Since this weekend, the big AI companies serving California owe you something: a free tool that answers the question you keep asking mid-scroll. Is this picture real? California's SB 942 — the AI Transparency Act — became operative August 2, and it quietly changes what you can demand of a suspicious image.
What just changed
SB 942 makes California the first state to enforce full-scale AI watermarking and detection. Any generative-AI provider with over a million monthly users now has to bake two disclosures into its output: a hidden one (metadata naming the system that made it) and a visible one (an actual label). Each provider also has to offer a free, public detection tool. A companion law, AB 853, synced the timing with the EU's provenance rules and roped in platforms and camera makers too. The point is simple — make fakes and scams checkable.
So let's check. Five steps, quickest first.
1. Look for the label
Some generators already stamp a watermark in a corner or faintly across the background, and SB 942's label rule means you'll be seeing these a lot more. A visible label ends the debate on the spot. No label? That tells you nothing yet — keep going.
2. Pull up the receipts
The real verification layer is called C2PA — a tamper-evident metadata standard backed by OpenAI, Adobe, Google and Leica, among others. When Firefly, DALL-E, Imagen or Midjourney makes an image, it signs a cryptographic record: what tool made it, whether AI was involved, who signed it, whether anything's been changed since.
Reading it takes seconds. Free C2PA viewers are drag-and-drop — the manifest pops up with creator, tool, timestamp and edit history. There's a Chrome extension that does it from the right-click menu, entirely on your machine.
3. When the receipts are torn off, run a detector
Now the annoying part. Instagram, X, Facebook and TikTok strip metadata — C2PA manifests included — when they re-encode uploads. The proof vanishes precisely where the fakes circulate.
That's the job of pixel-based detectors, which analyze the image itself instead of its paperwork. Sightengine and DeepAI both offer free ones, and the detectors SB 942 forces out of major providers won't cost you anything either. Google's SynthID helps here too — an invisible watermark woven into the pixels of generated images, built to survive what EXIF data can't.
4. Read the boring metadata
Got an actual file rather than a social post? Ordinary metadata still snitches. Real photos usually list a camera make, model and settings. AI images usually don't. You'll also see creation dates and any editing tools used.
5. Your eyes go last
Fact-checkers at places like Snopes still nail fakes the old way — warped hands, impossible shadows, edges that don't add up. But they're also the first to admit the generators improve every month. Eyeballing is your tiebreaker now, not your test.
The fine print
Nothing here is a guarantee. Missing credentials don't prove a photo is real, and detectors misfire. But run the stack — label, credentials, detector, metadata, eyes — and very little slips through. The receipts finally exist. Get in the habit of asking for them.
Image: jamies.x. co, via Pexels





