AI-assisted creation is not the same as fraud. A legitimate organization may use generative tools for drafting, translation, design, or accessibility, while a fully human-authored document can still contain false information. A responsible review separates the file’s observable signals from claims about origin, authenticity, and intent.

A signal can justify a follow-up. It cannot, by itself, establish how a document was created or why.

1. Define the question before examining the file

“Was AI involved?” is usually too broad to support a consequential decision. Write down the material question instead: whether a stated amount reconciles, whether the source can be verified, whether the file’s provenance supports the claimed workflow, or whether a specific inconsistency needs an explanation.

2. Prefer provenance over visual guessing

The C2PA Content Credentials specification defines signed manifests that can bind provenance assertions to an asset. A valid, trusted manifest can support claims about the signer and recorded history. The specification deliberately does not turn those assertions into a judgment that content is good, bad, accurate, or factual.

Interpret each provenance state proportionally

Provenance is strongest when it is preserved across the full workflow and validated against an appropriate trust model. It complements—not replaces—content review and source verification.

3. Record visible inconsistencies without calling them “AI tells”

Look for elements that fail to cohere with repeated structures in the same document. Examples include a logo whose geometry changes between pages, recurring fields with unexplained font or spacing shifts, broken table rules, clipped text, misaligned digits, or labels that conflict with nearby content. Record the exact page and region rather than a general impression.

Every visual anomaly needs a benign-explanation check. OCR, accessibility remediation, font substitution, template migration, scanning, compression, manual form completion, and ordinary editing can all create irregular output. Visual polish is not proof of human authorship, and a visual defect is not proof of AI generation.

4. Test text, layout, and math as one system

Generated prose can be fluent while the document fails at relationships that should remain stable. Compare definitions, dates, units, currencies, identifiers, headings, page references, and repeated terms. Then recompute the arithmetic rather than trusting printed totals.

Ocolta’s on-device Integrity Scan can capture supported file signals and document math without uploading the file. Its deterministic findings still require the same proportional interpretation described in the published methodology.

5. Treat metadata as context, not an origin label

Start with the original file when possible. Its binary signature, declared type, creator or producer fields, timestamps, revision structure, and embedded content may help reconstruct a workflow. But routine export, printing, scanning, combining pages, signing, or accessibility processing can rewrite or remove metadata.

A named AI tool can support a narrow observation about a recorded producer field; it does not prove which content the tool created. Clean or missing metadata likewise does not establish human authorship. Review the exact format and evidence available in Ocolta’s coverage matrix before drawing conclusions from a PDF, screenshot, scan, or image.

6. Assume unseen generators are an open generalization problem

Research on synthetic-image detection treats performance on previously unseen generators as a central challenge, not a solved property. The official CVPR proceedings for FakeInversion (CVPR 2024) and Community Forensics (CVPR 2025) each evaluate ways to improve cross-generator behavior. That research direction is itself a warning against treating one detector as a universal origin oracle.

Results for generated images also do not automatically transfer to mixed documents containing live text, vector objects, raster images, forms, templates, and later edits. New model families and ordinary document transformations can fall outside the data a system was evaluated on. Unless a tool publishes a relevant, reproducible test against the exact file type and deployment conditions, describe its output as an indicator—not a reliable origin determination.

7. Use model-assisted review to organize evidence, not decide the case

Ocolta AI Deep Review can separate fraud-risk indicators from AI-generation indicators and report locations, confidence, benign explanations, limitations, and next steps. It can also be incomplete, inaccurate, refused, or unable to determine. The feature is an opt-in upload through Ocolta and OpenRouter to a policy-eligible model endpoint, so review its consent disclosure before submitting an authorized file.

A model reviewing another model’s possible output is not independent source verification. Use it to structure questions for a human reviewer, then obtain stronger evidence through a known source channel.

8. Finish with a human and source-verification checklist

What a responsible conclusion sounds like

Prefer: “The document contains an unexplained layout inconsistency on page 2 and a total that does not reconcile. These observations do not establish origin or intent. Request an authorized source copy and clarification.”

Avoid: “This detector says the document is AI-generated” or “the person submitted a fraudulent document.” Those statements outrun what a file-only review can support.

Keep the conclusion narrower than the evidence

No supported AI-generation indicator is proof of human origin. An AI-generation indicator is not proof of false content. A source-verified fact should remain distinct from both.

Primary references