
People vary in their ability to spot AI-generated images, but appearance alone is not proof. This guide explains the research, which visual clues deserve investigation, why modern generators are harder to detect, and the verification steps businesses should use.
AI-generated images have become much more realistic. A few years ago, distorted hands, garbled text and impossible faces often gave synthetic images away. Those clues still appear, but they are becoming less dependable as image-generation systems improve.
Research suggests that people differ in their ability to distinguish real and AI-generated images, and that performance depends heavily on the type of image being assessed. That does not mean a small group of naturally gifted people can reliably authenticate everything they see. A confident judgement based on appearance is not the same as evidence.
For important business, financial or public decisions, visual inspection should be followed by checking the source, context, publication history and available provenance information.
Last checked: 28 July 2026.
What did the research find?
A large-scale experiment published by Microsoft Research in June 2025 investigated how effectively people can distinguish AI-generated images from real ones. Using data collected from an online awareness game, the study analysed approximately 287,000 image evaluations completed by over 12,500 participants around the world during a one-week period in August 2024. The overall success rate was approximately 62 per cent — a modest ability only slightly above chance.
The image set included around 350 copyright-free real photographs and approximately 700 AI-generated images created using several different generation systems, including DALL·E 3, Stable Diffusion 3, Stable Diffusion XL, Amazon Titan and Midjourney v6, as well as GAN-based synthetic faces. The study noted that the images were not selected to represent the average output of any one generator but rather to include a mix of easier and more challenging examples.
Participants were most accurate with human portraits and struggled significantly with natural and urban landscapes.
This study was submitted to arXiv as a preprint and had not completed formal peer review at the time of publication. Its findings reflect performance on a specific set of images and a specific group of participants during one week in 2024 — not permanent human ability.
A detection score measures performance on that particular set of images at that particular point in the development of AI — not permanent human ability.
Why might some people perform better?
Several factors may influence how well someone identifies AI-generated images, though none provides a reliable guarantee.
| Factor | What it may provide | Its limit |
|---|---|---|
| Experience with AI tools | Recognition of recurring generation patterns | May not transfer to newer systems |
| Visual attention | Longer inspection of edges, reflections and text | Time-limited in real-world conditions |
| Photography or design experience | Noticing inconsistent lighting, anatomy or perspective | Not all inconsistencies indicate AI generation |
| Familiarity with the subject | Spotting errors in known products, locations or people | Unfamiliar subjects provide fewer reference points |
| Prior training | Awareness of specific artefacts in tested image sets | May increase false accusations; clues become obsolete |
| Device and viewing conditions | High-resolution screen reveals detail | Screenshots and social-media compression remove detail |
The Microsoft Research study noted that the experiment drew global participants without controlling for demographic characteristics or prior training. Where findings on age, experience or other factors are reported, they should be treated as indicative rather than definitive.
Which images are hardest to judge?
Difficulty varies by image category. The Microsoft Research study found that participants were most accurate with human portraits and least accurate with natural and urban landscapes.
Portraits may sometimes be easier to assess because people are highly familiar with faces. Anatomy, jewellery, expressions and symmetry create more opportunities for inconsistency, and hair and skin detail may expose generation artefacts. Landscapes and urban scenes may be harder because there is no single recognisable identity to compare against, minor structural errors are less noticeable, and unusual natural formations can still be genuine.
An image with fewer familiar reference points may feel believable simply because the viewer has less knowledge against which to test it.
Do not assume that portraits are always easier or that landscapes are always harder. The difficulty depends on the specific image, the generation model used and the viewer's background.
Confidence is not accuracy
People can be correct and confident, correct but uncertain, wrong and uncertain, or wrong and highly confident. A person who frequently sees AI imagery may become more accurate — or merely more confident.
Consider the difference between two responses to a suspicious image. Person A notices an unusual hand and declares the image fake. Person B checks the original publisher, reverse-image search results and available provenance information before reaching a conclusion. Person B is following the stronger verification process even if Person A guessed correctly.
A critical distinction
Being right once does not prove the method was reliable.
Overconfidence can cause real harm through falsely accusing a photographer, dismissing genuine evidence, sharing misinformation, damaging a person's reputation, rejecting legitimate customer documentation or making poor fraud decisions.
Visual clues that deserve a closer look
The following may justify further investigation. They are warning signs, not proof.
- Text and lettering: meaningless words, inconsistent fonts, broken letters, labels that change between objects, mirrored or incomplete writing
- Hands, teeth and small details: inconsistent anatomy, merged fingers, duplicated jewellery, mismatched earrings, objects blending into hands, implausible dental patterns
- Lighting and shadows: multiple incompatible light directions, shadows that do not match the object, reflections showing missing or different objects, inconsistent highlights
- Background and repetition: repeated people, duplicated windows, recurring plants, repeating texture, objects that dissolve into each other, architecture that changes shape
- Perspective and geometry: lines that do not converge logically, impossible staircases, furniture with inconsistent depth, distorted wheels or circular objects, doors or windows that cannot function
- Context and physics: impossible object placement, clothing behaving unnaturally, inconsistent weather, liquid or smoke moving implausibly, objects casting no shadow, unsupported structures
- Identity and continuity: for images of known people or places, check recognised features, official sources, badges, uniforms, logos, location details and whether the event actually occurred
These are warning signs, not proof. Photography, editing, compression, panorama stitching, HDR processing and unusual real-world conditions can create similar effects.
Why old AI-spotting rules are failing
Early image-generation systems often struggled with hands, text, eyes, teeth, jewellery, symmetry, reflections and object continuity. Modern systems increasingly generate readable text, preserve faces, follow photographic styles, produce realistic lighting, maintain object consistency, edit only part of a real photograph and combine real and synthetic elements.
As a result, counting fingers is not a reliable authentication method. Smooth skin does not prove AI generation. Dramatic lighting does not prove AI generation. Unusual depth of field does not prove AI generation. Perfect composition does not prove AI generation.
The clues that exposed yesterday's image generator may not expose tomorrow's.
Real images can look artificial
Genuine photographs may appear synthetic because of smartphone computational photography, portrait-mode blur, HDR processing, noise reduction, low-light processing, filters, heavy compression, panorama stitching, studio lighting, retouching, long exposures, tilt-shift photography, staged scenes or rare weather and natural events.
An edited image is not automatically AI-generated. An image may be: a genuine unedited photograph; a conventionally edited photograph; a composited image; partly generated or inpainted; entirely AI-generated; a screenshot of another image; a photograph of a screen; or generated and then heavily edited.
"Real or AI?" is often too simple a question for the way modern images are created.
Context is often more useful than pixels
Before inspecting pixels, ask: Who published this image? Where was it first posted? Is the account genuine? When was it allegedly taken? Does the event appear in reliable reporting? Are there other photographs or videos? Does the location exist? Is the image trying to provoke urgency or emotion? Is someone using it to request money, access or confidential information?
The story surrounding an image may reveal more than the image itself.
Fraudsters may use real photographs with a false story, old photographs presented as current, images from another country, manipulated screenshots, stolen profile photographs, AI-generated people or partly edited genuine images. The verification question should therefore include: Is it synthetic? Is it manipulated? Is it genuine but miscaptioned? Is it being used in a deceptive context?
Reverse-image and visual search
Reputable reverse-image and visual-search tools may help identify earlier versions, the original photographer, different captions, other websites using the image, a stock-photography source or the same image used in previous scams.
Limitations: new images may not yet be indexed; screenshots may produce poor matches; cropped images can be harder to find; private posts may not be searchable; and absence of a match does not prove authenticity.
Before uploading an internal or personal image to a public verification service, consider confidentiality, personal data and organisational policy.
Can AI-detection tools be trusted?
AI-image detectors may analyse statistical patterns, generation artefacts, frequency information, metadata, watermarks, known model signatures and image structure. However, results may be affected by compression, resizing, screenshots, filters, editing, cropping, new generation models, mixed real and synthetic content and images not represented in training data.
Potential outcomes include false positives (a real image labelled AI-generated), false negatives (an AI image labelled real), uncertain results and different tools returning different answers.
Key limitation
An AI detector produces an assessment — not a certificate of truth.
Do not use a consumer detector as the sole basis for disciplinary action, refusing a claim, accusing an individual, rejecting evidence, making a payment decision or publishing an allegation.
What are Content Credentials?
Content Credentials are based on the C2PA technical standard — an open specification developed by the Coalition for Content Provenance and Authenticity. They are designed to provide tamper-evident information about where content came from, which device or application created it, whether it was edited and whether generative AI was involved where declared by the creating tool.
Content Credentials are sometimes described as a nutrition label for digital media: they provide information about origin and editing history rather than declaring whether the content is good, truthful or harmless.
Strengths include cryptographically signed provenance, information linked to the creation and editing process and useful evidence about origin. Limitations include: not every device or application supports them; platforms may remove or fail to display credentials; screenshots may lose the connection; absence of credentials does not prove an image is fake; and valid provenance does not prevent misleading captions.
Provenance can tell you something about how a file was made. It cannot independently prove that the story attached to it is true.
Watermarks, labels and metadata
A visible label is text or a symbol displayed to the viewer. An invisible watermark is a signal embedded into the content and designed to survive some forms of editing. Metadata is information stored with the file, which may include device, date, application, location and editing details. Content Credentials are cryptographically signed provenance records following the C2PA standard.
Metadata can be removed or altered. Labels may be missing or incorrect. Watermarks may not survive every transformation. Different providers use different systems. A screenshot can remove useful provenance. No single method provides complete certainty.
A practical image-verification workflow
- 1Pause — do not share, approve or act immediately
- 2Identify the claim — what is the image being used to prove?
- 3Check the source — who published it, and is the account or website genuine?
- 4Find the earliest version — look for the original upload rather than a screenshot or repost
- 5Inspect the context — check date, place, caption, event and surrounding posts
- 6Examine the image — look for inconsistencies without treating them as proof
- 7Search for other copies — use reputable reverse-image or visual-search tools
- 8Check official sources — look for confirmation from the organisation, the person involved, trusted media or official records
- 9Review provenance — check for available Content Credentials, metadata or platform labels
- 10Use detection tools cautiously — treat results as supporting information rather than a verdict
- 11Escalate high-risk cases — seek specialist advice where the image affects payments, identity, employment, insurance, legal evidence, safeguarding, security, reputation or public communications
- 12Record the decision — where business risk warrants it, retain the image, original URL, date, verification steps, sources, decision and approver
The verification principle
Pause, trace, compare and verify — do not decide authenticity from appearance alone.
Business uses and risks
Businesses increasingly use AI images for blog illustrations, social posts, concept art, campaign ideas and internal presentations. Risks include misleading customers, unrealistic product presentation, incorrect representation of staff or premises, brand damage, copyright uncertainty and undisclosed synthetic testimonials.
In recruitment and HR, potential concerns include fake applicant identities, manipulated documents, synthetic profile photographs and staff misuse of colleague images. For customer service and payments, images may be used to support identity claims, damaged-goods claims, delivery disputes or insurance evidence. Businesses should not approve material transactions from an image alone.
In security and impersonation, AI images may support fake profiles, romance scams, supplier impersonation, executive impersonation, fraudulent recruitment and social engineering. The image often creates credibility; the fraud normally succeeds because the victim then takes an action.
How businesses should use their own AI-generated images
A transparent internal policy should cover approved image-generation tools, commercial usage rights, personal and confidential information, use of real people's likenesses, customer consent, labelling, file storage, source prompts, editing records, accessibility, stereotypes and bias, approval and retention.
- ☐ The image is suitable for the intended audience
- ☐ It does not falsely represent a real event
- ☐ It does not imply a real customer endorsement
- ☐ It does not misrepresent a product
- ☐ It does not use a person's likeness without appropriate authority
- ☐ Usage rights have been checked
- ☐ Sensitive information was not entered into the tool
- ☐ Any required disclosure is included
- ☐ Accessibility text accurately describes the image
- ☐ A human has reviewed unusual or inappropriate details
- ☐ The original file and creation record are retained where appropriate
- ☐ Provenance information is preserved where practical
Transparency is particularly important when a synthetic image could reasonably be mistaken for evidence of a real person, place, product or event.
Practical business implications
- Staff need a verification process — do not rely on the employee who claims to be 'good at spotting AI'
- High-risk images require escalation — an image connected to money, identity, reputation or legal evidence needs stronger checks
- Businesses should label their own content appropriately — trust is easier to preserve than rebuild
- Contextual fraud matters more than perfect pixels — a genuine image can support a false story, and a synthetic image can support a familiar social-engineering attack
- Policies must keep changing — visual artefacts and detection tools become outdated as generation models improve
Image literacy is not memorising today's AI mistakes; it is knowing how to verify tomorrow's media.
Questions to ask before trusting an image
- 1What claim is this image being used to support?
- 2Who supplied it?
- 3Can the original source be located?
- 4Is the account or website genuine?
- 5When and where was the image first published?
- 6Is the caption supported by other evidence?
- 7Are there additional images or videos?
- 8Does a reputable independent source confirm the event?
- 9Does the file contain useful provenance information?
- 10Has the image been screenshotted, cropped or recompressed?
- 11Could it be genuine but miscaptioned?
- 12Could only part of it have been generated or altered?
- 13Has a detection tool been treated as proof rather than an indicator?
- 14What happens if our judgement is wrong?
- 15Does this require specialist, legal or forensic review?
- 16Who is authorised to approve the decision?
The IT Club View
People naturally want a quick answer to the question: 'Is this image real?' Generative AI has made that answer much harder.
Some people may perform better on image-identification tests because they have relevant experience, pay closer attention or recognise the weaknesses of a particular generation model. That is useful, but it is not a dependable business control. The danger is that a person who has correctly identified several synthetic images begins treating intuition as authentication.
The most important skill
The most valuable skill is not spotting AI. It is knowing when an image needs verification.
Businesses should move away from guessing from appearance, relying on one employee, treating online detectors as final, assuming metadata tells the whole story and responding emotionally to viral content. They should move towards checking the original source, understanding the claim, comparing reliable evidence, reviewing provenance, escalating high-risk cases and documenting important decisions.
In a world of synthetic, edited and miscaptioned media, trust should come from traceable evidence rather than visual confidence.
Need to check an image before sharing or acting?
Use our Image Authenticity Verification Checklist to trace the source, review the context, compare evidence and record your decision.
Administrator Technical Note
This section provides guidance for organisations managing synthetic media, image verification and provenance. It is intended for IT administrators, compliance leads and security teams rather than general readers.
Acceptable-use policy
An acceptable-use policy for AI image generation should cover: approved generation platforms; permitted business use cases; prohibition on entering confidential, personal or sensitive data into generation tools; requirements for consent before using a real person's likeness; commercial licensing requirements for the jurisdiction; prohibition on creating misleading synthetic evidence; disclosure requirements for synthetic images; prohibited uses including harassment, impersonation and fraudulent evidence; approval thresholds for public-facing content; retention of original files and creation records; and investigation and reporting routes.
Provenance
When evaluating C2PA and Content Credentials for your organisation, review device and application support, whether credentials are preserved through your editing workflow, export and conversion processes, platform compatibility (social networks frequently strip metadata), whether signed capture is relevant for your use cases, and how your asset-management system handles provenance records. A screenshot can remove the connection between an image and its credential. Do not imply that C2PA adoption alone establishes truth or prevents misleading captions.
Image-verification process
A formal verification process for high-risk images should include: collection of the original file; source URL and capture date; account verification; metadata extraction; Content Credentials review; reverse-image searching; visual inspection; detection-tool results with known limitations noted; corroborating evidence; chain of custody; named reviewer; and a decision record. Where proportionate, compute a cryptographic hash of the file before any processing.
Detection tools
Before adopting an AI-image detector, evaluate: image types supported; generator coverage; false-positive and false-negative rates; effect of compression, screenshots, filters and editing; mixed real-and-synthetic handling; version and model update frequency; confidence calibration; privacy and data retention; API security; audit logging; independent testing; and appeal and human-review process.
Do not configure an automated detector to make high-impact decisions without testing, human review and a process for challenging incorrect results.
Microsoft 365 and Google Workspace
Consider restricting unapproved AI image tools through browser controls or device management, data-loss prevention policies, approved file-storage locations, sensitivity labels, retention policies, audit logs, external sharing restrictions, staff reporting routes and secure evidence preservation procedures.
Incident response
Create a response process covering: executive impersonation; fake customer evidence; fraudulent supplier profiles; reputational attacks using synthetic images; fabricated staff images; manipulated screenshots; synthetic intimate or abusive content; law-enforcement referral; legal preservation; takedown requests; and communications response. Do not repeatedly forward or download harmful synthetic content unnecessarily. Preserve evidence securely and restrict access to people who require it.
Operational Heartbeat
Image risk changes as generation models improve, detection tools age, platforms alter their labels, provenance standards change, staff adopt new image tools, content libraries grow, marketing suppliers change, scams evolve, file-conversion processes remove metadata and legal and regulatory expectations change.
A recurring review should check: approved image-generation tools; active licences; staff usage; synthetic-media policy; labelling practice; commercial usage rights; stored prompts and originals; Content Credentials support; provenance preservation; detection-tool performance; known false positives; reported incidents; customer complaints; training; supplier contracts; high-risk verification procedures; platform changes; and corrective actions.
Operational Heartbeat
Synthetic media needs an operational heartbeat: tools, labels, provenance, incidents and verification procedures should be reviewed rather than assumed to remain reliable.
Plain-English Takeaway
Some people are better than others at noticing possible signs of AI-generated imagery, but visual judgement is not proof. Check who published the image, find the earliest version, compare independent sources and review any available provenance information. Use AI detectors only as supporting evidence, and escalate images involving money, identity, reputation or legal decisions.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
AI Hallucinations: How to Get More Reliable Answers
Generative AI can produce a fluent, confident answer that contains an invented fact, a false quotation or a source that does not support the claim. Here is how businesses can reduce the risk — and verify what matters.
Read articleAmazon Rufus: Can AI Help You Find a Better Deal?
Amazon has placed a generative AI shopping assistant inside its app and website. Rufus can compare products and answer questions — but can it really tell you whether a deal is genuinely good?
Read articleThe 5 New AI-Era Work Roles Business Owners Should Understand
AI is blurring the lines between traditional job titles. Meet the five emerging work roles — Prototyper, Builder, Sweeper, Grower and Maintainer — and what they mean for your team.
Read article