Methodology · limitations · privacy
How this works — and where it stops
AI Watermark Checker is deliberately narrow: it reads the layers that can be publicly and cryptographically verified, and refuses to guess about the layers that can't.
What the tool reads
- Container scan: JPEG APP11 segments, PNG caBX chunks and WebP C2PA chunks are assembled into a JUMBF manifest store.
- JUMBF walking: description boxes (“jumd”) carry labels such as c2pa.claim, c2pa.actions, c2pa.signature; content boxes are decoded.
- CBOR claims: generator strings, generator info (name/version), dc:format, title.
- Action history: c2pa.created / edited / converted-style records with timestamps and software agents.
- Signature presence: we locate the signature box, so you can see whether claims are covered by a signature. (Full certificate-chain validation is on the roadmap and is not performed yet — we don't pretend.)
- XMP/EXIF hints: text-level vendor markers (Midjourney, editor names, “AI-generated” tags) treated strictly as soft signals.
Verdict taxonomy
| Level | Meaning |
|---|---|
| c2pa-ai | AI provenance found. A signed C2PA manifest was parsed and its generator matched a known AI vendor. Strong, structural evidence — metadata, not judgement. |
| c2pa-other | Credentials found (unknown generator). Manifest parsed, but the generator string isn't a family we catalog. Raw strings are surfaced for your own judgement. |
| hints | Weak hints only. No manifest; text-level markers survived in XMP/EXIF. Anyone can write those strings, so they are treated as soft. |
| no-credentials | No provenance found. Nothing checkable in the layers we read. Never interpreted as 'human-made'. |
What it cannot see — by design
- SynthID pixels (Google; also used by OpenAI's verify evidence): verification is gated behind Google's portals. We link to where it can be checked instead of faking it — see Gemini & SynthID.
- Claude's text watermark: key-required, Anthropic-gated API. See the Claude page for why we won't fake a detector for it.
- Certificate-chain integrity: planned, not shipped; until then signature boxes are reported as presence, not as validation.
- GPU-statistical “AI detection”: we deliberately don't operate a pixel classifier — those produce accusation-grade false positives on natural photos.
Privacy
All file parsing happens in your browser with JavaScript on bytes already loaded into memory. No file is uploaded, no file metadata or contents are ever transmitted, and there is no account. The one network event triggered is fetching a sample file if you click a sample — which is a plain download from this same site.
Traffic measurement: this site loads Google Analytics (gtag) to understand aggregate page popularity. It does not see the names or contents of any file you inspect. If you prefer zero third-party scripts, block googletagmanager.com — the tools work fully offline.
Independence
AI Watermark Checker is not affiliated with Anthropic, OpenAI, Google, or Adobe, and reads only open standards (C2PA, JUMBF, RFC 8949 CBOR). Vendor names appear only to identify provenance records. Trademarks belong to their owners.
Change log
- v0.1.0 — 2026-09-29: browser-side C2PA reader (JPEG/PNG/WebP), vendor pages (Claude, GPT Image, Gemini), hidden-character scanner, synthetic sample suite + self-test.