Photo authenticity

How to prove a photo is real in the AI era

By the LockProof Team · Last updated July 20, 2026

Here is the uncomfortable part: in 2026 you can no longer prove a photo is real by looking at it. AI can generate a convincing photo of something that never happened, and a real photo can have fake damage painted into it in seconds. So how to prove a photo is real in the AI era has a different answer than it did five years ago. It is not about inspecting the image harder. It is about where the image came from, and whether it was touched after. Provenance, not inspection. Here is why every shortcut fails, and the one approach that holds up.

The proof problem got worse this year

Insurers noticed first, because they pay for it. A 2026 Verisk study found that 99% of insurers say they have already encountered manipulated or AI-altered documentation, and 98% agree AI editing tools are driving a rise in digital fraud (SAS / Verisk, 2026). The examples are mundane, which is what makes them dangerous: a real photo of an intact van with a cracked bumper painted in by AI, then submitted for thousands in repairs; a coffee stain generated onto a chair and presented as tenant damage (Debevoise & Plimpton). None of it took skill. Fabricating a believable photo used to need an expert and an afternoon. Now it needs a prompt.

For anyone who relies on a photo as a record — a completed repair, a delivered load, a finished cleaning, a caregiver visit — that is the whole game. If a photo can be faked in seconds, “here is a photo” is not proof anymore. It is a claim, and claims are what get disputed.

A worker taking a photo on a phone at the moment of the job
Photo: alleksana / Pexels

Looking at the image is not a test

The instinct is to look harder — count the fingers, check the shadows, zoom into the reflections. That worked on the clumsy fakes of a couple of years ago. It does not work now. The current generation of image models produces photos that pass a careful human look, and the tells people share online are outdated by the time they spread. Treating “it looks real” as evidence is exactly how the fabricated van claim gets paid.

An AI detector gives you a probability, not proof

The next instinct is to run the image through an AI-detection tool. Those tools return a score — “95% likely real” — and a score is not evidence. Two things make it worse. First, detectors disagree: the same image can come back 95% real from one and 60% AI from another, and you have no way to settle which is right (Snopes). Second, they degrade fast — every new image model is trained against the last detector. A number that changes depending on which tool you ask, and gets weaker every month, is not something to stake a disputed invoice on.

The metadata inside a photo can be rewritten

Then people reach for the EXIF data — the camera model, the GPS, the timestamp baked into the file. It feels authoritative. It is trivially editable. Every one of those fields can be changed in seconds with free tools, and a photo’s embedded timestamp can be set to any date you like. Metadata that the person submitting the photo can rewrite is not a record of anything. It is one more thing to fake.

What holds up is provenance, captured at the moment

Notice the pattern in what fails: every one of them tries to judge the photo afterit already exists. By then it is too late — the fake is baked in. The only approach that holds up flips the order. You establish where the photo came from at the moment it is taken, in a way the person holding the phone cannot control, and you seal that record so it cannot be edited afterward. That is provenance, and it is the one signal the experts converge on.

For consumer photos, the emerging standard is C2PA content credentials — a tamper-evident record of an image’s origin and edit history, backed by Adobe, Microsoft, Sony, Nikon, and the BBC. Think of it as a nutrition label for a photo: not a judgment of whether the content is good, just a verifiable record of where it came from and whether it was altered. For field work — a job, a visit, a delivery — the same principle takes a more direct form.

How this works for a work photo

LockProof is built on that flip. A worker gets a text link, and the link opens a live camera — the gallery is blocked, so a worker cannot just attach an old photo, a stock image, or an AI-generated file. The photo has to be taken live, through the link, right then. That closes the most common shortcut — uploading a picture you did not just take. It does not make fakery impossible; someone determined could still photograph a screen. What it does is force the photo to be captured rather than chosen, which shuts the easy door.

Then the record is sealed. At capture, the photo is stamped with a server-set time the worker cannot change, its GPS location, and a SHA-256 fingerprint over the image, the location, and the time — a chain of custody. If anyone edits the record afterward, the fingerprint no longer matches, so the change is detectable. Be precise about what that proves: it proves the record has not been altered since it was captured, and that the photo came in live through the link at that place and time. It does not certify that the scene itself is truthful — no capture can. What you get is narrower and honest: provenance and integrity — where a photo came from, and that it has not been touched since.

Taking a live photo through a phone camera at the moment of the work
Photo: Los Muertos Crew / Pexels

Every way to check a photo, and whether it is proof

Way to check a photoIs it proof?What it actually tells you
Look at the imageNoWhether it fools a human — which AI now beats
Run an AI detectorNo, a guessA probability score that tools disagree on
Read the EXIF metadataNoFields the sender can rewrite in seconds
C2PA content credentialsYes — provenanceA tamper-evident origin and edit history
Live capture + server time + hashProvenance + integrityWhere the photo came from, and that it was not altered after

None of this makes a photo automatically admissible in court — that is a judge’s call, and no software can promise it. What it does is narrower and honest: it makes each photo a dispute-ready record with a clear chain of custody, so when a client or a payer questions the work, you are not arguing “it looks real.” You are showing where the photo came from and that it has not been touched. See what that looks like in a sample verified record, or how field teams put it to work in field service.

Common questions

Can you tell if a photo is AI-generated just by looking?

Not reliably, not anymore. Current image models produce photos that pass a careful human look, and the visual “tells” people share online are outdated fast. Treating “it looks real” as proof is exactly how a fabricated photo gets accepted. Looking harder at the image is not a test.

Do AI image detectors prove a photo is real?

No. Detectors return a probability, not evidence, and different tools disagree on the same image — 95% likely real from one, 60% AI from another, with no way to adjudicate. They also weaken as new image models train against them. A score you cannot settle and that decays monthly is not proof.

Can a photo's timestamp and metadata be faked?

Yes, easily. The EXIF data inside a photo — camera model, GPS, timestamp — can all be rewritten in seconds with free tools, and an embedded timestamp can be set to any date. Metadata the sender controls is not a record of anything; a server-set time they cannot change is a different thing entirely.

What actually proves a photo is real?

Provenance captured at the moment the photo is taken, in a form the sender cannot control, then sealed so it cannot be edited afterward. For consumer images that is C2PA content credentials; for field work it is live-only capture plus a server-set time and a SHA-256 chain of custody.

How do I prove a work photo is real for a dispute?

Capture it so a fake is hard to slip in, and seal it so it cannot be altered after. LockProof opens a live camera only — gallery uploads are blocked, so a worker cannot attach an old or AI-generated file — then stamps each photo with GPS, a server-set time, and a SHA-256 fingerprint. That gives you a dispute-ready record of where the photo came from and that it has not been touched since — not a guarantee the scene is real, but a record you can stand behind.

Make every work photo prove itself

Book a 15-minute demo and watch a real job come back as a verified record: a live photo captured through the link, with GPS, a server-set time, and a SHA-256 chain of custody.