Meta AI watermark and the AI Info label: what triggers what
Meta marks its generated images two ways: an imperceptible pixel watermark, and standard provenance metadata - C2PA manifests and IPTC digital-source-type fields. The automatic « AI Info » label on Instagram and Facebook is driven mainly by that metadata, which is why images edited through tools that drop it often lose the label.
Two systems, one label
Meta marks generated images in two ways, and only one of them drives the label people actually see.
The pixel watermark is imperceptible and designed to survive ordinary editing. Meta does not publish its detector or its strength.
The metadata is standard, and that is the interesting part: C2PA manifests, and the IPTC digitalSourceType field. These are industry formats, not Meta inventions, which is why Meta can label images generated by other companies' tools. When Meta announced it would label AI content across its platforms, this interoperability was the mechanism.
Why the label is inconsistent, and what that reveals
The most common complaint is that the label appears on one image and not on another from the same generator. That inconsistency is informative: it shows the label follows the file's metadata rather than an analysis of the picture.
An image that passed through an editor that discards unknown metadata blocks arrives at upload with nothing to read. One exported directly from the generating tool arrives with a full manifest. Same pixels, different journey, different outcome.
It also explains the reverse complaint - photographs receiving the label. A real photo edited with a generative fill, or processed by software that writes digitalSourceType, carries the signal even though the scene was captured.
Reading your own file first
Before assuming anything about a specific image:
exiftool -a -G1 image.jpglists every tag. Look forDigitalSourceTypeand for a large JUMBF block, which is C2PA.- The Content Credentials verification page reports what a manifest claims and whether its signature validates.
- Re-uploading a file you already published tells you nothing new: the platform may have stripped or rewritten metadata on the first pass.
What processing changes
Metadata first: C2PA manifests, IPTC provenance fields, XMP blocks and text chunks are removed. What remains is a file that declares nothing about its origin - which is the normal state of most images in circulation.
Then the sensor layer. Grain at intensity 0.018 supplies the noise floor a generated image lacks. Lateral chromatic aberration reaches 1.25 px at the corners and none at the centre. The frequency stage attenuates periodic upsampling residue at 0.88 of Nyquist.
The encode writes camera EXIF and the quantization table of the make it declares, so the compression and the claim agree rather than contradict.
The honest boundary
This addresses the metadata path - the one that drives the label deterministically. It makes no claim about Meta's pixel watermark, and it does not change whether a human reviewer finds the image implausible.
Fidelity is measured per image: the sheet above gives SSIM and PSNR for this one, against its source.
Why this matters beyond the label itself
The label is cosmetic on a personal post. It stops being cosmetic when the image carries commercial weight - an ad creative, a product shot, a cover. Reach and engagement differ once a post is marked, and advertisers have reported changes in delivery on labelled creative.
That is the real reason people search for this: not vanity, but distribution. It is also why the metadata path matters more than the watermark. The label is what changes behaviour, and the label follows the metadata.
Order of operations
Process last, after every edit. Metadata is written and rewritten by each tool in a chain, so a file cleaned early and then exported through a design tool can arrive at upload carrying fresh provenance fields written by that tool.
The same applies to composition. If lettering or a logo is added after processing, that layer carries none of the sensor treatment, leaving a frame where part of the image is statistically cleaner than the rest. Run the pass on the finished export, once.
What is measured
Fidelity is computed for each image rather than asserted once: the sheet above gives SSIM and PSNR for this one, against its source. Typical values across the corpus sit between 0.87 and 0.90 SSIM. No detector pass rate appears anywhere on this site, because any figure would describe one detector version on one day.
| What is checked | Value |
|---|---|
| Accepted formats | PNG, JPEG, WebP |
| Maximum size | 20 MB |
| Maximum dimension | 8192 px on the longest side |
| Sensor grain intensity | 0.018 |
| Lateral chromatic aberration | 1.25 px at the corners, none at the centre |
| Frequency cutoff | 0.88 of Nyquist |
Questions
What actually triggers the AI Info label?
Industry provenance metadata, mainly: C2PA manifests and the IPTC digital-source-type field that generation tools write into the file. Meta reads those signals at upload. It also applies its own classifiers, but the metadata path is the deterministic one.
Why do some AI images get the label and others not?
Because the label follows the metadata, not the pixels. An image exported through a tool that drops the manifest arrives without the signal. Two images from the same model can therefore behave differently depending on the path they took to your phone.
Does the label appear on Instagram and Facebook the same way?
The same underlying signals feed both, since it is one system. Presentation differs - placement and wording have changed several times - and Meta has adjusted how prominently it shows on edited-with-AI content.
Can the pixel watermark be removed?
Meta does not publish its strength or its detector, so there is no measurement that would support a claim in either direction. This page makes none. What is deterministic is the metadata layer.
What does PassReal do to a Meta AI image?
It strips C2PA manifests, IPTC provenance fields and XMP blocks, applies a sensor model, smooths frequency residue, and writes camera EXIF with a matching quantization table. The output is an ordinary JPEG.
Limits
Naturalization operates on the pixels and on the file, not on the content of the image. A subject that is implausible - six fingers, inconsistent reflections, text that does not read - stays implausible after processing, and a human reviewer will notice it. PassReal changes what a statistical classifier measures, not what a person sees.
Results vary by generator, by subject and by detector, and detectors are retrained. No pass rate is published on this page because none has been measured in a way that would still hold next month.
Three images, no card, no expiry.