For property managers

Move-out damage photos: what you can actually prove, and what you can't

A tenant moves out. Your maintenance tech walks the unit, photographs a scorched countertop and a door with a fist-sized hole, and you withhold $1,400 of a $1,800 deposit. Three weeks later the tenant's response arrives, and it is not the response you used to get. It is not "that was there when I moved in." It is:

"Those photos are AI. You generated them."

You know they are not. You cannot show that you know.

That sentence is now available to every tenant for free, it costs nothing to say, and in front of a small-claims judge or a state deposit arbitrator it does real work — because the judge also cannot tell. This is the part of AI-generated imagery that actually reaches property management, and it arrives from a direction most people do not expect. The threat is not mainly that tenants will fabricate damage. It is that your own honest documentation has quietly lost its authority.

The thing worth understanding: proving real is easier than proving fake

Every claim you read about AI image detection is some version of "upload a picture, get a percentage." Treat that as a warning sign. We tried to build one twice. The second attempt looked at eighteen ordinary photographs — a dog, a coffee cup, a plate of food — and called seventeen of them fake. It is switched off and it is staying off. Anyone selling you a confidence score on an arbitrary JPEG is selling you a number that will eventually humiliate you in a hearing.

But there is an asymmetry that does not get talked about, and it is the useful one:

A file made by a camera usually carries evidence that it was made by a camera. A file made by an image generator does not carry evidence that it was made by a camera.

When your tech photographs that countertop, the phone writes a block of data into the file alongside the pixels: make and model of the device, lens, exposure, the software that saved it. A Samsung Galaxy writes Samsung SM-F966U. A Sony body writes SONY ILCE-7M4. An image that came out of Midjourney or DALL-E has none of that, because there was no camera and no lens and no exposure time.

So the question to ask about your own evidence is not "can I prove this isn't AI." It is "does my photo still carry the marks of the camera that took it?" That question has a checkable answer.

Three things that destroy your evidence, all of which you are probably doing

Here is the part that matters operationally, because the marks are fragile and most property management workflows shred them without anyone noticing.

1. Your tech sends photos over WhatsApp, Messenger, or text. These strip metadata on upload, by design, as a privacy feature. The photo that lands in your inbox is a re-encoded copy with the camera information gone. It looks identical. It proves nothing.

2. Someone screenshots instead of saving. A screenshot is a new image of an old image. Everything underneath is gone. This is the single most common way good evidence becomes useless, and it usually happens because screenshotting is faster than finding the download button.

3. Photos are pulled back out of a portal, a PDF, or an email thread. Many systems re-compress on upload or on export. The copy in your case file may not be the copy your tech took.

None of these are exotic. They are the normal path a photo takes through a normal property management office, and each one converts a defensible record into an assertion.

What to change on Monday, at zero cost

That last one is the whole discipline. Evidence is only worth collecting if you find out it survived while you can still do something about it.

Where a verification tool fits, stated precisely

We build one — impostershield.com/verify — and the honest description of what it does is narrower than what you will be promised elsewhere:

It reads what is in the file. Camera make and model, editing software, and Content Credentials (the C2PA standard, which OpenAI, Adobe and Google now attach to generated images). If the file says it came from a Sony ILCE-7M4, it tells you. If the file carries a credential naming an AI tool as its generator, it tells you that too, and quotes the tool by name. It runs entirely in your browser — the files do not upload anywhere.

It says "can't verify" and means it. When a file has been stripped — the WhatsApp case, the screenshot case — there is nothing to read, and the answer is that we could not tell. Not a percentage. Not a lean. The absence of evidence is not evidence that a photo is real, and it is not evidence that a photo is fake. Any tool that turns silence into a number is guessing and hiding it.

Two more limits worth stating plainly, because you will find them yourself otherwise: camera metadata can be edited by someone who knows how, so it is strong corroboration and not a signature. And while we read Content Credentials and report what they say, we do not currently perform full cryptographic validation of their signature chain — so treat a credential as a strong labelled claim, not as a court-grade seal.

The paid tier produces a dated report at a fixed URL listing each file's SHA-256 hash. That hash is a fingerprint: it lets an arbitrator confirm that the file in their hands is byte-for-byte the file your report describes, unchanged since the day the report was filed. It does not prove the photograph is real — nothing does — and we will not write a sentence that implies otherwise.

The realistic version of this

Nobody is going to hand you certainty. What is actually available is this: if you collect photos in a way that preserves what the camera wrote, and you check that it survived on the day you take them, then when a tenant says "those are AI" you can answer with the make and model of the phone that took them, on a dated record with a hash anyone can verify.

That is not proof. It is a considerably better position than the one you are in now, which is your word against a sentence that costs nothing to say.


ImposterShield reads the evidence inside image and video files. It runs in your browser and uploads nothing. If a file has been stripped, it says so — that is the product working, not failing.

Check a photo right now

Take a picture of whatever is in front of you, drop it on the page, and see what your own camera writes into a file. Free, and nothing is uploaded.

Open the checker