
  • Even if you upload the original image to contentcredentials.org, the data will be read out.
  • The further information about the AI image will be called up there:
    • „This image was generated with an AI tool“
    • Application used: Bria Ai
    • AI tool used: Bria AI
    • Action: „Created“ (i.e., not edited)
    • An editing history is also created
    • In these data, authors can also be listed, which is naturally brilliant for tracking authorship
  • If you are a photographer or digital artist, you can, for example, naturally embed relevant information for yourself into the image using Lightroom, such as:
    • „Producer“, i.e., your name.
    • Linking social media accounts: e.g., Behance, Instagram, LinkedIn, X
    • Which software(s) were involved
    • Possibly origin of image components
    • Possibly editing steps
    • Possibly camera model
    • AI opt-out: „This photo may not be used for training AIs“
  • However, the credentials are lost if:>
    • You save the file with another program / re-save it
    • Your content management system converts uploaded images (e.g., PNGs) into, for example, WebP, as happens here with WordPress
    • Who wants credentials to be „unlosable“ in the file, as „Durable Content Credentials“, must additionally use digital watermarks (e.g., from providers like Digimarc, ATSC, Adobe Trustmark etc.) or fingerprinting (e.g., from Adobe or Digicaps).
      This is then called „Soft Binding“. In this case, the asset first gets a watermark (which remains even in screenshots, conversions, and metadata deletions) and secondly an associated metadata file, which sits on a server. A comparison can then be made via an API to see if there is a cr-file for the watermark or fingerprint (and what is in it).
      Click here for more info.
  • And the credentials are also added for banal edits. Example: You have an image isolated by AI. The AI provider can then insert a CR snippet into the image. Your image is therefore considered AI-modified. One can argue over the sense and non-sense of this.

Warning: This is not absolutely robust

Example: I uploaded an image generated with ChatGPT to Bria and edited it there. The ChatGPT image had credentials. Bria deleted the credentials during editing – inpainting, i.e., the additional addition of image content – and overwrote them with its own Bria credentials. The credential implementations by the providers are therefore not compatible.

In the reverse direction – editing an image from Bria with ChatGPT – the credentials are also overwritten.

Image 1: The credentials from OpenAI – looks good (OpenAI even creates 2 credentials, for the creation and for the editing)

Image 2, after editing with Bria (an additional image hangs on the wall above in the picture) – only the Bria credential is there

Retrofitting Content Credentials Support

Suppose you have your own image editing or social media management tool that does not support Content Credentials. Can the support be retrofitted? Yes.

But 1: Content Credentials must be cryptographically signed with a private key. This can be done, for example, with the official library c2pa-node. With this, you can create a new „Manifest“ for an asset. This is signed with a (expensive to purchase) certificate (from your company), making it a hard-coded part of the file.

But 2: You naturally want to pass the cr-data of all assets in a layout. Therefore, the source manifests of the files must first be read out, for example with c2pa-js. These data, for example from AI images, should then be stored in a database, mapped to the original image. For assets without cr-data, you must capture the data yourself („Self Assertion“). When exporting a layout consisting of several (AI-)images, a new manifest is then generated. The „old“ cr-data are not cobbled together; instead, an updated history with a „family tree“ is written into the file.

So: Content Credentials in files can be broken extremely easily and are extremely difficult to secure and expand. However: It is possible. Nevertheless, the problem remains that the further usage chain of the assets can still delete the cr-data, such as WordPress plugins, CDNs or DAMs with resizing tools, platforms etc. Additionally, there is the human factor: if a colleague takes an image with cr and „edits“ it with, for example, MS Paint and then places it back on the server, the data is also lost.

For signing, there are commercial full-service providers, for example, DigiCert Content Trust Manager or EZDRM for Videos.
A certificate provider is, for example, GlobalSign, where you can subscribe to a „PersonalSign 2 Department“ certificate for approx. 200 Euro per year plus VAT; this is a (2025) recommendation from the IPTC from a PDF. For „free“ options, there is currently nothing.

AI Image Detection with Gemini

Gemini „can“ „recognise“ AI images. Via an offer called „Verify AI“. So, some of them. Only those that contain a clear „SynthID“ watermark and/or cr-data.

Both can be bypassed!

First, here is a „doesn’t work“ example, followed by a „works“ example.

Here is a „doesn’t work“ example:

I uploaded an „oil painting“ created with Bria into Gemini, asking „Is this AI-generated“. The image originally had cr-data. However, I stripped all metadata from the image beforehand (which image editing tools do; I have my own, based on React-Konva).

Gemini’s answer: „No idea if the image is AI, but“.

If you take the „original“ image from Bria – it contains C2PA metadata – Gemini recognises this, but can (yet) not read it properly.

The „official“ tool of the Content Authority (https://verify.contentauthenticity.org/) naturally recognises the C2PA data in the original image (nothing is recognised in the „stripped“ image):

Here is now the „partially works“ example.

I had this photo created with Nano Banana Pro (Gemini 3 Pro Image Preview), the „expensive“ version. It was supposed to be a moodboard with „stylish press photographers“ (in reality, there are no stylish press photographers, you know what I mean). You can see relatively quickly that it is AI (the guy on the left with the two cameras on top of each other…).

Colleague Gemini is certain here:

„The image file contains secure data sets indicating that these media contents were completely created with AI by Google LLC and processed with AI tools from Google Media Processing Services.

This type of data set is referred to as C2PA provenance data (Content Credentials), which securely embed the origin and history of the content in the file.“

This means: Google recognises C2PA data here but does not speak about SynthID. Suspicious!

The C2PA tool also recognises the data:

And what about image crops? Here the C2PA data is removed. Let’s take the man with the flat cap (or rather, the beret):
(Ignore the „KI-generiert“ badge in the image: it’s inserted by my content management system / DAM to mark AI generated assets)

Result:

Google SynthID fingerprinting / watermarking does NOT work. It is not robust enough for image crops, or it is not cleanly implemented in Nano Banana Pro.

Another image crop is also not recognised:

However, I can see as a human that the camera looks very strange; the lens is slightly rounded. „Distorted“ geometries are therefore indicators of AI (or other post-processing; you can also mash things together using Photoshop, Gimp, Affinity & Co.).

This means: There is no absolutely secure AI image detection.

Conclusion: Still in the early stages

Traceability or proof of origin for images is a great thing. You may eventually have to adapt to this long-term:

  • Certified images can be verified as „real“ or „AI-heavy“ by the user (or by software, browsers…).
  • Images without a certificate (or watermark) could automatically arouse suspicion (or be rejected by software or browsers)
  • For EU AI Act compliance, overlays, such as icons etc., are the first choice
  • „Dark powers“ will not give a toss about all this and, of course, will not label AI-generated fake news if possible. And I would bet a euro or two that in the future we will not be spared from brain-dead AI-generated ads for nonsense products on YouTube and news websites.

The further development will have to be awaited. Basically, labelling is a very good idea. Ultimately, it will come down to a combination, as legislators and platforms tick differently.

Contact

[hubspot portal=“6963721″ id=“801761dc-4aea-42b7-a3a1-9e84892bb766″ version=““ type=“form“]

Which file formats understand Content Credentials?

cr can be embedded into common „user-visible“ media file formats for images, videos, and audio that you need in everyday digital life. Traditional formats like GIF and BMP did not make it onto the list.

  • Exchange formats:
    • PDF
  • Image formats:
    • JPEG (= .JPG)
    • PNG
    • WebP
    • TIFF
    • DNG
    • HEIC
    • HEIF
    • SVG
    • AVIF (AV1)
  • Video formats:
    • M4A (= .MP4)
    • MOV
    • AVI
  • Audio formats:
    • MP3
    • WAV
Gern 5 Sterne vergeben

Zu Hause » Mag » (Non-)AI Images: Labeling and Recognition – Content Credentials, SynthID & EU AI Icons

Erstellt am:

Zuletzt aktualisiert: