Can You Still Tell an AI Image From a Real Photo? The Detection Arms Race Is Getting Uncomfortable

A little web game called "Can you tell which images are AI-generated?" hit the Hacker News front page this month with 112 points and 85 comments. The premise is simple: you get shown a stream of images and guess real or generated. The comments converged on the same confession. People who work with images for a living were scoring barely better than coin flips.
A few days later, a different HN thread featured Pangram, a startup selling AI detection for both text and images, with a 27-comment discussion about whether detection can work at all. Between the two threads sits the uncomfortable state of the field: telling generated images from real ones is getting harder faster than detection is getting better.
Why your eyes keep losing
The tells that used to work are gone or nearly gone. Garbled hands, melted text, inconsistent lighting, waxy skin: each fix shipped in successive model generations. Text rendering, long the reliable giveaway, is now a solved problem in the leading models, which is partly why image benchmarks started weighting it so heavily. What remains is a subtler gap. Generated images are often slightly too coherent, textures a little too even, backgrounds a little too willing. Humans notice the vibe and cannot articulate it, which is exactly why a guessing game embarrasses everyone.
The Loki question makes the point in a different register. A post on r/StableDiffusion asked how people are producing AI images that so precisely preserve a specific actor's appearance across new outfits and scenes. The answer, from people who do it, is reference-based generation and fine-tuned adapters, none of which require exotic tooling anymore. Likenesses that would have taken a VFX house years ago are now an afternoon project, and the person asking could not tell which of the images flooding their feed were model outputs.
Detection as a product, detection as a policy
Pangram's pitch is that detection is tractable when you train detectors as aggressively as generators. The HN discussion pushed back with the standard and mostly correct objections: detectors generalize poorly to unseen models, they produce false positives that harm real photographers, and any published detector becomes a target that the next model release silently defeats. There is also the provenance approach, C2PA-style content credentials, which sidesteps detection by asking cameras and generators to sign their outputs. It helps when everyone cooperates. It does nothing for the image someone re-encoded and stripped.
Policy is moving anyway. Restaurants using AI food photography became a minor news story this month via a Wall Street Journal piece, and the backlash was less about deception in the abstract than about the specific betrayal: the burger you order should look like the burger in the ad. That is a social detection mechanism, crowd-sourced trust, and it is stricter than any classifier.
What the HN threads actually debated
The two Hacker News discussions split the problem neatly. The game thread was mostly people reporting scores and trading tips, and the tips are a decent fossil record of what used to work: look at the hands, check the text, inspect reflections, count the fingers on background pedestrians. Nearly all of those checks now return false negatives on current models. Text rendering in particular stopped being a reliable tell once the leading models made it a benchmark priority; a generated storefront with legible signage was a novelty two years ago and is a default behavior now.
The Pangram thread ran more skeptical. The objections in the comments were the standard ones, and they hold: detectors trained on yesterday's generators miss tomorrow's, false positives fall hardest on real photographers whose work gets flagged as synthetic, and publication of a detector is an open invitation for the next model to be trained against it. One comment made the asymmetry concrete: a generator only needs to fool the detectors that exist, while a detector needs to catch every generator, including ones not yet released. That is a losing race by construction, which is why the commercial detection products mostly sell to institutions with moderation obligations rather than to individuals curious about a suspicious image.
Provenance, the boring alternative
The alternative that keeps coming up is content credentials: cryptographically signed metadata, C2PA-style, attached at capture or generation. Cameras sign what the sensor saw. Generators sign what the model made. Editing tools preserve or annotate the chain. Nothing about that requires detecting anything, which is its main virtue, since detection is a permanent arms race and signing is a plumbing standard.
The weaknesses are equally structural. Signing is voluntary, metadata is stripped by screenshots and re-encodes, and the chain only proves where an image came from, never whether the original was honest. A signed AI image is still an AI image. But as platforms begin surfacing credentials, the presence of a clean chain becomes a trust signal the way HTTPS became one, and its absence starts to read as a question the image cannot answer.
The social layer is stricter than the technical layer
Between detection and provenance sits the mechanism that actually did the work this month: crowds. The restaurant story spread because customers recognized the gap between photographed and served food, not because a classifier flagged it. The boomer grandkid images became a story because parents in the group chat said no. The Loki images prompted a subreddit to ask how they were made, and got an answer within a day. Communities detect the way detectors cannot, by knowing context.
That suggests a division of labor worth taking seriously. Machines are fine at scale screening, flagging bulk uploads for human review. Humans are fine at context, spotting that the burger in the ad has no crumbs because no burger does. Provenance is fine at the source, where the honest actors are. No single layer catches everything, which is exactly why the game that embarrassed everyone remains useful calibration rather than a verdict.
What this means for people who publish images
If you publish or commission images, three habits follow from the current state. First, labeling generated content is becoming a trust asset rather than an admission. The creators who disclose, and there is a visible split in r/StableDiffusion threads about how to handle anti-AI comments, are building audiences that stay when disclosure happens up front. Second, provenance metadata is cheap to keep and occasionally decisive; platforms are beginning to surface it, and the cost of preserving it is a settings toggle. Third, for anything where the image makes a factual claim (news, products, evidence), assume your audience has a coin-flip detector and a screenshot tool. The only durable defense is being truthful about what the image is.

The game that embarrassed everyone is worth playing anyway. Ten minutes against a shuffled deck of real and generated images recalibrates your confidence in a useful direction. The images you fail on were not failures of attention. They are the new baseline, and the baseline moves every month.
Related articles
Huawei's Ascend Chips Are Building an Alternative Road for AI Image Models
Image models are compute-hungry, and the hardware story just got a second road. What Huawei's Ascend push means for who can afford to build and run them.
Apple Now Wants to Train AI on Your Data, and Image Models Are in the Crosshairs
The privacy company now wants to train on your photos. Apple's reported reversal is a signal about where training data comes from next.
Grok's Image Generation Mess Is Rewriting the Rules for Everyone Else
Millions of non-consensual deepfakes, investigations on three continents, and a paid-subscription patch. What the Grok crisis settled about AI image responsibility.
Chinese AI Image Models Are Winning Fans Overseas, and Washington Is Watching
The adoption is technical first, political second. Developers download what works, and right now that is increasingly from Chinese labs.