Before AI images reach clients, audit your media library

Illustrated infographic summarizing: AI images need a media-library audit before they reach clients

By Greg Nowak. Updated 26 August 2026.

An AI image can leave the generator with useful provenance signals and reach a client without them. Between those two points, a CMS may resize it, an optimization service may convert it to WebP or AVIF, a CDN may recompress it, and an editor may download a derivative instead of the original.

This is an operations problem disguised as image metadata. If your agency or marketing team uses AI-generated visuals, you need to know which file was approved, what evidence accompanied it, and what the recipient actually received. A short audit of the real media path is more useful than a policy that simply says provenance should be preserved.

One upload can become many different files

WordPress creates image sub-sizes after upload. Drupal image styles can crop, scale, rotate, desaturate, or otherwise transform an original. Themes, plugins, DAM integrations, and CDNs may introduce further renditions. The image displayed on a landing page may therefore be several processing steps removed from the uploaded asset.

Those steps matter because provenance is not a single universal label. C2PA Content Credentials use cryptographically signed manifests to communicate an asset's origin and history. SynthID embeds an imperceptible watermark in the media itself. Metadata may provide richer context, while a watermark may remain detectable through some transformations that remove metadata.

OpenAI now says supported images generated through ChatGPT, Codex, and its API include both C2PA metadata and SynthID watermarks. That layered approach is important: losing one signal does not necessarily mean losing every signal. Equally, finding no supported signal does not prove that an image was made without AI. Older assets, unsupported providers, extensive edits, and stripped metadata can all produce an inconclusive result.

What should a media-library audit prove?

The audit should answer a practical question: can your team trace a client-facing image back to its approved source and explain what happened along the way?

Choose a small but representative test set. Include files from the generators your team actually uses, images edited in your normal creative software, and the formats commonly delivered to clients. Run each file through the production workflow rather than a clean demonstration environment.

  1. Save the untouched source file and record its provider, creation date, format, and verification result.
  2. Upload it through the same CMS interface editors use.
  3. Generate the crops, thumbnails, responsive sizes, and modern formats used by the site.
  4. Request the public page through the CDN and download the image a visitor would receive.
  5. Test the source, stored original, important derivatives, and downloaded public file with the relevant verification tools.
  6. Repeat any normal manual handoff, such as copying the image into a presentation or re-uploading it to a campaign platform.
A compact audit matrix for each representative image
Checkpoint File to test Evidence to record Operational decision
Generation Untouched download Provider, format, C2PA result, and watermark result Define an acceptable source record
CMS ingest Stored original Hash or file comparison and verification result Confirm whether the original is preserved
CMS rendition Key thumbnail, crop, and responsive size Dimensions, format, and signals retained or lost Approve, reconfigure, or document the transformation
Public delivery File downloaded from the CDN URL Headers, final format, and verification result Confirm what visitors and clients actually receive
Client handoff Final presentation or asset-package file Source reference, approval status, and disclosure note Make one version authoritative

Test evidence, not just visual similarity

Two images can look identical while carrying different evidence. Record results per file rather than writing “the image passed.” Name the exact rendition, URL, file format, test method, date, and outcome. Keep screenshots or exported verification reports where approval or contractual requirements justify them.

Use the verifier associated with the signal you expect. A C2PA-aware verifier can inspect supported Content Credentials. Google says Gemini can check images for SynthID, while OpenAI provides a verification service for provenance signals associated with supported OpenAI-generated media. Provider-specific tools are not general truth detectors: they answer narrower questions about supported signals and origins.

Provenance also does not establish factual accuracy, copyright ownership, consent, or permission to use a person's likeness. Those require separate editorial and legal checks. Treat provenance as evidence about origin and processing—not as an automatic approval stamp.

What if the CMS removes a signal?

Removing or changing a signal is not automatically a failed workflow. Performance, compatibility, privacy, or design requirements may justify transformations. The failure is allowing that change to happen without an explicit decision or replacement control.

A sensible operating model is to retain an untouched original, publish optimized derivatives, and connect both to the same editorial record. That record can hold the provider, prompt or job reference where appropriate, human approver, permitted uses, disclosure decision, and final client-delivery file. Editors should also know that downloading an image from the front end may not retrieve the approved original.

For higher-risk campaigns, add a release checkpoint: the project manager verifies the exact delivery files after all exports and transformations. For routine web illustrations, a documented source record and tested CMS configuration may be proportionate. The control should match the commercial and reputational risk.

Turn the audit into a usable workflow

The useful deliverable is not a long technical report. It is a map of the publication path, a short record of tested transformations, and clear instructions for designers, editors, project managers, and client-facing staff. It should identify where originals live, which services alter files, which renditions are approved for handoff, and who decides when disclosure is required.

If your team cannot yet answer those questions, test the path before the next client delivery. Greg can help map a WordPress or Drupal media workflow, inspect the important transformations, and turn the findings into practical editorial controls. Start a conversation about your media-library audit.

Related on GrN.dk

Need help with this kind of work?

Talk to Greg about your media workflow Get in touch with Greg.

Sources

Seneste artikler

Få en ugentlig marketingrapport fra GA4 og Google Ads med kontrollerede beregninger, tydelige dataforbehold og et kort AI-udkast, der hjælper jer på mandagsmødet.

Brug AI til webshoppens alt-tekster med en overskuelig pilot: kortlæg billederne, få danske forslag, og kontrollér resultatet i WordPress og WooCommerce.

AI-baseret ticketanalyse kan afsløre gentagne klager, produktfejl og huller i dokumentationen – uden at virksomheden behøver endnu en chatbot.

OpenSSH 10 fjerner DSA og advarer om nøgleudveksling, der ikke er post-kvantesikker. Her får du en metode til at afgrænse SFTP-oprydningen uden at svække alle SSH-forbindelser.

Botforespørgsler overstiger nu menneskelig webtrafik. Lær at auditere AI-crawlere, fastsætte regler på stiniveau, håndhæve robots.txt og måle det forretningsmæssige afkast.

Cloudflares Tunnel-opdateringer fra 2026 forbedrer kortlægning, overvågning af replikaer, logstreaming og overdragelse – men synliggør samtidig svagt ejerskab og mangelfuld praksis for failover og logging.

Sådan bruger du AI til mødenoter og opfølgning, mens faste regler beskytter CRM-data, kundematch og pipeline mod fejl og forhastede ændringer.

Drupal 10 når end of life den 9. december 2026. Brug denne praktiske kortlægning til at afgrænse arbejdet med Drupal 11-parathed, Composer-efterslæb, moduler og custom code.

Apache 2.4.67 tydeliggjorde risikoen ved overtagne reverse proxies. Læs, hvordan du opgraderer til 2.4.68, gennemgår HTTP/2, AJP og .htaccess og tester ændringerne sikkert.

WooCommerce-blokke er standarden, men ikke alle webshops er klar. Brug denne praktiske gennemgang, testplan og rollback-procedure til at beskytte omsætningen i checkout.