Detecting AI-generated content in 2026 is not “look at the hands.” The hands got fixed. The useful split is provenance: did this file carry a signed history of how it was made, and is that history still attached? C2PA Content Credentials and SynthID watermarks are the two signals that actually shipped. Everything else — GPTZero-class text scores, “too many em-dashes,” a weird ear — is a hunch you should not take to HR.

On 19 May 2026 OpenAI and Google both pushed the same direction: C2PA for the chain of edits, SynthID for a watermark that survives some re-encoding, and public verifiers so people can check. Google said SynthID had been stamped into over 100 billion images and videos. OpenAI’s Verify tool reads Content Credentials and SynthID on images and, as of that week, supported audio. That is the stack. It is not universal, and AI-generated content that went through a phone screenshot will often have none of it.

C2PA, SynthID, and Verify

AI-generated content versus a camera file with C2PA credentials
A camera photo and an AI image can look identical. C2PA Content Credentials mark the camera file; SynthID marks many generated files — when the original is still intact.

C2PA Content Credentials are a signed manifest: who generated or shot the file, what tools touched it, whether it was edited. Pixel 10 was the first phone to write them in the native camera app; Google is spreading that to video on older Pixels. Meta said Instagram would start recognizing those camera credentials. A valid C2PA chain is good evidence that AI-generated content came from a participating tool — or that a photo was an unaltered camera original. It is also metadata. Strip the header, re-save as a JPEG from Preview, post a crop to a group chat, and the chain is gone.

SynthID is the durable mark Google DeepMind embeds in pixels, video, and audio. OpenAI partnered to put SynthID on ChatGPT and API images so a file that lost its C2PA still might flag as AI-generated content from a participating generator. Chrome and Search were slated to surface C2PA and SynthID checks after Google I/O 2026. That helps when the file is the file. It does not help when the file is a photo of a screen.

SignalWhat it provesHow it dies
C2PA credentialsA signed history from participating cameras and toolsRe-encode, screenshot, many social compressors
SynthIDThis likely came from a SynthID generatorNot every model; heavy edits; some prints
Platform labelsTikTok/Meta/X think it is labeled AICross-posting, downloads, bad exporters
Text “AI detectors”Almost nothing you should fire someone overNon-native English, editors, short copy
Reverse image searchThe picture existed before, or it didn’tBrand-new gens with no index yet

OpenAI Verify, Google’s “Is this made with AI?” prompts, and the C2PA public verifiers are the right first click when you still have the original file. If you only have a WhatsApp recompress, you are already in hunches. Treat AI-generated content findings as evidence in a pile, not as a courtroom.

What still fools you

C2PA and SynthID on AI-generated content until the file is re-encoded
C2PA is a signed chain from camera or tool to a verifier. A screenshot or a re-saved JPEG drops the chain. That is how most fakes travel.

The adversary is not a movie. It is a person who screenshots. Most viral AI-generated content is a crop of a crop. Credentials die. SynthID may or may not survive. Voice clones of a CFO asking for a wire are audio that may have a watermark if they came from a participating API and you have the file — and will not if they came from a random eleven-labs clone through a phone call. The EU AI Act’s marking rules push participating vendors. They do not bind a basement model.

Text is worse. Classifiers still light up on careful non-native English and on humans who edit like editors. They miss AI-generated content that was rewritten once by a person. Do not run a student’s essay through a detector and call it misconduct. Do not run a support ticket through one and call it a bot. Read it. Check facts. Ask for the source file. The agentic tools essay is about the loop that writes; this page is about the file it emits.

A real camera can still lie. C2PA on a Pixel shot of a staged scene is provenance of the capture, not truth of the world. AI-generated content is not the only way to defraud. It is the cheap way. Reverse image search, a phone call to the person in the photo, and a second channel still beat a watermark on a claim that someone was arrested.

A workflow that survives a screenshot

Detecting AI-generated content in text, images, and audio
Text detectors still misfire. Images need C2PA or SynthID on the original file. Audio needs that file plus a verifier — not a hunch about the hands.

For an image: keep the original. Run a C2PA viewer. Run OpenAI Verify or Google’s checker. Reverse-search. If the claim is money or reputation, call a human. For audio: get the file, not a voicemail recap; check SynthID where the tool supports it; call back on a number you already had. For text: check the facts against a source you control. AI-generated content that invents a cPanel feature will still fail a five-minute click on the live panel.

  • Prefer original files. Screenshots are the attack.
  • Stack signals: credentials + watermark + reverse search + a human.
  • Do not fire, expel, or wire money on a single detector score.
  • On your own site, do not let a form accept mystery identity documents without a process. That is the identity theft page.

If you publish, attach Content Credentials when the tool offers them. If you run WordPress, do not strip EXIF and manifests in a “smush” plugin and then wonder why nothing verifies. Image “optimization” that re-encodes everything is how honest AI-generated content and honest camera files both become anonymous blobs. Compress with a tool that keeps the manifest, or keep a sidecar.

The honest 2026 sentence: you can often detect AI-generated content when the generator cooperated and the file is intact. You can rarely detect it when someone tried. Policy that assumes otherwise will punish the wrong people. Teach the workflow. Keep the original. Call the human.