NewThe detectors that scored perfect collapsed the hardest under attack.
Back to publications
Fraud story

The refund photos that do not fray right.

A refund claim now arrives with a photo of damage that never happened. Named retailers are already catching AI-generated damage images, the tell is physical rather than pixel-level, and a labeling deadline that could have helped passed in August 2026.

Article · September 2026 · 5 minute read

Return fraud used to need a real damaged item. Now it needs a photo, and the photo can be generated or edited in seconds. Named retailers are already receiving refund claims backed by damage that never happened, and, convincing as the images are, the tell that catches them is not in the pixels.

The sheets that did not fray

Reviewing refund-claim photos of "torn" sheets, the bedding brand Boll and Branch noticed that the rip did not fray the way cotton actually does, and one of the images carried an AI watermark. Modern Retail names the bag brand Bogg as facing the same wave, and these are not anonymous complaints on a forum. They are named companies describing a specific, repeatable attack on their returns process.

A named category now

The fraud-prevention firm Forter reports that AI-generated damage claims are the fastest-growing form of return abuse, and a separate practitioner who catalogued 35 distinct return-fraud types lists "AI-generated damage photos" as its own established category, with concrete tells: reused or edited image hashes, EXIF anomalies, and claim text that reads identically across unrelated customers. Both are interested parties who sell detection, so weigh them as such. Even so, it is the named-retailer incidents above that make the category real rather than a sales pitch.

The tell is physical, not pixel-level

The Boll and Branch detail is the important one. Photorealistic as the image was, what gave it away was that the fabric did not behave like fabric: cotton frays a particular way, and the generated tear did not. That is the failure mode independent testing keeps finding, photorealism holding while material and structural behaviour does not. A generator can make a rip look sharp; it cannot reliably make it fray, cast the right shadow, or respect how the object is built.

This is why "does the image look real" is the wrong test. The question that catches these is where and how an image departs from physical plausibility, which is exactly what a whole-image "is it AI" classifier misses on a real photo with one edited region, and exactly the kind of localized edit insurers are already catching in claim photos. Scored on a clean benchmark, such a classifier can look near perfect; scored on what platforms actually deliver, it can collapse to near random.

The deadline already passed

There was a regulatory lever, and its date is behind us. Article 50 of the EU AI Act made transparency obligations applicable on 2 August 2026: AI-generated or manipulated imagery that could pass as authentic must carry a visible, embedded label, and the duty binds deployers as well as providers, with fines up to 15 million euros or 3 percent of global turnover. The practical catch is that the mark has to survive download and reshare. Alt text and metadata do not travel with an image once it is screenshotted into a claim. So the obligation exists, and the images arriving in refund claims still do not carry a usable label.

What it means for marketplaces

If your returns or listings process accepts a photo as evidence, the image is now an attack surface, and two things make it grow rather than self-correct. Sellers report that AI product photos have not hurt conversion, so there is no market deterrent, and platform enforcement against copied and synthetic listings is slow. That leaves measurement. The only honest answer to whether your checks catch an AI-edited damage photo is to run them against current tooling, at the scale and under the compression your real uploads carry.

Margen does not sell a detector or a returns product. We are an independent third party that red-teams these checks under adversarial, platform-realistic conditions and reports where they hold and where a fake gets through.