The problem this site was built around
Most tools in this category output a percentage. An image is 87% likely to be AI-generated; a paragraph is 92% likely to be machine-written. The number looks like a measurement, people act on it as one, and it is a guess whose calibration does not survive contact with compressed, cropped, edited, or re-shared content — which is most content.
The harm is not abstract. Students have been failed, freelancers have lost contracts, and photographers have been accused of faking their own work on the strength of a confident number produced by a classifier operating far outside the conditions it was evaluated in.
So this site was built on the opposite premise: report only what can actually be inspected, name the strength of each piece of evidence, and refuse to convert an absence of evidence into a verdict.
How results are classified
Every file result falls into one of four classes, and the distinction between them is the entire product. Collapsing them into a single score is precisely the mistake we are trying to avoid.
- Verified credential — a C2PA manifest parses, its signature verifies, and its hard binding matches the file. Provenance statements can be attributed to a signer.
- Validation problem — a credential exists but a check failed. This can mean tampering, and much more often means re-encoding, an expired certificate, or an unfamiliar signer.
- Metadata hint — editable EXIF, IPTC, or XMP strings mention a tool or provider. A lead worth following, never proof.
- No verified signal — nothing inspectable was found. The most common outcome, and the one carrying the least information.
What we refuse to build
No AI probability score. We do not run a pixel classifier or a stylistic text classifier, because presenting a guess in the visual language of a measurement is the specific harm described above.
No fake watermark scanners. Perceptual watermarks such as Google's SynthID can only be verified by the provider that embedded them. A page claiming to detect one independently is either running a classifier and mislabelling it, or reading metadata and calling it something else. We say so on the relevant page instead of building a scanner that does not work.
No 'human-made' verdict. A missing credential means the file passed through a pipeline that strips provenance. It is not a certificate of human authorship and we will not render it as one.
No upload endpoint. This is an architectural commitment, not a policy that could be quietly relaxed — there is no server-side scan route to send content to.
How the browser-only architecture works
When you select an image, the file is opened through the browser's own file API. Its bytes are passed to two things: an open-source metadata parser, and the official C2PA WebAssembly validator running in a worker. Both execute inside your tab.
Preview images use temporary object URLs that exist only in the tab's memory and are revoked when you replace the file or leave the page. C2PA reader resources are explicitly released after every analysis. Pasted text lives in React state and is discarded on reload.
There is no database, no account system, no scan history, and no shareable report URL, because each of those would require storing something. The absence of those features is what makes the privacy claim structural rather than promissory.
Who this is for
Journalists and fact-checkers who need to know what a file's provenance actually establishes before publishing a claim about it, and who need the distinction between a signature failing and a certificate being unfamiliar.
Photographers and creators checking whether their Content Credentials survived a publishing pipeline, or checking a photo for embedded location data before posting it.
Educators and reviewers who have been told a detector score is evidence and want to understand why it is not, and what fairer alternatives exist.
Developers and technical readers who want the raw manifest, the issue codes, and the full metadata field list rather than a simplified badge.
How the site is funded
AI Origin Check is free and carries advertising. It can be free because it does not run media analysis on a server — the expensive part of this kind of tool is compute, and here that cost sits on your device rather than ours.
Advertising is deliberately constrained. Ads never appear inside the checker, next to upload or scan controls, inside results, or on the About, Privacy, Terms, and Contact pages. Automatic ad placement is disabled so the network cannot introduce units near the tool.
No file, filename, pasted text, metadata value, manifest content, or scan result is ever passed to an advertising network, an analytics service, or any third party. This is enforced by an allow-list in the code and covered by a regression test, not by intention alone.
Who maintains it
AI Origin Check is built and maintained independently, not by a company selling detection services — which matters, because a vendor whose revenue depends on confident verdicts has a poor incentive to tell you when a verdict is not available.
Corrections are welcome and taken seriously. If something here is technically wrong, or a result is described in a way that overstates what the evidence supports, write to hello@aiorigincheck.com with the specifics and it will be fixed.
The technical claims on this site are grounded in published specifications rather than our own assertions, and the relevant sources are linked on each page so you can check them directly.
Frequently asked questions
Why does this site not give an AI percentage?
Because a percentage implies a calibrated measurement, and pixel or style classifiers are not calibrated across real-world conditions. A confident wrong number causes real harm to the person it is used against.
Is AI Origin Check free?
Yes, with no account, no usage limit, and no paid tier. It is funded by advertising, which is kept out of the checker, the results, and the policy pages.
Do you store the files I check?
There is nothing to store them with. No upload endpoint, no database, no scan history. Files are processed by WebAssembly and JavaScript running inside your own browser tab.
Can I use this for journalism or legal work?
It is an inspection aid, not a source of legal proof. It shows you what a file's provenance and metadata contain, which is a starting point for verification rather than a conclusion.
Primary sources
The technical claims on this page follow the published specifications below rather than our own assertions.
- C2PA technical specification 2.3
The normative definition of manifests, claims, assertions, hard bindings, and validation states.
- Content Authenticity Initiative developer docs
Implementation guidance and the open-source SDKs, including the browser SDK this site uses.
- European Commission AI transparency guidance
The EU framework driving machine-readable marking obligations for synthetic content.