Can AI Forge a Signature? How to Tell a Real One

ChatGPT signed real cartoonists' names to drawings they never made. The signatures looked genuine.
A forged signature on a contract, showing how AI can forge a signature that looks real
October 9, 2026

TL;DR: Yes, AI can forge a signature. In October 2026 Nieman Lab showed that ChatGPT had put the signatures of more than 15 New Yorker cartoonists on cartoons they never drew. Looking at a signature is no longer enough to know whether it is genuine. What tells you is a check of who signed, when, and whether the document has changed since. TRUE Sign, TRUE Verify and TRUE Original are built on that check.

Can AI forge a signature?

Yes. A generative image model can draw a signature in the right corner at the right slant, and in October 2026 Nieman Lab found that ChatGPT had done so with the names of more than 15 New Yorker cartoonists. The artists had drawn none of the cartoons.

It began with Brendan Loper. In late August 2026 a cartoon of Dolly Parton and Tim Curry, dressed as Dr. Frank-N-Furter, arriving together at the pearly gates went viral, with BLOPER, Loper's signature, in the bottom right corner. A Parton fan had asked ChatGPT for "a New Yorker-style cartoon" and posted the result to Facebook, and one tweet of it collected 25,000 likes, Andrew Deck reported in Nieman Lab on 5 October 2026. Loper first heard about it in a text from his twin brother. Emails and messages from strangers followed, asking whether the cartoon was his.

He had not drawn it.

He was not alone. Nieman Lab documented more than 15 New Yorker cartoonists whose signatures ChatGPT had used, among them Harry Bliss, Emily Flake, Joe Dator, Pat Byrnes, Peter Vey, Jason Adam Katzenstein, George Booth, Liza Donnelly, Ellis Rosen and Saul Steinberg. Flake, a contributor since 2008, found her own pen name, "e. flake," on cartoons she never drew. "It's like somebody attributed a quote to me that I didn't say," she said. After Nieman Lab contacted OpenAI, ChatGPT began answering New Yorker-style prompts with "This prompt may violate our guardrails concerning similarity to third-party content," yet it still signed some of its generic cartoons with real cartoonists' names.

Why did a cartoonist call his signature a certificate of authenticity?

For Brendan Loper, the signature is the claim that a drawing is his. "The signature for me is the certificate of authenticity," he said, he told Nieman Lab, and he read the fake as an attack on himself: "It felt very much like a violation of my personhood."

"I'm not a territorial person, but my name is my name," he said. "If I put my name on it, it's official, it's mine. It really is a brand. It's the mark that I made."

That is how it was for a long time. A signature was your property and a mark of authenticity, on a cartoon as much as on a contract or a diploma. That held once. Today a prompt to an image model is enough to get a signature that looks exactly like the original.

Can you tell by looking whether a signature is real or forged?

Rarely with confidence. The classic tests look for traces of a human forger with a pen, and the California League of Independent Notaries, which lists them, still concedes that "it is not always easy to spot a forged signature." Its list includes unnatural pen lifts, retouched letters and the trick of turning the signature upside down, so the eye sees a drawing instead of reading a name.

A generated image has no pen to lift. In a 2016 experiment at University College London, a group asked which of several seemingly handwritten envelopes a computer had produced chose wrongly 40% of the time, Engadget reported.

Inspection is also a thin net in practice. Among the 1,921 occupational fraud cases in ACFE's Occupational Fraud 2024: A Report to the Nations, 6% were first detected by document examination and 43% by a tip.

The same goes for contracts and diplomas carrying a scanned signature. Looking at one, there is simply no way to know whether it is genuine. That takes new technology: proof recorded on a blockchain when the document is signed or issued, which anyone can check later.

Can an AI detector tell whether a signature is genuine?

A detector can say whether a picture looks machine-made. It cannot say who put the name there or whether that person approved it. Digital Trends noted that OpenAI's public image verification tool checks for signals from OpenAI's own products, and that a hit "can't confirm that the artist named on the cartoon made or approved it."

The advice in that article is to look for the cartoon in the artist's portfolio or the publication's archive before crediting anyone. That is a sound instinct: ask a record the named person controls, not the picture.

Is forging a signature a crime?

Yes. In Sweden, where TRUE Original is based, chapter 14, section 1 of the Swedish Criminal Code (brottsbalken) makes it document forgery, urkundsförfalskning, punishable by up to two years in prison when the act creates a risk in matters of evidence. The wording covers anyone who states another person's name "genom att skriva eller på liknande sätt ... eller på annat sätt", in other words by writing or in a similar way or in any other way, so it does not depend on the tool.

The same section counts an electronic document as a urkund when it was made as evidence and has an issuer designation "som kan kontrolleras på ett tillförlitligt sätt", one that can be checked reliably (our translation).

How common is signature and document forgery?

ACFE does not report forged signatures as a category of their own. Its nearest category is check and payment tampering, where a person steals funds by "intercepting, forging, or altering a check or electronic payment". It appeared in 217 of the 1,921 cases in the 2024 report (11%), with a median loss of $155,000.

What is the difference between looking at a signature and verifying it?

Looking compares a picture with a memory of how the signature ought to look. Verifying asks what a picture cannot answer: who identified themselves, when, and whether the document is the same as it was. Article 26 of eIDAS, Regulation (EU) No 910/2014, sets such requirements for an advanced electronic signature: it must be "uniquely linked to the signatory", "capable of identifying the signatory", and "linked to the data signed therewith in such a way that any subsequent change in the data is detectable."

Digg, the Swedish Agency for Digital Government, lists three things a recipient can check by machine on a signed document: that it has not changed since it was signed, who signed it, and that the signature comes from a trusted issuer with correct cryptographic checks. Digg adds that this evidence can weaken or lapse over time, so the recipient should validate the document on receipt and keep both the signature and the result.

A pasted image of a signature has none of these properties. Nothing links it to a person, nothing in it identifies anyone, and an edit to the page leaves no trace in the picture.

How can an organisation protect the names and signatures on its certificates and diplomas?

TRUE Original secures the signatures on certificates and diplomas with blockchain. The signature is part of the document, and the document's fingerprint is anchored on public blockchains, among them Ethereum and Polygon, when it is issued. Swap the signature or paste in a new one and the copy no longer matches, which anyone checking the document in TRUE Verify sees at once. TRUE Original has issued over 900,000 documents for 200+ issuers in 15+ countries.

A diploma carries a rector's name, a licence an inspector's, a contract two directors'. Each name is a picture until something checks it. A TRUE Original document can open on the issuer's own domain, so the reader also sees whose record it is. How AI-made fake certificates fail the same check is covered in Can AI make a fake certificate or diploma?

How does TRUE Sign protect a signature?

TRUE Sign has the signer identify with BankID or Freja ID, seals the finished document with proof that travels with the file, and anchors the document's fingerprint so it can be checked independently of TRUE. You upload a PDF, the counterparty opens a link and signs in the browser.

BankID is what Swedes already carry on their phone, and Freja ID also works for counterparties outside Sweden. The fingerprint is a cryptographic hash of the file: change one letter and the fingerprint changes. Anchored in an independent source, it lets anyone show later that exactly this file looked exactly like this at exactly that moment. More on the signing flow in What is an electronic signature? and at TRUE Sign.

How does TRUE Verify check a signed document?

TRUE Verify compares a document with the proof left behind when it was signed or issued, and returns a security level that reflects the proof it finds. You paste a certificate link, a document ID or a PDF, or scan a TRUE QR code. TRUE Verify is free and needs no account.

The levels run from Signed + Secured, a blockchain record plus an eIDAS signature, down to No Origin, where no proof is found. An edited copy looks the same to the eye and fails the check. For a step by step guide to checking a diploma or certificate, see How to check if a certificate is real.

Loper's cartoon had the right name in the right corner and nothing to check it against.

Sources

Talk to us to see what value TRUE would create for your organisation:

Every organisation we work with started with the same question. Give us thirty minutes and we will show you what your own documents would be worth.

Book a call

More insights

Not sure where to start? Let us help!

You have questions, we have answers. Fill out the form to speak to our experts.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Hand holding smartphone with glowing floating digital document overlay symbolizing mobile document verification against blurred background

Trusted by leading organisations worldwide