1. An image can carry more than one signal
Content Credentials can describe signed origin and transformations; EXIF metadata describes file fields; some providers publish provider-specific signals. These layers answer different questions and should be read separately.
2. C2PA is not a visual detector
A valid credential provides cryptographic evidence within the verifier's scope. It does not inspect the scene to decide whether it is true and does not identify the person who created the file by itself.
3. No signal does not mean no AI
A platform may remove metadata, a screenshot may lose it, or the file may come from a workflow created before these signals existed. Absence is an unknown result, not a negative proof.
4. Ask what was actually observed
Look for a manifest, integrity, asset binding, signer, AI disclosure, metadata and warnings. An honest summary should also state what the verifier could not check.
5. A social download may not be the original
Downloads, screenshots and recompression can change bytes and metadata. Check the file you actually have and keep its acquisition context.
6. Editable fields need context
EXIF, XMP and IPTC can be changed. Their presence or absence does not establish authorship, intent or semantic authenticity.
7. A shareable result should minimize data
To ask for a second opinion, share the signal and warning summary rather than the image, coordinates, filename or private field values.
8. Local checking is the first step
H/M's free flow separates provenance and privacy checks in the browser. Professional cases still need human review and the original source.
9. OpenAI has a separate check for its own signals
This local workspace inspects C2PA and metadata. OpenAI Verify separately looks for supported OpenAI signals, including C2PA and SynthID. No detected signal does not prove an image did not come from OpenAI.
Frequently asked questions
Hogar Mas · hogarmas.net
Does this checker say whether an image is fake?
No. It describes observed provenance and metadata signals. It does not issue a truth, authorship or falsity verdict.
Does no C2PA mean the image was made by AI?
No. The credential may never have been added, or another workflow may have removed it.
Does a valid Content Credential prove the whole image?
It supports the integrity of signed evidence and its asset binding within the validator's scope; it does not prove the semantic truth of the scene.
Can I upload a private image?
The local verifier processes the file in the browser. Avoid sharing sensitive images unless needed, and keep only the minimum summary required for review.
What should I do when the result is unknown?
Keep the original, review where it came from, compare another available copy and document which signal was missing. Do not turn an unknown result into an accusation.
How can I check whether an image is from ChatGPT?
Use this local workspace to inspect C2PA and metadata the file still carries. For OpenAI-specific signals, including C2PA and SynthID, use OpenAI Verify. Neither result proves an image origin by itself.
Official guidance consulted
OpenAI: Verify OpenAI-generated images · C2PA 2.4: Content Credentials specification
