Check a photo before you believe it.

AuthentiScan looks for the signature a camera or an AI tool leaves behind. Sometimes that gives a clear answer. Often it doesn't — and we tell you that instead of guessing.

Three answers, not two

Most tools give you a percentage. We'd rather give you the truth.

A number like "87% AI" sounds precise and usually isn't. AuthentiScan reports what it actually found, and names the state it landed in.

Verified

A camera signed this

The file carries Content Credentials that check out cryptographically, and the contents haven't changed since. This is the strongest evidence available today.

Declared

The maker says it's AI

The tool that generated it said so, in a signature we can verify. Not a guess on our part — a declaration on theirs.

Can't tell

There's nothing here to go on

No signature, no metadata, nothing to read. This is the most common result, and it means exactly what it says. It is not a soft way of saying "fake".

What it checks

Four things, all of them real

Content Credentials (C2PA)

The provenance standard backed by Adobe, Google, OpenAI, Leica, Sony, Nikon and the BBC. We verify the signature chain and check the content hash still matches the file.

Changes after signing

If a file was signed and then altered, the hash breaks. We catch that down to a single byte — and it's a finding about the chain of custody, not about whether the picture is real.

Generator metadata

Stable Diffusion, ComfyUI, Midjourney, DALL·E, Firefly, Sora, Veo and others sometimes write their name into the file. Nobody adds those tags by accident.

Who encoded it

Which software wrote the JPEG, read from its quantisation tables. This tells you about the file's history, not its truth — and we label it that way.

Where it fails

A clean result is not proof of anything

Plenty of AI tools embed nothing at all. Screenshots wipe every trace. Messaging apps strip metadata on upload. So when AuthentiScan finds nothing, that silence is often worth nothing — and the app says so, in those words, instead of showing you a reassuring green tick.

Here is what the major tools actually leave behind, as of September 2026.

Does this tool mark its output?
ToolSignatureWatermarkSurvives a screenshot
OpenAI (DALL·E, GPT Image)YesYesYes
Google (Gemini, Imagen, Veo)YesYesYes
Adobe FireflyYesYesMostly
MidjourneyNoNoNo
Stable Diffusion, self-hostedNoNoNo
FLUX, run locallyNoNoNo

Read the bottom three rows carefully. An image from those tools looks exactly like a real photograph to any provenance check, including ours. Anyone claiming otherwise is selling you a number they can't stand behind.

For business

Article 50 marking, checked and recorded

Since 2 August 2026, the EU AI Act has required providers of generative systems to mark their output in a machine-readable format, and deployers to label deepfakes. AuthentiScan answers one factual question about any file: does it carry that marking?

That's a property you can check, not a score you have to trust. We report which checks ran, which couldn't, and what was found.

This is a technical observation about a file, not a legal conclusion. Article 50 compliance depends on conduct that can't be determined by inspecting a file, and AuthentiScan is not a law firm. Talk to a qualified EU practitioner.