Section: Justice & law Author: V Reading time: ~27 min Sources and further reading: 22 items Topics: photography, evidence, criminal proceedings, EXIF, metadata, expert, optics SEO / Working Title: Is the photo proof? When an image can be deceiving even without editing
Is the photo proof? The question sounds simple until we notice that we are not comparing one thing. A picture can be unedited and still be deceiving from an angle. The hash can confirm the file and say nothing about the scene. EXIF can carry the date which is just the device clock. And photo recognition has legal safeguards that viral “I recognise the perpetrator” does not. The following text covers the illusion without pixel adjustments. Generative forgery is another contention.
1. Three people over one photo, three different conclusions
Let's imagine three people over one JPEG in a file. The prosecutor says: the file is unedited, so it shows what happened. The defender says: the crop is tight, the wide angle enlarges the foreground, and the camera clock is off by an hour. The expert says: the copy fits, the metadata is readable, but I do not comment on the guilt. The journalist writes on the network: "you see."
Everyone is a little right. But no one compares the same layer. The public prosecutor compares the admissibility of the evidence with the weight of the conclusion. The defender compares the geometry, frame and time with the label. The expert compares the integrity of the file and professional questions with a legal assessment that does not belong to him [3][6]. The journalist compares the impression of the scene with the evidentiary process.
At first glance, it is a dispute whether a photograph is evidence. In fact, it is a dispute as to which question the photograph should carry. Does it prove that the file exists? That he was unchanged after a certain point? That the person was there? That she was standing at a certain distance? That she did something on purpose? Each sentence needs a different support.
Therefore, they can all be partly right and the common verdict still wrong. Photography can be acceptable and weak. It can be unedited and misleading. It can have the right hash and the wrong label. It may have an EXIF time that does not correspond to the civil time of the event. So the first rule is not: believe or not believe the photo. It reads: write one sentence that the picture is supposed to prove.
2. An unedited photo has at least six layers
One image looks like one thing. She is not. It's a string of optics, frame selection, moment, metadata, compression and legal usage. If we mix these layers, a false certainty is created: the pixels are not modified, so the label is true; metadata contains coordinates, so we know who stood there; the copy has the same hash, so the scene happened.
Six layers of unedited photography:
- Optics and geometry. Focal length, wide angle distortion, telephoto compression, stand height and viewing direction. The distance and size in the picture are not meters.
- Frame selection. Cropping, frame boundaries, and what's left out of the field. A genuine fragment may attest to a different plot than the caption claims.
- Time. Trigger moment, device clock, time zone, GPS date and file system time. One date does not have to be the time of the act [8].
- Staging and choosing the moment. Posing, rearranging objects and the decisive moment without a before and after picture. SWGDE separates staging from pixel manipulation [10].
- File string. Original, export, JPEG compression, social network, downloaded copy and attachment in file. Each step can change something else [9][11].
- Procedural use. Item or document, inspection attachment, photo recognition, expert examination or investigative attempt [1][2][4][5].
This layering is not a word of mouth. Determines where the error occurred and who can review it. If the time isn't right, we don't deal with Photoshop right away. If the distance does not fit, we do not solve the EXIF right away. If someone recognises a person from a photograph, we do not only deal with the sharpness of the face, but also the process, the selection of comparison persons and whether someone has seen the person recognizing them beforehand [2][18].
Illustrative diagram: The same JPEG can confirm the bit-match of the copy in one layer, open the question of angle in the second, and serve only as a reference aid in the third. None of these sentences alone say what happened in the world.
3. The best proof is the one whose fallacy you will see in time
Authenticity is often sought in photography. This is reasonable but incomplete. Equally important is what kind of deception the image can produce, whether it can be recognised, how much it costs to repair it, and whether the conclusion can be reversed. A bad caption on an internal memo is a cheaper mistake than publicly labeling a person as a perpetrator. A misjudged viewing distance can change the entire meaning of a scene.
| A kind of failure | What does he look like? | How to test | What will limit the damage |
|---|---|---|---|
| Angle and perspective | The right frame enlarges the foreground, reduces the background, or distorts the distance | Survey sketch, scale, investigative attempt according to § 104c | Multiple locations, on-site measurements, expert [4][5][12] |
| Cutout and moment | There is no action before, after or outside the field | Original against cutout, series of images, source description | Do not rewrite the label for proof of action |
| Metadata as plot | DateTimeOriginal or GPS are read as certain time and place of crime | Compare OffsetTime, GPSDateStamp, device clock and file string | Take EXIF as a hypothesis, not as a judgment [8][10][13] |
| Production | The scene was physically edited before exposure | Comparison with the scene, additional footage, witnesses, expert | Separate staging from pixel manipulation [10][14] |
| Compression and string | An 8×8 artifact or missing EXIF is read as a hit or clean | The original from the camera against the copy from the network | Keep the original file and describe the path [9][11] |
A photograph's ability to show something is one axis. The second is the observability of the fallacy, the third is the reversibility of the conclusion, and the fourth is the impact. For low damage, careful wording may be sufficient. When it comes to guilt, identity, or reputational interference, the question needs to be slowed down and compartmentalized.
The hash validates the file. They won't verify the scene.
— Jiný Kontext
4. Evidence is not a verdict
The Criminal Code in Section 89, odst. 2, works with an open list: anything that can contribute to clarifying the matter can serve as evidence [1]. This sentence opens the door to photography. It doesn't say how much weight a particular photo has. It doesn't say that one JPEG is enough. Nor does it say that the court should accept the caption that the picture came with.
This is where admissibility gets confused with persuasiveness. A photograph can be a means of evidence as it can contribute to clarification. It does not follow that she clarified herself. It can show the location of a thing, the state of a place, a person's face, damage to an object, or the order of events. However, each of these conclusions must be read in the context of the other evidence and the question the photograph is intended to answer.
The Charter of Fundamental Rights and Freedoms holds the framework of a fair trial [7]. It is not a slogan that will automatically win one side. It is a reminder that evidence is evaluated in a trial where the other side can object, the expert can explain the limits, and the court must not mistake impression for reasoning.
So the correct sentence is not: the photograph is or is not evidence. It reads: a photograph is a possible means of evidence and its weight depends on what we infer from it, how it was created, how it was preserved and how it fits into other findings.
This phrase is important outside of the courtroom as well. Public debate often jumps from admissibility to judgment in one motion. "It's on file" translates to "it's true." "It's in the photo" translates to "nothing to talk about". But the file may also contain weak evidence that has yet to be evaluated. And a photograph can be the proper beginning of proof, not its end.
A free evaluation of the evidence is not a free narrative. It means that each resource is read according to its content, origin, context and relation to other evidence. An image without scale can be strong for car color and weak for distance. A snapshot with the exact time in the metadata can be strong for the file string and weak for the time of the act if we don't know the device clock. This unevenness is the reason why a photograph should not carry more sentences than it can actually carry.
5. Hash validates the file. They won't verify the scene
A hash is useful because it holds a very narrow query. If we have the original file and a copy of it, the hash can show if they are bitwise identical. In forensic work, this is an important foundation of integrity. However, this is not proof that the scene took place in the world as the caption claims.
SWGDE in the document Best Practices for Image Authentication version 2,0 of 20 November 2024 differentiates file integrity, image authentication, and content analysis [10]. The integrity of the copy is the question of whether specific data has not been changed. Image authentication examines whether the image shows signs of tampering or virtual origin. Content analysis asks what the image captures. That's three different jobs.
The same distinction helps to see C2PA and Content Credentials. They can carry claims about the origin and modifications of the file. They are not proof of the truth of the scene. This technology belongs in a broader sense to the origin of the file, not to the verdict on the plot [22]. This is an important contrast for the generative image, but the point of this text is narrower: even the right set can carry the wrong conclusion.
So when someone says "hash sits", we hear a valuable sentence. But we must not translate it into "it happened that way". The correct translation is: this copy corresponds to this file. Only then do we ask whether the file was created from the given scene, whether the label fits and whether the image can carry a legal conclusion.
The file string therefore needs to be described plainly. Who had the original? When was the copy made? Has it gone through an application that changes resolution or metadata? Is the file an original file, an export, a screenshot, or a version downloaded from the network? Each answer changes only a certain part of the certainty. A screenshot can be faithful to what someone saw on the display. However, it is not the same as a camera file.
This is where the difference between technical purity and evidentiary value comes into play. Forensic work can tell very accurately that a particular copy has not been altered after being secured. That's a solid step. But it must not be used as a shortcut to a conclusion about the origin of the whole event. Integrity is the floor, not the ceiling.
6. Cutout is a selection. It's not the whole plot
Cropping does not require any pixel truth manipulation. Just move the frame limit. A real fragment will remain, but it may show a different story than the whole. A hand in mid-motion can look like an attack. An out-of-frame group can explain why a person backs off. The thing on the table may be important just because there is a scale next to it that the cutout removed.
Another Context's published text on true footage and false inference addresses a similar problem with video: the true clip can be deceiving when cut out of wider context [21]. This is not a repeat of this article. This is a still image. With photography, the cutout is even harder because we often don't see a second before and after. We only see the border that someone has chosen.
So pixel non-adjustment is not completeness. If a photograph is to prove the presence of an object, a cutout may be sufficient. If it is to prove an attack, intent or sequence of events, one frame may be too narrow. The crucial question is: what is left out of the picture and could change the meaning of what is left inside.
This is not a call to distrust every slide. It's a challenge to precision. A photograph can be strong evidence of door damage. Weaker evidence of motive. And very weak evidence of what happened two seconds before the exposure.
7. Angle and focal point are not a meter
Opticians have no morals. A wide angle close-up enlarges the foreground and expands the space. A telephoto lens flattens the distance and zooms in on the background. An eye-level camera creates a different relationship between characters than a low-to-the-ground camera. None of this is a scam. It is the way the lens converts space into a plane.
Therefore, it is dangerous to measure distance, crowd size, or hand position from just one image without a scale. Hany Farid, in his work on photo forensics, describes that image geometry can help, but needs support in the camera model, scene and other data [12]. One photo can open a question. She doesn't have to close it herself.
The criminal code knows the search and the investigative attempt. The photo during inspection, along with sketches and aids, should help to get a complete and faithful image of the object of inspection [4]. An investigation attempt according to § 104c can verify whether the event could have happened under certain conditions [5]. This is not photo editing. It is a way to check the angle, distance and sighting ability.
So the practical question is not whether the photo "looks clear." They are: do we know the focus, camera position, height, scale, distances and the possibility to repeat the shot under comparable conditions? Without it, the meter conclusion from the photo is more of an impression than evidence.
A simple illustration is enough. A person in the foreground of a wide-angle photograph can appear larger and closer than a person a step further away. Two people photographed with a telephoto lens can appear as if they are standing close together, even though there is a clear space between them. Both images may be genuine. Both can be deceiving if the meters are inferred from them without further ado.
Therefore, scale, sketch and the ability to return to the site are valuable in process use. Not because the photo is suspicious. Because the image area itself does not contain all the information about the space. Where it is only a matter of documentation of the damaged lock, a photograph may be sufficient. Where the distance of the hand from the object or the visibility of the person from a certain place is concerned, space must come back into play.
8. The camera clock is not the civil time of the act
EXIF can carry data about the file and how the image was taken. This is useful. It is not an independent event timestamp. The DateTimeOriginal field refers to the time on the device. If the camera clock was wrong, the reading will also be wrong. If the time zone is missing, the data may appear more accurate than it is.
CIPA lists the history of the Exif standard including version 2,32 from 2019 and the newer version 3,1 translated from 2026 [8]. These numbers measure the version of the spec, not the truth of a particular image. Newer metadata can work with time shift fields. Older files may not have them. And even with a new file, the metadata is a record of the device, not a witness with memory.
The difference between DateTime, DateTimeOriginal, GPSDateStamp, GPSTimeStamp and file system time can be confusing to the layman. But that's where the meaning often breaks down. The civil time of the act is a matter of event. EXIF time is a device issue. File system time can be incurred during copying. The GPS time may refer to a notation other than the user-visible date.
When these times diverge, this is not automatically evidence of fraud. It's a reason to ask the question. The correct sentence is: metadata supports the acquisition time hypothesis if we know the device clock, band, file origin, and copy path.
9. GPS in EXIF is not proof of who was behind the lens
GPS in EXIF looks solid because it has numbers and a map. Here, too, the sentence needs to be narrowed down. The GPS coordinates in the metadata can tell where the device was located according to its record. They do not say by themselves who held the device, who is in the picture, whether the coordinates were not affected by the environment and whether it was an original file.
GPS.gov lists a typical accuracy of 4.9 meters in open-sky radius for GPS-enabled smartphones; the page was modified on 3 March 2022, according to the file [13]. This number measures the horizontal accuracy of smartphones under good conditions. It does not measure accuracy inside a building, in a street between houses, under a bridge, or the veracity of an EXIF record. The same source also lists URE values of up to 2.0 meters for a signal in space and the FAA figure of up to 1.82 meters for high-quality airborne receivers for the period 1 October to 31 December 2020 [13]. These are not numbers for a regular phone photo.
Three metadata tests
The first test is time: does the DateTimeOriginal match the OffsetTime and possibly the GPS time? The second is the original: is it the original from the device, or a downloaded copy from the web that might have removed the EXIF? The third is meaningful: even if the coordinate fits, which sentence is it supposed to prove? The presence of a device is not the same as the presence of a specific person in front of the lens.
SWGDE specifically notes that metadata may be limited, missing, or altered [10]. Therefore, the absence of EXIF is not proof of purity or fraud. The presence of EXIF is not the truth of the scene. It is a trace to be read with other traces.
The map impression must be handled with particular care. The coordinates look like a pin stuck into reality. In fact, it is data written to a file at a certain time and by a certain device. If a photo is circulating as a copy, it may not be clear whether the metadata comes from the original, from the export, or from later processing. If it was taken in poorer reception conditions, the accuracy may deteriorate. If the question is the identity of the person, not even idealcoordinates do not solve it.
Practically, GPS helps mainly as a direction to verify. Shows the place to look for an inspection, witness or other record. It can support a conclusion if it fits with the environment, time, and other evidence. She is not supposed to take on the role of the person who explains who was holding the phone and why the picture was taken.
10. Staging is not Photoshop
Delusion can occur before the trigger. Someone rearranges objects, asks a person to repeat a gesture, moves a sign, removes a scale, or chooses a moment that turns the whole situation into a different story. The pixels can then be unmodified. But the scene is no longer a spontaneous recording of the action.
SWGDE refers to staging as the physical preparation of a scene prior to exposure and distinguishes it from digital image manipulation [10]. That is essential. Pixel hit detection may not tell you anything about the staging. Error Level Analysis or similar popular shortcuts can look for traces of file modifications. They won't say who moved the glass before the picture was taken.
News ethics has known this boundary for a long time. The NPPA Code prohibits the staging of news photographs and the alteration of events to be documented [14]. It is not a criminal norm for the Czech file. It's a useful analogy: a photojournalist can be deceptive with a true image if the scene was created for the shot.
It does not follow that every pose is a fraud. The wedding portrait is staged and no one is mistaking it for evidence of a fight. The problem begins where a staged or chosen moment is presented as spontaneous evidence of the plot. Then it is not enough to examine the pixels. The scene needs to be explored.
11. Compression changes the file even without intent to deceive
JPEG is useful precisely because it makes the file smaller. However, lossy compression is not neutral. The ITU-T T.81 / ISO/IEC 10918-1 standard works with baseline JPEG, among other things, with blocks of 8×8 samples [9]. This number measures the technical block of compression, not proof of modification. Edge artefacts, loss of detail or blockiness can arise from the normal file path.
A social network, messenger or editorial system can recalculate the image. May discard metadata. It can change the resolution. It can re-compress an already compressed file. Then when someone sees a strange artifact, they can't automatically Photoshop it. And when metadata is missing, it can't automatically make it evidence that someone was trying to hide something.
In its 2017 Image and Video Forensic Enhancement Manual, ENFSI addresses, among other things, how adjustments to brightness, contrast or gamma affect what the observer sees [11]. Highlighting can help read a detail. However, it does not in itself mean a conclusion of guilt. A laboratory-enhanced image is a work output that must describe the method and limit.
Therefore, the correct question is not whether the file "looks compressed". They are: do we have the original, do we know the path of the file and can we distinguish between normal compression and decisive change of content? Without it, a technical artifact becomes too fast a story.
This also applies to normal highlighting. Brightening a dark image can help you read a license plate or the outline of an object. At the same time, it can change the impression of contrast, shadow or color. If such output is used procedurally, it must be clear what was done and why. The highlighted image is not a new witness. It is a utility to be returned to the original and to the method.
12. Photo recognition is not an internet search
Recognizing a person from a photo is a sensitive matter. § 104b of the Criminal Code provides for reconnaissance and provides safeguards for reconnaissance based on a photograph. The recognised person should not be shown in isolation, but among at least three other photographs of persons who are not significantly different from him. The person carrying out the reconnaissance should be interviewed in advance about the circumstances under which he perceived the person. The law also deals with the ban on showing a recognised person in advance [2].
Three additional images are the procedural minimum in Czech criminal proceedings, not statistical certainty of correct identification. This number measures the construction of the act, not the probability of error. If the selection of people is wrong, if the witness has seen the photo on the Internet beforehand, or if the feed becomes informal "recognition", the procedural value decreases.
Before photo recognition
Is the person among at least three other similar images? Was the witness interviewed beforehand? Did he not see the person in question in the media, on a social network or in police material before the act? Isn't this a situation where the comments on the internet first created the name and then the photo only confirmed it?
In the case law for recognition in misdemeanor proceedings, the NSS works with the analogy of insurance policies according to the criminal code [18]. That's not an error rate number. It's a reminder that photo recognition is not a free vote of the audience. It is a procedural act with rules, because human certainty can appear solid even when it has arisen from bad choices.
13. An expert clarifies expertise. He does not assess guilt
An expert is needed precisely where the layman's view is not enough: image authenticity, metadata, compression, mountability, geometry, light, scale or file chain. The Criminal Code in § 105 to 107 works with an expert and expert opinion. However, experts are not competent to evaluate evidence or resolve legal issues [3]. The law on experts regulates their status and responsibility [6].
This is an important brake on both sides. When an expert says that he did not find signs of digital manipulation, this does not automatically mean that the act took place. When an expert says that the metadata is not reliable, it does not automatically mean that the photo is fake. The expert answers professional questions within the scope of the assignment. The court evaluates the evidence as a whole.
Viral culture does not like this boundary. He wants one authority to say "true" or "false." Forensic work is often less effective. It will say: the copy is the same, the EXIF is incomplete, the compression corresponds to the path through the platform, the geometry from one frame is not enough, it is impossible to comment on the staging without comparing it to the scene.
That is her strength. Expertise is not meant to replace a judge. It is to narrow the uncertainty, name the limits, and prevent the layman's impression of a straight line, shadow, or angle from carrying more than it can bear.
14. The review attachment is not viral proof
A photo in a review log has a different value than an image in a comment thread. The Criminal Code in Section 113 provides for the fact that photographs, sketches and other aids are attached to the search report, if this is necessary for a complete and accurate picture of the subject of the search [4]. The photo here is not a lonely image. It's part of the act.
The policing and forensic literature on digital traces emphasizes documentation, securing and evaluation in the process, not just the visual impression of a single copy [19]. At the scene of the crime, the sequence of images, scale, orientation, description, who took the image, when, with what and in what context can be important. Without it, the same image may lose some of its meaning.
The same JPEG therefore proves a different thing in a different context. As an attachment to the survey, it can help to visualize the place. As an isolated screenshot on the network, it can only show that someone has shared a fragment. As a downloaded copy without metadata, it can be a useful clue, but a weaker carrier of provenance.
It's not that internet photography is always worthless. The point is that the processing framework adds information that the image itself does not carry. When the frame is missing, the viewer must not paint it with certainty.
15. Generative forgery is another article. A right angle is sufficient here
With the advent of image models, it's tempting to turn every debate about photography into the question of whether it was created by AI. But this text stands elsewhere. The published article of Another Context about the fact that photography alone is no longer enough deals with synthetic images, C2PA, detectors, watermarks and legal labeling [20]. This is a case where the image was created by a camera and the pixels were not significantly changed.
This boundary is important. The deepfake detector will not verify that the unedited image correctly represents the distance. Content Credentials won't say that the viewport didn't miss the decision maker. Hash doesn't recognise that the scene was staged before exposure. Generative forgery is a difficult problem. But that's not the only way the image is deceiving.
This also changes the editorial and legal reflex. If a synthetic image is suspected, we ask about the origin, manifest, model and label. For a true but deceptive image, we ask about angle, time, frame, scene and process. Confusing these two questions means using the right tool on the wrong layer.
This does not mean that the generative image is not a risk. It follows that sometimes a much older problem is enough: the photographer stood close, the lens was wide, the surroundings remained out of the frame, and the viewer completed the story.
16. A one-sentence question can carry more than a viral JPEG
The practice test should be simple and safe. It does not teach how to edit EXIF, how to prepare a staging, or how to bypass recognition. It teaches to split the question.
What needs to be tested
First, write one sentence: what is the photograph supposed to prove? Identity of a person, presence of an object, distance, time, intention and order of events are different questions. One photo can carry the first and not carry the second.
Then you want the whole image, not just a slice. If there is a series of images, read it as a series, not as a single moment. For your own file, compare the metadata: DateTimeOriginal, OffsetTime, GPSDateStamp and GPSTimeStamp. Take them as a hypothesis and write down where the file comes from [8][10][15][16][17].
Then comes the geometry. If distance, size, or location are inferred from a photograph, look for scale, focus, habitat, and the ability to verify on the spot. When it comes to identity, don't confuse feed recognition with § 104b recognition [2]. As for the expert question, it belongs to experts and other evidence, not voting in the comments [3][6].
The test result should not read "true" or "false". It should read: the slide supports this narrow sentence, it does not support this other sentence, and the third one needs additional support.
This way of writing a conclusion is less attractive than a viral caption, but better protects the sense of the proof. "The photograph shows that the object was on the table" is a different sentence than "the photograph proves who put it there". "The metadata corresponds to the evening hours of the device" is a different sentence than "the act occurred at the given civil time". "The witness marked the person in the reconnaissance" is a different sentence than "the Internet recognised the person". When the sentences don't add up, a photo can be useful without taking away from itbecame the truth switch.
17. The question is not whether the photo is real. It sounds like it's allowed to flow from it
The most convenient answer would be: the unedited photo shows the truth. It would be short. And it would be dangerously wide. Photography is powerful precisely because it acts as a direct piece of the world. But between the world and the conclusion stand optics, frame, time, metadata, compression, scene and process.
The hidden cargo is not Photoshop. It is a conclusion that an unedited fragment cannot support. One sees the gesture and completes the intention. It sees the GPS coordinate and fills in the person. He sees three faces in the selection and adds confidence. He sees the block artifact and completes the hit. He sees the hash and completes the truth of the scene.
An unedited image can be deceiving in terms of angle, crop and time. Pixel purity is not the truth of the story.
— Jiný Kontext
So the question is not whether the photo is real. It reads: which one sentence is this picture supposed to prove — and which layer, optics, cut-out, time, production, ensemble or process does not bear that conclusion.
Related texts in this series
- On the website: Photos alone are no longer enough — generative falsehood. True record, false conclusion — context cropping for the right video. This text is a hoax without modification.
- Deepfake: How to spot a fake video or photo?
- What to do if someone misuses your photo…
