AI or Not Detects 98% of Cropped Meta AI Images. Meta's Own Tool Catches 35%.
An AI or Not benchmark of 205 Meta AI photos found Meta's Content Seal watermark rarely survives a crop.

On July 7, Meta launched its first image generation model built in-house at Meta Superintelligence Labs. Originally, Meta was partnering with Midjourney for their image generation but now has launched their own, proprietary generator. A day after launch, the company released a web tool, Identify images generated with Meta AI, to help identify AI-generated content with a watermark.
The tool searches for the invisible watermark of the model that generated the image, called Content Seal. Meta's launch post says the watermark stays intact "even when cropped, compressed, resized, or screenshotted."
We decided to put it to the test.
To test the watermark, AI or Not ran 205 AI-generated images through two conditions: untouched and cropped. Each image was run through the Meta AI detector and the AI or Not detection API. Reuters ran its own test of Meta's detector on 40 Meta AI images and found the same failure.

Key Takeaways on AI Image Detection for Meta AI
- On 103 untouched Meta AI images, AI or Not detected 100% (103/103) while Meta's own tool detected 98.1% (101/103).
- On 102 cropped versions of Meta AI images, AI or Not detected 98.0% (100/102) but Meta's own tool detected 35.3% (36/102).
- The tool failed more with landscape and scene photos, catching just 9.6% of cropped versions (5 of 52), than with portraits, food and objects (62.0%, 31 of 50).
- AI or Not never dropped below 96.2% in either batch.
- In a separate Reuters test of 40 Meta AI images, Meta's tool confirmed the originals 100% of the time but caught only 45% of the versions cropped to between 1/3 and 1/2 of their original size.
What Meta's Content Seal AI Detector Actually Does
Content Seal is an invisible watermark that is added to an image as soon as it is generated by Meta. The watermark is supposed to hold, so it does not disappear when an image is cropped, when it is taken a screenshot of, when it is re-uploaded or re-encoded by another service.

The Content Seal watermark detector can only detect images generated by Meta models; the watermark detector won't work on images that have been watermarked by other companies using C2PA content credentials or SynthID by Google. It cannot read images from old Meta AI models that were not watermarked by the new Content Seal watermark either.
Testing Meta AI Image Detection on 205 Images
The 205 images were generated by Meta AI. The images were split into two sets: 103 untouched and 102 cropped. The first set of images were left untouched and then run through Meta's watermark detector and the AI or Not detection API. For the second set of images, every image was cropped and then run through the same two detectors.

Reuters Found the Same Meta AI Detection Gap
Reuters did its own test with 40 Meta AI photos. The 40 images were all verified by the Content Seal watermark detector. However, 55% of the images that were cropped to roughly 1/3 to 1/2 the size of the original image were not verified by the Content Seal watermark detector. Meta told Reuters that the Content Seal signal "may be lost if an image is heavily cropped."
Siwei Lyu, a computer science professor at the University at Buffalo (SUNY) who researches AI image forensics, told Reuters:
"Watermark-based methods can be highly effective when the watermark remains intact, but any modification that removes or weakens the embedded signal, such as cropping, resizing, heavy compression, or editing, may reduce their effectiveness, depending on how the watermark is designed."
Why AI Watermarks and Provenance Checks Break When an Image Is Edited
C2PA Content Credentials are provenance signals that travel with an image file to give it metadata about its original creation. A visible watermark is a pattern or a phrase that is placed in the frame of an image and can be easily removed by cropping the image. Invisible watermarks, like Content Seal, are embedded in the pixels of an image. These can get lost if an image is cropped, resized, re-encoded or heavily compressed. And regeneration attacks, which add noise to an image and rebuild it with a diffusion model, removed over 99% of invisible watermarks in tests.
Anatoly Kvitnitsky, CEO and founder of AI or Not, put it this way:
"Watermarks and provenance metadata like C2PA are genuinely excellent for one job, confirming an AI image at the moment it's created. Think of them as the birth certificate for original AI content. But the second someone crops, screenshots, or re-encodes that image, those signals can break or be stripped away entirely, and that is precisely the gap adversaries attack. Purpose-built models like AI or Not's are trained specifically against those adversarial manipulations, so they keep detecting the AI image itself, not just the label that was attached to it."
Content-based detection, the approach AI or Not uses, is less prone to loss or degradation over time, and still works on images that have been cropped, screenshotted, re-encoded, or in any other form of adversarial edits. For example, in an analysis of AI or Not's detector, it maintained a 98% detection rate of AI images in the benchmark set, even after the images were cropped.

What Cropped AI Images Could Mean for Fraud
For users who want to disclose that their images are AI generated, like on social media, keeping the original images untouched is a great approach and perfect for provenance tools like C2PA, Content Seal and SynthID. However, when fraudsters want to deceive whoever is looking at the image, they will go through greater lengths to circumvent the off-the-shelf checkers.
This issue becomes a problem when:
- A fake identity is used for a KYC or ID verification.
- A doctored photo of damage is submitted with an insurance claim.
- A cropped image is used for spreading misinformation on social media.
All of these images are almost always cropped, screenshots or re-uploaded by someone else.
This is where AI or Not's industry leading AI image detection models shine, keeping its 98% accuracy, even against adversarial attacks.
Meta AI Detection FAQ
Can Meta AI Detect Its Own Cropped Images?
The Meta AI detector for images generated with Meta AI is not designed to detect images made by other companies. The tool can detect images that have been watermarked with Content Seal for original images generated by Meta AI with an accuracy of 98.1%. However, for cropped or edited images, even originally generated by Meta AI, Meta's detection rate drops to 35.3%. In a separate Reuters test of 40 images, Meta's tool detected the original images 100% of the time but only 45% of the time once they were cropped by roughly 1/3 to 1/2 of the original size. AI or Not's image detection detected 100% of originally generated images and 98% of cropped Meta AI images.
Why Do AI Watermarks Break When an Image Is Cropped?
A watermark, like Meta's Content Seal or Google's, is embedded in an image as soon as it is created. As shown with this study, and with Reuters', AI watermarks often break after an image is cropped or edited. Leading AI image detector AI or Not proved that even with an edited image without a watermark, visible or invisible, present, it can still detect cropped or edited images with 98% accuracy.
How Accurate Is AI Detection on Cropped or Tampered Images?
AI or Not held 98% accuracy at detecting AI images even after they had been cropped, screenshotted, re-uploaded or re-encoded. The watermark detection, used by Meta, however, will be unable to detect the AI image after it has been cropped. AI or Not detected 100% of the originally AI generated images.
Are AI Watermarks and C2PA Still Useful?
Yes, the AI watermarks and C2PA are a good way to verify that an image was made by a company at the time of creation. However, AI or Not's image detection provides the highest accuracy for detection even if the AI image was cropped, screenshotted, re-uploaded and re-encoded.
What do you get with AI or Not?
Instantly get your AI detection API to start building, and protecting.

AI detection covering images, text, video and audio.
All content checked gets deleted, instantly.
Start detecting AI for free, scale with pay-as-you-go.
AI to fight AI.