Features

Power your results with AI, data, and teamwork. All you need for web operations in one platform

User Support

Your go-to support page for troubleshooting and getting the most out of MONJI+

Blog
Jul 17, 2026
WebOps

“Was This Image Made with AI?” — How to Manage Image Provenance in Website Operations Before Clients Ask

“Was this image made with AI?”
“Where did this image come from?”
“Is it okay to use this on a client’s commercial website?”

Recently, we have started hearing these kinds of questions more often when publishing images on websites.

In the past, when choosing images, the main things we checked were how they looked and how they performed:
whether the image looked clean, displayed quickly, and stayed intact on mobile.

Those things are still important.

But as AI-generated images have become more common, the questions around images have started to change.

It is no longer only about how an image looks.
Teams also need to be able to explain:

  • Where did this image come from?
  • Who created it?
  • Was AI used?
  • Is it safe to use commercially?

Through our own work publishing both photos and AI-generated images on client websites, we have felt how difficult it can be to trace an image’s origin later.

This article is for website operations managers, directors, and production teams that publish photos and AI-generated images on client sites. We will explain why image provenance is becoming more important, and how to start recording it in a practical way.

Why This Problem Is Becoming More Common

Background 1: AI-Generated Images Have Expanded the Range of Visual Assets

With AI image generation, the ways teams prepare website visuals have expanded significantly.

You can buy stock photos.
You can shoot original photos.
You can receive assets from a client.
You can generate images with AI.

Having more options is a major advantage for production and operations teams.

But the more options there are, the more decisions and checks are required.

For example:

  • Is the license for the client-provided photo valid?
  • Has an image taken from the internet been mixed into the project by mistake?
  • Does the AI-generated image contain elements too close to someone else’s work or a real person?
  • Is this company truly allowed to use the image?
  • Can the image be edited or reused?

Until now, many teams have managed images using file names and folders.

However, file names and folders do not tell you who created the image, where it came from, whether AI was used, or whether it can be used commercially.

When a project is handed over to another person six months later, someone may ask:

“Where did this photo come from again?”

And the team may not be able to answer right away.

That small gap can gradually become a real operational issue.

Background 2: Content Credentials Are Making Image Provenance More Visible

One mechanism gaining attention in this context is Content Credentials.

Content Credentials is a way to record the provenance of an image.
It is based on the C2PA industry standard and works somewhat like an ingredient label for digital content, showing how an image was created or edited.

The information recorded may include:

  • Who created it and when
  • Which tool was used
  • Whether AI was used
  • What kind of edits were made

This information is embedded into the image data with a digital signature.
By checking it through a dedicated viewer, anyone can review the image’s provenance. If the data has been altered, that can also be detected.

As of 2026, Content Credentials are being embedded by default in images created with tools and services such as Adobe Firefly, OpenAI’s DALL-E 3 and Sora, Bing Image Creator, and photos taken with Google Pixel 10. Google has also started showing provenance information in Search and Chrome.

The important point here is how different this is from a traditional watermark.

A visible watermark burned into an image can be removed by cropping or recreating the image.
Content Credentials, on the other hand, are designed to carry provenance as part of the image data.

In other words, we are moving from an era of judging whether an image “looks AI-generated” to an era of checking whether provenance is recorded in the data.

Steps to Start Managing Image Provenance

STEP 1: Make the Current Situation Visible

The first step is to make visible which images are currently being used on your websites.

You do not need to start by managing the provenance of every single image perfectly.
A more realistic approach is to begin with key images used on client sites or your own site.

For example, start with:

  • Main visuals on top pages
  • Key visuals on service pages
  • Images used in ads or landing pages
  • Images that include people
  • Images that may have been generated with AI
  • Images provided by clients

The information you record should not be too complicated.

Start with fields such as:

  • Image usage
  • Source
  • Creator or provider
  • Whether AI was used
  • Whether commercial use is allowed
  • Whether editing is allowed
  • Whether credit attribution is required

At this stage, the important thing is to identify images where the details are unclear.

If you cannot immediately tell where an image came from, that image needs to be checked.
Simply making unclear assets visible in a list can reduce a lot of operational uncertainty.

With MONJI+, website operation rules and confirmation histories can be stored in one place. This makes it easier for teams to share rules and notes about image usage, even when the person in charge changes.
Learn more about MONJI+

STEP 2: Record and List Image Information as Part of Monthly Operations

Next, avoid treating image provenance checks as a one-time audit.
Instead, make them part of your regular monthly website operations.

Even if Content Credentials are embedded in the image itself, it is risky to rely on them completely.

That is because provenance data can disappear.

For example:

  • Metadata may be removed when an image is converted, compressed, or saved again
  • Provenance data may be stripped when uploading to social media or external tools
  • Many images still do not support Content Credentials
  • It is also possible to intentionally remove provenance metadata

This means that an image is not automatically safe just because it has provenance data.
At the same time, an image is not automatically suspicious just because it does not have provenance data.

Provenance embedded in an image should be treated as one useful clue.

On top of that, it is important to keep a record outside the image itself.

For example, you can keep a simple note together with the image:

  • This main visual was generated with Firefly. The person shown does not exist.
  • This photo is a purchased stock asset. Commercial use is allowed. No credit required.
  • This logo was provided by the client. Whether it can be edited needs confirmation.
  • This background was photographed in-house. Usage is limited to this project.

Even notes at this level can make a major difference when someone asks about the image later.

Instead of asking only whether the image itself contains provenance data, it is better to ask:

“Can our team explain how this image is being used?”

That standard is much easier to apply in real operations.

STEP 3: Turn Several Months of Records into Operational Rules

Image provenance management does not have to start with detailed rules.

In fact, if the rules are too complicated from the beginning, they may not last.

A more realistic approach is to first record what kinds of images your team actually handles over several months.
Then, turn repeated patterns into operational rules.

For example:

  • When using AI-generated images, record the tool used and the purpose of generation
  • When using images that look like people, confirm that they do not depict real individuals
  • For client-provided images, record the provider and permitted usage scope
  • For purchased assets, record whether commercial use is allowed and whether credit is required
  • Do not use images with unknown sources on new pages

These rules should be placed somewhere that everyone on the production or operations team can access.

New team members and people asked to replace images should be able to check that place first.
This helps prevent image confirmation work from becoming dependent on a single person’s memory.

Using a website operations platform like MONJI+ makes it easier to store asset handling rules and confirmation histories together with other website operations information. The key is not to treat image management as a separate task, but to include it naturally within website operations.

What Changed in Practice

After we started recording image provenance, the biggest change was the speed of decision-making around images.

Previously, when someone asked about an image, we had to trace:

  • Who originally had the file
  • Which folder it was stored in
  • Whether a previous person in charge knew the answer

But when the source and usage conditions are recorded together with the image, the starting point for confirmation becomes clear.

We can answer:

“This image was AI-generated.”
“This photo is a purchased stock asset.”
“This logo was provided by the client.”
“This background was photographed in-house.”

Being able to say this makes communication with clients much smoother.

We also came to believe that AI-generated images do not necessarily need to be hidden.

It may not always be necessary to state on the website that an image was AI-generated.
However, within the team and between the team and the client, it is better to be clear about which images were made with AI.

That alone reduces anxiety when someone unexpectedly asks later:

“Was this made with AI?”

Rather than hiding it, it is stronger to be able to answer openly.

That, we believe, leads to trust when using AI-generated images.

Notes and Limitations

Image provenance management is not a perfect form of proof.

Even when an image has Content Credentials, metadata can be lost during conversion or compression.
Many images still do not support the system.
It is also possible to intentionally remove only the provenance data.

So, the existence of provenance data does not mean everything can be trusted unconditionally.

At the same time, it is not realistic to say that every image without provenance data is unusable.
Many client-provided images, older in-house photos, and long-used assets may not have provenance information embedded in the image file.

The important thing is to treat provenance not as complete proof, but as one piece of information for judgment.

Then, keep records outside the image as well.
Record the source, usage conditions, whether AI was used, and whether editing is allowed in a place the team can check.

This two-layer approach will become increasingly important for website operations.

MONJI+: A Website Operations Platform Built from Real Production Work

Images and text can now be prepared quickly with AI.
That has already become normal.

Precisely because of that, what matters more is being able to keep track of:

“Where did this image come from?”
“What is the basis for publishing it?”

MONJI+ is a website operations platform that helps teams centralize website operation rules, asset handling, and confirmation histories.

In an era where content can be created quickly, keeping a record of where things came from quietly supports the trustworthiness of a website.

▼About MONJI+
https://monji.tech/plus/

▼Start for free
You can try all features with a 30-day free trial. A free plan is also available.
https://monji.tech/plus/trial/

▼We welcome your feedback
https://monji.tech/plus/co-creation/

Conclusion

As AI-generated images become more common, website images are no longer judged only by how they look.
Teams also need to be able to explain where those images came from.

Content Credentials are an important clue for checking image provenance.
However, they may disappear during conversion, compression, or uploading, so it is risky to rely on them completely.

That is why website operations teams should also keep records outside the image itself.

Which images were generated with AI?
Where did each image come from?
Can it be used commercially?
Can it be edited?

If this information is stored somewhere the team can see, you can respond calmly even when a project is handed over or a client asks questions later.

We do not record provenance in order to avoid AI-generated images.
We record it so that we can use them with confidence.

That is the kind of preparation website operations will increasingly need.

check the list.