
In the first week of August 2026 a New York software company announced that its platform had found something in a painting attributed to Caravaggio. Not a hidden figure, not a lost inscription — a restoration. Somebody, at some point, had worked on the picture, and no document said so. The system noticed because the brushwork in that passage did not behave like the brushwork around it.
That is a genuinely useful thing for a machine to do, and it is worth being precise about why. It is not the same as the thing the machine is usually asked to do, which is to say yes, this is a Caravaggio or no, it isn't. Those two tasks look identical from outside the laboratory. They are not, and the gap between them is where the entire argument about AI art authentication lives.
The senator who catalogued ears
The idea that you could identify a painter by his least important details is not a Silicon Valley idea. It belongs to Giovanni Morelli (1816–91), an Italian politician who had trained in medicine and comparative anatomy in Munich, and who spent the 1870s publishing in the Zeitschrift für bildende Kunst under the name Ivan Lermolieff — a loose anagram of his own surname, dressed up as a Russian.
The disguise was theatre. The method was serious. Morelli argued that a painter's real signature is not the signature. It is the fingernails. The earlobes. The fold of a knuckle — the passages an artist executes on autopilot, from habit, because no one is looking at them. Faces are composed. Drapery is designed. An ear is just an ear, and so an ear is honest. He printed plates of ears the way a naturalist prints beetles, and used them to pull Lorenzo di Credi apart from Leonardo.
Morelli's insight was that forgers copy the parts people look at. His method went straight to the parts nobody looks at.
Berenson built a career on it. Carlo Ginzburg later placed Morelli in the same intellectual family as Freud and Sherlock Holmes: three nineteenth-century readers of the involuntary trace, all convinced that the small unguarded detail gives away more than the deliberate statement. It is, in every respect that matters, a feature-extraction algorithm — written a century before anyone had a machine to run it on.
So when a convolutional neural network is trained to recognise an artist by micro-patterns of brushwork rather than by subject or composition, it is not inventing a new epistemology. It is Morelli, automated, at a resolution he could not have reached with a magnifying glass and a good memory.
What the machines have actually said
The best-known operator is Art Recognition, founded in 2019 in Adliswil near Zurich by Dr Carina Popovici and Christiane Hoppe-Oehl. Its models need roughly 700 training images of an artist's secure work and about three days of computation. The output is a probability.
Those probabilities have not been quiet. In 2021 the company compared the National Gallery's Samson and Delilah against 148 uncontested Rubens paintings and reported a 91 per cent probability that it was not by Rubens. The picture had been doubted since the 1960s, when it emerged that a previous certifier of Rubens attributions had issued certificates for cash. The National Gallery's response was flat: not one single Rubens specialist doubts the attribution.
Then Caravaggio. As Bendor Grosvenor reported, the same technology assessed a version of the Lute Player owned by the art historian Clovis Whitfield — sold at auction in 2001 as "Circle of Caravaggio" — and returned a figure of 85.7 per cent by the artist himself. Keith Christiansen, then head of European paintings at the Metropolitan Museum, had written to Whitfield in 2007 that "no one — certainly no modern scholar — has ever or ever would entertain the idea that your painting could be painted by Caravaggio."
Set aside who is right. Look at the decimal place. 85.7 per cent. That single digit after the point does an enormous amount of rhetorical work: it converts a model's confidence score into something that sounds measured, like a lab assay. It is not a measurement of how much of the canvas Caravaggio painted. It is a number describing how closely this object resembles the objects in a training folder.
The Raphael that broke the spell
The clearest evidence of the problem is a small round Madonna known as the de Brécy Tondo, because it is the one picture that two different AI systems have judged in opposite directions.
In 2023 a team at the University of Bradford, led by Hassan Ugail, ran facial recognition software over the Tondo and Raphael's Sistine Madonna. The Madonna faces came back 97 per cent similar, the children's faces 86 per cent. Headlines followed: AI discovers a lost Raphael.
Art Recognition then ran the same painting through its own system and concluded, at around 85 per cent probability, that Raphael did not paint it.
Both results can be correct, which is the uncomfortable part. Facial recognition asks whether two faces are the same face. A competent sixteenth-century copyist working from Raphael's cartoon would produce a 97 per cent facial match, because that is precisely what copying is. The question was never whether the face matched. It was whether the hand matched — and facial recognition, a tool built to unlock phones and scan borders, has no opinion about hands.
The forgeries you cannot train on
Underneath the disagreements sits a structural flaw that no amount of computation fixes.
To teach a model the difference between a real Rubens and a fake one, you need examples of both. Real Rubens paintings are available. Fakes good enough to matter are not — because a forgery that is catalogued as a forgery is one that somebody already caught. The ones that count, the ones a museum would want a machine to flag, are by definition sitting in collections under the master's name, unlabelled, quietly polluting the very training set that is supposed to detect them. Popovici has been open about this: the shortage of negative examples — works not by the artist but close to him in style — is the field's hardest problem, which is why methods for augmenting training sets with synthetic examples are in such demand.
So the model does not learn Rubens versus a skilled forger. It learns Rubens versus everything else in my folder. Ask it about a period copy, a workshop replica, a pupil's variant or a nineteenth-century pastiche and it will still produce a confident percentage, because producing a percentage is the only thing it can do.
There is a second, quieter distortion. These systems read a photograph, and a photograph of an old picture is a photograph of four centuries of varnish, retouching, relining and cleaning. When a machine reports anomalous brushwork, the honest first hypothesis is not "different artist" but "different restorer" — the thing that has actually changed the surface most. An aggressively cleaned picture may read as anomalous; one untouched since 1650 may read as pure. That is a condition signal wearing an attribution costume.
Why the August announcement is a different animal
Which brings us back to the Caravaggio in the news this month. The company involved, QuantumSpace — founded in Italy in 2019, now headquartered in New York with an office in Milan — is not primarily in the verdict business. Its archive covers some 68,000 paintings, from which it has generated roughly 3.5 billion data points, up to 60,000 from a single work, across more than fifty datasets: colour, surface physics, condition, provenance records, conservation reports. The whole thing is held as a knowledge graph rather than a classifier — a network of relationships you can interrogate, not a black box that votes.
What it found in the Caravaggio was an undocumented restoration. Note the shape of that claim. It is falsifiable: point a scanner at the passage and you will see whether there is later paint there or not. It does not require the machine to have an opinion about genius. It requires it to notice that one region of a surface is not behaving like the rest — and then hand the anomaly to a human who can go and look. The company's own framing is that it flags anomalies for experts rather than delivering judgements, and on the evidence so far that modesty is the most technically defensible position anyone in this field holds.
The market pressure behind all this is obvious: global fine-art sales run at roughly $60 billion a year, with annual forgery losses estimated as high as $1.6 billion — itself an estimate of an invisible quantity, to be read with the same suspicion as an 85.7. And the research is getting narrower and better for it. A deep-learning study of Rubens attribution posted in November 2025 reports high accuracy in separating the master's hand from his workshop's — a far more answerable question than authenticity.
Honest limits
Three cautions, in the spirit of the thing.
First, none of these results has settled a single disputed attribution. Samson and Delilah still hangs as a Rubens. The Lute Player is still contested. The de Brécy Tondo is still whatever it was before two machines argued about it. AI has changed the volume of the conversation, not its conclusions.
Second, my reading of Morelli as a proto-algorithm is an interpretation, and it can be pushed too far. Morelli was looking at objects in front of him with a trained anatomist's eye, in daylight, over decades; a network is looking at a JPEG. The continuity is in the logic, not in the practice.
Third, the percentages are not comparable across systems. Art Recognition's 85 per cent and Bradford's 97 per cent are different statistics answering different questions, and setting them beside each other — as every headline about the Tondo did — is a category error that the technology's own vocabulary invites.
What survives all of this is the older discipline. Attribution has always been an argument built from provenance documents, technical imaging, pigment dating, workshop practice and the accumulated experience of people who have stood in front of thousands of pictures. We have written before about how a documented chain of ownership decides a painting's fate, and about the rediscoveries that follow when that evidence is finally assembled — the Velázquez that spent decades under another name, the Rembrandt with a turban under its paint, the de Hooch with a soldier under two centuries of overpaint. In every case the machine, where one was involved, produced a lead. A person produced the finding. The same division is now being tested on far older objects, where ancient DNA was swabbed off painted cave walls in the hope of naming the artists — and where the laboratory was again careful to call its result a trace rather than an attribution.
Morelli understood the division perfectly. He looked at ears because ears are evidence. He never claimed the ear was the verdict.
Frequently asked questions
Can AI authenticate a painting on its own? No museum or major auction house currently treats an AI result as proof of authorship. The models return a probability derived from visual pattern analysis; they carry no provenance, no documents and no material evidence. In practice the output functions as one argument among several.
Why did two AI systems disagree about the de Brécy Tondo? Because they were built for different jobs. Bradford's facial recognition measured whether two faces match — 97 per cent for the Madonnas, 86 per cent for the children — which a good copyist working from the same cartoon would also achieve. Art Recognition's model looked for an artist's brushwork signature and concluded, at about 85 per cent, that Raphael was not the painter.
What does "85.7 per cent by Caravaggio" actually mean? It is a confidence score, not the share of the canvas painted by the artist. It describes how closely the picture's brushwork resembles the works in the training set, and it says nothing about workshop participation, later restoration, or how well a skilled forger could imitate the same features.