VerifiedReturn
Blog Sign in Start free
Shopify For Shopify merchants

AI-generated damage photos are breaking photo-proof returns

A customer can now generate a cracked screen, a torn seam, or a dented parcel in under a minute. If your returns policy still accepts “please attach a photo,” you are collecting the easiest kind of evidence to fake.

The shift

The cost of a fraudulent claim just went to near zero.

Photo-proof used to raise the effort. A claimant had to stage damage, find lighting, and send something that at least looked like the item they bought. Generative image tools removed that work. The picture no longer has to have existed in the world.

Plausible in seconds

A prompt plus a product shot is enough to invent a cracked display, a stained hem, or a crushed carton. Reverse image search will not find a copy, because there is no copy.

Gallery uploads are the weak point

Any form that says “choose a file” accepts a download, a screenshot, or a generated JPEG. You cannot tell whether the camera was pointed at the item five minutes ago.

Returnless refunds amplify it

If you refund on a photo and never see the item, the image is the claim. Weak evidence is not a paperwork problem. It is a cash problem.

What no longer holds

EXIF, reverse search, and provenance badges are not a policy.

EXIF is theatre

Camera metadata is stripped by messaging apps, browsers, and editors. It is also trivial to invent. A missing GPS tag is not evidence of fraud, and a present one is not evidence of honesty.

Reverse image search misses originals

Search finds reused stock and recycled refund photos. A freshly synthesised image has no index history. “No matches” is the expected result for both a genuine first-time photo and a generated one.

C2PA is almost never there

Content credentials can attest that a file came from a signing camera or editor. Consumer phones and chat apps do not attach them to the JPEGs that land in a returns inbox. Absence is the default, not a signal.

Human review does not scale

Agents can spot an obvious AI artefact. They cannot sit on every cracked-screen claim, and the artefacts are getting quieter. A process that depends on a sharp-eyed human is already behind.

What still holds

Provenance at the moment of collection, not inferred later.

You cannot reliably reconstruct whether a file is real after it has left the device. You can collect it in conditions you control: live, in the browser, from the customer’s phone, while they move around the item.

01

Live capture

The customer opens a short link and takes photos in the session. There is no “choose from gallery” path. The stills are taken now, on this device.

02

Device and motion

A short clip while they move around the item, plus signals that the session came from a real phone rather than a virtual camera or a scripted browser.

03

A hash and a trail

Every file gets a SHA-256, a timestamp, and an audit log. You are not arguing about an attachment that arrived in an email thread.

How VerifiedReturn does it

One store link. Media, signals, and a score.

Paste the link into a returns email, a helpdesk macro, or a Loop / ReturnGO step. The customer types the order number they already have. You are billed when they submit, not when they open the page.

Two scores, not one blended number

confidence_score asks whether this is a live capture from a real phone. object_score asks whether the subject is a physical object rather than a display. A phone pointed at a monitor can pass every device check and still fail the object checks. The decision is the worse of the two bands.

Pass, review, or fail — with the weights

You see the raw signals behind the number: virtual camera, automation, screen-recapture cues, motion during the clip. The score is decision support. You still decide the refund.

Screen recapture is its own problem

An AI image shown on a laptop and re-photographed is not a generated JPEG in a form field. It is a real camera pointed at a plane. VerifiedReturn treats that as a different failure mode from a live shot of the item.

API and webhooks if you already have an RMA

Create a session with external_reference and an optional return URL. We POST session.completed, failed, and expired with a signature header.

Policy

Write the collection method into the return, not a follow-up email.

Ask for live capture on damaged, defective, and “does not match description” reasons. A gallery upload is enough for a size exchange where you will see the item anyway. It is not enough for a returnless refund.

Tell the customer, in the request itself, that photos must be taken in the capture page. If you leave a gap — “email us a photo if you can” — the generated image will arrive in that gap.

Keep the score next to the media when an agent decides. A pass is not a determination of fact, and a fail is not a finding of fraud. It is a reason to look, or a reason to proceed.

Shopify Works alongside Shopify returns

Stop refunding damage you never saw.

Send one link. Your customer photographs the item live on their phone. You see the damage and whether the photo is real, before you approve the refund.