Somebody in Hohhot won first prize in a city photography competition with a picture of sanitation workers resting on a bench. It is the sort of photograph that wins civic contests everywhere. Ordinary people, honest work, a bit of dignity in the frame.
Then a stranger on the internet looked at the writing on the workers' hi-vis vests and noticed it was gibberish. Not a language he could not read. Gibberish, the confident nonsense that image generators produce when they try to render text.
The organiser checked, confirmed the image had been generated rather than photographed, pulled the prize, and suspended its bimonthly contest series for what it called rectification. Its statement said the incident had "exposed shortcomings in competition oversight and judging standards". That was the middle of July.
I want to be precise about who did what. A panel of judges looked at that image and awarded it first place. A member of the public looked at the same image and read the vest.
Three catches, and not one of them by a judge
It had happened twice already in the three months before.
In April, Hasselblad Masters 2026 announced seventy finalists and people on Reddit went through them. One street photograph had a Coca-Cola bottle in it whose label was a garbled mess, which is the same tell as the vest. Somebody then brightened the image and found the table it sat on was missing its legs. Hasselblad disqualified the entry on 18 May and replaced the finalist.
That same month, Tokina pulled the overall winner of its own photo contest after a Reddit user found an invisible SynthID watermark in the file, the marker Google's tools leave in images they have touched. Tokina said it would "reconsider the selection process by establishing additional checkpoints".
The Tokina case is the one worth sitting with. The detection technology worked exactly as designed. A machine-readable signal was present, somebody read it, and it settled the question.
That somebody was a stranger on a forum running a checker on his own time. It was not the contest.
What a Content Credential actually promises
There is a large, well-funded, serious effort to fix this. It is called C2PA, and Content Credentials are what it produces: a cryptographic manifest attached to an image saying which camera or which tool made it, and what happened to it afterwards. Adobe, Google, Microsoft, OpenAI, Sony and the BBC are all on its steering committee. TikTok joined them on 27 July and says it has now labelled over three billion pieces of content as AI-generated.
Their own documentation is careful about what that buys you. The Content Authenticity Initiative says plainly that Content Credentials "provide a positive signal about the origin and history of an image, but they don't provide a negative signal about the authenticity of an image". Their analogy is a cereal box. A label tells you what is inside, and a box with no label tells you nothing at all. It is not evidence of poison.
That is an honest description of what they built, and I have no argument with it. They are not claiming to catch fakes. They built a way for someone with nothing to hide to prove it. My problem is with everything that has been stacked on top of that while nobody was looking.
Nikon signed a photograph that was not one
In September 2025, a reader of a Nikon rumour site found that the Z6III's multiple exposure mode would happily blend a non-photographic image with a real capture and then sign the result. The camera's authenticity service attached a valid credential to a picture that was partly fabricated, and the signature checked out.
Nikon suspended the service on 5 September, saying it had been "temporarily suspended while we work diligently to resolve the issue". Later that month it went further and revoked every certificate it had ever issued, telling users that the certificates loaded onto cameras "during the period between the service launch and its suspension will be invalidated". Every honest photograph anyone had signed with a Z6III lost its credential along with the fakes.
As far as I can tell it is still down. The most recent tracking I can find had it suspended in February, Nikon has announced no resumption since, and that puts it at eleven months and counting. The Z6III was the only Nikon body that ever shipped the feature, so Nikon currently has no camera that can sign anything.
I have written before about the bugs that announce themselves and the ones that stay silent. This is the third sort and it is the worst of them. The system did not go quiet and it did not throw an error. It said yes, with a cryptographic signature on it, about a thing that was not true.
Signing is a subscription now
Suppose you want to be one of the honest photographers this machinery is built for. What does it cost?
If you shoot Leica, nothing. The M11-P has signed at capture since 2023 and it is on by default. If you shoot Sony, you need what Sony calls a Digital Signature Upgrade License, and its own page says licences "are available for purchase by news organisations and related photojournalists, with wider availability following in due course". If you shoot Canon, its Authenticity Imaging System started rolling out in May and Canon's announcement states that "C2PA functionality requires paid activation". If you shoot Nikon, there is nothing to buy, because it is switched off.
So on two of those four the ability to prove your photograph is a photograph is a paid feature currently pointed at newsrooms, and on a third it does not work at all. Everyone else gets to be unverifiable by default.
Then the file has to survive the trip. C2PA's own specification says, in its security section, that "C2PA does not offer any protection against the complete removal of C2PA manifests from assets", and its own blog admitted in January that "it is still common for social media and content platforms to remove metadata". Recompression on upload strips the manifest as a side effect. A signed photograph that has been through an ordinary social feed arrives looking exactly like an unsigned one.
The law landed on the honest party too
On 2 August the EU's AI Act transparency rules came into force. The Commission's own announcement is blunt about images: deepfakes "will have to be labelled". Providers of systems that generate synthetic content have to mark their output in a machine-readable format, and whoever publishes a deepfake has to disclose it.
Both of those duties sit on the person making and publishing the image. I read the guidance looking for the other half, the part that says what a competition or a picture desk should do with an entry it receives, and it is not there. There is no obligation on the receiving end, because the law has nothing to give the receiving end to work with. There is not even a mandated standard yet. The Commission published a code of practice on marking in June and it is voluntary.
I run a small agency inside the EU with no legal department, so I read these things when they land. This one does not help the judges in Hohhot at all.
The tell is a bug, and bugs get fixed
Every catch above came from the picture being wrong. Garbled characters on a vest. A garbled bottle label. A table with no legs. One watermark, found by an amateur.
Garbled text is not a property of synthetic images. It is a defect in a particular generation of models, and it is being actively engineered out. The detection method with a perfect record so far is a bug report, and somebody is fixing it.
It gets worse when you ask which tools a winning entry is likely to come from. OpenAI, Google and Adobe all sign their generated output as synthetic by default, which is genuinely good of them. Midjourney ships no C2PA manifest and no known invisible watermark. Grok has neither. The generators best suited to producing a photorealistic image that fools a jury are the ones that attach nothing, and the ones that attach something are attaching it to a file that Instagram will strip on the way past.
The academic work on C2PA itself is not reassuring either. A paper published in April by eleven authors concludes that "the C2PA specifications and implementations do not achieve any of their claimed security goals". A separate one built an asset carrying a valid manifest claiming human authorship while its pixels carried an AI watermark, both passing their own checks, with no cryptographic compromise needed to do it.
I went looking for a single documented case where Content Credentials caught a forgery or settled a real dispute. I did not find one.
I typed it into the front matter myself
The hero image at the top of this page was generated by a machine. You know that because the front matter of this file has a line in it that says ai_generated: true, and another one naming the tool, and my site renders a credit from them.
Nothing verifies that line. No signature, no manifest, no certificate authority. It is a string in a YAML block that I typed, in a file I control, and if I deleted it tomorrow nothing anywhere would notice or complain. It is worth precisely what my willingness to keep typing it is worth.
The same goes for the declaration a contest asks an entrant to sign, for the credential on a Leica file, and for the label the EU now requires. Every one of them is a mechanism for an honest party to say something. Not one of them is a mechanism for checking, and after years of building, the only thing that has caught anybody is a stranger noticing that a word in the picture was spelled wrong.
The question worth asking is who is willing to say, and what happens to them when they lie. In Hohhot the answer to the second half was that a local arts federation suspended its own competition and said the responsible parties would be dealt with under the applicable rules. That is the entire enforcement apparatus in this story, and it belongs to a city photography contest in Inner Mongolia.
I will keep typing the line. It is not much, but it is the same thing everyone else here is offering, and at least mine is free.

