Skip to main content
Research

Which AI Images Are Easiest to Detect?

Not all AI images are equally detectable. Watermarks, provenance, subject matter and post-processing decide which get flagged — and which slip through.

August 5, 2026 6 min readBy Tim GeithnerReviewed 8/5/2026
Which AI Images Are Easiest to Detect?

"Can detectors tell?" is the wrong question. Two images from two generators, of the same subject, at the same resolution, can sit at opposite ends of the detectability scale — and most of the gap has nothing to do with which model is "better."

What actually determines whether an image gets flagged is a stack of independent factors: whether a watermark was embedded, whether provenance metadata survived export, what the picture is of, how it was exported, and what was done to it afterwards. Understanding the stack is more useful than any leaderboard, because the leaderboard changes with every model release and the stack does not.

Layer 1: embedded watermarks — deterministic when present#

The strongest signal is the one that does not care what the picture looks like. Where a generator embeds a durable watermark such as SynthID into the content during generation, a matching detector returns a confident verdict, and ordinary editing does not remove it. That is a near-binary outcome, not a probability.

Coverage is the catch — and it cuts both ways, which is why our AI watermark overview separates what can be inspected from what can be removed. Watermark detection only recognizes watermarks it knows. Content from a generator using a different scheme, or none, returns nothing — and a negative result is not evidence of authenticity. We covered the mechanics and the limits in what SynthID is.

Practically: output from major commercial models with embedded watermarking is the easiest category to detect, and there is no clever export setting that changes that.

Layer 2: provenance metadata — loud, but fragile#

Most commercial generators also write a C2PA manifest or an IPTC field into the export declaring the tool that made the file. Where it survives, it is the cheapest possible detection: read the field, done. Platform ingest pipelines do this at upload.

But it is genuinely fragile. Screenshot the image, re-save it in an editor that does not preserve manifests, run it through a messaging app that recompresses uploads, or pass it through any tool that rewrites metadata, and the manifest is gone. That is why the same image can be trivially identified in one workflow and invisible to metadata checks in another — nothing about the picture changed, only its file history.

Layer 3: pixel statistics — where the interesting variation lives#

Strip both the watermark question and the metadata, and you are left with the image itself. Here detectors look for the ways generated pixels differ from camera pixels: frequency-domain characteristics no lens produces, noise that is too uniform or missing entirely, absent PRNU-style sensor patterns, over-smooth texture, colour channels that are too tightly correlated, compression history that does not match a camera pipeline. The full breakdown is in how AI image detectors work.

Several things move this layer significantly.

Architecture. Older GAN-based generators left periodic, grid-like fingerprints that a frequency analysis picks out almost trivially. Diffusion models do not produce that particular artefact, but they have their own characteristic signatures — most notably an unnaturally clean noise floor, because the entire generative process is denoising. A real photograph is full of noise, structured by the sensor that captured it. A generated one is suspiciously quiet.

Model generation. Newer models produce more natural high-frequency detail and are correspondingly harder for pixel analysis. This is the one axis where "better model = harder to detect" genuinely holds — and it is also why detectors are retrained continuously.

Export path. A PNG straight from the generator preserves the artifacts perfectly. A JPEG that has been through a platform's recompression pipeline has had a second quantization applied, which muddies some signals and, awkwardly, introduces double-compression traces that are themselves a detectable anomaly. Recompression rarely helps as much as people expect.

Resolution and aspect ratio. Images at exactly the model's native output dimensions are a weak but real signal, and unusual aspect ratios produced by outpainting often leave detectable seams and texture discontinuities at the boundaries.

Layer 4: subject matter — the most underrated factor#

The same generator can produce a nearly undetectable image and an obvious one, depending only on what you asked for.

Hard for detectors, easy for humans: hands, teeth, eyeglass frames, jewellery, text on signage, crowd scenes, complex machinery, reflections and stairs. These fail at the semantic level — a person spots the impossible geometry instantly, while a pixel classifier may not care at all.

Easy for detectors, hard for humans: close-up portraits, product shots on plain backgrounds, smooth skin and fabric, studio lighting. There is nothing obviously wrong to look at, but the surfaces are exactly where over-smoothing and missing sensor noise are most measurable.

Genuinely ambiguous for both: heavily textured natural scenes — foliage, gravel, water, weathered surfaces — at moderate resolution. The dense high-frequency content masks the statistical differences, and there is no anatomy to get wrong.

This inversion explains a lot of internet arguments. Human intuition and machine detection are strong in almost opposite places, so "obviously fake" and "detector says fake" frequently point at different images.

Layer 5: what you did afterwards#

Post-processing changes the answer, often in the direction people do not expect.

Upscaling usually increases detectability. Modern upscalers are generative. They invent plausible detail according to a learned prior, which means they stamp their own regular texture across the entire image — a second synthetic fingerprint, frequently more uniform than the first.

Heavy filtering and grain plugins are their own tell. Uniform synthetic grain applied on top of a generated image is not the same as sensor noise. Real noise varies with luminance, differs per colour channel, and interacts with the demosaicing pipeline. A flat grain overlay is easy to distinguish from that once anyone looks.

Screenshotting removes provenance and adds display artifacts. It reliably kills the metadata layer. It does nothing to embedded watermarks, and it adds resampling traces of its own.

Composite work is genuinely harder to call. An image where generated elements are blended into real photography produces mixed signals across regions, and most detectors return a single global score that averages the evidence into something uninformative.

What follows from all this#

If you are trying to assess an image, do not run one tool and quote the number. Check whether provenance metadata exists, run a watermark check if the suspected source supports it, run pixel analysis, and then look at the picture yourself for semantic errors. Four different questions, four different failure modes — the practical routine is in is this photo AI.

If you are trying to reduce the exposure of your own work, the sequencing matters. Metadata is the loud layer and the easy one; the pixel layer is where the durable work happens, and it is where a converter or a grain filter does nothing useful. Our Photo Humanizer targets that layer directly — believable sensor noise, frequency-domain characteristics closer to a real camera pipeline, colour decorrelation, texture perturbation against over-smoothing — and pairs it with plausible camera metadata rather than an empty block, entirely in your browser. Some refinement passes stay proprietary; the principle does not.

And be honest about the ceiling. Embedded watermarks are engineered to survive exactly the operations people try first. Detectors retrain on new models and on the countermeasures used against them. What you can do is stop treating a generated file as one undifferentiated problem, identify which of the five layers is actually exposing it, and work on that one — which is a much more productive exercise than asking which generator is currently winning.

Review method, sources and limits

Reviewed by
Tim Geithner · Founder and technical reviewer
Last reviewed
August 5, 2026

We compare current primary documentation with the implemented browser data flow and, where stated in the article, repeatable hands-on observations. A detector score is not proof of authorship or provenance. No controlled benchmark is claimed unless the article names its sample, tested version, date and method; third-party products and policies can change.

Primary references

SynthGuard.net — privacy-first tools

Humanize AI media locally and choose a clearly disclosed text mode.

Images, video and detector scans stay on your device. Light-mode text is local; deeper text modes use the protected inference route. No detector outcome is guaranteed.

All third-party names, logos and trademarks (e.g. Hive, Optic, Sensity, Sightengine, Illuminarty, GPTZero, Instagram, TikTok, OnlyFans, Fanvue, SynthID, C2PA) are the property of their respective owners. SynthGuard is an independent service and is not affiliated with, endorsed by, sponsored by, or partnered with any of these companies or platforms. Detector and platform names are used solely for descriptive comparison under § 6 UWG / Art. 4 Directive 2006/114/EC.

Frequently asked questions

Glossary terms in this article

Keep reading