Studies / S6
Do AI-generated images on Wikimedia Commons carry provenance marks?
Abstract
Wikimedia Commons stores uploaded files byte for byte. It therefore shows which AI provenance marks reach a public archive when the host does not strip them. We enumerated every file Commons labels as AI-generated: the Category:AI-generated images tree (530 categories) and {{PD-algorithm}}, 8,971 files in total. We then inspected 2,084 originals from a month-stratified sample with ai-mark-lint, downloading, checking and deleting each one.
Two populations are reported. The main population is the category tree plus {{PD-algorithm}} files with AI evidence in their categories (1,585 measured files); some of these images are AI-modified rather than AI-generated. The union adds the other {{PD-algorithm}} files (2,084 measured).
Marks in the main population. The share of files with a machine-readable AI mark rose sharply in June 2026: from 25.8% of January–May uploads (n = 532) to 50.2% of June–July uploads (n = 313). That is +24.4 percentage points; a bootstrap that resamples upload days gives +14.7 to +33.6. August–September (n = 461) shows 43.4%, or 53.3% without one large unmarked batch of coats of arms.
Before and after 2 August. The comparison of January–July with August–September, when Art. 50(2) of the EU AI Act became applicable, gives +8.4 pp (day-cluster bootstrap +0.2 to +17). It depends on that batch: without it, the difference is +17.8 pp. Neither comparison can be attributed to the AI Act.
Kinds of mark. Almost every mark is a C2PA manifest, mostly from OpenAI and Google. The IPTC DigitalSourceType alone marks 1.5% of main files. A readable Chinese AIGC label appears on 1 file of the union, and 3 more files carry a double-encoded label.
Validation. We found a defect in our own validator: ai-mark-lint 0.1.0 rejected 302 of the 625 readable manifests (union), 187 of them because no extended-key-usage list was configured. The defect is fixed in 0.1.1. With the corrected rule, 117 manifests (18.7%) fail, for these reasons:
- certificates that have expired in manifests without a time-stamp (85);
- content changed after signing (32);
- C2PA first-action rule violations (26);
- Microsoft Paint manifests (12).
With the official C2PA Trust List, 452 of 624 manifests (72%) are valid and trusted.
Cite this study
EasyxLab (2026). Do AI-generated images on Wikimedia Commons carry provenance marks? Study S6. EasyByte Hub S. Coop. Mad. https://github.com/easybytehub/easyxlab/tree/main/studies/s6-commons-ai-marks@techreport{easyxlab_s6,
title = {Do AI-generated images on Wikimedia Commons carry provenance marks?},
author = {{EasyxLab}},
institution = {EasyByte Hub S. Coop. Mad.},
number = {S6},
year = {2026},
url = {https://github.com/easybytehub/easyxlab/tree/main/studies/s6-commons-ai-marks}
}