
How to use AI chatbots safely: the privacy settings that matter
The AI chatbot privacy settings that matter in ChatGPT, Gemini, Copilot and Claude: training opt-outs, temporary chats, memory and deleting your history.
AI & Software · How-to
How to spot AI-generated images and deepfakes: check context, run a reverse image search, look for Content Credentials and watermarks, and know detector limits.

Key takeaways
No single trick reliably exposes an AI-generated image or deepfake: today’s generators rarely leave obvious glitches, and detector tools can be wrong in both directions. What works is a layered check, starting with the context, then the image’s history, then Content Credentials and watermarks, and only then a close look at the pixels. Here’s how to do each step on your phone or computer, and what each result can and can’t tell you.
A few years ago, AI images gave themselves away with six-fingered hands and gibberish signs. Current image models make far fewer of those mistakes, so the old tells are no longer dependable.
The U.S. National Institute of Standards and Technology (NIST) describes automated detection as “a constant cat-and-mouse game” in its report on synthetic content. Detectors often work best on images from the generators they were trained on, and as models improve, people have a harder time spotting fakes too: NIST cites a 2024 study in which people’s accuracy at judging images, video and audio was close to chance.
Two more complications:
So the goal isn’t a yes-or-no verdict from one glance. It’s to gather enough evidence to decide whether to trust, share or ignore an image.
The fastest checks don’t involve the image at all.
Many deepfake scams work like phishing: the fake is just bait. Our guide to spotting phishing covers the same pressure tactics.
A reverse image search looks for the same or similar pictures elsewhere online. It can reveal an older original, a different caption, the real photographer, or a fact-check that has already debunked it.
In the Google app or on Google Search, search for an image, open it in the image viewer, select About, then Learn more about an image. Google says this can show when it may have first seen similar versions, other pages that use the image, and information about whether it was captured with a camera or generated with AI. Google also cautions that this metadata can be modified, so it may not be accurate, and that the feature is only available in some regions. Google Lens, Bing Visual Search and TinEye are useful alternatives.
What to look for:
Some AI tools and cameras now label their output in ways software can read.
Content Credentials are based on the open standard from the Coalition for Content Provenance and Authenticity (C2PA). They’re a signed, tamper-evident record of how a file was created and edited. Google’s Pixel 10 phones add them to every photo taken with the Pixel Camera app, according to Google’s announcement, and Google Photos shows them in the image details. OpenAI says supported images made with ChatGPT, Codex and the OpenAI API carry both C2PA metadata and an invisible watermark.
Invisible watermarks such as Google DeepMind’s SynthID are woven into the image itself. Google says they’re designed to survive common changes such as cropping, filters and compression.
Here are the free checkers worth knowing, as of 2026:
| Tool | What it looks for | If it finds something | If it finds nothing |
|---|---|---|---|
| Content Credentials Verify | C2PA Content Credentials in the file | Shows the recorded origin and edit history, including AI tools if logged | Tells you little: credentials may have been stripped or never added |
| Gemini app | Google’s SynthID watermark and Content Credentials | All or part was made or edited with Google AI | It could still come from another AI tool |
| OpenAI Verify | OpenAI’s C2PA metadata and SynthID watermarks | It was generated or exported with OpenAI tools | It could still be AI, including from OpenAI if the signal was lost |
To use Gemini, upload the image and ask something like “Was this created or edited by Google AI?” Google’s help page lists limits, including files of 100 MB or less and roughly 10 image checks per 24 hours.
Almost nothing. OpenAI notes that metadata can be stripped when a file is uploaded, edited, converted or shared, and that watermarks can degrade with compression, cropping and other changes. A screenshot creates a brand-new file without the original metadata, too. And many cameras and AI tools add no labels at all. The C2PA explainer also warns that provenance information alone can’t tell you whether content is true or accurate: a genuine photo can still be staged or miscaptioned.
Third-party detectors analyze the pixels and give a probability score. They can help, but they can also miss fakes and flag real photos, especially with images from newer generators. Never treat one score as proof, and never use one to accuse someone.
If the image survives the first three steps and still feels wrong, zoom in on the highest-resolution copy you can find. The FBI’s list of warning signs is a good checklist:
A few more places where AI often slips:
Remember that these are clues, not proof. A flawless image isn’t automatically real, and one odd detail doesn’t make an image fake.
Video and audio fakes are especially useful to scammers. The FBI says criminals have used AI-generated voice clips to impersonate people and get into bank accounts. It also lists lag, voices that don’t quite match, and unrealistic movement as signs of a fake video. Watch for lips that drift out of sync, odd blinking, and edges around the hairline or jaw that flicker when the head turns.
Voice cloning is even harder to catch by ear. The FTC warns that a scammer needs only a short clip of a family member’s voice, which may be posted online, to fake a call. So don’t rely on your ears:
The FBI also suggests limiting how much of your image and voice is public, for example by making social accounts private. Our cybersecurity coverage has more ways to lock down your accounts.
You can’t reliably spot AI-generated images by eye alone, and no detector is foolproof. Work from the outside in: check who posted it and why, trace its history with a reverse image search, look for Content Credentials or a watermark, and only then study the details. If money or personal information is involved, skip the analysis and verify the person through a channel you already trust.
If you use AI tools yourself, our guide to writing better AI prompts is a good next step. For more plain-English help, browse our AI coverage or the latest guides on RedAndWhiteMagz.com.
Not reliably enough to settle the question on their own. NIST notes that detectors often perform best on content from the generators they were trained on and can struggle with newer models, and they can also flag real photos as fake. Treat a detector score as one clue alongside context, image history and provenance checks.
Content Credentials are tamper-evident records, based on the open C2PA standard, that can travel with a photo or video and show how it was made and edited, including whether AI tools were used. They are easy to lose when a file is screenshotted or re-uploaded, so a missing credential doesn't mean an image is fake, and a present one doesn't prove the scene is true.
Only partly. The Gemini app can check an uploaded image for Google's SynthID watermark and for Content Credentials. If it finds SynthID, all or part of the image was made or edited with Google AI. If it doesn't, the image could still have come from another company's AI tool.
Hang up and contact the person on a phone number you know is theirs, or reach them through another family member. The FBI suggests agreeing on a secret word or phrase with your family for exactly this situation. Requests to wire money, send cryptocurrency or buy gift cards are classic scam signs, and you can report them at ReportFraud.ftc.gov.
First published . Spotted an error? Read our editorial policy and tell us.
Contact RedAndWhiteMagz.com
Spotted a new gadget, a scam making the rounds or a mistake in one of our guides? Tell us. We read every message and reply as quickly as we can.
