AuthentiScan looks for the signature a camera or an AI tool leaves behind. Sometimes that gives a clear answer. Often it doesn't — and we tell you that instead of guessing.
A number like "87% AI" sounds precise and usually isn't. AuthentiScan reports what it actually found, and names the state it landed in.
The file carries Content Credentials that check out cryptographically, and the contents haven't changed since. This is the strongest evidence available today.
The tool that generated it said so, in a signature we can verify. Not a guess on our part — a declaration on theirs.
No signature, no metadata, nothing to read. This is the most common result, and it means exactly what it says. It is not a soft way of saying "fake".
The provenance standard backed by Adobe, Google, OpenAI, Leica, Sony, Nikon and the BBC. We verify the signature chain and check the content hash still matches the file.
If a file was signed and then altered, the hash breaks. We catch that down to a single byte — and it's a finding about the chain of custody, not about whether the picture is real.
Stable Diffusion, ComfyUI, Midjourney, DALL·E, Firefly, Sora, Veo and others sometimes write their name into the file. Nobody adds those tags by accident.
Which software wrote the JPEG, read from its quantisation tables. This tells you about the file's history, not its truth — and we label it that way.
Plenty of AI tools embed nothing at all. Screenshots wipe every trace. Messaging apps strip metadata on upload. So when AuthentiScan finds nothing, that silence is often worth nothing — and the app says so, in those words, instead of showing you a reassuring green tick.
Here is what the major tools actually leave behind, as of September 2026.
| Tool | Signature | Watermark | Survives a screenshot |
|---|---|---|---|
| OpenAI (DALL·E, GPT Image) | Yes | Yes | Yes |
| Google (Gemini, Imagen, Veo) | Yes | Yes | Yes |
| Adobe Firefly | Yes | Yes | Mostly |
| Midjourney | No | No | No |
| Stable Diffusion, self-hosted | No | No | No |
| FLUX, run locally | No | No | No |
Read the bottom three rows carefully. An image from those tools looks exactly like a real photograph to any provenance check, including ours. Anyone claiming otherwise is selling you a number they can't stand behind.
Since 2 August 2026, the EU AI Act has required providers of generative systems to mark their output in a machine-readable format, and deployers to label deepfakes. AuthentiScan answers one factual question about any file: does it carry that marking?
That's a property you can check, not a score you have to trust. We report which checks ran, which couldn't, and what was found.
This is a technical observation about a file, not a legal conclusion. Article 50 compliance depends on conduct that can't be determined by inspecting a file, and AuthentiScan is not a law firm. Talk to a qualified EU practitioner.