# imadethisup.org, full text export Complete prose of every substantive page on imadethisup.org, generated from the site source. Published by Global Cyber Institute, Inc. (501(c)(3), EIN 84-2148770). Licensed CC BY-NC 4.0, attribution and a link back to the source page are required. Inline citation markers have been removed for readability; the full reference list for each item is on its page. AI-use disclosure: https://imadethisup.org/ai-disclosure ======================================================================== # I made this up. So can anyone else. URL: https://imadethisup.org/ Summary: Independent reference on synthetic media, deepfakes, voice clones, generative imagery. Research, defense, and recovery from the Global Cyber Institute. ======================================================================== - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # Architecture as evidence. URL: https://imadethisup.org/research-lab Summary: A sourced reference on generative models, forensic detection methods, benchmark datasets, and the cross-generator generalization problem. ======================================================================== ## Research-lab FAQ. A Generative Adversarial Network is a pair of neural networks, a generator that produces candidate samples and a discriminator that judges them, trained against each other in a minimax game. Goodfellow et al. introduced the framework in 2014 (arXiv:1406.2661); it underpinned the first wave of high-fidelity face synthesis. A diffusion model that operates in the compressed latent space of a pretrained autoencoder rather than in pixel space. Introduced by Rombach et al. at CVPR 2022 (arXiv:2112.10752); this is the architecture behind Stable Diffusion and most modern open-weight image generators. Detectors trained on outputs from one generator overfit to that generator's specific spectral and structural artifacts. Applied to images from an unseen architecture, accuracy can drop sharply. This cross-generator generalization gap is the central open problem in synthetic-media forensics. Frank et al. (ICML 2020, arXiv:2003.08685) showed that GAN images carry severe artifacts in the frequency domain caused by upsampling operations common to all current GAN architectures. Spectral-residual analysis remains a strong baseline, though robustness to compression and to diffusion-family generators is an active question. Often barely. Groh et al. (PNAS 2022, doi:10.1073/pnas.2110013119) ran the largest study to date and found ordinary observers performed at roughly the level of leading detection models, with both making different kinds of mistakes. Crowds combined with model predictions outperformed either alone. It is a solution to a specific problem: identifying media produced by cooperating generators. It does not address adversarial uses of non-cooperating models, watermark removal attacks, or content that was never watermarked in the first place. Detection and provenance are complementary, not substitutes, see the Provenance guide. ## Where detection science meets practice - Why deepfake detectors fail on new generators The cross-generator generalization problem, in depth, the open problem this page names. - When the file lies about itself What happens when the file’s own metadata is fabricated rather than merely wrong. - Deepfakes and the integrity of evidence in family court Why authentication discipline, not better detection, is what actually holds up. - When the dispute is about AI: arbitration's new rules for AI discovery and evidence How arbitration rules now gate inspection of a model and its training data. - Detector results on deepfakes found in the wild Deepfake-Eval-2024 ran detectors against deepfakes circulating online; reported AUC fell 45 to 50 percent. - What a deepfake detector score does not tell you Why a detector’s benchmark score says little about generators released after it was trained. - When audio deepfake detectors fail on new voice generators The same generalization gap in audio, and what it means for citing a detection result in a report. - What the US AI Safety Institute says still needs research The US AI Safety Institute’s own list of what synthetic-content mitigation still cannot do. ## From research to defense. A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. - The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # When the call sounds like the CEO, but isn't. URL: https://imadethisup.org/war-room Summary: A reference on synthetic-media corporate threats: business email compromise, voice cloning, executive impersonation, and the protocol that stops them. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "alternateName": "Global Cyber Institute", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "Article", "headline": "The War Room, Deepfake fraud, BEC, and executive impersonation defense", "author": { "@type": "Organization", "name": "imadethisup.org Editorial" }, "description": "Practitioner's reference on synthetic-media corporate threats with a six-step authentication protocol.", "url": "https://imadethisup.org/war-room", "datePublished": "2026-04-27", "dateModified": "2026-08-30", "publisher": { "@id": "https://imadethisup.org/#org" }, "image": "https://imadethisup.org/assets/og/war-room.png", "mainEntityOfPage": "https://imadethisup.org/war-room", "about": [ { "@type": "Thing", "name": "Business email compromise", "sameAs": "https://en.wikipedia.org/wiki/Business_email_compromise" }, { "@type": "Thing", "name": "Speech synthesis", "sameAs": "https://en.wikipedia.org/wiki/Speech_synthesis" }, { "@type": "Thing", "name": "Mail and wire fraud", "sameAs": "https://en.wikipedia.org/wiki/Mail_and_wire_fraud" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "abstract": "Synthetic voice and video are now inexpensive enough for ordinary fraud crews, which makes business email compromise and executive impersonation a process problem rather than a detection problem. The control that defeats them is out-of-band callback verification on payment instructions above a set threshold, applied regardless of how convincing the request sounds.", "inLanguage": "en-US", "isAccessibleForFree": true }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "War Room", "item": "https://imadethisup.org/war-room" } ] }, { "@type": "HowTo", "name": "Six-step protocol to defeat synthetic-media authorization fraud", "description": "Operational controls for finance, executive, and security teams to defeat voice-clone and deepfake video fraud (BEC, executive impersonation).", "totalTime": "PT30M", "step": [ { "@type": "HowToStep", "position": 1, "name": "Out-of-band callback", "text": "Confirm all financial requests above an agreed threshold via a number stored in your corporate directory, never the number that initiated the request." }, { "@type": "HowToStep", "position": 2, "name": "Challenge phrase", "text": "Pre-shared, rotated quarterly, never spoken on camera or stored in shared documents. Synthetic systems cannot improvise." }, { "@type": "HowToStep", "position": 3, "name": "Liveness on video", "text": "Ask the caller to turn their head 90 degrees and obscure half the face with a hand. Many real-time face-swap pipelines fail visibly under sharp profile angles or partial occlusion." }, { "@type": "HowToStep", "position": 4, "name": "Provenance check", "text": "If the asset arrives with a Content Credentials (C2PA) manifest, verify it cryptographically at contentcredentials.org/verify. If not, treat it as unverified by default." }, { "@type": "HowToStep", "position": 5, "name": "Slow the wire", "text": "Build a 30-minute soft hold into payments above a defined threshold. Most synthetic-media frauds depend on momentum." }, { "@type": "HowToStep", "position": 6, "name": "Document and report", "text": "Log the call. Preserve audio, video, and message metadata. Report to the FBI Internet Crime Complaint Center (ic3.gov) within 24 hours." } ] }, { "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "How big is the BEC problem?", "acceptedAnswer": { "@type": "Answer", "text": "The FBI's IC3 2024 Annual Report counted 21,442 reported business email compromise incidents in 2024 with $2.77 billion in adjusted losses. Total cybercrime losses across all categories reached $16.6 billion, a 33% year-over-year increase." } }, { "@type": "Question", "name": "What was the Arup deepfake fraud?", "acceptedAnswer": { "@type": "Answer", "text": "In late January / early February 2024, an Arup Hong Kong finance employee was tricked into making 15 wire transfers totaling roughly USD 25 million after a video conference in which every other participant, including the supposed CFO, was an AI-generated deepfake. Arup confirmed the incident publicly in May 2024. CIO Rob Greig described it as 'technology-enhanced social engineering.'" } }, { "@type": "Question", "name": "What is the single best protection against voice-clone fraud?", "acceptedAnswer": { "@type": "Answer", "text": "An out-of-band callback to a number stored in your corporate directory, never the number that initiated the request. Combine with a 30-minute soft hold on payments above a defined threshold and a pre-shared challenge phrase rotated quarterly. The FBI IC3 Recovery Asset Team reports a 66% success rate freezing funds when reported quickly." } }, { "@type": "Question", "name": "Are AI-voiced robocalls illegal?", "acceptedAnswer": { "@type": "Answer", "text": "In the United States, yes. The FCC's February 8, 2024 Declaratory Ruling (FCC 24-17) confirmed that AI-generated voice calls fall within the Telephone Consumer Protection Act's restrictions on 'artificial or prerecorded voice' calls and require prior express consent. The ruling was effective immediately." } }, { "@type": "Question", "name": "Where do I report a synthetic-media fraud?", "acceptedAnswer": { "@type": "Answer", "text": "File with the FBI Internet Crime Complaint Center at ic3.gov within 24 hours, preserve audio and message logs, and notify your bank's fraud team to attempt a recall. The IC3 Recovery Asset Team can attempt to freeze fraudulent transfers if alerted promptly." } } ] } ] } Skip to content Research Lab War Room Safety Suite Provenance Tools References Case law Blog Retain → MENU Home / War Room 05 / 09, THE WAR ROOM When the call sounds like the CEO, but isn't. Synthetic voice and video are now within budget for ordinary fraud crews. The question is no longer if, but which protocol fires first. Below: the case data that should change your finance controls, a six-step authentication protocol, and the regulatory framework you can lean on after the fact. $2.77 B U.S. BEC losses reported to the FBI IC3, 2024, across 21,442 incidents. FBI IC3 2024 Annual Report $25 M Single-incident loss at Arup Hong Kong, January 2024, a deepfake video conference impersonating the CFO and colleagues. CNN, May 2024 66% Success rate of the FBI IC3 Recovery Asset Team in freezing fraudulent BEC transfers when reported promptly. FBI IC3, 2024 Annual Report In short Synthetic voice and video are now inexpensive enough for ordinary fraud crews, which makes business email compromise and executive impersonation a process problem rather than a detection problem. The control that defeats them is out-of-band callback verification on payment instructions above a set threshold, applied regardless of how convincing the request sounds. 01 · The case that changed corporate posture Arup Hong Kong, late January 2024, fifteen wires, twenty-five million dollars, four minutes per transfer. The finance employee in Arup's Hong Kong office initially received an email from an account claiming to be the firm's UK-based CFO, asking that several confidential transactions be deployed. The employee suspected phishing, the right instinct. He was reassured when he joined a video conference where the CFO and several colleagues appeared on camera, looked and sounded like themselves, and walked him through the transfers in real time. Every other participant on the call was an AI-generated deepfake. Over the course of the call he authorized fifteen separate wire transfers, totaling approximately USD 25 million, to five accounts controlled by the perpetrators. Arup confirmed the incident publicly in May 2024. The firm's chief information officer, Rob Greig, framed it explicitly: "None of our systems were compromised and there was no data affected... this was technology-enhanced social engineering." The relevant lesson is operational, not technical. Every Arup system was intact. The break point was the company's payment-approval workflow, specifically, that a video call could substitute for an out-of-band callback above the wire-transfer threshold. SOURCES CNN, "Finance worker pays out $25 million after video call with deepfake 'chief financial officer'" - CNN, "Arup revealed as victim of $25 million deepfake scam" - Fortune, "A deepfake 'CFO' tricked British design firm Arup" - World Economic Forum, "Lessons learned from a $25m deepfake attack" ## Three deepfake fraud incidents that did not make the front page. A UK-based managing director, insured through Euler Hermes, was talked into wiring €220,000 (≈ USD 243,000) to a Hungarian supplier after a phone call with what he believed was his German parent-company CEO, recognizable by "slight German accent" and the "melody" of the voice. Funds were funneled onward into accounts in other countries. A third call, asking for a further payment, was refused when the originating number was identified as Austrian, not German. Wall Street Journal, August 2019. Sophos analysis, archived copy In July 2024 a Ferrari executive received WhatsApp messages from a number resembling but not matching CEO Benedetto Vigna's, then a phone call using a deepfake of Vigna's voice and accent. The attempt failed when the executive asked the caller to name the title of a book Vigna had personally recommended a few days earlier, an answer the synthetic system did not have. Bloomberg, 26 July 2024. Bloomberg coverage In April 2024 a LastPass employee received calls, texts, and a voicemail using an audio deepfake of CEO Karim Toubba, over WhatsApp, outside normal company communication channels. The employee flagged the channel choice and forced urgency as social-engineering hallmarks and reported to internal security; LastPass disclosed the attempt to share lessons. LastPass blog, April 2024. LastPass disclosure ## Six controls that stop deepfake wire fraud. Adopt the lot. Each step below is operational, not technical, and addresses a specific failure mode visible in the deepfake fraud cases above. The protocol assumes that the synthetic media will eventually look and sound flawless. ## War Room FAQ. The FBI's IC3 2024 Annual Report counted 21,442 reported business email compromise incidents in 2024 with $2.77 billion in adjusted losses. Total cybercrime losses across all categories reached $16.6 billion, a 33% year-over-year increase. In late January / early February 2024, an Arup Hong Kong finance employee was tricked into making 15 wire transfers totaling roughly USD 25 million after a video conference in which every other participant, including the supposed CFO, was an AI-generated deepfake. Arup confirmed the incident publicly in May 2024. CIO Rob Greig described it as "technology-enhanced social engineering." (CNN, May 2024) An out-of-band callback to a number stored in your corporate directory, never the number that initiated the request. Combine with a 30-minute soft hold on payments above a defined threshold and a pre-shared challenge phrase rotated quarterly. The IC3 Recovery Asset Team reports a 66% success rate freezing funds when reported quickly. In the United States, yes. The FCC's Declaratory Ruling FCC 24-17 (8 February 2024) confirmed that AI-generated voice calls fall within the TCPA's restrictions on "artificial or prerecorded voice" calls and require prior express consent. The ruling was effective immediately. File with the FBI Internet Crime Complaint Center at ic3.gov within 24 hours, preserve audio and message logs, and notify your bank's fraud team to attempt a recall. The IC3 Recovery Asset Team can attempt to freeze fraudulent transfers if alerted promptly. Most consumer-grade conferencing platforms do not. Real-time deepfake detection is an open research area, challenge-response approaches (asking the caller to perform unexpected gestures or answer personal questions) currently outperform passive detectors in production. The Ferrari attempt was foiled informally by exactly this technique. ## Cases and protocols behind this page - What the Arup deepfake actually proves, and what it doesn't The $25M Arup fraud, and the single control that would have stopped it. - Building a deepfake incident-response plan for smaller firms The hour-one sequence for a smaller firm: detect, contain, preserve, notify, recover. - Deepfake defense for real-estate closings, at the process layer, not the model The same attack aimed at title, escrow, and closing workflows. - “Follow the money” is no longer enough Why financial tracing alone stops proving the case once the inducement is synthetic. - Reg S-P's new baseline for smaller firms The compliance baseline that happens to blunt AI-enabled fraud. - Why deepfake impersonation works, and what stops it Why these attacks target a decision rather than a detector, and the procedural control that stops them. ## From defense to recovery. A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. - The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # If it's your face; it's your fight. URL: https://imadethisup.org/safety-suite Summary: A practical map of U.S. deepfake law, reporting workflows, hash-takedown services, and a quiz that shows you where your own detection floor is. ======================================================================== - 2025 TAKE IT DOWN Act, federal criminal + 48-hour platform obligation S.146 (119th Congress). Signed into law 19 May 2025. Criminalises knowingly publishing non-consensual intimate visual depictions of minors or non-consenting adults, including deepfakes, and obligates covered platforms to remove such content within 48 hours of a valid report. Platforms had one year (to 19 May 2026) to set up the notice-and-removal process. Bill page. - 2024 FCC ruling, AI voices in robocalls subject to TCPA FCC Declaratory Ruling 24-17 (8 February 2024) confirmed AI-generated voice calls fall within the TCPA's restrictions on "artificial or prerecorded voice" calls. Effective immediately on adoption. FCC order PDF. - 2025 State coverage, uneven, but accelerating By mid-2025, roughly 30 U.S. states had specific deepfake non-consensual-intimate-imagery statutes; nearly all states had broader NCII laws applicable to AI content; and approximately 45 states had criminalised AI-generated CSAM. Penalties range from misdemeanour to felony with multi-year prison terms and fines up to $30,000. State definitions vary; not every older NCII law clearly covers AI-generated content. See the National Conference of State Legislatures' 2024 deepfake legislation tracker and Public Citizen's state intimate-deepfakes tracker. ## How to report a deepfake of yourself, in order. 01 · NOW Preserve evidence 02 · HASH FOR PROACTIVE TAKEDOWN, pick by age in the imagery if adult → StopNCII.org if < 18 → NCMEC Take It Down 03 · FILE ON PLATFORM, both routes if you can · NCII / synthetic-media policy · DMCA copyright (faster*) parallel · within hours 04 · LAW ENFORCEMENT, by character of the content if sexual / <18 → tips.fbi.gov if fraud / voice → ic3.gov 05 · DOCUMENT HARM, for any future civil claim 05 · CIVIL Therapy costs · lost income · timestamps DEFIANCE pending: would give 10-yr SoL · $150K+ CONSULT a lawyer image-based abuse experience * Qiwei et al. (arXiv:2409.12138, 2024) found copyright reports cleared in 25 hours vs 0% over 3 weeks for NCII reports on a major platform. Fig. 05 · Reporting workflow with branches 01 Preserve evidence, first. Archive each URL at archive.org with a wayback timestamp. Screenshot with the system clock visible. Save originals before deletion. Record platform handles, post IDs, and dates. Do not contact the perpetrator before consulting counsel. - 02 Hash and submit for proactive removal. If you are 18+, use StopNCII.org, your image is hashed locally on your device, only the hash is shared, participating platforms (Meta, TikTok, Reddit, Bumble, Snap, X, OnlyFans, and others) match against it. If the imagery was captured when you were under 18, use NCMEC Take It Down, which uses the same hash mechanism for minors. - 03 File on the platform, under multiple categories. Cite the platform's synthetic-media or non-consensual-intimate-imagery policy explicitly. Where you hold copyright in any underlying image used in the deepfake, also file a DMCA copyright report, Qiwei et al. (2024, arXiv:2409.12138) found that on at least one major platform, copyright reports yielded 100% removal within 25 hours, while non-consensual-nudity reports yielded 0% over three weeks. File under both routes if you can. - 04 Law enforcement, where applicable. If imagery is sexual or shows a minor: tips.fbi.gov or local law enforcement. If voice-clone or financial fraud is involved: IC3 (FBI). The Cyber Civil Rights Initiative's Safety Center is a free resource for survivors. - 05 Document the impact, for any future civil claim. If DEFIANCE becomes federal law; it would provide a 10-year statute of limitations and liquidated damages of $150,000+. The bill has passed the Senate twice (2024, 2026) but has not cleared the House. State NCII / right-of-publicity / IIED claims may be available now in your jurisdiction. Track therapy costs, lost income, and other documented harms. Consult a lawyer with experience in image-based abuse before filing, many will take these on contingency. ## Eight verified sources on U.S. deepfake and image-abuse law. ## Safety Suite FAQ. The DEFIANCE Act (Disrupt Explicit Forged Images and Non-Consensual Edits Act) is a pending federal bill, not enacted law. It would create a federal civil cause of action for adults depicted in non-consensual intimate digital forgeries, liquidated damages of $150,000 ($250,000 with aggravating factors), 10-year statute of limitations. S.3696 (118th Cong.) passed the Senate by unanimous consent on 23 July 2024 but did not pass the House before the Congress expired. Reintroduced as S.1837 (119th Cong.) and passed the Senate again by unanimous consent in January 2026, still pending in the House. The TAKE IT DOWN Act (S.146, 119th Congress) was signed into law on 19 May 2025. It criminalises knowingly publishing non-consensual intimate visual depictions of minors or non-consenting adults, including deepfakes, and requires covered platforms to provide a notice-and-removal process that takes content down within 48 hours of a valid report. If you're 18 or over, hash the image at StopNCII.org, your file never leaves your device, and the hash is shared with participating platforms. If the imagery was taken when you were under 18, use NCMEC Take It Down. A peer-reviewed audit (Qiwei et al., 2024) also found that copyright-based DMCA reports yielded faster removal than non-consensual-nudity reports on at least one major platform; file under both routes if applicable. (1) StopNCII.org or NCMEC Take It Down for hash-based platform takedown. (2) The platform's own reporting flow, citing its synthetic-media policy explicitly. (3) For sexual or minor-involving content, FBI tips.fbi.gov. (4) For voice-clone or financial-fraud variants, FBI Internet Crime Complaint Center. (5) For any future civil claim, under existing state NCII / right-of-publicity / IIED law, or under DEFIANCE if and when it becomes federal law, preserve evidence and consult a lawyer before contacting the perpetrator. It depends on the specific test set, the specific generator, and whether observers work alone or in crowds. The largest published study, Groh et al. (PNAS 2022), n = 15,016, found ordinary observers and the leading automated detector similarly accurate while making different kinds of mistakes. On the sampled videos the model reached ~80%, the non-recruited crowd mean also ~80%, and the recruited crowd mean ~74%. The model scores ~65% on the full 4,000-video holdout set, a different population. So crowds beat individuals; trained reviewers do better still; but a single untrained viewer should not assume better-than-model performance without forensic tooling. Probably yes for some scenario, but coverage is uneven. By mid-2025, roughly 30 states had specific deepfake-NCII statutes, nearly all states had broader NCII laws that may apply to AI content, and approximately 45 states had criminalised AI-generated CSAM. See the NCSL tracker or Public Citizen's tracker for the current state of your jurisdiction. ## The law and the cases behind this page - What the TAKE IT DOWN Act actually changes, and what it doesn't What the statute reaches, what it leaves untouched, and the 48-hour obligation. - Deepfakes are reshaping workplace sexual harassment When synthetic intimate imagery follows a person to work, and what Title VII covers. - Deepfakes and the integrity of evidence in family court When fabricated media enters a custody fight and does its damage before it is disproved. ## Sign the truth, not the lie. A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. - The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # Sign the truth, not the lie. URL: https://imadethisup.org/provenance Summary: Detection plays defense; provenance plays offense. A reference on C2PA Content Credentials, JPEG Trust, watermarking, and their real limits. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "alternateName": "Global Cyber Institute", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "Article", "headline": "Provenance, C2PA, Content Credentials, and the verification stack", "author": { "@type": "Organization", "name": "imadethisup.org Editorial" }, "description": "Practitioner's reference on cryptographic media provenance.", "url": "https://imadethisup.org/provenance", "datePublished": "2026-04-27", "dateModified": "2026-08-30", "publisher": { "@id": "https://imadethisup.org/#org" }, "image": "https://imadethisup.org/assets/og/provenance.png", "mainEntityOfPage": "https://imadethisup.org/provenance", "about": [ { "@type": "Thing", "name": "Coalition for Content Provenance and Authenticity", "sameAs": "https://en.wikipedia.org/wiki/Content_Authenticity_Initiative" }, { "@type": "Thing", "name": "Digital watermarking", "sameAs": "https://en.wikipedia.org/wiki/Digital_watermarking" }, { "@type": "Thing", "name": "Synthetic media", "sameAs": "https://en.wikipedia.org/wiki/Synthetic_media" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "abstract": "Provenance establishes where a media asset came from and what was done to it, using cryptographic signatures applied at creation rather than analysis applied afterwards. C2PA Content Credentials is the leading open standard and JPEG Trust is the ISO complement. Provenance does not prove an image is true, it proves what a signer asserted.", "inLanguage": "en-US", "isAccessibleForFree": true }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "Provenance", "item": "https://imadethisup.org/provenance" } ] }, { "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "What is C2PA?", "acceptedAnswer": { "@type": "Answer", "text": "The Coalition for Content Provenance and Authenticity (C2PA) is an open technical standard for cryptographically signing the origin and edit history of digital content. The signed structure is called a 'Content Credential', built from X.509 certificates, CBOR, and JUMBF, and embedded in the asset itself. The current public specification is version 2.2 (1 May 2025), preceded by 2.1 (20 September 2024)." } }, { "@type": "Question", "name": "Who supports C2PA today?", "acceptedAnswer": { "@type": "Answer", "text": "Steering members include Adobe, Microsoft, Google, OpenAI, Meta, BBC, Sony, and Truepic. As of 2024, TikTok was the first major social platform to attach Content Credentials to AI-generated uploads; Google integrated Content Credentials into Search and ad systems; Amazon attached them to Titan Image Generator outputs; LinkedIn displayed them on uploads; and Google's Pixel 10 (September 2025) reached C2PA Conformance Assurance Level 2, the highest currently defined for a mobile camera app." } }, { "@type": "Question", "name": "Is C2PA a solution to deepfakes?", "acceptedAnswer": { "@type": "Answer", "text": "It is a solution to a specific problem: identifying media produced by cooperating tools and platforms. It says 'this asset was produced by these tools, in this order.' It does not say the underlying claim is true; does not address adversarial uses of non-cooperating models; does not survive every transformation; and does not retroactively apply to content that was never signed. Detection and provenance are complementary, not substitutes." } }, { "@type": "Question", "name": "Can a watermark be removed?", "acceptedAnswer": { "@type": "Answer", "text": "Often, yes, though the difficulty depends on perturbation budget. Saberi et al. (arXiv:2310.00076) showed a fundamental trade-off between watermark evasion error and spoofing error for low-perturbation methods. For high-perturbation methods, model-substitution adversarial attacks remain effective. Watermarking is a useful production signal for cooperating actors; it is not a closed defense against motivated adversaries." } }, { "@type": "Question", "name": "What is JPEG Trust?", "acceptedAnswer": { "@type": "Answer", "text": "ISO/IEC 21617, JPEG Trust, is an international standard for asserting media authenticity, provenance, attribution, IP, and integrity throughout the life cycle of an asset. The Core Foundation (Part 1) was approved for publication at the JPEG 105th Meeting in Berlin in October 2024. Part 3 covers watermarking. JPEG Trust is complementary to C2PA, not a competitor." } } ] } ] } Skip to content Research Lab War Room Safety Suite Provenance Tools References Case law Blog Retain → MENU Home / Provenance 07 / 09, PROVENANCE Sign the truth, not the lie. Detection plays defense, it always trails generation. Provenance plays offense: cryptographically assert where an asset came from and what was done to it, before it travels. C2PA is the leading open standard. JPEG Trust is the ISO complement. Both are instrumented; both have limits. v 2.2 Current C2PA Technical Specification, released 1 May 2025; preceded by 2.1 (20 September 2024). spec.c2pa.org First social TikTok became the first major social platform to attach Content Credentials to AI-generated uploads in 2024. Adobe blog · Sept 2024 Top tier Google Pixel 10 (Sept 2025) reached C2PA Conformance Assurance Level 2, the highest tier currently defined for a mobile camera app, using Tensor G5 + Titan M2. C2PA whitepaper, Oct 2025 In short Provenance establishes where a media asset came from and what was done to it, using cryptographic signatures applied at creation rather than analysis applied afterwards. C2PA Content Credentials is the leading open standard and JPEG Trust is the ISO complement. Provenance does not prove an image is true, it proves what a signer asserted. 01 · What a Content Credential actually is A Content Credential is a signed manifest, embedded in the asset itself. The Content Credential is a cryptographically bound structure that records the provenance of a digital asset. It contains one or more assertions, statements about the asset, such as its origin, modifications, and use of AI tools. Each assertion is signed; the signatures chain to an X.509 certificate hierarchy with a published C2PA Trust List that covers both hardware and software issuers. The technical foundations are deliberately conservative: X.509 certificates (RFC 5280), CBOR (RFC 8949), and JUMBF (ISO 19566-5). The manifest is embedded directly in the file (not stored out-of-band), so it travels with the asset across most platforms and most transformations. Verification is open and free. Anyone can check a Content Credential at contentcredentials.org/verify, drag a file in and the public reader resolves the chain. CITATIONS C2PA Technical Specification 2.1 (20 Sep 2024), PDF - C2PA Technical Specification 2.2 (1 May 2025), PDF - C2PA & Content Credentials Explainer 2.2, spec.c2pa.org - C2PA whitepaper, October 2025, PDF ## The C2PA chain of custody: from capture to verification, with a hash at every hop. HASH CHAIN, sealed at each hop · resolved to the C2PA Trust List root at /verify ↓ root of trust 01 CAPTURE Camera or model signs first claim 02 EDIT Each tool appends & signs assertion 03 PUBLISH ✓ Manifest sealed inside the file 04 DISTRIBUTE Survives platform reupload where supported 05 VERIFY Public reader resolves to trust list root Manifest = JSON-LD claim set + cryptographic signature, embedded in the asset Public reader: contentcredentials.org/verify Fig. 06 · C2PA chain of custody, end to end · spec v 2.2 03 · Adoption, where Content Credentials actually appear Where Content Credentials actually appear, from cameras to social platforms. CAMERA / DEVICE Hardware capture Sony, Leica, and Canon ship Content Credentials in select bodies. Google's Pixel 10 (September 2025) reached C2PA Conformance Assurance Level 2, the highest tier currently defined for a mobile camera app, using its Tensor G5 SoC and Titan M2 security chip. C2PA whitepaper, Oct 2025 Adobe Firefly, OpenAI DALL·E 3, Microsoft Designer, and Amazon Titan Image Generator (v1 and v2) attach Content Credentials at generation time. Adobe also offers Content Authenticity for Enterprise and a Content Authenticity API. Adobe Summit 2024 TikTok was first social platform to attach Content Credentials to AI-generated uploads (2024). LinkedIn displays them on posts. Meta joined the C2PA steering committee. Google integrated Content Credentials into Search and into ad systems. Adobe blog · Sept 2024 ## Honest about the limits of C2PA Content Credentials. A Content Credential states "this asset was produced by these tools, in this order." It does not say the underlying claim is true, that the framing is fair, or that nothing was missed. Treat the manifest as a ladder, not a verdict. A signed manifest is a positive assertion by a cooperating actor. It does not attach to content from non-cooperating models, content stripped of metadata, or content that was never signed in the first place. Detection (see the Research Lab) and provenance are complementary. Saberi et al. (arXiv:2310.00076) showed a fundamental trade-off between evasion error and spoofing error for low-perturbation watermarks; high-perturbation watermarks are vulnerable to model-substitution attacks. Watermarking is a useful production signal for cooperating actors, not a closed defense. ## JPEG Trust is the ISO complement to C2PA. JPEG Trust (ISO/IEC 21617) is an international standard for asserting authenticity, provenance, attribution, intellectual-property rights, and integrity throughout the life cycle of a media asset. The Core Foundation (Part 1) was approved for publication at the JPEG 105th Meeting in Berlin in October 2024. Part 3 covers watermarking. JPEG Trust is complementary to C2PA, not a competitor, both standards bodies are coordinating on interoperability through the World Standards Cooperation working group on AI watermarking, multimedia authenticity, and deepfake detection. For a survey of the broader watermarking landscape, including on-device approaches, robustness benchmarks, and known attacks, see the "Watermarking for AI Content Detection" review (arXiv:2504.03765) and Saberi et al. on the fundamental limits of detection and watermarking robustness (arXiv:2310.00076). - JPEG Trust home, jpeg.org/jpegtrust - JPEG 105th Meeting press release (December 2024), jpeg.org press - World Standards Cooperation on AI watermarking, WSC ## Three concrete next steps on Content Credentials, by role. Adopt a workflow that attaches a Content Credential at capture (camera or generation tool) and preserves it through edit. Adobe Firefly, OpenAI DALL·E 3, Microsoft Designer, and Amazon Titan emit credentials by default; verify your CMS preserves them on upload. Drag any image into contentcredentials.org/verify to inspect its manifest. Treat the absence of a credential as "unverified by default" rather than "therefore fake." The reference implementations are open source under Apache-2.0: c2pa-rs (Rust) and c2pa-js (JavaScript). Both ship with example apps for signing and verification. ## Eight verified sources on C2PA and JPEG Trust. ## Provenance FAQ. The Coalition for Content Provenance and Authenticity (C2PA) is an open technical standard for cryptographically signing the origin and edit history of digital content. The signed structure, called a Content Credential, is built from X.509 certificates, CBOR, and JUMBF, and embedded in the asset itself. The current public specification is version 2.2 (1 May 2025). Steering members include Adobe, Microsoft, Google, OpenAI, Meta, BBC, Sony, and Truepic. As of 2024, TikTok was the first major social platform to attach Content Credentials to AI-generated uploads; Google integrated Content Credentials into Search and ad systems; Amazon attached them to Titan Image Generator outputs; LinkedIn displays them on uploads; and Google's Pixel 10 (September 2025) reached C2PA Conformance Assurance Level 2, the highest tier currently defined for a mobile camera app. It is a solution to a specific problem: identifying media produced by cooperating tools and platforms. It says "this asset was produced by these tools, in this order." It does not say the underlying claim is true; does not address adversarial uses of non-cooperating models; does not survive every transformation; and does not retroactively apply to content that was never signed. Detection (the Research Lab) and provenance are complementary, not substitutes. Often, yes, though the difficulty depends on perturbation budget. Saberi et al. (arXiv:2310.00076) showed a fundamental trade-off between watermark evasion error and spoofing error for low-perturbation methods. For high-perturbation methods, model-substitution adversarial attacks remain effective. ISO/IEC 21617, JPEG Trust, is an international standard for asserting media authenticity, provenance, attribution, IP, and integrity throughout the life cycle of an asset. The Core Foundation (Part 1) was approved for publication at the JPEG 105th Meeting in Berlin in October 2024. Part 3 covers watermarking. JPEG Trust is complementary to C2PA, not a competitor. The official public reader is at contentcredentials.org/verify. Drag a file in and the reader resolves the chain to the C2PA Trust List root. The libraries to do the same in your own application are c2pa-rs (Rust) and c2pa-js (JavaScript), both Apache-2.0 licensed. ## How Content Credentials hold up as evidence - What Content Credentials establish, and what they do not What a Content Credential asserts, what it does not, and why a missing one proves nothing. - What the C2PA conformance registry actually lists Reading the C2PA Conforming Products List directly: which devices are certified, and at what assurance level. - Synthetic media disclosure obligations now in force The marking and disclosure duties for synthetic media that took effect on 2 August 2026. - Authenticating AI-touched evidence: do we need a new rule? What a provenance record has to do to satisfy Rule 901(b)(9). - When the file lies about itself Why embedded metadata is not provenance, and how the two differ under scrutiny. - Forensic neutrals: who decides when digital evidence is contested? Who decides when the parties cannot agree that a record is authentic. - Why deepfake detectors fail on new generators The detection ceiling that makes signing at creation worth the effort. ## From provenance to the reading room. A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. - The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # Every claim on the site has a citation. Find them here. URL: https://imadethisup.org/references Summary: Every claim on this site carries a citation. Search and filter 38+ verified papers, federal sources, investigations, and standards by audience. ======================================================================== ## Where the primary synthetic-media work lives. Coalition for Content Provenance and Authenticity c2pa.org Federal Bureau of Investigation, Internet Crime Complaint Center ic3.gov Cybersecurity and Infrastructure Security Agency cisa.gov National Institute of Standards and Technology, Face Recognition Vendor Test & AISI nist.gov European Union Agency for Cybersecurity enisa.europa.eu JPEG Trust (ISO/IEC 21617) standardisation jpeg.org/jpegtrust Cyber Civil Rights Initiative cybercivilrights.org Cornell preprint server, primary source for most CS/ML papers cited here arxiv.org ## Take the references back to the work. A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. - The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # What courts have actually held about deepfakes and fabricated evidence URL: https://imadethisup.org/case-law Summary: IRAC summaries of 20 US decisions on deepfakes, AI-generated exhibits, and fabricated citations, each written from the opinion itself. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "alternateName": "Global Cyber Institute", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "CollectionPage", "name": "Deepfake and AI evidence case law", "description": "IRAC summaries of 20 United States decisions on deepfakes, AI-generated evidence, and fabricated citations, written from the opinions themselves.", "url": "https://imadethisup.org/case-law", "isPartOf": { "@id": "https://imadethisup.org/#org" }, "about": [ { "@type": "Thing", "name": "Deepfake", "sameAs": "https://en.wikipedia.org/wiki/Deepfake" }, { "@type": "Thing", "name": "Federal Rules of Evidence", "sameAs": "https://en.wikipedia.org/wiki/Federal_Rules_of_Evidence" }, { "@type": "Thing", "name": "Hallucination (artificial intelligence)", "sameAs": "https://en.wikipedia.org/wiki/Hallucination_(artificial_intelligence)" }, { "@type": "Thing", "name": "Digital forensics", "sameAs": "https://en.wikipedia.org/wiki/Digital_forensics" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "inLanguage": "en-US", "isAccessibleForFree": true, "dateModified": "2026-08-30", "abstract": "United States courts have begun deciding cases about synthetic media directly. Decisions since 2024 address whether video evidence can still be authenticated by circumstantial detail in an era of deepfakes, when AI-generated intimate imagery is criminal, what sanctions follow filing citations a language model invented, and whether an AI voice clone of a candidate is actionable under telephone and election law." }, { "@type": "ItemList", "name": "Decisions on synthetic media and fabricated evidence", "numberOfItems": 20, "itemListOrder": "https://schema.org/ItemListOrderDescending", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "United States v. Steven Anderegg (7th Cir. 2026)", "url": "https://imadethisup.org/case-law/united-states-v-anderegg-7th-cir-2026" }, { "@type": "ListItem", "position": 2, "name": "Dineen/Shibata v. Kotchka (Ariz. Ct. App. 2026)", "url": "https://imadethisup.org/case-law/dineen-shibata-v-kotchka-self-represented-litigant-arizona-sanction" }, { "@type": "ListItem", "position": 3, "name": "Estate of Lane Caviness v. Atlas Air, Inc. (11th Cir. 2026)", "url": "https://imadethisup.org/case-law/caviness-akerlund-atlas-air-eleventh-circuit-hallucinated-briefs" }, { "@type": "ListItem", "position": 4, "name": "In re María V. Irizarry Centeno; Anissa M. Bonilla Irizarry (P.R. 2026)", "url": "https://imadethisup.org/case-law/in-re-irizarry-centeno-bonilla-irizarry-puerto-rico-no-ethical-sanction" }, { "@type": "ListItem", "position": 5, "name": "Jigsaw Productions, Inc. v. U.S. Securities and Exchange Commission (D.D.C. 2026)", "url": "https://imadethisup.org/case-law/jigsaw-productions-v-sec-deepfake-risk-foia-exemption" }, { "@type": "ListItem", "position": 6, "name": "Prososki v. Regan (Neb. 2026)", "url": "https://imadethisup.org/case-law/prososki-regan-nebraska-supreme-court-fictitious-authority" }, { "@type": "ListItem", "position": 7, "name": "Matter of M.S. (M.H.) (N.Y. Ct. App. 2026)", "url": "https://imadethisup.org/case-law/matter-of-ms-mh-deepfake-video-authentication" }, { "@type": "ListItem", "position": 8, "name": "State v. Dore (Conn. App. Ct. 2026)", "url": "https://imadethisup.org/case-law/state-v-dore-conn-app-2026" }, { "@type": "ListItem", "position": 9, "name": "State of Iowa v. Max Amyda (Iowa Ct. App. 2026)", "url": "https://imadethisup.org/case-law/state-v-amyda-deepfake-claim-video-authentication" }, { "@type": "ListItem", "position": 10, "name": "Cassata v. Michael Macrina Architect, P.C. (N.Y. Sup. Ct., Suffolk Cty. 2026)", "url": "https://imadethisup.org/case-law/cassata-macrina-architect-suffolk-county-firm-and-supervisor-sanctions" }, { "@type": "ListItem", "position": 11, "name": "Pennington v. First Hand Land, LLC (D.C. Ct. App. 2026)", "url": "https://imadethisup.org/case-law/pennington-v-first-hand-land-forged-court-order-sanction" }, { "@type": "ListItem", "position": 12, "name": "Noland v. Land of the Free, L.P. (Cal. Ct. App. 2025)", "url": "https://imadethisup.org/case-law/noland-land-of-the-free-california-ai-fabricated-quotations" }, { "@type": "ListItem", "position": 13, "name": "Bradley Day and Tracey Day v. Elvis Dean Thompson (La. 2025)", "url": "https://imadethisup.org/case-law/day-v-thompson-surveillance-video-in-camera-review" }, { "@type": "ListItem", "position": 14, "name": "Brasse v. State (Md. App. Ct. 2025)", "url": "https://imadethisup.org/case-law/brasse-v-state-md-app-2025" }, { "@type": "ListItem", "position": 15, "name": "League of Women Voters of New Hampshire v. Kramer (D.N.H. 2025)", "url": "https://imadethisup.org/case-law/league-of-women-voters-v-kramer-ai-robocall-motion-to-dismiss" }, { "@type": "ListItem", "position": 16, "name": "State v. Currie (Ohio Ct. App., 1st Dist. 2025)", "url": "https://imadethisup.org/case-law/state-v-currie-deepfake-objection-probation-search-photo" }, { "@type": "ListItem", "position": 17, "name": "United States v. Clint Robert Schram (8th Cir. 2025)", "url": "https://imadethisup.org/case-law/united-states-v-schram-8th-cir-2025" }, { "@type": "ListItem", "position": 18, "name": "Mooney v. State (Md. 2024)", "url": "https://imadethisup.org/case-law/mooney-v-state-video-authentication-circumstantial-evidence" }, { "@type": "ListItem", "position": 19, "name": "Pegasystems Inc. v. Appian Corporation (Va. Ct. App. 2024)", "url": "https://imadethisup.org/case-law/pegasystems-v-appian-authenticating-software-evidence" }, { "@type": "ListItem", "position": 20, "name": "Matter of Gabriel H. (N.Y. App. Div., 4th Dep't 2024)", "url": "https://imadethisup.org/case-law/matter-of-gabriel-h-dk-fourth-department-deepfake-weight" } ] }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "Case law", "item": "https://imadethisup.org/case-law" } ] } ] } Skip to content Research Lab War Room Safety Suite Provenance Tools References Case law Blog Retain → MENU Home / Case law CASE LAW What courts have actually held about deepfakes and fabricated evidence 20 United States decisions on synthetic media, AI-generated exhibits, and citations that turned out not to exist. Each is summarised in IRAC form from the opinion itself. Summaries are written from the opinion, not from a headnote, by the automated process described at our AI disclosure. Every quotation was located in the text of the decision it is attributed to. Nothing here is legal advice. In short United States courts have begun deciding cases about synthetic media directly. Decisions since 2024 address whether video evidence can still be authenticated by circumstantial detail in an era of deepfakes, when AI-generated intimate imagery is criminal, what sanctions follow filing citations a language model invented, and whether an AI voice clone of a candidate is actionable under telephone and election law. All Authentication Sanctions Criminal Civil Election 20 of 20 cases, most recent first. 2026-08-25 United States v. Steven Anderegg (7th Cir. 2026) Because the AI-generated images charged against Anderegg depict no actual child, Stanley v. Georgia and Ashcroft v. Free Speech Coalition bar prosecuting him under 18 U.S.C. section 1466A(b)(1) for possessing that obscene material in his own home. Criminal Read → - 2026-07-15 Dineen/Shibata v. Kotchka (Ariz. Ct. App. 2026) A self-represented Arizona litigant who files an opening brief containing hallucinated case citations produced by generative AI, and who does nothing to verify them and nothing to correct the brief once the problem is identified, both asserts and maintains claims that are groundless and not made in good faith under A.R.S. section 12-349, and neither his lack of legal training nor his lack of intent to deceive is a defence. Sanctions Read → - 2026-07-10 Estate of Lane Caviness v. Atlas Air, Inc. (11th Cir. 2026) A lawyer who signs Eleventh Circuit briefs filled with AI-generated citations to nonexistent cases, and who then purports to withdraw the wrong set of citations and hallucinates the replacements too, violates his professional obligations to his clients and to the court and will be referred to the circuit's Committee on Lawyer Qualifications and Conduct. Sanctions Read → - 2026-04-21 In re María V. Irizarry Centeno; Anissa M. Bonilla Irizarry (P.R. 2026) Filing court papers containing non-existent or misattributed citations produced with technological assistance is sanctionable conduct in Puerto Rico under Canons 18, 35, and 38 and Rule 9.1 of the Rules of Civil Procedure, but where the lawyers have no disciplinary history, corrected the record promptly, and paid the trial court's sanction, the Supreme Court of Puerto Rico may admonish them and archive the complaint rather than discipline them. Sanctions Read → - 2026-03-23 Jigsaw Productions, Inc. v. U.S. Securities and Exchange Commission (D.D.C. 2026) A federal agency cannot satisfy the Freedom of Information Act's foreseeable harm requirement by asserting that a released recording could be manipulated into deepfakes, at least where the subject is an exceptionally public figure who is already a frequent deepfake target and the agency shows no concrete reason why one more recording would actually impede his privacy interests. Civil Read → - 2026-03-20 Prososki v. Regan (Neb. 2026) Submitting fictitious authority to a Nebraska court is resolved under the existing rules of professional conduct and court rules whether or not generative AI produced it, and a brief riddled with fabricated citations may be stricken, the appeal dismissed, and counsel referred to the Counsel for Discipline. Sanctions Read → - 2026-02-17 Matter of M.S. (M.H.) (N.Y. Ct. App. 2026) The New York Court of Appeals held that Erie County failed to authenticate three videos under People v Patterson where neither the person who allegedly recorded them nor the third party who extracted and supplied them testified, and it reasoned that the increasing prevalence of deepfake videos makes authentication by matching circumstantial details in a video to a witness's personal observations a more suspect method. Authentication Read → - 2026-02-10 State v. Dore (Conn. App. Ct. 2026) Connecticut's second degree child pornography statute is not overbroad, because General Statutes section 53a-193 (13) limits it to depictions of real children, and the state need not present expert testimony to prove that an image depicts a real child; a defendant arguing that AI-generated imagery has made lay identification unreliable must put evidence of that technology into the record. Criminal Read → - 2026-01-28 State of Iowa v. Max Amyda (Iowa Ct. App. 2026) The Iowa Court of Appeals held that a digital video may be authenticated under Iowa Rule of Evidence 5.901(b)(4) entirely on circumstantial evidence of its distinctive contents and the surrounding circumstances, and that a defendant's speculative claim that the video is a deepfake, unsupported by any record evidence, does not raise a genuine question about the original's authenticity under Iowa Rule of Evidence 5.1003. Authentication Read → - 2026-01-27 Cassata v. Michael Macrina Architect, P.C. (N.Y. Sup. Ct., Suffolk Cty. 2026) A lawyer who copies another lawyer's brief into her own papers adopts its fabricated citations as her own, and under 22 NYCRR 130-1.1 the supervising attorney and the firm may be sanctioned alongside her where firm-level safeguards did not reach the conduct and no one corrected the record promptly. Sanctions Read → - 2026-01-08 Pennington v. First Hand Land, LLC (D.C. Ct. App. 2026) Submitting a blatantly forged court order as a basis for relief is conduct utterly inconsistent with the orderly administration of justice, and the District of Columbia Court of Appeals will dismiss the appeal outright where discipline is unavailable, monetary sanctions are unrealistic or inadequate, and merely disregarding the forgery would leave the forger no worse off. Civil Read → - 2025-09-12 Noland v. Land of the Free, L.P. (Cal. Ct. App. 2025) No brief or other paper filed in any California court should contain a citation, whether supplied by generative AI or any other source, that the attorney responsible for filing it has not personally read and verified, and an appeal whose briefs are peppered with fabricated citations is frivolous and supports a personal monetary sanction on counsel. Sanctions Read → - 2025-05-09 Bradley Day and Tracey Day v. Elvis Dean Thompson (La. 2025) A Louisiana trial court cannot perform the La. C.E. art. 607(D)(2) balancing test on surveillance video without first reviewing the video in camera, and because artificial intelligence and modern editing have greatly increased the risk of manipulation, the party filmed must have a meaningful opportunity to assess the authenticity of and any weaknesses in the footage. Civil Read → - 2025-03-27 Brasse v. State (Md. App. Ct. 2025) Maryland's child pornography statute is not facially overbroad, because section 11-208 reaches only images of an actual child and computer-generated images, including deepfakes, that are indistinguishable from an actual and identifiable child, and a defendant challenging it must show that it prohibits a substantial amount of protected speech. Criminal Read → - 2025-03-26 League of Women Voters of New Hampshire v. Kramer (D.N.H. 2025) The District of New Hampshire held that an AI voice-cloned robocall telling voters that casting a primary ballot would waste their general election vote plausibly pleads an attempt to intimidate, threaten or coerce under Section 11(b) of the Voting Rights Act, and that robocall vendors who did not write the message may still face Telephone Consumer Protection Act liability if they were so involved in placing the calls, or knowingly allowed their platform to be used unlawfully, as to be deemed to have initiated them. Election Read → - 2025-02-28 State v. Currie (Ohio Ct. App., 1st Dist. 2025) The Ohio First District held that a probation officer relying on a social media photograph to establish reasonable grounds for a probation search is not required to authenticate the image or rule out digital manipulation, where the probationer offered no account of how such authentication could be performed and reasonable suspicion does not demand that innocent explanations be eliminated. Authentication Read → - 2025-02-12 United States v. Clint Robert Schram (8th Cir. 2025) A jury may determine from the images themselves that advertised child sexual abuse material depicts real children, and the government need not produce evidence to negate a defendant's speculative assertion that the children depicted were computer generated. Criminal Read → - 2024-08-13 Mooney v. State (Md. 2024) The Supreme Court of Maryland held that video footage may be authenticated through circumstantial evidence under Maryland Rule 5-901(b)(4), including a portion of the video that no testifying witness personally observed, and that the advent of image-generating artificial intelligence does not at present displace existing methods of authenticating video. Authentication Read → - 2024-07-30 Pegasystems Inc. v. Appian Corporation (Va. Ct. App. 2024) Electronic evidence in Virginia is authenticated under the same very modest Rule 2:901 standard as anything else, the possibility that electronic evidence can be tampered with does not raise that standard absent a specific claim of tampering, and it is an abuse of discretion to exclude software while forbidding the proponent from attempting to authenticate it merely because it sits on a different device than the one used in discovery. Civil Read → - 2024-07-03 Matter of Gabriel H. (N.Y. App. Div., 4th Dep't 2024) The Appellate Division, Fourth Department held that three hacked security camera videos were sufficiently authenticated by circumstantial evidence of their distinctive characteristics, by a detective's testimony matching the living room and its furnishings, and by an FBI agent's testimony that he saw no signs of tampering, and that a respondent's assertion that the videos could be deepfakes did not reduce their weight where Family Court found no cuts, edits or timestamp jumps. Authentication Read → Authentication disputes of this kind usually turn on what an examiner can establish about the file itself rather than on what the video appears to show, which is work for an independent forensic examiner. A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. - The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # Plain answers, with citations. URL: https://imadethisup.org/faq Summary: Plain answers on synthetic media, deepfakes, AI fraud, detection, C2PA provenance, and U.S. law, every one carrying a primary-source citation. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "alternateName": "Global Cyber Institute", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "FAQ", "item": "https://imadethisup.org/faq" } ] }, { "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "What is synthetic media?", "acceptedAnswer": { "@type": "Answer", "text": "Any image, audio, or video artifact produced or materially altered by a generative model, including face-swap, voice-clone, full-frame synthesis, and parameter-level edits indistinguishable from authentic capture." } }, { "@type": "Question", "name": "What is the difference between a deepfake and synthetic media?", "acceptedAnswer": { "@type": "Answer", "text": "Synthetic media is the umbrella term. Deepfake is the colloquial label for one subset, typically face-swap or voice-clone content created with deep neural networks. Synthetic media also includes full-frame text-to-image generation, voice cloning, lip-sync edits, and manipulated audio that is not a face-swap." } }, { "@type": "Question", "name": "Are deepfakes illegal?", "acceptedAnswer": { "@type": "Answer", "text": "It depends on how they are made and used. Generation alone is generally not illegal. Distribution can be civil or criminal under: the TAKE IT DOWN Act (S.146, 119th Congress; signed into law 19 May 2025); the FCC TCPA AI-voice rule (FCC 24-17, 8 February 2024); federal wire-fraud statutes; and roughly 30 state-level deepfake-NCII statutes plus broader state NCII and right-of-publicity laws. The DEFIANCE Act (S.1837, 119th Congress) has passed the Senate twice (2024 and 2026) but has not passed the House, so it is not yet federal law." } }, { "@type": "Question", "name": "Is this site affiliated with any company?", "acceptedAnswer": { "@type": "Answer", "text": "imadethisup.org is a public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770). It is anonymously run by thought leaders from across the cybersecurity, forensics, and policy industries. There is no advertising, no sponsorship, and no third-party tracking." } }, { "@type": "Question", "name": "What is a GAN?", "acceptedAnswer": { "@type": "Answer", "text": "A Generative Adversarial Network is a pair of neural networks, a generator that produces candidate samples and a discriminator that judges them, trained against each other in a minimax game. Goodfellow et al. introduced the framework in 2014 (NeurIPS, arXiv:1406.2661)." } }, { "@type": "Question", "name": "What is a latent diffusion model?", "acceptedAnswer": { "@type": "Answer", "text": "A diffusion model that operates in the compressed latent space of a pretrained autoencoder rather than in pixel space. Introduced by Rombach et al. at CVPR 2022 (arXiv:2112.10752); the architecture behind Stable Diffusion." } }, { "@type": "Question", "name": "What is C2PA?", "acceptedAnswer": { "@type": "Answer", "text": "The Coalition for Content Provenance and Authenticity, an open standard for cryptographically signing the origin and edit history of digital content. Signed structures are called Content Credentials and are embedded in the asset itself. Current spec: 2.2 (1 May 2025)." } }, { "@type": "Question", "name": "How can I tell if an image is AI-generated?", "acceptedAnswer": { "@type": "Answer", "text": "Look for asymmetric eye specular highlights, diffuse hairline boundaries, glyphic background text, repeating micro-patterns, and tooth-by-tooth inconsistencies under motion. None of these is sufficient on its own, current-generation outputs often pass visual inspection. Verify the asset's Content Credential at contentcredentials.org/verify if one is present." } }, { "@type": "Question", "name": "How accurate are humans at detecting deepfakes?", "acceptedAnswer": { "@type": "Answer", "text": "Groh et al. (PNAS 2022, n=15,016) compared ordinary observers with the leading computer-vision detector and found them similarly accurate while making different kinds of mistakes. On the sampled videos the model reached ~80%, the non-recruited crowd mean also ~80%, and the recruited crowd mean ~74%. The model scores ~65% on the full 4,000-video holdout set, which is a different and larger population. So crowds beat individuals; trained reviewers do better still; but a single untrained viewer should not assume better-than-model performance without forensic tooling." } }, { "@type": "Question", "name": "What was the Arup Hong Kong deepfake fraud?", "acceptedAnswer": { "@type": "Answer", "text": "In late January / early February 2024, an Arup finance employee in Hong Kong made fifteen wire transfers totaling roughly USD 25 million after a video conference in which every other participant, including the supposed CFO, was an AI-generated deepfake. Arup confirmed publicly in May 2024." } }, { "@type": "Question", "name": "What does the TAKE IT DOWN Act require?", "acceptedAnswer": { "@type": "Answer", "text": "S.146 (119th Congress), signed 19 May 2025, criminalises knowingly publishing non-consensual intimate visual depictions of minors or non-consenting adults, including deepfakes, and requires covered platforms to remove such content within 48 hours of a valid report." } } ], "about": [ { "@type": "Thing", "name": "Deepfake", "sameAs": "https://en.wikipedia.org/wiki/Deepfake" }, { "@type": "Thing", "name": "Synthetic media", "sameAs": "https://en.wikipedia.org/wiki/Synthetic_media" }, { "@type": "Thing", "name": "Generative artificial intelligence", "sameAs": "https://en.wikipedia.org/wiki/Generative_artificial_intelligence" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "abstract": "The imadethisup.org FAQ answers common questions about synthetic media, deepfakes, generative-AI fraud, detection methods, content provenance, and United States law. Answers are grouped by subject, and each carries an inline citation to a primary source with a link to the longer treatment elsewhere on the site where a short answer is not sufficient.", "inLanguage": "en-US", "isAccessibleForFree": true, "dateModified": "2026-08-30" } ] } Skip to content Research Lab War Room Safety Suite Provenance Tools References Case law Blog Retain → MENU Home / FAQ FREQUENTLY ASKED Plain answers, with citations. We grouped the questions by where the answer lives on the site. Where a single citation is enough; it's inline. Where the answer is longer, we link to the deep page and include the citation here too. Jump to: → The basics - → Research & detection - → Business & fraud - → Personal & legal - → Provenance & standards - → About this site The imadethisup.org FAQ answers common questions about synthetic media, deepfakes, generative-AI fraud, detection methods, content provenance, and United States law. Answers are grouped by subject, and each carries an inline citation to a primary source with a link to the longer treatment elsewhere on the site where a short answer is not sufficient. ## Synthetic media and deepfakes: definitions, scope, and who's affected. Any image, audio, or video artifact produced or materially altered by a generative model, including face-swap, voice-clone, full-frame synthesis, and parameter-level edits indistinguishable from authentic capture. The term is broader than "deepfake" and includes both consensual uses (film VFX, accessibility dubbing, research) and adversarial ones (impersonation, fraud, image-based abuse). See the glossary. Synthetic media is the umbrella term. Deepfake is the colloquial label for one subset, typically face-swap or voice-clone content created with deep neural networks. Synthetic media also includes full-frame text-to-image generation, voice cloning, lip-sync edits, and audio manipulation that is not face-swap. It depends on how they are made and used. Generation alone is generally not illegal. Distribution can be civil or criminal under the TAKE IT DOWN Act (federal law since 19 May 2025), the FCC TCPA AI-voice rule, federal wire-fraud statutes, or roughly 30 state-level deepfake-NCII statutes plus broader state NCII / right-of-publicity laws. The DEFIANCE Act (S.1837, 119th Congress) has passed the Senate twice but not the House; it is not yet federal law. U.S. enterprise scale: the FBI's 2024 IC3 Annual Report recorded $16.6 billion in total cybercrime losses (a 33% YoY increase), with $2.77 billion attributable to BEC alone across 21,442 incidents. Personal scale: the Cyber Civil Rights Initiative's 2017 nationwide study found approximately 1 in 8 U.S. social-media users had had a sexually explicit image shared without consent or had been threatened with such, with women approximately twice as likely as men to be targets. ## How the technology works and how the field tries to detect it. A Generative Adversarial Network is a pair of neural networks, a generator that produces candidate samples and a discriminator that judges them, trained against each other in a minimax game. Goodfellow et al. introduced the framework in 2014 (NeurIPS, arXiv:1406.2661). See the Research Lab. A diffusion model that operates in the compressed latent space of a pretrained autoencoder rather than in pixel space. Introduced by Rombach et al. at CVPR 2022 (arXiv:2112.10752); the architecture behind Stable Diffusion and most modern open-weight image generators. Detectors trained on outputs from one generator overfit to that generator's specific spectral and structural artifacts. Applied to images from an unseen architecture, accuracy can drop sharply. This cross-generator generalization gap is the central open problem in synthetic-media forensics. See Wang et al. (arXiv:1912.11035) and Frank et al. (arXiv:2003.08685). The mechanism, and the three things the field does about it, are set out in why deepfake detectors fail on new generators. Groh et al. (PNAS 2022, n=15,016) compared ordinary observers with the leading computer-vision detector and found them similarly accurate while making different kinds of mistakes. On the sampled videos the model reached ~80%, the non-recruited crowd mean also ~80%, and the recruited crowd mean ~74%. The model scores ~65% on the full 4,000-video holdout set, which is a different and larger population. So crowds beat individuals; trained reviewers do better still; but a single untrained viewer should not assume better-than-model performance without forensic tooling. Measured against deepfakes that were actually circulating, the models do not reach the accuracy of trained analysts either, see detector results on deepfakes found in the wild. A deepfake detection method by Ciftci, Demir, and Yin (IEEE TPAMI 2020) that exploits photoplethysmographic (PPG) signals, subtle skin-tone shifts from blood circulation, present in real portrait videos but not preserved in synthetic content. Reported accuracies in the paper: 96% on the original FaceForensics dataset (2018), 94.65% on FaceForensics++, 91.50% on Celeb-DF. Degrades on compressed video. (Intel later commercialised a real-time variant under the same name.) The most commonly cited are FaceForensics++ (Rössler et al., ICCV 2019; arXiv:1901.08971); the Deepfake Detection Challenge dataset (Dolhansky et al., 2020; arXiv:2006.07397); and ASVspoof for audio (Yamagishi et al., 2021). See the Research Lab. A score quoted from one of these benchmarks describes that benchmark and not the file in front of you, which is the subject of what a deepfake detector score does not tell you. ## Deepfake fraud: operational defenses for organizations. An out-of-band callback to a number stored in your corporate directory, never the number that initiated the request. Combine with a 30-minute soft hold on payments above a defined threshold and a pre-shared challenge phrase rotated quarterly. The IC3 Recovery Asset Team reports a 66% success rate freezing funds when reported quickly. See the full six-step protocol in the War Room, and why deepfake executives fool people and what actually stops them for why the control has to sit outside the channel the attacker chose. In late January / early February 2024, an Arup Hong Kong finance employee made fifteen wire transfers totaling roughly USD 25 million after a video conference in which every other participant, including the supposed CFO, was an AI-generated deepfake. Arup confirmed publicly in May 2024 (CNN, 16 May 2024). What the case does and does not establish about detection is unpacked in what the Arup deepfake actually proves. A Ferrari executive received WhatsApp messages and a phone call using an AI-generated voice clone of CEO Benedetto Vigna. The executive asked the caller to name the title of a book Vigna had personally recommended a few days earlier. The synthetic system did not have the answer (Bloomberg, 26 July 2024). The technique generalizes, see "challenge phrase" in the War Room. In the United States, yes. The FCC's Declaratory Ruling FCC 24-17 (8 February 2024) confirmed AI-generated voice calls fall within the TCPA's restrictions on "artificial or prerecorded voice" calls and require prior express consent. Effective immediately on adoption. File with the FBI Internet Crime Complaint Center at ic3.gov within 24 hours, preserve audio and message logs, and notify your bank's fraud team to attempt a recall. The IC3 Recovery Asset Team can attempt to freeze fraudulent transfers if alerted promptly. Write the sequence down before you need it: building a deepfake incident-response plan for smaller firms sets out detect, contain, preserve, notify, recover against NIST SP 800-61. ## If a deepfake of you is circulating. (1) Preserve evidence (archive URLs, screenshot with system clock, save originals). (2) Hash and submit to StopNCII.org (adults) or NCMEC Take It Down (imagery from when you were under 18). (3) Report on the platform under both NCII and copyright (Qiwei et al. 2024 found copyright reports cleared faster than NCII reports on a major platform). (4) For sexual or minor-involving imagery, file with FBI tips.fbi.gov. (5) Consult a lawyer about civil claims under existing state NCII / right-of-publicity / IIED law (and under the DEFIANCE Act if and when it becomes federal law). Walk-through in the Safety Suite. The DEFIANCE Act (Disrupt Explicit Forged Images and Non-Consensual Edits Act) is a pending federal bill, not enacted law. It would create a federal civil cause of action for adults depicted in non-consensual intimate digital forgeries, liquidated damages of $150,000 ($250,000 with aggravating factors), 10-year statute of limitations. S.3696 (118th Cong.) passed the Senate by unanimous consent on 23 July 2024 but did not pass the House. Reintroduced as S.1837 (119th Cong.) and passed the Senate again by unanimous consent in January 2026, still pending in the House. S.146 (119th Congress), signed 19 May 2025. Criminalises knowingly publishing non-consensual intimate visual depictions of minors or non-consenting adults, including deepfakes, and requires covered platforms to remove such content within 48 hours of a valid report. What it leaves untouched, including Section 230 and stronger state statutes, is covered in what the TAKE IT DOWN Act changes. Probably yes for some scenario, but coverage is uneven. By mid-2025, roughly 30 states had specific deepfake-NCII statutes, nearly all states had broader NCII laws that may apply to AI content, and approximately 45 states had criminalised AI-generated CSAM. See the NCSL tracker or Public Citizen's tracker. DEFIANCE addresses intimate forgeries specifically. For non-sexual deepfakes, common-law theories include false light (in jurisdictions that recognise it), defamation, right of publicity, intentional infliction of emotional distress, and copyright (where you hold rights in the underlying source material). Consult a lawyer in your jurisdiction; do not contact the perpetrator before doing so. ## Cryptographic content authenticity. The Coalition for Content Provenance and Authenticity, an open standard for cryptographically signing the origin and edit history of digital content. Signed structures (Content Credentials) are embedded in the asset itself. Current spec: version 2.2 (1 May 2025). A credential is a signed assertion about a file's history rather than proof that the depicted events happened, a distinction drawn out in what Content Credentials establish, and what they do not. Steering members include Adobe, Microsoft, Google, OpenAI, Meta, BBC, Sony, and Truepic. As of 2024, TikTok was the first major social platform to attach Content Credentials to AI-generated uploads; Google integrated Content Credentials into Search and ad systems; Amazon attached them to Titan Image Generator outputs; LinkedIn displays them on uploads. ISO/IEC 21617, the international standard for asserting media authenticity, provenance, attribution, IP, and integrity. The Core Foundation (Part 1) was approved for publication at the JPEG 105th Meeting in Berlin in October 2024. Complementary to C2PA, not a competitor. Often, yes, though difficulty depends on perturbation budget. Saberi et al. (arXiv:2310.00076) showed a fundamental trade-off between evasion error and spoofing error for low-perturbation watermarks. Watermarking is a useful production signal for cooperating actors; not a closed defense against motivated adversaries. The official public reader is at contentcredentials.org/verify. Drag a file in and the reader resolves the chain. Library implementations: c2pa-rs (Rust) and c2pa-js (JavaScript), Apache-2.0. Which products are certified to sign or validate, and at what assurance level, is a public record you can read yourself: see what the C2PA conformance registry actually lists. ## Who runs imadethisup.org, its license, and how to reach us. imadethisup.org is a public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770). It is anonymously run by thought leaders from across the cybersecurity, forensics, and policy industries. There is no advertising, no sponsorship, and no third-party tracking. See About. Every claim links to a primary source, peer-reviewed paper (publisher canonical PDF or arXiv preprint), official standard, federal agency document, or originating news investigation. The full bibliography is at References. To report a broken link, email info@imadethisup.org. Yes, content is released under CC BY-NC 4.0 and the underlying code is released under the MIT License. Attribution to imadethisup.org / Global Cyber Institute is required. For commercial reuse, write info@imadethisup.org. Operating costs are covered by Global Cyber Institute's general nonprofit funding. There is no advertising, no paid placement, no sponsored content, and no cookie-based tracking. See the privacy policy for full data practices. Email info@imadethisup.org with the URL of the page in question, the specific claim, and a primary source for the correction. Corrections are reviewed weekly. Look for asymmetric eye specular highlights, diffuse hairline boundaries, glyphic background text, repeating micro-patterns, and tooth-by-tooth inconsistencies under motion. None of these is sufficient on its own, current-generation outputs often pass visual inspection. Verify the asset's Content Credential at contentcredentials.org/verify if one is present, remembering that a missing credential proves nothing on its own, for the reasons given in what Content Credentials establish, and what they do not. In late January / early February 2024, an Arup finance employee in Hong Kong made fifteen wire transfers totaling roughly USD 25 million after a video conference in which every other participant, including the supposed CFO, was an AI-generated deepfake. Arup confirmed publicly in May 2024. ## Want the full picture? A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. - The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # Working definitions for a moving field. URL: https://imadethisup.org/glossary Summary: A working glossary of synthetic-media, deepfake, and digital-forensics terms, from BEC to C2PA to PPG. Searchable, and cited where a source exists. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "alternateName": "Global Cyber Institute", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "DefinedTermSet", "name": "imadethisup.org Glossary", "url": "https://imadethisup.org/glossary", "publisher": { "@id": "https://imadethisup.org/#org" } }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "Glossary", "item": "https://imadethisup.org/glossary" } ] }, { "@type": "WebPage", "@id": "https://imadethisup.org/glossary#page", "url": "https://imadethisup.org/glossary", "about": [ { "@type": "Thing", "name": "Synthetic media", "sameAs": "https://en.wikipedia.org/wiki/Synthetic_media" }, { "@type": "Thing", "name": "Deepfake", "sameAs": "https://en.wikipedia.org/wiki/Deepfake" }, { "@type": "Thing", "name": "Digital forensics", "sameAs": "https://en.wikipedia.org/wiki/Digital_forensics" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "abstract": "The imadethisup.org glossary defines the synthetic-media, deepfake, generative-AI, and digital-forensics terms used across the site, in the specific sense the site uses them. Where a term originates in a paper, a technical standard, or a statute, the primary source is cited inline. Entries are searchable and range from business email compromise to C2PA.", "inLanguage": "en-US", "isAccessibleForFree": true, "dateModified": "2026-08-30" } ] } Skip to content Research Lab War Room Safety Suite Provenance Tools References Case law Blog Retain → MENU Home / Glossary GLOSSARY Working definitions for a moving field. We use these terms across the site in a specific way. Where a term has a primary source, a paper, a standard, or a statute, the citation is inline. Search to jump. entries · last updated 2026-08-30 In short The imadethisup.org glossary defines the synthetic-media, deepfake, generative-AI, and digital-forensics terms used across the site, in the specific sense the site uses them. Where a term originates in a paper, a technical standard, or a statute, the primary source is cited inline. Entries are searchable and range from business email compromise to C2PA. AAdversarial example An input designed to cause a machine-learning model to misclassify, often imperceptibly different from a clean input. In synthetic-media forensics, adversarial examples are used both to attack detectors and to evaluate their robustness. AASVspoof A series of community challenges on automatic speaker verification anti-spoofing, including, since 2021, a deepfake-speech detection track. See Yamagishi et al., 2021. AAudio deepfake A synthetic audio recording, typically a voice clone of a target speaker, produced by a generative model trained on or conditioned on samples of that voice. Detection benchmark: ASVspoof. Detectors carry over poorly to voice generators they were not trained on, see when audio deepfake detectors fail on new voice generators. BBEC (Business Email Compromise) A class of fraud in which the attacker impersonates a trusted contact, typically an executive, vendor, or finance counterparty, to authorize a wire transfer or change of banking details. The FBI's IC3 2024 Annual Report recorded $2.77B in U.S. BEC losses across 21,442 incidents. For the best-documented synthetic-media variant, see what the Arup deepfake actually proves. CC2PA Coalition for Content Provenance and Authenticity. An open technical standard for cryptographically signing the origin and edit history of digital content. The signed structure is called a Content Credential. Current spec: version 2.2 (1 May 2025). Products that have passed the C2PA conformance program are listed in a public registry, read in what the C2PA conformance registry actually lists. CChallenge–response An authentication pattern in which the verifier asks the asserted party for information only that party should know, or to perform an action only the real entity could perform. Useful against real-time deepfakes, see the Ferrari case (Bloomberg, 2024) and why deepfake executives fool people and what actually stops them, which explains why the check has to run outside the channel the caller used. CCISA U.S. Cybersecurity and Infrastructure Security Agency. Co-author of the September 2023 NSA/FBI/CISA Cybersecurity Information Sheet Contextualizing Deepfake Threats to Organizations (PDF). CContent Credential The signed manifest produced under the C2PA standard. Contains assertions about an asset's origin, edits, and use of AI tools, signed with X.509 certificates and embedded directly in the asset. It records what a signer asserted, not that the depicted events happened, see what Content Credentials establish, and what they do not. CCross-generator generalization The ability of a deepfake detector trained on outputs from one generator to maintain accuracy on outputs from a different generator. The central open problem in synthetic-media forensics. See Wang et al. (arXiv:1912.11035), and what a deepfake detector score does not tell you for the size of the reported drop. DDeepfake Colloquial term for synthetic media, typically face-swap or voice-clone content, produced by deep neural networks. A subset of the broader category of synthetic media. DDEFIANCE Act Pending federal bill, not enacted law. Disrupt Explicit Forged Images and Non-Consensual Edits Act. S.3696 (118th Cong.) passed Senate by unanimous consent on 23 July 2024; did not pass House. Reintroduced as S.1837 (119th Cong.); passed Senate again by unanimous consent in January 2026; still pending in House. Would, if enacted, create a federal civil cause of action for adults depicted in non-consensual intimate digital forgeries, liquidated damages of $150,000+; 10-year statute of limitations. Until it clears the House the federal regime here is criminal-only, as set out in what the TAKE IT DOWN Act changes. DDFDC Deepfake Detection Challenge dataset. 100,000+ paid-actor face-swap videos released by Meta AI in 2020 (Dolhansky et al.). DDiffusion model A class of generative model trained to invert a gradual noising process. Used in Stable Diffusion, DALL·E 3, and most modern open-weight image generators. Latent-space variant introduced by Rombach et al. (CVPR 2022). Detectors trained on GAN-family output often fail on diffusion-family output and the reverse, see why deepfake detectors fail on new generators. FFaceForensics++ Benchmark dataset of 1,000 source video sequences manipulated with four pipelines (Deepfakes, Face2Face, FaceSwap, NeuralTextures). The defacto starting point for face-manipulation detection. Rössler et al., ICCV 2019. What a reported score on it does and does not mean is covered in what a deepfake detector score does not tell you. FFakeCatcher A real-time deepfake detection method by Ciftci, Demir, and Yin (IEEE TPAMI 2020) that exploits PPG signals. Biosignal features like these are one of the few threads that survive a change of generator, see why deepfake detectors fail on new generators. FFrequency-domain analysis A forensic method that converts an image into the frequency domain (e.g., via DCT or FFT) to expose upsampling artifacts characteristic of GAN-generated content. Frank et al., ICML 2020. Those artifacts are an upsampling fingerprint of one decoder family, which is why the method does not transfer, see why deepfake detectors fail on new generators. GGAN (Generative Adversarial Network) A pair of neural networks, generator and discriminator, trained against each other. Goodfellow et al., NeurIPS 2014. IIC3 (Internet Crime Complaint Center) The FBI's online portal for receiving cybercrime complaints from the public. Publishes the annual Internet Crime Report. Reporting URL: ic3.gov. Where the report fits in the first hour of an incident is set out in building a deepfake incident-response plan for smaller firms. JJPEG Trust ISO/IEC 21617. International standard for asserting media authenticity, provenance, attribution, IP, and integrity. Core Foundation (Part 1) approved at JPEG 105 in Berlin, October 2024 (press release). LLiveness detection Active or passive verification that the subject in front of a camera or microphone is a real, live person rather than a recording, photo, or synthetic stream. Used in identity verification and conferencing anti-fraud workflows. MManifest (C2PA) The structured, signed JSON-LD claim set embedded in an asset under the C2PA standard. Contains assertions about origin, edits, and AI use, signed with an X.509 chain. NNCII (Non-Consensual Intimate Imagery) Sexual or intimate imagery shared without the depicted person's consent, including AI-generated "digital forgeries" under the (enacted) TAKE IT DOWN Act and the (still-pending) DEFIANCE Act. NNCMEC National Center for Missing & Exploited Children. Operates the Take It Down hash service for those whose intimate imagery was taken when they were under 18. PPPG (Photoplethysmography) The optical measurement of subtle skin-tone changes caused by blood circulation. Used as a deepfake forensic signal because synthetic faces do not preserve a coherent PPG signal. See FakeCatcher (TPAMI 2020). PProvenance The chain of facts about a digital asset's history, its source, the tools that created or altered it, the platforms that distributed it. Cryptographic provenance is the focus of the C2PA standard. SStable Signature A watermarking method that fine-tunes a latent-diffusion image generator to embed a recoverable binary signature in every output. Fernandez et al., ICCV 2023. SStopNCII.org A free service operated by SWGfL/Revenge Porn Helpline that hashes intimate images locally on a user's device and shares only the hash with participating platforms for proactive matching and removal. For adults 18+. stopncii.org. SSynthetic media Any image, audio, or video artifact produced or materially altered by a generative model, broader than "deepfake" and including consensual uses (film VFX, accessibility dubbing) and adversarial ones (impersonation, fraud, NCII). SSynthID Google DeepMind's family of watermarking systems for AI-generated text, image, audio, and video. SynthID-Image is documented in arXiv:2510.09263. TTAKE IT DOWN Act S.146 (119th Congress); signed into law 19 May 2025. Federal criminal prohibition on knowingly publishing non-consensual intimate visual depictions, with a 48-hour platform takedown obligation. Bill page. A practical reading for survivors, platforms, and counsel is in what the TAKE IT DOWN Act changes. TTCPA Telephone Consumer Protection Act. Federal statute regulating unsolicited calls, including (per FCC Declaratory Ruling 24-17) AI-generated voices in robocalls. VVoice clone A synthetic audio recording that imitates the voice of a specific target speaker, produced by a generative model trained on samples of that voice. Now within budget for ordinary fraud crews, see the Arup, Ferrari, LastPass, and 2019 Euler Hermes cases in the War Room, and deepfake wire fraud in real-estate closings for how the same technique lands on title and escrow workflows. WWatermark (generative) A signal embedded in AI-generated content (visible or imperceptible) that allows downstream identification of the producing model. Examples: SynthID, Stable Signature. Limits: adversarial removal, perturbation/spoofing trade-offs (Saberi et al.). Why signing works only for cooperating actors is discussed in why deepfake detectors fail on new generators. Continue Definitions are upstream of accuracy. References → The Research Lab → A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. Written with AI · citations machine-verified SectionsThe Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # Free, fast, no signup. URL: https://imadethisup.org/tools Summary: Free tools with no signup: a deepfake calibration quiz, a real-vs-synthetic slider, the C2PA verifier, and StopNCII and NCMEC hash takedown. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "alternateName": "Global Cyber Institute", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "Tools", "item": "https://imadethisup.org/tools" } ] }, { "@type": "WebPage", "@id": "https://imadethisup.org/tools#page", "url": "https://imadethisup.org/tools", "about": [ { "@type": "Thing", "name": "Deepfake", "sameAs": "https://en.wikipedia.org/wiki/Deepfake" }, { "@type": "Thing", "name": "Coalition for Content Provenance and Authenticity", "sameAs": "https://en.wikipedia.org/wiki/Content_Authenticity_Initiative" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "abstract": "imadethisup.org provides free interactive tools for synthetic-media literacy with no signup required: a deepfake calibration quiz that measures a reader's own detection accuracy, and a real-versus-synthetic comparison slider. The tools page also lists trusted third-party services for verifying content provenance and for removing non-consensual intimate imagery, including StopNCII and NCMEC.", "inLanguage": "en-US", "isAccessibleForFree": true, "dateModified": "2026-08-30" } ] } Skip to content Research Lab War Room Safety Suite Provenance Tools References Case law Blog Retain → MENU Home / Tools TOOLS Free, fast, no signup. Two interactive widgets we built into the site, and a curated list of trusted third-party services for verifying provenance and getting non-consensual content removed. We do not collect data from any of these tools beyond the standard server logs described in the privacy policy. Which products are certified to produce or check Content Credentials is itself a public record, read in what the C2PA conformance registry actually lists. PRINCIPLE Calibrate before you trust On the videos sampled for Groh et al. (PNAS 2022, n = 15,016), the leading automated detector reached ~80% and the non-recruited crowd mean also reached ~80%, with the recruited crowd mean at ~74%. The paper reports humans and the model as similarly accurate while making different kinds of mistakes. Verify what you can; default to skepticism for what you can't. (Groh et al., PNAS 2022.) In short imadethisup.org provides free interactive tools for synthetic-media literacy with no signup required: a deepfake calibration quiz that measures a reader's own detection accuracy, and a real-versus-synthetic comparison slider. The tools page also lists trusted third-party services for verifying content provenance and for removing non-consensual intimate imagery, including StopNCII and NCMEC. 01 · Tool Real-vs-Synthetic comparison slider. Drag the green divider. The right side is treated as the synthetic specimen, with forensic markers indicating common artifact zones. REAL · CAPTURED · 2024-08-11 SYNTHETIC · GAN-Δ · 99.4% ⇆ ← drag · authentic capture 50% / 50% synthetic generation · drag → Stylized teaching aid. The two halves are abstract pattern fields; there is no claim being made about a specific photograph. A confidence figure like the one in the caption describes the benchmark a detector was tuned on, not the file in front of you, see what a deepfake detector score does not tell you. 02 · Tool Spot-the-fake calibration quiz. Five specimens. The point is not a high score; it is knowing your floor before you trust your gut. Same widget as on /safety-suite. PROTOCOL Why this matters Groh et al. (PNAS 2022) ran the largest study to date and found ordinary observers performed at roughly the level of leading detection models, with both making different mistakes. Crowds combined with model predictions outperformed either alone, but inaccurate model predictions decreased human accuracy. Measured against deepfakes that were actually circulating, the models still trail trained analysts, see detector results on deepfakes found in the wild. 03 · Verified third-party services Tools we recommend, but didn't build. We do not run these services and have no affiliation with their operators. We list them because they are the canonical, primary-source utilities for the workflows described elsewhere on the site. Two of them carry caveats worth reading first: a Content Credential is a signed statement about a file's history rather than proof that the depicted events happened (what Content Credentials establish, and what they do not), and the two takedown services now sit alongside a federal 48-hour removal duty (what the TAKE IT DOWN Act changes). PROVENANCE Content Credentials Verifier Drag a file in to inspect its C2PA manifest, edit history, and signing chain. Operated by the Content Authenticity Initiative. contentcredentials.org/verify → TAKEDOWN · ADULTS StopNCII.org Hash-based takedown for adults 18+. Hashing happens locally on your device; only the hash is shared with participating platforms (Meta, TikTok, Reddit, Bumble, Snap, X, OnlyFans, more). stopncii.org → TAKEDOWN · MINORS NCMEC Take It Down For those whose intimate imagery was taken when they were under 18. Same local-hash approach; operated by the National Center for Missing & Exploited Children. takeitdown.ncmec.org → FRAUD REPORTING FBI IC3 FBI Internet Crime Complaint Center. File BEC, voice-clone, and deepfake-fraud incidents here. The Recovery Asset Team froze 66% of fraudulent BEC transfers in 2024 when alerted promptly. ic3.gov → CRIMINAL TIPS FBI Tips For sexual or minor-involving synthetic imagery, including non-consensual deepfakes prosecutable under the TAKE IT DOWN Act. tips.fbi.gov → SUPPORT CCRI Safety Center Free Cyber Civil Rights Initiative helpline and resource library for survivors of image-based abuse. cybercivilrights.org → EVIDENCE Wayback Machine Capture URLs with a verifiable timestamp before content is removed. Operated by the Internet Archive. archive.org/web → DEVELOPER c2pa-rs / c2pa-js Open-source reference implementations of the C2PA standard. Apache-2.0 licensed. Use these to add Content Credentials signing or verification to your own application. github.com/contentauth → LEGAL TRACKER NCSL deepfake legislation tracker National Conference of State Legislatures' running tracker of deepfake-related bills and laws across the U.S. states. ncsl.org → Continue Tools without context are toys. Read the page that frames each one. The Safety Suite → The War Room → Provenance → A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. Written with AI · citations machine-verified SectionsThe Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Trademarks, statutes, agency names, and third-party product references appear for identification and citation only and do not imply endorsement, affiliation, or sponsorship. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. We do not sell, rent, or trade visitor data. California, Virginia, Colorado, Connecticut, Utah, Texas, and EU/UK residents may request access, correction, or deletion of personal information by writing info@imadethisup.org. Read the full privacy policy → ======================================================================== # Short, sourced notes on a moving field. URL: https://imadethisup.org/blog Summary: Short, sourced notes on synthetic media, case analyses, research summaries, and policy explainers from the editorial team at imadethisup.org. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "alternateName": "Global Cyber Institute", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "Blog", "@id": "https://imadethisup.org/blog#blog", "name": "imadethisup.org Blog", "url": "https://imadethisup.org/blog", "publisher": { "@id": "https://imadethisup.org/#org" }, "about": [ { "@type": "Thing", "name": "Synthetic media", "sameAs": "https://en.wikipedia.org/wiki/Synthetic_media" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "abstract": "The imadethisup.org blog publishes short, sourced notes on synthetic media: case analyses, research summaries, and policy explainers. Every post cites primary sources, statutes, court filings, peer-reviewed papers, and federal agency documents, and links to the same reference collection used across the rest of the site. The full archive is available as an RSS feed.", "inLanguage": "en-US", "isAccessibleForFree": true, "dateModified": "2026-08-30" }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "Blog", "item": "https://imadethisup.org/blog" } ] } ] } Skip to content Research Lab War Room Safety Suite Provenance Tools References Case law Blog Retain → MENU Home / Blog BLOG Short, sourced notes on a moving field. Case analyses, research summaries, and policy explainers from the editorial team. Every post links to the same primary sources we cite elsewhere on the site. Available as RSS. Every post carries one or two topic tags: case, research, law, provenance, business, academic, personal. Use the search box and the topic buttons below to narrow the archive. In short The imadethisup.org blog publishes short, sourced notes on synthetic media: case analyses, research summaries, and policy explainers. Every post cites primary sources, statutes, court filings, peer-reviewed papers, and federal agency documents, and links to the same reference collection used across the rest of the site. The full archive is available as an RSS feed. All Case Research Law Provenance Business Academic Personal 31 of 31 posts, newest first. 2026-08-30 What invisible watermarks can and cannot survive. Research on attacking invisible watermarks reveals removal, forgery and detection-degradation are distinct threats. Robustness is conditional, not absolute. PROVENANCE Read → - 2026-08-30 Reporting non-consensual imagery: what one audit found. An audit of reporting mechanisms for non-consensual intimate imagery shows different outcomes depending on which platform route victims use. PERSONAL Read → - 2026-08-29 Why deepfake impersonation works, and what stops it. Deepfake attacks on executives target decision-making, not media detection. The control that works is procedural verification outside the attack channel. BUSINESS Read → - 2026-08-29 When audio deepfake detectors fail on new voice generators. Audio deepfake detectors trained on one set of voice generators often fail on others. What the research says about using detection results in reports. RESEARCH Read → - 2026-08-29 What the US AI Safety Institute says still needs research. The US AI Safety Institute has published specific research gaps in synthetic content mitigation. Here is what it says does not work yet. RESEARCH Read → - 2026-08-29 Penalties for breaching the EU AI Act's disclosure rules. Article 99(4)(g) puts breaches of the AI Act's synthetic-content transparency duties in the EUR 15 million or 3 percent tier. Who enforces, and how fines are set. LAW Read → - 2026-08-29 What Content Credentials establish, and what they do not. Content Credentials are signed statements about a file's history, not proof that the depicted events happened. Their absence is uninformative on its own. PROVENANCE Read → - 2026-08-29 Detector results on deepfakes found in the wild. Deepfake-Eval-2024 tested detectors on deepfakes actually circulating online. Reported AUC fell by 45 to 50 percent against laboratory benchmarks. RESEARCH Read → - 2026-08-29 Synthetic media disclosure obligations now in force. Providers and deployers must mark and disclose AI-generated content under Article 50. Requirements took effect 2 August 2026. LAW Read → - 2026-08-29 What the C2PA conformance registry actually lists. The C2PA registry lists seven devices with certified Content Credentials. Which camera makers appear, which haven't, and how you can verify it yourself. PROVENANCE Read → - 2026-08-29 What a deepfake detector score does not tell you. Detectors score highly on the benchmark they trained on. Measured performance on generators released later is a different and much weaker number. RESEARCH Read → - 2026-06-15 Reg S-P’s new baseline for smaller firms. The SEC's amended Reg S-P turns a dusty privacy rule into a cybersecurity mandate, written incident response, 30-day customer breach notice, and vendor oversight, with the smaller-firm deadline now here. BUSINESSLAW Read → - 2026-06-15 Defending AI-assisted e-discovery review. TAR has been judicially blessed for over a decade and generative-AI review is joining the workflow, but the hard part is defending the process: proportionality, validation by recall and precision, and a human who certifies under Rule 26(g). LAWRESEARCH Read → - 2026-06-15 AI governance: what the CISO actually owns. When an organization adopts AI, governance lands on the security chair, the CISO's remit across NIST AI RMF, ISO/IEC 42001, the EU AI Act, deepfake risk, and board reporting. RESEARCHBUSINESS Read → - 2026-06-15 Arbitration’s new rules for AI evidence. The JAMS AI Disputes Rules show how to gate AI-touched evidence, secured-environment expert access to models and data, disclosure of AI use, and proportionality. LAWRESEARCH Read → - 2026-06-15 AI tools and attorney-client privilege. Pasting client material into a third-party AI tool can breach confidentiality and waive privilege, what ABA Rule 1.6, Formal Opinion 512, and FRE 502 require counsel to do. LAWBUSINESS Read → - 2026-06-15 A deepfake incident-response plan for small firms. A checklist-driven playbook for voice-clone and deepfake incidents, detect, contain, preserve, notify, recover, grounded in NIST SP 800-61, FBI IC3, and CISA guidance. BUSINESSCASE Read → - 2026-06-15 Agentic AI: who answers when an agent trades?. Autonomous AI agents are trading and drafting disclosures with little supervision, so when one breaks the securities laws, who answers? The SEC's "AI washing" cases and why agency law keeps the firm liable. RESEARCHLAW Read → - 2026-06-15 The hallucination tax on unverified AI citations. A fabricated AI citation is no glitch; it's a self-inflicted breach of the duty of competence that taxes the whole proceeding in sanctions, wasted hours, and lost credibility. LAWRESEARCH Read → - 2026-06-15 “Follow the money” is no longer enough. A cloned voice induces the wire and on-chain layering erases the trail, why financial tracing alone no longer proves modern fraud, and what investigators must add. LAWBUSINESS Read → - 2026-06-15 Who decides when digital evidence is contested?. When adversaries deadlock over whether digital or AI evidence is authentic, courts can appoint a neutral technical authority under FRCP 53 or FRE 706 whose only client is the record. LAWRESEARCH Read → - 2026-06-15 Investigating fraud when the evidence can be fake. Generative AI lets fraudsters fabricate documents and voices, and lets investigators be misled by fluent synthetic artifacts. How curiosity and rigor keep an investigation honest. CASERESEARCH Read → - 2026-06-15 Deepfake wire fraud in real-estate closings. Voice and video impersonation is hitting title, escrow, and closing workflows. The break point isn't the model; it's the missing out-of-band callback on wiring instructions. CASEBUSINESS Read → - 2026-06-15 Deepfakes and evidence integrity in family court. In custody court a fabricated clip lands before anyone proves it fake, but Rules 901 and 902, used affirmatively, put the authentication burden back where it belongs. LAWRESEARCH Read → - 2026-06-15 Authenticating AI evidence: is Rule 901 enough?. Rule 901's lenient gate met its match in generative AI, 901(b)(9), 902(13)-(14), proposed Rule 707, and what litigators should do now. LAWACADEMIC Read → - 2026-06-15 Deepfakes are reshaping workplace harassment. Synthetic intimate imagery of a coworker is a workplace event, not a private one, and Title VII reaches conduct that never happened at the office. LAWPERSONAL Read → - 2026-06-15 When the file lies about itself. Generative AI can fabricate the hidden author, date, and provenance metadata we rely on to prove a file is authentic. How to verify with hashing and Content Credentials. RESEARCHPROVENANCE Read → - 2026-06-15 The copyright fight over generative-AI creations. Two copyright fights collide over generative AI, whether AI output can be owned, and whether training on copyrighted works was lawful. LAWRESEARCH Read → - 2026-04-27 What the Arup deepfake actually proves. The break point wasn't the model. It was the absence of an out-of-band callback above the wire-transfer threshold. CASEBUSINESS Read → - 2026-04-27 Why deepfake detectors fail on new generators. A short tour of the cross-generator generalization gap, the field's central open problem. RESEARCHACADEMIC Read → - 2026-04-27 What the TAKE IT DOWN Act changes. A practical reading of S.146 for survivors, platforms, and counsel. LAWPERSONAL Read → More posts coming. Suggest a topic at info@imadethisup.org. A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. No advertising. No third-party trackers. Source-coded; corrections welcome at info@imadethisup.org. - The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only and reflects the views of Global Cyber Institute, Inc. and contributing researchers as of the date of publication. It does not constitute legal, investigative, technical, or professional advice, and no attorney–client, consultant–client, or fiduciary relationship is created by accessing or relying on the material. Statutes, case law, threat actors, generative-model capabilities, and detection methods evolve quickly; users should verify current authority before acting. Read the full disclaimer → We collect the minimum information needed to operate the site. Our host records standard server logs (IP, user agent, request time, referring URL, response code) for security and abuse prevention; logs are retained no longer than 30 days. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. Read the full privacy policy → ======================================================================== # Find the right expert for the matter in front of you. URL: https://imadethisup.org/retain-an-expert Summary: Retain an independent expert on deepfakes and synthetic media for litigation, expert-witness work, investigations, or corporate consulting. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "alternateName": "Global Cyber Institute", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "Service", "name": "Retain a deepfake expert", "description": "Independent referral coordination for deepfake and synthetic-media expert engagements: litigation/expert-witness, investigation, corporate consulting, and press/media work.", "provider": { "@id": "https://imadethisup.org/#org" }, "url": "https://imadethisup.org/retain-an-expert", "serviceType": "Expert referral", "about": [ { "@type": "Thing", "name": "Deepfake", "sameAs": "https://en.wikipedia.org/wiki/Deepfake" }, { "@type": "Thing", "name": "Digital forensics", "sameAs": "https://en.wikipedia.org/wiki/Digital_forensics" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "abstract": "Global Cyber Institute coordinates introductions to independent experts on deepfakes and synthetic media, covering litigation and expert-witness work, internal investigations, corporate consulting, and press commentary. Inquiries submitted through the form on this page are routed to a vetted examiner. The organisation is a United States 501(c)(3) nonprofit and the experts are independent.", "inLanguage": "en-US", "isAccessibleForFree": true, "dateModified": "2026-08-30" }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "Retain an expert", "item": "https://imadethisup.org/retain-an-expert" } ] }, { "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "How are experts vetted?", "acceptedAnswer": { "@type": "Answer", "text": "Vetting includes credential review (peer-reviewed publication record, prior expert-witness experience, institutional affiliations), conflicts screening against the matter you describe, and a check for any financial relationship with platforms, detection vendors, or generative-AI providers whose work is at issue. Experts who do not pass independence review are not surfaced for that matter." } }, { "@type": "Question", "name": "Does Global Cyber Institute receive any payment for referrals?", "acceptedAnswer": { "@type": "Answer", "text": "No. The Institute does not take referral fees, retainers, kickbacks, or commissions. Fee terms are negotiated directly between you and the expert. The referral function is a public-service activity of the 501(c)(3)." } }, { "@type": "Question", "name": "What happens after I submit?", "acceptedAnswer": { "@type": "Answer", "text": "Your inquiry lands in our shared editorial mailbox at info@imadethisup.org. We confirm receipt, ask any clarifying questions, and route the matter to one or more vetted experts. They reply directly. We do not retain the substance of your submission longer than needed to make the introduction; see the privacy policy." } }, { "@type": "Question", "name": "Can I request a specific expert?", "acceptedAnswer": { "@type": "Answer", "text": "Yes. If you have a name in mind, include it in the description field. We will check our roster and conflicts and, if available, route directly. If the named expert is not available; we will offer alternatives." } }, { "@type": "Question", "name": "I'm a journalist on deadline. Can I jump the queue?", "acceptedAnswer": { "@type": "Answer", "text": "Mark your inquiry \"Immediate\" in the urgency field. Press inquiries with a deadline of less than 24 hours are routed within hours of receipt during business days. Outside business hours, write to info@imadethisup.org with \"URGENT PRESS\" in the subject line." } }, { "@type": "Question", "name": "I represent a victim. Is this the right channel?", "acceptedAnswer": { "@type": "Answer", "text": "Yes, for litigation or investigation. For immediate practical help with non-consensual intimate imagery (independent of a legal matter), the fastest first step is the hash-takedown services on the Safety Suite page (StopNCII.org for adults, NCMEC Take It Down for under-18). Use this form when you also need a forensic or expert-witness role." } }, { "@type": "Question", "name": "Does this create an attorney–client or expert-witness relationship?", "acceptedAnswer": { "@type": "Answer", "text": "No. Submitting this form is an inquiry only. No fiduciary, attorney–client, consultant–client, or expert-witness relationship is created until the expert and you (or your client) execute a written engagement agreement. Until then, do not transmit privileged or confidential material through this channel." } } ] } ] } Skip to content Research Lab War Room Safety Suite Provenance Tools References Case law Blog Retain → MENU Home / Retain an expert RETAIN A DEEPFAKE EXPERT Find the right expert for the matter in front of you. Global Cyber Institute coordinates introductions to independent experts on deepfakes and synthetic media, across litigation, investigation, corporate consulting, and press. Submit the form below and we will route your inquiry to a vetted expert appropriate to the matter, jurisdiction, and timeline. Independent Experts have no financial relationship to platforms, vendors, or commercial detection products. Conflicts checked at intake. Discreet Inquiries are handled confidentially. We share only the minimum information needed to match you to an expert. See privacy policy. In short Global Cyber Institute coordinates introductions to independent experts on deepfakes and synthetic media, covering litigation and expert-witness work, internal investigations, corporate consulting, and press commentary. Inquiries submitted through the form on this page are routed to a vetted examiner. The organisation is a United States 501(c)(3) nonprofit and the experts are independent. 01 · What we cover Five common kinds of deepfake expert engagement. LITIGATION Expert-witness and consulting Deposition, declaration, and trial-testimony support from digital forensic expert witnesses in civil and criminal matters involving alleged deepfakes, voice clones, non-consensual intimate forgeries (NCII), or AI-altered evidence. Pre-litigation analysis and Daubert-aware report drafting. INVESTIGATION Internal and incident-response Forensic analysis of suspect imagery, audio, or video; chain-of- custody documentation; integration with C2PA Content Credentials workflows; coordination with law enforcement (FBI IC3, NCMEC) and specialised counsel. When a matter calls for it; we can help you retain a forensic expert to lead the technical examination. CORPORATE Risk & protocol consulting Board briefings on synthetic-media risk; design of authentication protocols (out-of-band callback, challenge phrase, liveness on video) for finance, executive, and AP teams; tabletop exercises; crisis-communications scaffolds. PRESS Background & on-record commentary Background briefings, on-record statements, and technical commentary for journalists covering deepfake incidents, the DEFIANCE Act / TAKE IT DOWN Act, FCC TCPA AI-voice rule, or related policy. EDUCATION Expert speakers & training Conference keynotes, CLE/CPD-eligible training modules for law firms and in-house counsel, university guest lectures, and governmental advisory engagements. OTHER Bespoke matters Standards-body participation, peer review, policy testimony, or other expert engagements not listed above. Tell us what you need in the description field below. 02 · Inquiry Tell us what expert help your matter needs. All fields marked with a green dot are required. Replies typically within one business day; urgent matters are triaged ahead. RECEIVED Thank you, your inquiry is on its way. We'll reply from info@imadethisup.org, typically within one business day; urgent matters are triaged ahead. If your email app opened instead, just press send to complete your message. Company website Your name ● Email ● Organisation Firm, in-house team, agency, outlet Your role e.g. counsel, partner, GC, journalist, security lead Type of matter ● Litigation / expert-witness Internal investigation / incident response Corporate consulting / protocols / training Press / media commentary Education / speaking / CLE / governmental Other (describe below) Urgency ● Immediate, within 24 hours (active incident, deposition, deadline) Within a week Standard, within a month Exploratory, no current deadline Jurisdiction (optional) Brief description of the matter ● Do not include privileged content, full names of victims, or detail you would not put in an unsolicited email. We can set up a more secure channel after first contact. I understand this submission contains no privileged or confidential information; that submitting it does not create an attorney–client, consultant–client, or expert-witness relationship; and that I have read the disclaimer and privacy policy. Send inquiry → Or write directly: info@imadethisup.org PRINCIPLE Independence first We do not refer to experts who have a financial relationship to a specific detection product, social platform, or generative-AI vendor whose tooling is at issue in the matter. Conflicts are checked at intake. FEES Set by the expert, not by us Global Cyber Institute does not take a referral fee, retainer, or commission. Fee terms are negotiated directly between you and the expert. The Institute remains a 501(c)(3) nonprofit; the referral function is a public-service activity. URGENT? Do these things first For active financial fraud: FBI IC3 within 24 hours. For non-consensual intimate imagery: StopNCII.org (adults) or NCMEC Take It Down (under-18). For sexual or minor-involving imagery: tips.fbi.gov. For immediate danger: 911. 03 · Frequently asked Retention FAQ. How are experts vetted? Vetting includes credential review (peer-reviewed publication record, prior expert-witness experience, institutional affiliations), conflicts screening against the matter you describe, and a check for any financial relationship with platforms, detection vendors, or generative-AI providers whose work is at issue. Experts who do not pass independence review are not surfaced for that matter. Does Global Cyber Institute receive any payment for referrals? No. The Institute does not take referral fees, retainers, kickbacks, or commissions. Fee terms are negotiated directly between you and the expert. The referral function is a public-service activity of the 501(c)(3). What happens after I submit? Your inquiry lands in our shared editorial mailbox at info@imadethisup.org. We confirm receipt, ask any clarifying questions, and route the matter to one or more vetted experts. They reply directly. We do not retain the substance of your submission longer than needed to make the introduction; see the privacy policy. Can I request a specific expert? Yes. If you have a name in mind, include it in the description field. We will check our roster and conflicts and, if available, route directly. If the named expert is not available; we will offer alternatives. I'm a journalist on deadline. Can I jump the queue? Mark your inquiry "Immediate" in the urgency field. Press inquiries with a deadline of less than 24 hours are routed within hours of receipt during business days. Outside business hours, write to info@imadethisup.org with "URGENT PRESS" in the subject line. I represent a victim. Is this the right channel? Yes, for litigation or investigation. For immediate practical help with non-consensual intimate imagery (independent of a legal matter), the fastest first step is the hash-takedown services on the Safety Suite page (StopNCII.org for adults, NCMEC Take It Down for under-18). Use this form when you also need a forensic or expert-witness role. Does this create an attorney–client or expert-witness relationship? No. Submitting this form is an inquiry only. No fiduciary, attorney–client, consultant–client, or expert-witness relationship is created until the expert and you (or your client) execute a written engagement agreement. Until then, do not transmit privileged or confidential material through this channel. ContinueWant to learn first, decide later? The War Room → The Safety Suite → The Research Lab → A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770). No advertising. No third-party trackers. Corrections: info@imadethisup.org. Written with AI · citations machine-verified Sections The Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share ======================================================================== # A public-education project on synthetic media, built to outlast its founders. URL: https://imadethisup.org/about Summary: A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit. Anonymously edited. No advertising, sponsorship, or tracking. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "alternateName": "Global Cyber Institute", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk.", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ] }, { "@type": "AboutPage", "name": "About, imadethisup.org", "url": "https://imadethisup.org/about", "isPartOf": { "@id": "https://imadethisup.org/#org" } }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "About", "item": "https://imadethisup.org/about" } ] }, { "@type": "WebPage", "@id": "https://imadethisup.org/about#page", "url": "https://imadethisup.org/about", "about": [ { "@type": "Thing", "name": "Synthetic media", "sameAs": "https://en.wikipedia.org/wiki/Synthetic_media" } ], "speakable": { "@type": "SpeakableSpecification", "cssSelector": [ ".answer-block p", "h1" ] }, "abstract": "imadethisup.org is published by Global Cyber Institute, Inc., a United States 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. The site is edited anonymously as a matter of policy, carries no advertising or sponsorship, and uses no third-party tracking. Editorial content is licensed CC BY-NC 4.0.", "inLanguage": "en-US", "isAccessibleForFree": true, "dateModified": "2026-08-30" } ] } Skip to content Research LabWar RoomSafety SuiteProvenanceToolsReferencesCase lawBlog Retain → MENU Home / About ABOUT A public-education project on synthetic media, built to outlast its founders. imadethisup.org is published by Global Cyber Institute, Inc., a U.S. 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. In short imadethisup.org is published by Global Cyber Institute, Inc., a United States 501(c)(3) nonprofit (EIN 84-2148770) advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk. The site is edited anonymously as a matter of policy, carries no advertising or sponsorship, and uses no third-party tracking. Editorial content is licensed CC BY-NC 4.0. 01 · Mission Mission: make synthetic-media research readable in one place and traceable to source. Generative models have collapsed the cost of producing convincing imagery, audio, and video to roughly zero. The cost of verifying any one piece of media has not fallen at the same rate. The asymmetry between generation and verification is the structural problem of the next decade, for researchers studying detection, for organizations protecting wire transfers and reputations, and for individuals whose faces and voices are now training data for the next attack. imadethisup.org exists to make the field's primary research, standards, and case data readable in one place, traceable to source, and free of charge. Every claim links to a primary source. Every recommendation is defensible against current authority on the date of publication. The project's only economic model is its parent nonprofit's general funding; there is no advertising, no paid placement, no sponsored content, and no behavioural tracking. Corrections are reviewed weekly and welcomed at info@imadethisup.org. 02 · Editorial Anonymously edited, on principle: why imadethisup.org puts no names on the masthead. The site is anonymously edited by thought leaders from across the cybersecurity, digital-forensics, and policy industries. We have made a deliberate choice not to put names on the masthead. Editorial anonymity reduces the surface for retaliatory targeting of contributors who write critically about specific incidents, actors, or vendors; it shifts attention from the editor to the citation. Reasonable people disagree about this trade-off. We accept the trade. Anonymity does not extend to accountability. Every claim is attached to a primary source readers can verify. The site, the parent organization, and the contact channel are public and unambiguous. Requests for correction are taken seriously and processed weekly. 03 · Method How imadethisup.org sources and verifies every claim. We prefer, in this order: peer-reviewed papers (publisher canonical PDFs and arXiv preprints); official statutes and agency documents; standards-body publications; and originating news investigations. We do not rely on aggregator summaries when the primary source is reachable. Where the field has moved past a previously cited finding, we either update the citation or remove the claim. Where a claim cannot be sourced to authority that holds up today, we omit it rather than soften it. The full bibliography is at the reference collection. 04 · License Reuse, freely: CC BY-NC 4.0 for the content, MIT for the code. Editorial content on imadethisup.org is released under Creative Commons BY-NC 4.0: free to copy, redistribute, and adapt for any non-commercial purpose, with attribution to imadethisup.org / Global Cyber Institute. Source code is released under the MIT License. For commercial reuse, including for-profit press, training data, or paid education programs, write info@imadethisup.org. ContinueFrom mission to method. Contact → References → Blog → A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770). No advertising. No third-party trackers. Corrections: info@imadethisup.org. Written with AI · citations machine-verified SectionsThe Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only. It does not constitute legal, investigative, technical, or professional advice. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. Read the full privacy policy → ======================================================================== # A site about synthetic media owes you a provenance statement about itself. URL: https://imadethisup.org/ai-disclosure Summary: How AI is used in producing this site, where it assists, where it is prohibited, and how every citation is verified before publication. ======================================================================== imadethisup.org is written with AI assistance and published under editorial responsibility. Large language models help with research triage, drafting, and structural editing. Weekly blog posts are researched, drafted and published by an automated agent without a human reading them first; every citation in those posts is machine-verified against its primary source, and a post whose sourcing fails that check is not published. Pillar pages, the glossary, references and organisation pages are hand-authored and human-reviewed. No photorealistic imagery on this site is AI-generated. ## Why imadethisup.org publishes an AI disclosure at all This project exists to argue that provenance should be disclosed rather than assumed. It would be incoherent to make that argument while staying silent about how our own pages are made. Most sites are not yet expected to publish a disclosure like this one. We think that expectation is coming, and we would rather be early than defensive. This page is written to be specific. "AI was used responsibly" is not a disclosure; it is a slogan. What follows is the actual division of labour. ## Where AI is used Research triage. Large language models are used to survey a topic, surface candidate sources, and summarise long primary documents, agency releases, final rules, court opinions, and peer-reviewed papers, so that a human editor can decide which ones are worth reading in full. The model narrows the field. It does not decide what is true. Drafting and structural editing. Article drafts, headings, summaries, and the "In short" answer blocks at the top of each post are produced with model assistance from source material and editorial direction, then revised by a human editor. Where an answer block or FAQ summarises an article; it is composed only from claims the article already makes and already cites. Site code and build tooling. The HTML, CSS, and the Node scripts in /scripts that generate this site's link-preview cards, structured data, and machine-readable indexes were written with AI assistance. The site is hand-maintained static HTML with no framework and no build step beyond those scripts. Link-preview cards. The 1200×630 OpenGraph card for each article is produced by a deterministic template script that typesets the article's own headline, topic tag, and date. It is code, not an image model. No card contains generated imagery. Weekly blog posts are published automatically. Once a week an automated editorial agent selects a topic, researches it, drafts it, verifies every citation against its primary source, and publishes it to this site without a human reading it first, provided every check passes. The pillar pages, glossary, references, and organisation pages are not produced this way; those remain hand-authored and human-reviewed. We disclose this because a site about synthetic media does not get to be vague about how its own content is made. ## Where AI is not used No synthetic photography, ever. This site publishes no AI-generated photographs, no photorealistic imagery, and no photographs of people at all. Every diagram is hand-authored SVG. A site that documents the harms of synthetic imagery does not get to decorate itself with it. No unverified citations. Citations are never accepted from a model's output on trust. Every citation in an automatically published post is fetched from its primary source and checked, source by source, against the specific claim it is attached to. A post whose sourcing fails that check is not published at all, not trimmed and not published without the failing citation. For hand-authored pages a human performs the same check by opening every source. This is the discipline we describe at length in our writing on the cost of unverified AI citations, and it would be indefensible to describe that duty and then not perform it. No synthetic quotations or attributed statements. Quotations from named individuals, agencies, and opinions are transcribed from the source document. A model is never asked to reconstruct or paraphrase what someone said and have it presented as a quotation. No generated legal, investigative, or safety advice. The operational guidance on this site, the authentication protocol, the incident-response steps, the reporting workflows, derives from named federal guidance, published standards, and documented cases, all cited inline. It is not a model's improvisation. It remains educational material, not professional advice; see the disclaimer. ## Editorial control over AI-published posts, without pre-publication reading No person reads an automatically published post before it goes live. Editorial control is still exercised, and it is worth being precise about where, because "nobody read it" and "nobody decided anything" are different claims and only the first is true here. Each post is written from a brief that a person prepared: the topic, the specific sources the post may draw on, the facts those sources were confirmed to state, and the angle. The agent cannot choose its own subject and cannot introduce a source that is not in the brief. The constraints it writes under, and the checks that decide whether the result publishes at all, were set by people. Global Cyber Institute, Inc. holds editorial responsibility for everything on this site, including posts no one read first. When a post publishes, an email goes to the editor listing what went live, the claims it rests on, the verification verdict recorded for each, and every source with its link. The post stays live unless somebody raises a correction. Publication is the beginning of review here rather than the end of it, which is a weaker guarantee than pre-publication reading and is stated as the weaker thing it is. We are deliberate about what that notification does and does not establish. Sending a message nobody is obliged to read shows that a message was sent, and nothing more. It does not mean a person read the post, and no page on this site will tell you otherwise. What it buys is speed: an editor who does read it can correct or withdraw a post quickly, and a reader who finds an error can trigger the same thing. If you find one, a broken link, or a citation that does not support the claim attached to it, write to info@imadethisup.org. Substantive corrections are noted on the page rather than quietly patched. ## What "verified" means for an AI-published post Five checks run before an automatically produced post reaches this site, and every one of them fails closed. A failure publishes nothing rather than publishing something weaker. - Citation verification. Each source is fetched and checked against the specific claim it supports. Any verdict other than "supports", including a source that cannot be reached, stops the run. An unverifiable citation is indistinguishable from a fabricated one. - Structural audit. Structured data must parse, the canonical must match the page's own route, no internal link may be dead, and the post must appear consistently across the sitemap, the feed, and the machine-readable index. - Editorial constraints. A repository-wide check enforces the site's editorial policies before anything is committed. - Duplication. A proposed topic that substantially repeats an existing post is rejected. - Cost ceiling. Each run is capped, and the cap is enforced before each step rather than measured afterwards. A week with no post is an acceptable outcome. A week with a fabricated citation is not. ## What a human checks on the hand-authored pages of imadethisup.org The pillar pages, glossary, references, FAQ, and organisation pages are written and reviewed by people. Each passes the same four checks, performed by a person: - Every cited source is opened, read, and confirmed to say what the article claims it says. - Every statutory citation is checked for current status, enacted, pending, amended, or superseded. Where a bill has not become law, the article says so explicitly. - Every factual assertion is traced to a primary source: a peer-reviewed paper, an official statute, a federal agency document, or the originating news investigation. - The full text is read end to end for accuracy and tone, and the editor takes responsibility for it. ## The limitation we cannot engineer away: language models fabricate confidently Language models produce fluent, confident text regardless of whether the underlying claim is correct, and they can fabricate citations, dates, and metadata that look entirely ordinary. We have written about that failure mode in both file metadata and legal citations. Our verification process is designed on the assumption that the model will sometimes be wrong and will not signal it. That process is human on the pages people write and automated on the posts the agent publishes, and neither kind of check is infallible. If you find an error, a broken link, or a citation that does not support the claim attached to it, please write to info@imadethisup.org. Corrections are reviewed weekly, and substantive corrections are noted on the page itself rather than quietly patched. ## AI crawlers are welcome here We do not restrict AI crawling. Our robots.txt explicitly permits GPTBot, OAI-SearchBot, ClaudeBot, Google-Extended, PerplexityBot, CCBot, Applebot-Extended and others, and we publish an llms.txt index plus a full-text export for machine consumers. The content is licensed CC BY-NC 4.0 and the purpose of the project is the broadest possible public reach. If an answer engine is going to summarise this subject for someone in a crisis; we would rather it summarised material that is sourced than material that is not. We ask one thing in return, which the licence already requires: attribute the material and link back to the page, so the reader can reach the primary sources themselves. ## Content provenance Where we publish or republish media that carries C2PA Content Credentials, we preserve the manifest rather than stripping it. The reasoning behind that commitment is set out on the provenance page. ## Changes to the AI disclosure This page is versioned with the site and carries a last-updated date. If our use of these tools changes materially, this page changes first. ======================================================================== # One mailbox. URL: https://imadethisup.org/contact Summary: One mailbox at info@imadethisup.org for press, corrections, collaboration, takedown requests, and privacy enquiries. We read all of them. ======================================================================== - { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://imadethisup.org/#org", "name": "Global Cyber Institute, Inc.", "taxID": "84-2148770", "nonprofitStatus": "Nonprofit501c3", "email": "info@imadethisup.org", "url": "https://imadethisup.org/", "contactPoint": { "@type": "ContactPoint", "contactType": "customer support", "email": "info@imadethisup.org", "availableLanguage": "English" }, "alternateName": "Global Cyber Institute", "logo": { "@type": "ImageObject", "url": "https://imadethisup.org/assets/svg/logo-mark.png", "width": 512, "height": 512 }, "sameAs": [ "https://projects.propublica.org/nonprofits/organizations/842148770" ], "description": "501(c)(3) nonprofit advancing research and literacy in cybersecurity, digital forensics, and synthetic-media risk." }, { "@type": "ContactPage", "url": "https://imadethisup.org/contact", "isPartOf": { "@id": "https://imadethisup.org/#org" }, "dateModified": "2026-08-30" }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://imadethisup.org/" }, { "@type": "ListItem", "position": 2, "name": "Contact", "item": "https://imadethisup.org/contact" } ] } ] } Skip to content Research LabWar RoomSafety SuiteProvenanceToolsReferencesCase lawBlog Retain → MENU Home / Contact CONTACT One mailbox. For press inquiries, corrections, collaboration, takedown questions, and privacy requests, write the same address. Global Cyber Institute, Inc. does not maintain a public mailing address; correspondence is conducted by email. EMAIL info@imadethisup.org Replies typically within a week. Time-sensitive takedown or fraud-incident requests are triaged ahead of routine correspondence. Press Background, on-record statements, expert references on synthetic-media incidents. Corrections Include the URL, the specific claim, and the primary source for the correction. Collaboration Researchers, journalists, and organizations seeking to share materials or co-publish. Takedown / abuse Imagery hosted on imadethisup.org. For content on third-party platforms, see /safety-suite. Privacy / data rights Access, correction, or deletion of personal information held by us. See our privacy policy. If your matter is urgent We are an educational nonprofit, not an emergency service. Active financial fraudNotify your bank's fraud team and file with the FBI Internet Crime Complaint Center within 24 hours: ic3.gov. Non-consensual intimate imageryHash and submit to StopNCII.org (adults 18+) or NCMEC Take It Down (under-18 imagery). Crime in progress / immediate dangerIn the United States, dial 911. For non-immediate FBI tips: tips.fbi.gov. A public-education project of Global Cyber Institute, Inc., a 501(c)(3) nonprofit (EIN 84-2148770). No advertising. No third-party trackers. Corrections: info@imadethisup.org. Written with AI · citations machine-verified SectionsThe Research Lab - The War Room - The Safety Suite - Provenance - References - Case law - Blog - FAQ - Glossary - Tools - Retain an expert - Sitemap - About - Contact - Disclaimer - AI disclosure - Privacy - Do Not Sell or Share Content on imadethisup.org is provided for general educational and informational purposes only. It does not constitute legal, investigative, technical, or professional advice. To report an inaccuracy, write info@imadethisup.org. Read the full disclaimer → We collect the minimum information needed to operate the site. We do not set cross-site cookies, fingerprint visitors, or transmit personal data to third parties for advertising. Read the full privacy policy → ======================================================================== # No part of this site is legal, investigative, technical, or professional advice. URL: https://imadethisup.org/disclaimer Summary: Educational content only. Nothing here is legal, investigative, technical, or professional advice, and reading it forms no relationship. ======================================================================== ## Educational use only The content published on imadethisup.org (the "Site") is provided by Global Cyber Institute, Inc. ("GCI") for general educational and informational purposes only. The Site reflects the views of GCI, its editors, and contributing researchers as of the date of publication. Nothing on the Site is intended to constitute legal, investigative, regulatory, technical, financial, medical, or other professional advice; nothing on the Site creates an attorney–client, consultant–client, fiduciary, or any other professional relationship between you and GCI, its editors, or any contributor. You should consult appropriately credentialed professionals for advice that responds to your specific facts. ## No warranty; field is changing rapidly The Site is provided on an "as-is" and "as-available" basis. GCI makes no representations or warranties of any kind, express or implied, with respect to the accuracy, currency, completeness, fitness for a particular purpose, non-infringement, or availability of the Site or any information, product, service, citation, or related graphic contained on the Site. Statutes, case law, agency guidance, threat actors, generative-model capabilities, and detection methods evolve rapidly; users must verify current authority before acting in reliance on any material on the Site. ## Citation, attribution, and trademark notice Trademarks, statutes, agency names, and third-party product or platform references appearing on the Site appear for identification, citation, comparison, criticism, news reporting, teaching, scholarship, or research purposes only. They do not imply endorsement, sponsorship, affiliation, or partnership between GCI and any referenced party. References to third-party services (including but not limited to StopNCII.org, NCMEC's Take It Down service, the FBI's Internet Crime Complaint Center, and the Content Authenticity Initiative) are included because they are authoritative primary sources for the relevant workflows; GCI does not operate or control those services. ## Citations may break or be superseded The Site links extensively to external primary sources. Those sources are not under GCI's control and may move, be amended, be retracted, or be replaced by superseding authority. GCI is not responsible for the content, accuracy, or availability of external resources. Where you discover a broken link or a superseded citation, please report it to info@imadethisup.org; corrections are reviewed weekly. ## Limitation of liability To the fullest extent permitted by applicable law, GCI, its officers, directors, editors, contributors, and affiliates shall not be liable for any direct, indirect, incidental, special, consequential, exemplary, or punitive damages, including but not limited to damages for loss of profits, goodwill, use, data, or other intangible losses, arising out of or in connection with your access to, use of, or inability to use the Site or any external resource referenced from the Site. ## Reporting an inaccuracy To report an inaccuracy or request a correction, write info@imadethisup.org. Please include the URL of the page in question, the specific claim, and the primary source supporting the correction. Corrections are reviewed weekly and applied transparently. ## Governing law This Disclaimer is governed by the laws of the United States. Any action arising from your use of the Site shall be brought exclusively in the federal or state courts of competent jurisdiction in the United States. ======================================================================== # We collect the minimum information needed to operate the site. URL: https://imadethisup.org/privacy Summary: Minimum data collection, no third-party trackers, no behavioural advertising. Data-rights instructions for the EU, UK, and several U.S. states. ======================================================================== ## 1. Who we are imadethisup.org (the "Site") is operated by Global Cyber Institute, Inc. ("GCI", "we", "us"), a U.S. 501(c)(3) nonprofit (EIN 84-2148770). For all privacy questions and to exercise any rights described below, write info@imadethisup.org. For the purposes of the EU/UK General Data Protection Regulation (GDPR), GCI is the controller of any personal data processed through the Site. We have not appointed a Data Protection Officer because the scale and nature of our processing do not require one under Article 37 GDPR. Our publication-related processing relies primarily on Article 6(1)(f) (legitimate interests) and Article 6(1)(a) (consent) where consent is the appropriate basis (e.g., the retain-an-expert form). For the purposes of California law (CCPA/CPRA) and the parallel statutes of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA), GCI is the business / controller. ## 2. What we do not do To save you reading further: we do not sell, rent, trade, or share for cross-context behavioural advertising any personal information about Site visitors. We do not use Google Analytics, Meta Pixel, TikTok Pixel, or any comparable behavioural-tracking service. We set no third-party cookies. We do not engage in profiling or automated decision-making with legal or similarly significant effects. We do not target advertising at anyone, anywhere, ever. ## 3. Categories of personal information we collect The CCPA/CPRA "categories of personal information" framework is the most useful taxonomy. Mapped to our actual processing: - Identifiers, IP address (server logs); name and email if you submit the retain-an-expert form or email us directly. - Internet or electronic network activity, request time, requested URL, referring URL, response code, user-agent string (server logs). - Geolocation, coarse, derived from IP at country/region resolution only; we do not collect precise geolocation, do not request browser geolocation permission, and have no need for it. - Professional or employment-related information, only if you voluntarily provide it via the retain-an-expert form (organisation, role, jurisdiction). - Inferences, none. We do not build profiles. - Sensitive personal information (CPRA), none collected. We do not request, infer, or process precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric data, health data, sex life or sexual orientation data, or government identifiers. The DEFIANCE-related content on the Site is general-audience educational material; we do not collect anything about you when you read it. We have not sold, shared, or otherwise disclosed any of these categories for cross-context behavioural advertising in the preceding twelve months, and we have no plans to. ## 4. Sources, purposes, and legal bases ## 5. Cookies and similar technologies The Site sets no third-party cookies. The only client-side persistence we use is a single first-party localStorage flag (imt-privacy-notice-dismissed-v1) whose sole purpose is to remember that you have already dismissed our informational privacy notice on this device. Under the EU ePrivacy Directive and UK PECR, this falls within the "strictly necessary" exception and does not require prior consent. If we ever introduce non-essential cookies or analytics; we will present an opt-in consent dialog before any such cookie is set, and we will update this section first. ## 6. Sub-processors and third-party services The Site relies on a small, named set of third parties: - Vercel Inc., website hosting and content delivery (United States). Vercel processes standard server-log data (described above) on our instructions. We also use Vercel Web Analytics, a privacy-preserving, first-party, cookieless analytics feature served from our own domain. It produces aggregate traffic measurements only; it sets no cookies, does not fingerprint visitors, does not build cross-site profiles, and does not collect or sell personal information. See vercel.com/docs/analytics/privacy-policy. - Bunny Fonts (BunnyWay d.o.o.), typeface delivery (European Union). We deliberately use Bunny Fonts rather than Google Fonts because Bunny Fonts is GDPR-compliant by design; it does not log requesting IP addresses, sets no cookies, and is hosted in the EU. See fonts.bunny.net/about. - Resend (Plus Five Five, Inc.), transactional email delivery (United States). When you submit the retain-an-expert form, the information you provide is transmitted to Resend solely to deliver your inquiry to our mailbox. Resend processes it on our instructions as a service provider/processor and does not use it for its own purposes. See resend.com/legal/privacy-policy. - Lead/automation provider (optional), where we have enabled it, a copy of a retain-an-expert submission may be sent to a customer-relationship or workflow-automation service we use to log and route inquiries, again as a processor acting on our instructions. Apart from the privacy-preserving first-party analytics described above, we use no other tracking on the Site, no advertising networks, no behavioural or cross-site analytics, no social widgets, no chatbots, no embedded video players, no fingerprinting services, no cross-context profilers. ## 7. Disclosures of personal information In the preceding twelve months, we may have disclosed limited personal information (specifically, the categories above) to: - Vercel, for the hosting and first-party analytics purposes described in §6. - Bunny Fonts, for the operational purpose of font delivery. - Resend (and, where enabled, our lead/automation provider), to deliver and log retain-an-expert form submissions, as described in §6. - Law-enforcement or regulatory authorities only where required by valid legal process or where we reasonably believe disclosure is necessary to protect life, prevent serious harm, or protect our rights or property. - Successors in interest in the event of a merger, acquisition, or transfer of GCI's assets, in which case the successor would be bound to honor this Policy. We have not disclosed personal information to a third party for cross-context behavioural advertising. We have not sold personal information. We have not "shared" personal information as that term is defined under the CPRA. ## 8. International data transfers The Site is operated from the United States. If you access the Site from outside the United States, your interactions are transferred to and processed in the United States. Where personal information of EU/UK residents is transferred to us, we rely on the European Commission's Standard Contractual Clauses (Module Three, processor-to-controller, where applicable) and on appropriate supplementary measures (TLS 1.2+ in transit, HSTS preload, short retention periods, no advertising secondary uses). For UK residents we additionally rely on the UK International Data Transfer Addendum to the EU SCCs. ## 9. Data Subject / Consumer rights Depending on where you live, you may have the following rights. We honor each of them, including for visitors not currently protected by a specific statute, as a baseline. There is no charge, and we will not retaliate against you for exercising any right. Universal rights we honor: - Right to know what personal information we hold about you and how we use it. - Right of access, receive a copy of personal information we hold about you. - Right to rectification / correction of inaccurate or incomplete personal information. - Right to erasure ("right to be forgotten"), have your personal information deleted, subject to narrow legal exceptions. - Right to restrict processing in certain circumstances. - Right to data portability, receive your personal information in a structured, commonly used, machine-readable format. - Right to object to processing based on legitimate interests. - Right to withdraw consent at any time, where processing is based on your consent. - Right not to be subject to fully automated decisions with legal or similarly significant effects. We do not make any such decisions. California (CCPA/CPRA) additions: - Right to opt out of sale or sharing. We do not sell or share personal information for cross-context behavioural advertising. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request. See your privacy choices. - Right to limit use of sensitive personal information. We collect no SPI, so there is nothing to limit; we surface the link anyway in our footer for transparency. - Right to non-discrimination for exercising any privacy right. - Right to designate an authorised agent to submit a request on your behalf, please attach reasonable proof of authorisation. EU/UK additions: - Right to lodge a complaint with a supervisory authority if you believe our processing infringes the GDPR. EU residents may contact their national Data Protection Authority (a list is at edpb.europa.eu). UK residents may contact the Information Commissioner's Office. To exercise any right, write info@imadethisup.org with the subject line "Privacy request," from the email address you wish to be associated with the request. We will respond within the time frame required by applicable law (45 days under the CCPA/CPRA, extendable by 45 days; one month under the GDPR, extendable by two months for complex requests). We may need to verify your identity by asking for information that matches what we already hold; this is to protect against unauthorised disclosure. ## 10. Global Privacy Control (GPC) We honor the GPC browser signal as a valid opt-out request under the CCPA/CPRA, the Colorado Privacy Act, the Connecticut Data Privacy Act, and other statutes that require it. Because we do not sell or share personal information in the first place, the practical effect of GPC on our Site is the same as for any other visitor: nothing changes about what we do or don't collect. We surface the GPC status on your device on the Privacy choices page. ## 11. Children's information The Site is intended for a general adult audience. We do not knowingly collect personal information from children under the age of 13 in the United States, under 14 in some U.S. states, or under 16 in the European Economic Area. If you believe we have inadvertently collected information from a minor, write us at info@imadethisup.org so we can delete it. ## 12. Security We use commercially reasonable technical, organizational, and physical safeguards to protect information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The Site is served over HTTPS with HSTS preload, modern TLS cipher suites, a strict Content Security Policy, X-Content-Type- Options nosniff, X-Frame-Options SAMEORIGIN, Referrer-Policy strict-origin-when-cross-origin, and a Permissions-Policy that forbids geolocation, camera, microphone, and interest-cohort access. No safeguards are absolute; we cannot guarantee security against all threats. In the event of a personal-data breach affecting EU/UK residents that is likely to result in a risk to their rights and freedoms; we will notify the relevant supervisory authority within 72 hours per Article 33 GDPR and notify affected individuals without undue delay where required by Article 34 GDPR. ## 13. Do Not Track and Do Not Sell or Share Some browsers transmit a "Do Not Track" (DNT) header. There is no consensus standard for how a Site must respond to DNT, but for the avoidance of doubt: we do no tracking, with or without the DNT header. We honor the more recent and standardized Global Privacy Control signal as our opt-out mechanism for sale and sharing. We do not sell or share personal information; the Do Not Sell or Share My Personal Information link in our footer leads to the dedicated Privacy Choices page where you can confirm and exercise this right. ## 14. Changes to this policy We may update this Privacy Policy from time to time. The "Last updated" date at the top of the page reflects the most recent revision. We will review the policy at least annually as required by the CCPA. Material changes will be flagged in the Site's blog where reasonably practicable; for the retain-an-expert form and any other consent-based processing, material changes will not apply retroactively to information collected before the change unless we ask for and receive your renewed consent. ## 15. How to contact us info@imadethisup.org, for all privacy, data-rights, opt-out, and complaint communications. For practical step-by-step instructions on exercising your rights, see your privacy choices. ======================================================================== # Reporting non-consensual imagery: what one audit found URL: https://imadethisup.org/blog/reporting-ncii-to-platforms-what-research-shows Published: 2026-08-30 Summary: An audit of reporting mechanisms for non-consensual intimate imagery shows different outcomes depending on which platform route victims use. ======================================================================== A 2024 audit study compared two reporting mechanisms available to victims of non-consensual intimate imagery: reports filed under non-consensual nudity violations and reports filed as copyright infringement [1]. The study uploaded AI-generated nude images to X, formerly Twitter, and tracked removal speed across both routes. The copyright infringement mechanism worked faster than the platform's dedicated non-consensual nudity mechanism [1]. Because the study tested AI-generated content on one platform, it measures reporting flow performance rather than addressing real victims' images or other platforms. ## What the audit measured Victims of non-consensual intimate imagery currently have two mechanisms available for reporting such content: as a non-consensual nudity violation, or as copyright infringement [1]. A 2024 audit study examined how fast each route resulted in removal on X, formerly Twitter [1]. The researchers uploaded 50 AI-generated nude images, reporting half under the non-consensual nudity mechanism and half under the copyright infringement mechanism [1]. By holding the content constant and varying only the reporting route, the study design isolated the effect of the mechanism itself rather than any property of the images [1]. ## What the audit found The copyright infringement mechanism was faster than the dedicated non-consensual nudity mechanism [1]. This finding is specific to the routing difference; it does not measure the absolute speed of removal on X or compare X to other platforms. ## Scope limits of the audit The study used AI-generated images rather than real victims' images [1]. This means the audit measures how the reporting mechanisms performed on synthetic content, not on actual intimate imagery of real people. The scope is further limited to one platform and one point in time. The findings do not extend to other platforms or other reporting mechanisms beyond these two. They do not measure whether either mechanism reliably removes content in all cases, or how quickly real victims' content is addressed. ## Broader context on platform reporting Non-consensual intimate imagery, also known as image-based sexual abuse, is mediated through online platforms [2]. Platforms function simultaneously as the crime scene, the judge determining whether material violates policy, and the jury deciding on consequences for perpetrators [2]. Research drawing on interviews with 13 victim-survivors described the reporting experience as fragmented and opaque [2]. Because this is a qualitative study of 13 participants, it documents the types of challenges survivors encountered rather than producing estimates of how common each experience is [2]. Reporting volume indicates how many reports a scheme receives, not whether removal succeeded, not how widespread the harm is, and not whether an increase in reports reflects growth in the harm or in awareness and willingness to report. ## Practical implications for someone reporting intimate imagery If you have non-consensual intimate imagery removed from X, the audit findings suggest that filing a copyright infringement report may be faster than using the dedicated non-consensual nudity route. This is a structural finding about that platform's systems, not a guarantee of removal speed or success. The copyright route may not be available for all content; for instance, it typically requires you to hold copyright to the image. The non-consensual nudity mechanism exists for cases where copyright protection does not apply. Neither mechanism is a substitute for other legal remedies, reporting to law enforcement, or legal advice tailored to your jurisdiction. - What the TAKE IT DOWN Act actually changes, and what it doesn't , the US statutory route, and the 48-hour duty a platform now owes you - Deepfakes are reshaping workplace sexual harassment , the same imagery when it follows someone to work ## Sources ======================================================================== # What invisible watermarks can and cannot survive URL: https://imadethisup.org/blog/how-robust-is-invisible-watermarking Published: 2026-08-30 Summary: Research on attacking invisible watermarks reveals removal, forgery and detection-degradation are distinct threats. Robustness is conditional, not absolute. ======================================================================== Invisible watermarks on AI-generated images face three distinct threats: removal (deleting an existing mark), forgery (adding a mark to unmarked content), and detection degradation (making marks harder to verify through image processing). Removal attacks can work across multiple generative models without customisation. Forgery requires only a single watermarked example and no knowledge of the watermarking scheme. Detection can degrade under standard image distortions and adversarial attacks. Watermarks raise the cost of misrepresentation but do not guarantee detection. Certified watermarking methods with provable robustness bounds exist, shifting the question from whether watermarking works to under what conditions it works. ## Three distinct attack threats on invisible watermarks Invisible watermarks embedded in AI-generated images are often presented as a straightforward answer to labelling synthetic content. But the research literature on attacking these marks reveals a more complicated picture. The threats fall into three categories, each with different implications for misuse. First is removal: an attacker deletes a watermark that is already present. Second is forgery: an attacker adds a watermark to content that was never watermarked, falsely claiming it as authentic or synthetic. Third is detection degradation: standard image processing, compression or distortion makes the watermark harder or impossible to verify, even though it has not been deliberately attacked. These are separate problems with separate defences, and conflating them muddles the actual stakes. ## Removal attacks and model-agnostic manipulation Early watermark removal attacks worked only against specific generative models, or succeeded only by severely degrading image quality. MarkNull, a 2024 study on arXiv, challenges this constraint. The authors present a model-agnostic removal attack that works by manipulating the latent representation of an image; [1] they argue that the robustness of digital watermarking against realistic, model-agnostic removal attacks remains poorly explored, and that existing attacks either succeed only against specific models or cause severe visual degradation. Their approach does not require customisation to a particular generative model, suggesting removal is more portable than prior work suggested. The mechanics matter for policy. If removal requires specialist knowledge of one model's architecture, the barrier is higher. If it is model-agnostic, the barrier is lower. MarkNull indicates the latter, though it does not settle how widespread the technique is in practice or how quickly it can be deployed against new watermarking schemes. ## Forgery: adding marks to unmarked content Forgery is a distinct threat. WMCopier, published on arXiv in March 2025, demonstrates that an attacker can forge a watermark onto arbitrary unmarked images without knowing the watermarking scheme in advance. [3] The attack requires only access to watermarked content, and the authors report success against both open-source and proprietary watermarking systems. This is different from removal because instead of erasing evidence of synthesis, forgery fabricates false evidence of authenticity or provenance. A related study, published in April 2025, shows that both removal and forgery are possible with only a single watermarked example and no knowledge of the watermarking algorithm or model weights. [2] The attack exploits the many-to-one mapping between images and the initial noise used in diffusion-based generation, allowing an attacker to perturb an image in or out of watermarked regions. This black-box constraint is important: it means an attacker does not need insider access or reverse engineering. ## Detection degradation under ordinary processing A third vulnerability, sometimes overlooked, is that watermarks can become undetectable through ordinary image operations. WAVES, a watermark benchmark published at ICML 2024, was built because the authors judged existing watermark evaluation insufficient. [4] The benchmark evaluates watermark detection jointly with image quality, and its stress tests span traditional image distortions alongside adversarial attacks. The authors report that their benchmark reveals previously undetected vulnerabilities in modern watermarking algorithms, suggesting that watermarks fail to detect reliably under conditions watermarking advocates may not have tested. This matters because JPEG compression, cropping, colour adjustment and other standard image editing are not attacks in the adversarial sense; they are routine. If a watermark degrades under routine processing, it fails its basic function as a label for synthetic content. ## The defence: certified watermarking with provable bounds The attack literature should not be read as a verdict that watermarking is useless. The counterweight is certified watermarking, a method presented at ECCV 2024 that adapts randomised smoothing to provide provable robustness guarantees. [5] Unlike empirical claims about robustness, certified watermarking gives a mathematical bound: the method states that its guarantees cover both removal attacks and forgery attacks. The existence of such methods shifts the conversation from whether watermarking works to under what conditions and at what computational cost it can work reliably. The certified approach is not universal. It requires acceptance of the specific watermarking scheme and its computational overhead. But it represents a principled alternative to asking watermarking to do everything without proof. ## What watermark robustness means for policy and practice The research record suggests that watermarks are a tool for raising the cost of misrepresentation, not a guarantee against it. Removal, forgery and detection degradation are real, documented threats with differing difficulty and detectability. Watermarks that are certified against specific attack classes offer more assurance than claims of robustness made without formal proof. Watermarks that have not been tested against removal, forgery and ordinary processing should not be trusted without independent evaluation. For organisations deploying watermarks, the honest position is calibration: understand what your watermark actually protects against, what it does not, and under what conditions detection can fail. For policymakers proposing watermarks as a solution to synthetic media, the gap between marketing claims and verified robustness is the gap where harm can occur. - What Content Credentials establish, and what they do not , the other approach to the same problem: signing at creation rather than marking the pixels - Why deepfake detectors fail on new generators , why the detection route this post is an alternative to keeps failing - What the US AI Safety Institute says still needs research , where the US AI Safety Institute puts watermarking on its list of unsolved problems ## Sources ======================================================================== # Detector results on deepfakes found in the wild URL: https://imadethisup.org/blog/deepfake-detectors-on-real-world-deepfakes Published: 2026-08-29 Summary: Deepfake-Eval-2024 tested detectors on deepfakes actually circulating online. Reported AUC fell by 45 to 50 percent against laboratory benchmarks. ======================================================================== Deepfake-Eval-2024 is a benchmark assembled from deepfakes that actually circulated online during 2024, rather than generated for evaluation. Open-source detectors that score highly on academic datasets drop sharply on it, with reported AUC decreasing by 50 percent for video, 48 percent for audio and 45 percent for image models. Commercial and finetuned models do better without closing the gap to human analysts. ## How Deepfake-Eval-2024 was assembled Most deepfake benchmarks are built by generating manipulated media on purpose, with known tools, under known conditions. Deepfake-Eval-2024 was assembled the other way round, from in-the-wild deepfakes collected from social media and from users of a deepfake detection platform during 2024 [1]. It contains 45 hours of video, 56.5 hours of audio and 1,975 images, drawn from 88 different websites in 52 different languages [1]. The distinction is the entire point of the exercise. A laboratory benchmark measures whether a detector can recognise the output of the specific tools used to build it. A collection of material that was actually circulating measures something closer to the question a journalist or an investigator is really asking. ## What the reported detector numbers do on Deepfake-Eval-2024 The authors state directly that academic benchmarks are out of date and not representative of real-world deepfakes [1]. Their measurement is that the performance of open-source state-of-the-art detection models drops precipitously when evaluated on Deepfake-Eval-2024, with AUC decreasing by 50 percent for video, 48 percent for audio and 45 percent for image models compared with previous benchmarks [1]. Two cautions belong with those figures. The first is that AUC is a ranking measure rather than a share of files correctly classified, so a fall in AUC is not the same quantity as a fall in accuracy, and the two should not be quoted interchangeably. The second is that the percentages above are relative changes against each model's own earlier benchmark result, which is how the authors express them, rather than absolute differences in the score. ## Commercial and finetuned models, and the ceiling above them The same work evaluates commercial detection models and models finetuned on Deepfake-Eval-2024, and finds they have superior performance to off-the-shelf open-source models, but do not yet reach the accuracy of deepfake forensic analysts [1]. That last clause is the one worth carrying around. The comparison the authors draw is not between a good detector and a bad one; it is between every model they tested and a trained human examiner, and the human is still ahead. ## Tuning changes the detector picture more than architecture does A second paper revisits the same benchmark and complicates the simple reading that open-source detection is hopeless. Initial reporting on Deepfake-Eval-2024 showed three finetuned open-source models achieving accuracies between 61 and 69 percent, against a leading commercial detector at 82 percent accuracy [2]. Revisiting one of those baseline approaches, which adapts standard pretrained vision backbones, the authors show that with better-tuned hyperparameters the same simple method reaches 81 percent accuracy on Deepfake-Eval-2024, surpassing the previously reported accuracy of that baseline by 18 percent and competing with commercial detectors [2]. Read together, the two papers say something more specific than "detectors do not work". A large part of the reported gap between open and commercial systems, on this benchmark, was a gap in tuning rather than in method. That is encouraging about the ceiling and discouraging about the published figures, because it means a headline number can move substantially without the underlying approach changing at all. The second paper also frames the choice as a set of tradeoffs between accuracy, computational cost and interpretability [2]. Interpretability is the one most likely to matter to anyone who has to explain a result to a court, an editor or a client, and it does not appear in a single accuracy figure. ## Reading a detector claim after these results Three questions follow from the measurements above, and none of them require agreeing with any particular conclusion. - Which benchmark produced the quoted figure. A number from a laboratory dataset and a number from in-the-wild material are not comparable, and the reported drop between them is large [1]. - Which metric the figure is. AUC and accuracy are different quantities, and both appear across this literature [1] [2]. - Whether the comparison being offered is against another tool or against a human examiner. On this benchmark, the models tested did not reach the accuracy of forensic analysts [1]. None of this makes detection useless. It makes a detector output a piece of evidence with known limits rather than an answer, which is a more modest role and a more defensible one. - Why deepfake detectors fail on new generators , why performance collapses on an unfamiliar generator - What the US AI Safety Institute says still needs research , what a standards body says is still unsolved - What a deepfake detector score does not tell you , how to read a detector claim after these results ## Sources ======================================================================== # Penalties for breaching the EU AI Act's disclosure rules URL: https://imadethisup.org/blog/eu-ai-act-article-50-penalties Published: 2026-08-29 Summary: Article 99(4)(g) puts breaches of the synthetic-content transparency duties in the EUR 15 million or 3 percent tier. Who enforces, and how fines are set. ======================================================================== Breaches of the EU AI Act's transparency obligations for synthetic content are penalised under Article 99(4)(g), which sets administrative fines of up to EUR 15,000,000 or 3 percent of total worldwide annual turnover, whichever is higher. Enforcement falls to Member State authorities rather than to the European Commission. For SMEs and start-ups the cap is whichever of those two figures is lower. ## Which tier Article 50 breaches fall into The AI Act sorts infringements into bands, and the transparency duties for synthetic content are not in the most severe one. Article 99(4) sets administrative fines of up to EUR 15,000,000 or, if the offender is an undertaking, up to 3 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher [1]. Subparagraph (g) of that list is "transparency obligations for providers and deployers pursuant to Article 50" [1]. For comparison, Article 99(3) reserves the top band for the prohibited practices in Article 5, at up to EUR 35,000,000 or 7 percent of worldwide annual turnover [1]. Article 99(5) sets a lower band, up to EUR 7,500,000 or 1 percent, for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request [1]. ## The SME rule inverts the calculation One provision is easy to miss and reverses the arithmetic for smaller organisations. Article 99(6) states that in the case of SMEs, including start-ups, each fine shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower [1]. So the general rule takes the higher of the fixed sum and the turnover percentage, and the SME rule takes the lower. For a small company, 3 percent of turnover will usually be far below EUR 15,000,000, and that smaller figure becomes the ceiling rather than the floor. ## Which authorities impose Article 50 fines: Member States, not one EU regulator Enforcement is national. Member States shall lay down rules on penalties applicable to infringements of the Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented [1]. Member States also designate or establish one or more national competent authorities to ensure implementation and enforcement [1]. The practical consequence is that there is no single European regulator for these duties. A publisher or platform operating across the Union deals with the authorities of the Member States it operates in, and the AI Act builds in a coordination step: where no objection has been raised within three months of notification, by a market surveillance authority of another Member State or by the Commission, a provisional measure taken by one Member State's authority is deemed justified [1]. ## Union institutions are treated separately, and far more lightly Fines against EU institutions, bodies, offices and agencies run on a different scale and through a different body. The European Data Protection Supervisor may impose them, with non-compliance with the Article 5 prohibitions attracting up to EUR 1,500,000 and non-compliance with other provisions up to EUR 750,000 [1]. ## How the size of an AI Act fine is decided The Regulation directs that, when assessing the amount, all relevant circumstances of the specific situation be taken into account, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences, and to the size of the provider, in particular where the provider is an SME including a start-up [1]. The ceiling is therefore a ceiling and not an expected outcome. ## The penalty regime started before the obligation it penalises The sequencing is unusual enough to be worth stating plainly. Article 113 provides that the Regulation applies from 2 August 2026, with exceptions, and one of those exceptions is that Chapter XII, which contains the penalty provisions, applies from 2 August 2025, with the exception of Article 101 [1]. The machinery for penalties has therefore been in force for roughly a year longer than the Article 50 transparency duties it can be applied to. Nothing follows from that about liability for conduct before 2 August 2026; it simply means the enforcement structure was standing and waiting when the obligations began. ## What is not yet known about Article 50 penalties in practice No enforcement precedent under Article 50 was found in the Regulation or in publicly available records at the time of writing, which is unsurprising given how recently the obligations began to apply. That means the practical questions, how strictly authorities read "machine-readable format", what disclosure they will accept as "clear and distinguishable", and how the artistic and satirical carve-out is applied, do not yet have answers from any decided case. This page describes what the instrument says. It is educational material and not legal advice, and anyone with a live compliance question should take advice in the relevant jurisdiction. Our companion page on what Article 50 requires sets out the obligations themselves. - Synthetic media disclosure obligations now in force , what Article 50 actually requires, which these penalties enforce - What the C2PA conformance registry actually lists , the marking infrastructure that exists today ## Sources ======================================================================== # Synthetic media disclosure obligations now in force URL: https://imadethisup.org/blog/eu-ai-act-article-50-deepfake-disclosure Published: 2026-08-29 Summary: Providers and deployers must mark and disclose AI-generated content under Article 50. Requirements took effect 2 August 2026. ======================================================================== Article 50 of the EU AI Act requires providers of AI systems to mark synthetic audio, image, video, and text in machine-readable format. Deployers must disclose deepfakes and AI-generated text about public-interest matters. A key exemption applies: public-interest text subject to human review or editorial control, with a named person or legal person holding editorial responsibility, need not be disclosed. ## What Article 50 requires Article 50 of the EU AI Act took effect on 2 August 2026 [1]. The provision imposes transparency obligations on two groups: providers of AI systems and deployers, the organizations and individuals who use those systems to create or distribute synthetic content [1]. Providers, the organizations that build and release AI systems, must ensure that any system generating synthetic audio, image, video, or text marks its outputs in a machine-readable format that is detectable as artificially generated or manipulated [1]. Machine-readable means technically parseable, not merely human-visible labeling. A deployer or third party should be able to detect the synthetic origin programmatically. Deployers have separate obligations. When they release synthetic media to the public, they must disclose the artificial origin of the content. The specific requirements depend on the type of content and its purpose [1]. ## Technical marking requirements for providers of AI systems Providers must make their marking solutions "effective, interoperable, robust and reliable as far as this is technically feasible" [1]. The regulation explicitly recognizes practical constraints. When assessing feasibility, providers may consider the costs of implementation and the "generally acknowledged state of the art," including relevant technical standards [1]. Different content types, such as video versus text, may justify different approaches. Important exemptions apply. Systems performing only assistive editing functions, like grammar correction, color correction, or exposure adjustment, are exempt from marking requirements [1]. Systems that do not substantially alter the semantic meaning of the input data are also exempt [1]. Uses authorized by law for detecting, preventing, investigating, or prosecuting criminal offences are exempt [1]. A gap remains. The regulation does not specify which technical standards, file formats, or metadata schemes satisfy the machine-readable format requirement. No implementing technical specification has been confirmed. Organizations deploying synthetic-media systems operate with compliance uncertainty on this point. ## Deepfake disclosure A deepfake, synthetically generated or manipulated image, audio, or video, is subject to an explicit disclosure rule [1]. Deployers of such systems must disclose to the public that the content has been artificially generated or manipulated [1]. This obligation does not apply where the use is authorized by law for law enforcement purposes [1]. It also does not apply to artistic, creative, satirical, fictional, or analogous works [1]. For such creative content, the transparency obligation is not eliminated but rather narrowed; deployers must disclose that the content was generated or manipulated, but only in an appropriate manner that does not hamper the display or enjoyment of the work [1]. ## AI-generated text for public interest reporting Article 50 also regulates text. Deployers of AI systems that generate or manipulate text for publication with the purpose of informing the public on matters of public interest must disclose that the text has been artificially generated or manipulated [1]. A significant exemption exists, and it depends on editorial practice. Deployers need not disclose AI-generated text if the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication [1]. This exemption is conditional on a practice, not on a technology. It requires three things: human review or editorial control, together with a named person or legal person holding editorial responsibility. An organization that automates content creation and removes human editorial oversight loses the exemption; the disclosure duty applies to that AI-generated content again [1]. Law enforcement uses are exempt [1]. The conjunction matters here and is easy to misread. The exemption applies where the content has undergone a process of human review or editorial control, and where a natural or legal person holds editorial responsibility for the publication [1]. It is a disjunction inside a conjunction: one of review or editorial control, plus someone who owns the result. A publisher that keeps neither review nor editorial control, or that can point to no person or legal person carrying editorial responsibility, is outside the exemption and owes the disclosure. ## What Article 50 leaves unsettled: marking standards and enforcement As checked on 30 August 2026, no enforcement action has been initiated since Article 50 took effect on 2 August 2026. No precedent exists yet for how regulators will interpret or enforce the transparency obligations. This is a claim with a short shelf life; check it again before relying on it. The technical scope of "machine-readable format" has not been defined by implementing regulation. The European Commission published a voluntary Code of Practice on Marking and Labelling of AI-generated Content [2], and an AI Act Service Desk provides guidance [2]. Whether the Code of Practice has binding legal effect or definitively answers what marking standards are required remains uncertain. ## What the disclosure duty means for counsel, newsrooms, and security teams For lawyers and compliance officers: your clients deploying synthetic-media systems face new legal obligations with undefined technical scope. You need to advise them on what Article 50 requires while acknowledging the gap in technical specifications. For journalists and news organizations: Article 50(4) creates a new obligation on you. When you publish AI-generated or AI-manipulated text about matters of public interest, you must disclose it, unless your organization maintains human editorial review and responsibility. If you shift to fully automated content creation, the exemption disappears. The disclosure duty applies. For security professionals: these obligations matter because breaches of the law become part of threat assessment, incident response, and digital forensics work. For individuals affected by synthetic media: Article 50 creates legal obligations for transparency when synthetic media is released. Enforcement has not begun, but the legal foundation now exists. - Penalties for breaching the EU AI Act's disclosure rules , the sanction for breaching the obligation described here - What Content Credentials establish, and what they do not , the machine-readable marking Article 50 contemplates ## Sources ======================================================================== # What a deepfake detector score does not tell you URL: https://imadethisup.org/blog/why-detector-scores-do-not-travel Published: 2026-08-29 Summary: Detectors score highly on the benchmark they trained on. Measured performance on generators released later is a different and much weaker number. ======================================================================== Deepfake detector scores describe performance on a specific benchmark, and published figures fall substantially when the same detectors meet generators they were not trained on. One chronological evaluation reports that generalisation to future generators, without retraining, is near-random. Anyone weighing a detector output for a report, a filing or a story needs to know which generators it was trained on. ## What a detector score actually measures When a paper reports that a deepfake detector reaches 98 percent AUROC on FaceForensics++ [5], that figure is a ranking measure, not a percentage of videos correctly classified. It describes how well the detector ordered a set of known real and fake examples relative to each other, on a particular collection of examples. Reading it as "98 percent accurate" overstates what was measured, and the gap between those two readings is where most misplaced confidence in detection lives. ## In-distribution results look strong Evaluated on the data distribution it was trained on, detection looks close to solved. Mean AUROC on FaceForensics++ is reported between 98.0 and 98.9 percent [1]. Those results come from testing against the same generation methods present in training, which is the condition under which detection is easiest. ## Cross-dataset results are substantially weaker Across 14 benchmarks spanning 2019 to 2025, average cross-dataset AUROC is reported between 91.2 and 91.6 percent, and the spread behind that average is wide: the best benchmark result is 99.8 percent and the weakest is 77.7 percent [1]. A single average conceals the range, and the range is the part that matters when the generator is unknown. The same pattern appears as benchmarks get harder. Detectors trained on FaceForensics++ are reported at 81.6 percent video-level AUC on Celeb-DF v1, 80.9 percent on v2, and 73.8 percent on Celeb-DF++, which incorporates 22 generation methods across face-swap, face-reenactment and talking-face [3]. ## Performance on generators released after training The most consequential measurement is forward transfer, meaning performance on generators that appeared after the training data was assembled. Work that reframes detection as a continual-learning problem, simulating the chronological evolution of generators across seven years, introduces a Forward Transfer AUC metric for exactly this and reports that generalisation to future generators without additional training remains near-random, at roughly 0.5 [2]. The explanation the authors give is the unique imprint characterising each generator [2]. That finding sets the terms for everything else. A detector is not learning what a manipulated video is in general. It is learning what the specific tools in its training set leave behind. ## An open question about what the benchmarks measure There is also reason to be careful about the benchmark figures themselves. A frozen self-supervised probe, meaning a general-purpose feature extractor not trained for forensics at all, reached 88.51 AUC on a video benchmark against 89 to 90 AUC for specialised detectors, and 79.72 AUC on an image benchmark against 83.0 for a specialised detector, a gap of about 3.3 points [4]. That image benchmark is Celeb-DF++ again, but scored a different way: these are frame-level figures for detectors trained on Celeb-DF [4], where the 73.8 above is a video-level figure for detectors trained on FaceForensics++ [3]. Different training set, different scoring unit, so the two Celeb-DF++ numbers are not comparable to each other. The authors argue that much of the signal these benchmarks capture reflects general understanding of the medium rather than forensic evidence of manipulation [4]. If a general-purpose model nearly matches a purpose-built one, then part of what the leaderboard rewards is not detection skill. That is an argument in the literature rather than a settled conclusion, and it is worth treating as such. ## Questions to ask before a detector output goes in a report None of this means detection is worthless. It means a bare score is not interpretable on its own. Before relying on one, establish: - Which generation methods the detector was trained on, and when that training set was assembled. - Whether the quoted figure is in-distribution or cross-dataset, since the published gap between those conditions is large [1]. - Whether any forward-transfer evaluation exists for the tool, given that measured forward transfer is reported as near-random in the work cited here [2]. - What the score is being asked to support. A ranking measure over a labelled test set is not a probability that one particular video is synthetic. A figure of 98 percent AUROC is a real result about a specific benchmark [1]. It is not a statement about the file in front of you, and the published cross-dataset and forward-transfer numbers are the reason to keep those two things apart. - Why deepfake detectors fail on new generators , the mechanism behind the numbers here - Detector results on deepfakes found in the wild , the in-the-wild figures this post refers to - When audio deepfake detectors fail on new voice generators , the same question for synthetic speech ## Sources ======================================================================== # What Content Credentials establish, and what they do not URL: https://imadethisup.org/blog/what-content-credentials-establish Published: 2026-08-29 Summary: Content Credentials are signed statements about a file's history, not proof that the depicted events happened. Their absence is uninformative on its own. ======================================================================== Content Credentials are tamper-evident, cryptographically signed records of how a file was created and edited, travelling with the asset. Reading one tells you what a signer asserted about the file's history. Content Credentials do not establish that the depicted events occurred, do not identify the person who used a tool, and their absence from a file is uninformative, because ordinary editing and re-encoding routinely strip metadata. ## What a Content Credential records C2PA describes Content Credentials as "tamper-evident, cryptographically signed data structures that travel with the asset", capturing "the recorded history of a piece of digital content" [1]. What that history covers is "how the content was created, what tools or processes were used, when and where it was made, and how it has changed over time" [1]. For media made with generative systems, the record can extend to what C2PA calls AI generation recipes, meaning prompts, reference images and inference parameters, along with regions marking where AI modification occurred [2]. ## How a credential is checked, and what the check depends on A credential carries cryptographic hashes of both the asset and the provenance data, so any modification, whether intentional or accidental, breaks that linkage and signals tampering [1]. That is a strong property and a narrow one. It tells you whether the record still matches the file. It says nothing about whether the record was true when it was written. Which is why the trust model matters more than the cryptography. Signing certificates come from "Certification Authorities (CAs) listed on the C2PA Trust List" after products complete "conformance evaluation and security assessment" [1]. A verified credential therefore means a particular signer, admitted through a particular process, asserted a particular history. Everything downstream of that rests on what that signer's system actually observed. C2PA is explicit that this varies. The information available to a system about what it started with, and about how edits were applied, will vary significantly [2], and what can be proven depends on system architecture and transparency level [2]. Two files can both carry valid credentials and offer very different amounts of real information. ## Four things a Content Credential does not establish The limits below are ordinary engineering limits rather than defects, and knowing them is what makes the credential usable as evidence rather than as reassurance. - Not that the depicted events happened. A credential can record that a file was made with a given tool on a given date. Whether the scene occurred, or the statement was made, is a separate question that provenance does not reach. - Not who the person was. The core specification does not support attribution of content to individuals or organisations [1]. A credential can show a file passed through a tool without identifying who operated it. - Not a restriction on use. Content Credentials are "not a form of DRM" [1]. They document; they do not control what anyone may do with the file. - Not reliable detection of synthetic media. C2PA states that Content Credentials establish provenance trails rather than foolproof synthetic content detection [2]. Material generated by a non-conformant tool, or re-exported outside a signed workflow, carries no indicator even where one would have been accurate. ## Why a missing credential proves nothing The asymmetry between presence and absence is the single most misread part of provenance, and it matters most to the people most likely to encounter it. A credential that is present and validates narrows the question of where a file came from. A credential that is absent narrows nothing at all, because stripping is the normal behaviour of ordinary software. A screenshot taken from a messaging app, a scan copied between systems, an image re-encoded by a platform on upload: each can arrive with no provenance metadata and nothing wrong with it. Treating a missing credential as a signal of manipulation would flag most authentic material in circulation. C2PA does describe a partial mitigation. Soft bindings, such as invisible watermarking or fingerprinting, can help rediscover the associated Content Credential even when it has been removed from the file [1]. That is a recovery mechanism rather than a guarantee, since not every tool applies soft bindings and not every verifier looks for them. ## Reading a credential as evidence Three questions make a credential usable and keep it in its lane. Who signed it, and is that signer on the C2PA Trust List [1]. How much did the signing system actually observe, given that this varies by architecture [2]. And what is the credential being asked to prove, as against what it records. Provenance is a genuine advance on having nothing, and the honest description of it is narrow. It moves a file from unknown origin toward a documented and checkable one. It does not adjudicate whether the content is true, and no part of the specification claims that it does. - What the C2PA conformance registry actually lists , who is actually on the C2PA Trust List, which this post tells you to check - When the file lies about itself , the opposite failure: metadata that is present and fabricated - Authenticating AI-touched evidence: do we need a new rule? , how a court receives a provenance claim - What invisible watermarks can and cannot survive , what the alternative to signing survives, and what it does not ## Sources ======================================================================== # What the C2PA conformance registry actually lists URL: https://imadethisup.org/blog/which-cameras-have-certified-content-credentials Published: 2026-08-29 Summary: The C2PA Conforming Products List is public. Reading it directly answers which capture devices are certified, at what assurance level, and against which spec. ======================================================================== The C2PA Conforming Products List is a public registry recording which products have passed the C2PA conformance program, at what assurance level, and against which version of the specification. Reading it directly is the difference between accepting a provenance claim and checking one. As retrieved on 29 August 2026 it held 174 conformant records. ## What the C2PA conformance program certifies The C2PA conformance program validates that a product adheres to the Content Credentials specification and meets a set of security requirements [1]. It covers three kinds of participant: generator products, which create Content Credentials; validator products, which read and check them; and certification authorities [1]. Conformance is therefore a statement about a specific product at a specific version, not a badge a company wears. The useful consequence is that the result is published. The Conforming Products List is a JSON file in a public repository [2], which means a provenance claim can be checked rather than taken on trust, by the person relying on it, at the moment they need to rely on it. ## What the registry contained on 29 August 2026 Retrieved on 29 August 2026, the list held 174 records, every one with a status of conformant [2]. Of those, 153 were generator products and 21 were validator products [2]. The registry is dominated by cloud services, editing tools and platform pipelines rather than cameras, which is worth knowing before reading anything into the handful of capture devices in it. The capture devices and capture applications present, with the maximum assurance level recorded for each, were: - Pixel Camera, Google, assurance level 2 [2] - Snapdragon 8 Elite Gen 5, Qualcomm Technologies, assurance level 2 [2] - Pixel Recorder, Google, assurance level 1 [2] - Xiaomi Camera, assurance level 1 [2] - vivo Camera and JOVI Camera, vivo Mobile Communication, assurance level 1 [2] - Proofmode for Android and Proofmode for iOS, assurance level 1 [2] - InReality Capture for Android and for iOS, assurance level 1 [2] Assurance level is worth attending to, because it is not evenly distributed. Across all 174 records, 7 reached level 2, 146 were at level 1, and the 21 validator products carried no assurance level at all [2]. A reader evaluating a provenance claim should look at which level applies to the specific product that made it, rather than treating certification as a single undifferentiated status. One detail is easy to miss and matters for how provenance will spread. Snapdragon 8 Elite Gen 5 is a mobile chipset rather than a finished camera [2]. Certification at that layer reaches every device built on the part, which is a different distribution mechanism from certifying one handset at a time. ## Most of the registry is certified against an older specification Specification version 2.4 is published, and the C2PA site points adopters at 2.3 [3]. The registry tells a slower story: of the 174 records, 166 were certified against specification 2.2, seven against 2.4, and one against both [2]. Published, recommended, and actually certified against are three different things, and only the third describes the software a reader will encounter in the wild. ## Camera manufacturers listed as members but not in the registry Canon Inc, Fujifilm Corporation, Leica Camera and Nikon Corporation are listed as C2PA general members [4]. None of the four appeared anywhere in the Conforming Products List as retrieved [2]. That fact needs stating carefully, because it is easy to over-read. Absence from the registry means no product from that manufacturer has been certified under the conformance program. It does not establish that a manufacturer has never shipped a Content Credentials feature in any product, and this article makes no claim about that. Certification and shipping are separate questions, and only the first is answered by the registry. Anyone who needs the second should ask the manufacturer about a specific model and firmware version. ## How to check the registry yourself The list is a single public JSON file in the C2PA conformance repository [2], so a claim about it is verifiable in about a minute without specialist tooling. Each record carries the applicant, the product name, the product type, the assurance level, the specification versions, the container formats the product can generate or validate, and dates for creation, conformance and last modification [2]. Two habits follow from that. First, when a product claims Content Credentials support, check whether it appears in the registry and at what assurance level, rather than accepting the marketing description. Second, when reading a claim about the registry, including this one, retrieve the file and confirm it, because the registry changes and any published summary of it is a snapshot with a date attached. ## What the registry does not tell you Conformance is not a statement that a given file's credentials are intact, that its signature validates, or that the content is truthful. It says a product met a specification and a set of security requirements at a point in time. A signed capture from a certified device still needs its manifest validated, and a credential can be absent for entirely innocent reasons, including an editing step that did not preserve it. Provenance narrows the question of where a file came from; it does not answer whether what the file depicts is true. - What Content Credentials establish, and what they do not , what a credential proves before the registry means anything - Synthetic media disclosure obligations now in force , the marking obligation this infrastructure is meant to satisfy ## Sources ======================================================================== # What the US AI Safety Institute says still needs research URL: https://imadethisup.org/blog/synthetic-content-research-gaps Published: 2026-08-29 Summary: The US AI Safety Institute has published specific research gaps in synthetic content mitigation. Here is what it says does not work yet. ======================================================================== The US AI Safety Institute identifies four technical research gaps: digital watermarking robustness, content authentication mechanisms, detection of synthetic materials, and safeguards preventing harmful model outputs. It also calls for social science research on how synthetic content affects information integrity, public trust, sensitive domains like education and counselling, and strategies against fraud and impersonation. ## What the AI Safety Institute says needs research The US AI Safety Institute has published a call to action naming specific research gaps in mitigating synthetic content risk. The document identifies areas where current work does not yet provide adequate protection, and appeals to public and private funders, academic institutions, civil society and industry researchers to prioritise them. The gaps fall into two categories: technical and social science. ## Technical research gaps The institute identifies four technical domains requiring frontier research. - Digital watermarking robustness - Content authentication mechanisms - Detection of synthetic materials - Safeguards preventing harmful model outputs The call does not specify what makes current work in these areas insufficient, only that research is needed. It names them as gaps, implying that existing solutions are not yet adequate for the scale and nature of the risk. ## Social science research gaps The institute calls for social science research addressing systemic impacts of synthetic content. This includes three areas: - How synthetic content affects information integrity and public trust - Its effects in sensitive domains such as education and counselling - Strategies to combat fraud and impersonation These gaps reflect a concern that technical solutions alone are insufficient. The institute is calling for research into how synthetic content circulates, whom it harms, and how to respond socially and institutionally, not only technologically. ## Why the institute is making this call Synthetic content has legitimate uses. But the institute states that its widespread production risks damaging information integrity and enabling harmful activities including child exploitation, fraud, and intellectual property violations. It frames this as a frontier research challenge requiring coordinated effort across sectors. ## Who the AI Safety Institute is asking to close the gaps The institute appeals explicitly to all stakeholders: public and private funders as well as academic, civil society and industry scholars. This is framed as a collective responsibility rather than a problem for any single sector to solve. The document is a statement that the research gaps it names are not yet closed by existing industry procurement, academic output, or government work. Whether a reader has been told detection is a solved problem, the institute's own assessment is that frontier research remains necessary. - What Content Credentials establish, and what they do not , the provenance limits named in that gap list, in full - Detector results on deepfakes found in the wild , the detection side of the same problem, measured - What invisible watermarks can and cannot survive , the watermarking gap on that list, with the attack research behind it ## Sources ======================================================================== # When audio deepfake detectors fail on new voice generators URL: https://imadethisup.org/blog/audio-deepfake-detection-generalization Published: 2026-08-29 Summary: Audio deepfake detectors trained on one set of voice generators often fail on others. What the research says about using detection results in reports. ======================================================================== Synthetic speech detectors encounter a fundamental generalization problem: systems trained on one set of voice generators degrade significantly when tested on generators they were not designed to detect. The gap is not simply that unseen generators produce harder examples to classify; they produce fundamentally different acoustic patterns. This means that boosting model capacity alone will not solve the problem. Detection results should be interpreted cautiously if the report does not confirm that the detector was trained on, or tested against, the specific synthesis method in question. ## The generalization gap in audio detection Audio deepfake detection systems perform well when tested on the same generators they were trained to recognize. When tested on voice synthesis tools they have never encountered, performance degrades substantially. This is not a minor calibration problem. Researchers who re-implemented published audio deepfake detection methods and evaluated them on a newly collected real-world dataset found that performance dropped significantly compared with results on the benchmark datasets those systems were tuned on. [1] The degradation occurs because the field's detection solutions have been fitted too closely to the prevailing audio deepfake benchmark, and do not carry over to real-world audio. [1] This is a structural problem with how the research has developed, not a temporary limitation that better engineering will soon resolve. ## Difference, not difficulty, drives the audio detection gap A crucial finding separates this from the intuition that unseen generators simply produce harder detection problems. Researchers decomposed the gap between in-domain and out-of-domain performance into two components: hardness (whether the examples are simply more difficult to classify) and difference (whether out-of-domain examples are fundamentally different in their acoustic properties). [2] The hardness component was found to be practically negligible. The gap is attributable almost entirely to the difference component. This means that deepfakes from an unseen generator are not simply harder versions of the same detection task; they present different acoustic patterns altogether. [2] The implication is direct: increasing model capacity, the currently dominant approach to improving detectors, may therefore not address the generalisation problem. [2] ## Zero-shot synthesis as a practical risk The threat from newer synthesis methods has grown more acute. Zero-shot text-to-speech models pose a higher risk because they can clone a voice from a single utterance. [3] Researchers have now constructed datasets of over 300 hours of speech generated by five advanced zero-shot text-to-speech models to test detector generalization. [3] Their conclusion was that existing audio deepfake detection datasets are outdated, leading to suboptimal generalisation of detection models. [3] ## What improves generalization One approach shows promise: attack-augmented training, where detectors are trained on data that deliberately includes varied synthesis methods. [3] This contrasts with the standard approach of training on a single benchmark dataset. Research indicates that such training approaches can improve detector performance. [3] The second lever is to understand and test against the specific distribution shifts your use case will encounter. Researchers have built a dataset to benchmark generalization under distribution shift, covering shifts in speaker characteristics, language, acoustic conditions and synthesis method. [4] They report that these distribution shifts degrade the performance of state-of-the-art detection approaches based on self-supervised features. [4] Their explicit recommendation is that reliance on synthetic speech detection in production should be evaluated against the distribution shifts actually anticipated. [4] ## What generalization failure means for detection results in reports A detection result has credibility to the extent that: - The detector was trained on, or tested against, the specific synthesis method in question. If the report does not specify this, the result should be treated with caution. - The detector was trained using attack-augmented methods that include multiple synthesis approaches, not a single benchmark dataset. - The report acknowledges the specific distribution shifts (speaker, language, acoustic conditions, synthesis method) between the training data and the material being tested. An EER (Equal Error Rate) or AUC (Area Under the Curve) score reported from benchmark testing does not reliably predict performance on a new voice generator. These metrics describe performance on the dataset they were measured on. They are not interchangeable with accuracy on novel generators. If you are deciding whether to include a detection result in a report, ask whether the evidence supports detection of that specific generator. Absence of that specificity does not mean the detector is useless, but it does mean the result should be qualified accordingly. - What a deepfake detector score does not tell you , the same caution applied to video detectors - Why deepfake impersonation works, and what stops it , why voice verification is the wrong control anyway - Detector results on deepfakes found in the wild , in-the-wild measurement across modalities ## Sources ======================================================================== # Why deepfake impersonation works, and what stops it URL: https://imadethisup.org/blog/why-deepfake-impersonation-defeats-detection Published: 2026-08-29 Summary: Deepfake attacks on executives target decision-making, not media detection. The control that works is procedural verification outside the attack channel. ======================================================================== Deepfake impersonation of executives works by manipulating trust cues and decision-making processes, not by deceiving the eye alone. The durable control is an out-of-band verification step, such as a separate phone call or in-person confirmation, that does not depend on detecting whether the media is real. ## Deepfake impersonation targets the decision, not the pixels A common response to deepfake impersonation is to invest in detection: teach staff to spot synthetic media, deploy tools to authenticate video or audio, train the eye. Research into how these attacks actually succeed suggests this approach misses the operative vulnerability. Synthetic-media impersonation attacks operate on human decision-making and trust cues rather than on media authenticity alone [1]. The attacker's goal is not to produce pixels so flawless that no tool can detect them. The goal is to create enough apparent legitimacy to cause a specific action: a wire transfer, credential disclosure, system access, document signing. The attack succeeds at the moment of decision, not at the moment of viewing. This distinction matters for control design. If the vulnerability is "the victim cannot tell real from fake," the natural response is better detection. But if the vulnerability is "the victim makes a decision based on trust signals in a context where verification is absent," then detection is incidental. The attacker has already moved past the authenticity problem by leveraging the urgency, authority, or relationship signals that the victim recognises as real. ## Why voice and video require verification outside the channel Speaker verification systems, which use voice patterns to authenticate callers, are vulnerable to synthesised speech [2]. Anti-spoofing detectors within these systems perform well against familiar audio synthesis methods and poorly against unfamiliar ones [2]. This generalisation problem means that a detection system trained on current synthesis techniques may fail against new ones. The practical implication is that a voice on a call alone is not sufficient for identity verification. The person hearing the voice recognises the executive's tone, speech patterns, the urgency in their words. All of these can be synthesised or imitated. A video call adds visual cues that feel confirmatory but do not actually confirm identity. None of these channels, alone or in combination, are sufficient authentication for high-value decisions [2]. This is not a criticism of those who fall for these attacks. The attacker has constructed a scenario in which the victim's normal pattern-recognition instincts, trained on years of legitimate communication, produce false confidence. The attacker has also compressed decision time. Executives who are busy, distracted, or under time pressure are more vulnerable not because they are less careful but because the attack targets the conditions under which humans make decisions with incomplete information. ## The control that works against deepfake impersonation is procedural verification If deepfake impersonation succeeds by manipulating the decision context rather than by deceiving media authenticity, then the control must operate outside that context. Out-of-band verification is the established term for this approach: a separate channel, using a different medium or a different party, that confirms the request before action. Examples include hanging up and calling the executive at a known number; asking the requester to confirm via email from a known account; or requiring sign-off from a second person before transfer. The critical property of this control is that it does not care whether the initial deepfake was convincing. It does not require staff to become forensic analysts of synthetic media. It breaks the attack by making the attacker choose: either impersonate the executive on a second channel, or escalate the attempt and risk detection. The procedural control is durable because it operates at the point of decision, not at the point of media consumption. Even if detection technology improves, or synthesis technology improves faster, or the attacker uses a new method that current detectors cannot recognise, the procedural check remains effective as long as it enforces a genuine second verification step. ## Implications for security and legal function For security teams, this research points toward investment in process rather than in media forensics. The question is not "Can we detect this deepfake?" but "Can we structure decisions so that even a perfect deepfake cannot cause the action alone?" This may mean defining high-risk transactions; requiring second sign-off for those transactions; establishing out-of-band confirmation protocols; and training staff in the conditions under which they should pause rather than in the signs of a synthetic media. For in-house counsel, the implication is that deepfake risk is a business continuity and fraud-prevention problem with procedural, not technical, solutions. It is relevant to policies on wire transfer authority, credentials management, and incident response, not principally to authenticity certification or media verification. The attack on executive impersonation is sophisticated in its use of synthetic media. The control that stops it is not. - What the Arup deepfake actually proves, and what it doesn't , the worked example of this exact thesis, at $25 million - Building a deepfake incident-response plan for smaller firms , the out-of-band protocol this post ends on, written out - What a deepfake detector score does not tell you , the evidence that detection is the wrong lever ## Sources ======================================================================== # "Follow the money" is no longer enough URL: https://imadethisup.org/blog/follow-the-money-ai-fraud Published: 2026-06-15 Summary: Cloned voices induce the wire; crypto rails launder the proceeds. When inducement is synthetic, financial tracing alone stops proving the case. ======================================================================== Transaction tracing still matters, but it no longer proves the case on its own. When the inducement is a cloned voice and the laundering runs through cross-chain bridges, tracing can establish flow and identify beneficiaries, yet it cannot show what people knew, what they said to each other, or how decisions were made. For decades, financial tracing has been the workhorse of fraud litigation. Subpoena the bank records, identify the transfers, follow the money to its final disposition, and the case largely builds itself. The methodology is mature, courts are comfortable with it, and forensic accountants have refined it into a rigorous discipline. None of that has changed. What has changed is the two ends of the pipe. At the front, generative AI now manufactures the inducement, the cloned executive, the fabricated relationship, the synthetic identity that opens the account. At the back, blockchain rails launder the proceeds at a speed and across a number of jurisdictions that no subpoena can chase in real time. Tracing remains essential. It is simply no longer sufficient. The scale is not theoretical. The FBI's Internet Crime Complaint Center logged a record $16.6 billion in reported cyber-enabled losses for 2024, a 33% jump over the prior year, with roughly $9.3 billion of that tied to digital assets, itself a 66% increase. Cryptocurrency investment fraud, the category that includes "pig butchering," alone accounted for $5.8 billion across more than 41,000 complaints. The Federal Trade Commission, counting a broader universe of consumer reports, put total 2024 fraud losses at $12.5 billion, with investment scams ($5.7 billion) the single largest category and cryptocurrency the second-most-used payment method by dollars lost. ## The inducement is now synthetic Traditional fraud needed a persuasive human, a salesperson, a forged letter, a spoofed email. Generative AI collapses that cost. In December 2024 the FBI warned that criminals are using generative AI "to commit fraud on a larger scale" by mass-producing believable personas, voices, and documents, reducing the time and effort needed to deceive a target. The textbook case is the 2024 Hong Kong incident in which a finance employee at the engineering firm Arup joined a video call populated by deepfaked colleagues, including a synthetic "CFO", and authorized fifteen transfers totaling roughly $25 million. The funds were gone before anyone in the real chain of command knew a meeting had supposedly occurred. As of the latest public reporting, no arrests had been announced and the money had not been recovered. The same dynamic operates upstream of any victim contact. In November 2024 the Financial Crimes Enforcement Network issued an alert (FIN-2024-Alert004) describing a surge in suspicious-activity reports tied to deepfake media used to defeat banks' identity-verification, authentication, and due-diligence controls, synthetic photos and videos deployed to open accounts that then funnel proceeds through check fraud, push-payment fraud, and loan fraud. When the account-opener is a fabricated identity, the "know your customer" record that a tracing analysis relies on to name a beneficiary is itself a forgery. ## The money trail is now on-chain Once funds move to cryptocurrency, the assumptions behind classic asset tracing degrade. Bank tracing presumes named, regulated intermediaries who respond to legal process within a single legal system. On-chain laundering presumes the opposite: pseudonymous addresses, automated mixers, and cross-chain bridges used for "chain hopping" that fragment a single flow across networks faster than counsel can serve a single subpoena. Chainalysis reports that stablecoins have come to dominate illicit transaction volume, and that sophisticated actors now insert additional layering steps, mixers and bridges, between an exploit and any cash-out point, precisely to break the linear trail that tracing depends on. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:12px} .mut{fill:#8a938a;font-size:10px} .grn{fill:#00b341;font-size:10px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} .dsh{stroke:#3a423a;stroke-width:1.4;fill:none;stroke-dasharray:4 4} TRADITIONAL TRACE, linear, named, subpoenable Victim Named bank KYC on file Beneficiary identified AI-INDUCED + ON-CHAIN, branching, pseudonymous Deepfake inducement cloned CFO / synthetic ID Wire / exchange on-ramp Mixer layering bridge → chain A Unknown wallets cross-chain hops bridge → chain B FIG. 1, Same dollar, two trails: one ends at a name; the other forks across chains. FIG. 1, A synthetic inducement at the entry point and on-chain layering at the exit. The transaction still happened; what tracing alone can no longer reconstruct is who, and with what knowledge. Why following the money cannot prove knowledge or intent The limitation of pure tracing was always evidentiary, not analytical. Tracing can establish flow and identify nominees, layering structures, and ultimate beneficiaries. It cannot, on its own, prove what people knew, what they said to one another, and how decisions were made. A defendant who claims to have processed transactions without knowledge of their character has a real defense even when every dollar can be followed; knowledge and intent live in communications, not in ledgers. The synthetic-inducement era widens that gap. When the persuasion was performed by an AI persona, there is no human salesperson to flip, and the deepfake artifact itself, the call recording, the generated image, its metadata and provenance, may be the only proof of how the victim was deceived. This is why a tracing analysis offered in isolation invites the argument that fund movement is consistent with many explanations, only some of them fraudulent, and why a communications record offered without financial corroboration invites the argument that statements were aspirational or taken out of context. Correlated, the two foreclose the alternative explanations each leaves open. A wire at 2:14 p.m. becomes different evidence when it sits in a sequence: a recorded video call at 11:30 a.m. in which a synthetic executive ordered a "secret transaction," a messaging directive at 1:47 p.m., a device geolocation, an account opened weeks earlier with a face that detection software flags as machine-generated. ## Four additions to a fraud investigation when the inducement is synthetic The transactional record stays the backbone. Around it, four additions have moved from optional to essential: - Preserve the inducement, not just the transfer. Capture the call recording, the synthetic media, and their metadata and provenance signals at the earliest moment. A deepfake artifact is both the proof of deception and, increasingly, contested evidence whose authenticity must itself be established. See the Provenance guide. - Pair financial and on-chain forensics from day one. Bring blockchain-analytics capability in at intake, not after the bank tracing stalls. Mixers and cross-chain bridges defeat sequential subpoenas; following the flow requires tooling built for pseudonymous, multi-chain movement. - Reconstruct the digital ecosystem. Messaging platforms, cloud repositories, device metadata, and geolocation supply the knowledge-and-intent record that ledgers omit, the difference between a transaction that occurred and a fraud you can prove. - Move at on-chain speed. Identity-verification controls assume a human; FinCEN's alert is a reminder that they no longer can. Freezes, exchange notices, and preservation demands have to be triggered in hours, because the laundering is. "Follow the money" was never wrong; it was complete. In an era when the inducement is generated and the trail is engineered to branch, the durable case is built on both ends at once, the synthetic artifact that proves how the victim was deceived, and the on-chain analysis that proves where the value went. Trace the money, yes. But authenticate the lie that started it, and chase the value across the rails that hid it. When the inducement is synthetic and the trail is on-chain, the two halves are rarely traced by the same person, most matters need media forensics working alongside financial tracing. - Investigating white-collar fraud when the evidence can be fake , the investigative discipline behind the tracing - Building a deepfake incident-response plan for smaller firms , the containment step that precedes recovery ## Sources ## Common questions on this topic It collapsed the cost of persuasion. Traditional fraud needed a persuasive human, a salesperson, a forged letter, a spoofed email. In December 2024 the FBI warned that criminals are using generative AI "to commit fraud on a larger scale" by mass-producing believable personas, voices, and messages. Bank tracing presumes named, regulated intermediaries who respond to legal process within a single legal system. On-chain laundering presumes the opposite: pseudonymous addresses, automated mixers, and cross-chain bridges used for "chain hopping" across jurisdictions. State of mind. Tracing establishes flow and identifies nominees, layering structures, and ultimate beneficiaries. It cannot prove what people knew, what they said to one another, or how decisions were made, which is precisely what a fraud case turns on. ======================================================================== # Agentic AI and accountability: who answers when an agent trades? URL: https://imadethisup.org/blog/agentic-ai-accountability-sec Published: 2026-06-15 Summary: Autonomous agents now place trades and draft disclosures. When one breaks securities law, who is liable? SEC “AI washing”, scienter, and agency law. ======================================================================== When an autonomous AI agent violates the securities laws, the firm that deployed it answers. Scienter can still be established by aggregating knowledge across corporate actors and imputing recklessness to a firm that permissions an agent into sensitive systems without controls, and where no individual's intent can be proven, common-law agency principles keep the principal liable. For most of the AI conversation, the synthetic-media problem and the financial-markets problem have lived in separate rooms. Deepfakes were a courtroom-and-elections issue; algorithmic trading was a market-structure issue. Agentic AI collapses the distinction. The same capability that lets a model fabricate a convincing video lets a goal-seeking agent generate a convincing, and false, statement to the market, then act on information it was never supposed to touch. The authenticity question and the accountability question turn out to be the same question, wearing different clothes. Agentic systems are no longer a demo. They are deployed inside banks, broker-dealers, and investment advisers, where they pursue goals, call tools, query databases, and execute multi-step workflows. The most aggressive deployments are permissioned to read internal email and deal rooms, place orders, or speak directly to investors. That is a profile the federal securities laws were not drafted to anticipate, and it forces a state-of-mind question those laws cannot dodge. ## The enforcement opening bell: "AI washing" The Securities and Exchange Commission has already drawn first blood, though on the easier end of the problem. In March 2024 the Commission announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for making false and misleading statements about their use of artificial intelligence. The firms paid $225,000 and $175,000 in civil penalties, respectively, to resolve violations of the antifraud and Marketing Rule provisions of the Investment Advisers Act. These were the agency's first enforcement actions targeting so-called "AI washing", overstating, or simply inventing, an AI capability to attract clients. Then-Chair Gary Gensler framed the principle in plain terms: "Public companies should make sure they have a reasonable basis for the claims they make" about their AI use, and "investors should be told that basis." The Delphia and Global Predictions orders were, importantly, about lying about AI. The harder cases, where a real, autonomous agent does something the firm never told it to do, are still ahead of us. But they sit on the same doctrinal foundation. ## The scienter map across the SEC antifraud provisions The Commission's antifraud toolkit is well worn but uneven in what it demands of a defendant's mental state. Section 10(b) of the Exchange Act and Rule 10b-5, along with Section 17(a)(1) of the Securities Act, each require scienter, an intent to deceive, or recklessness tantamount to intent, a standard fixed by the Supreme Court in Ernst & Ernst v. Hochfelder. By contrast, Sections 17(a)(2) and 17(a)(3) require only negligence, as the Court confirmed in Aaron v. SEC. That split, intent for some provisions, mere carelessness for others, has always mattered. Agentic AI makes it newly consequential, because the actor at the center of the conduct has no mental state at all. An autonomous trading agent illustrates the bind. Suppose a buy-side firm gives an agent read access to internal research, messaging platforms, and a deal-team document repository, and instructs it to optimize returns. In synthesizing signals, the agent ingests material nonpublic information, a draft deal memo, say, or leaked guidance buried in a forwarded email, and trades on it. No human told it to read the document; no human knew it had. Where is the intent to defraud? .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} AI agent acts trades on MNPI / publishes false statement has no mental state → trace upward Humans who deployed it access, goals, controls, sign-off reckless? Scienter counts 10(b) · 17(a)(1) · 17(b) careless? Negligence counts 17(a)(2) · 17(a)(3) The firm answers agency law · respondeat superior · control person the instrumentality acts; the principal is liable FIG. 1, Liability traces from a stateless agent up to the humans who deployed it, and ultimately to the firm. Negligence provisions catch what scienter cannot. Scienter still reaches the firm that deploys an agent, but negligence does more The intuition that agentic AI creates a "scienter vacuum" is wrong. Federal courts have long aggregated the knowledge of multiple corporate actors and imputed recklessness to an entity that deploys a dangerous instrumentality without adequate controls. A firm that permissions an agent into MNPI-rich systems without information barriers, knowing retrieval tooling will sweep that content into the decision surface, and deploys it anyway, is a firm whose executives face a live recklessness narrative. The agent's lack of a mind does not erase the minds of the people who built and aimed it. Even so, the negligence provisions will do the heavy lifting. Section 17(a)(2) requires only that a firm obtained money, trading profits qualify, by means of a material misstatement or omission, while acting negligently. The failure to wall off an agent's retrieval tools is negligent almost by definition. Expect the Commission to plead in the alternative: scienter under 10(b) and 17(a)(1) where the human deployment record supports it, and negligence under 17(a)(2) and (a)(3) as a parallel count that does not rise or fall with proof of intent. The same logic extends to communications. When an issuer deploys an agent to draft investor relations material or populate disclosures and the agent hallucinates a revenue figure or overstates a pipeline, the question becomes who "made" the statement. Under Janus Capital Group v. First Derivative Traders, the maker is the entity with ultimate authority over the statement, its content and whether to communicate it. An AI is not a person. The company that publishes the output under its own name is the maker, and negligence-based liability attaches readily. ## Agency law is the backstop when an AI agent acts for the firm Even where no individual human's scienter can be proven, the firm itself is likely to remain liable. The securities laws have long incorporated common-law agency principles to hold principals accountable for the acts of their agents within the scope of authority. Respondeat superior and apparent authority reach conduct by instrumentalities a firm deploys for its own benefit; Section 20(a) of the Exchange Act and Section 15 of the Securities Act add control-person hooks that do not turn on the state of mind of the controlled actor. An agentic AI is not a common-law agent in the juridical sense, it cannot form intent, hold duties, or be sued. But it is an instrumentality of the principal. When a firm permissions an agent into its systems, directs it toward a profit objective, and captures the upside of its trades or communications, the firm has adopted the agent's conduct. Courts will have little difficulty concluding that the company "acted" through the tool, and civil enforcement does not require any finer metaphysical distinction. ## What the SEC rulebook says now, and what it doesn't The regulatory text has been a moving target. In 2023 the Commission proposed a sweeping rule on conflicts of interest arising from the use of "predictive data analytics", covering AI, machine learning, and large language models, by broker-dealers and investment advisers. The instinct behind it was sound: supervisory obligations should scale with the autonomy of the tool. But the proposal drew heavy criticism for its breadth, and in June 2025 the Commission formally withdrew it along with thirteen other pending proposals. Any future rulemaking on agentic tools must now start from scratch. The lesson is not that the field is unregulated. It is that the durable law here is old law, antifraud statutes, scienter doctrine, and agency principles, rather than a bespoke AI rule that may never arrive. Firms waiting for a clarifying regulation before they govern their agents are waiting for the wrong thing. ## Four controls for a firm deploying an agentic AI system - Map the permissions before deployment. Inventory every data source an agent can read and every action it can take. MNPI repositories, deal rooms, executive email, draft filings, should be walled off at the retrieval layer, not merely by policy. - Document the deployment decision. The scienter analysis turns on what humans knew about an agent's access and capabilities. Written risk assessments, sign-offs, and red-team results are the record a firm will want when the Commission asks what diligence preceded deployment. See the Research Lab. - Supervise outputs, not just inputs. Human review of material agent-drafted communications is both a safeguard and a Janus-aligned way to fix who the "maker" is. For trading agents, the analogue is pre-trade surveillance tuned to detect anomalous, information-driven patterns. - Assume parallel theories. A compliance program defended only against intent-based claims will be caught flat-footed by a 17(a)(2) charge. The operative question is not "did anyone intend this?" but "was the deployment reasonable?" Agentic AI does not rewrite the securities laws; it stresses them. It will force regulators, courts, and compliance officers to take seriously a principle older than any algorithm: when a firm sends a powerful instrumentality into the capital markets, the firm answers for what the instrumentality does. Authenticity and accountability converge on the same discipline, the ability to prove what an actor did, and who stood behind it. When liability turns on what an agent actually did rather than on what its vendor says it does, closing that gap usually takes an independent technical examination of the system itself. - AI governance from the security chair: what the CISO owns , whose desk the deployment decision sits on - AI tools and attorney-client privilege: keeping confidences confidential , the confidentiality question agentic tools raise ## Sources ## Common questions on this topic Yes, though on the easier end of the problem. In March 2024 the Commission announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for making false and misleading statements about their use of AI. These "AI washing" cases target misrepresentation, not autonomous conduct. No. Section 10(b) and Rule 10b-5 require intent to deceive or recklessness, but federal courts have long aggregated the knowledge of multiple corporate actors and imputed recklessness to an entity that deploys a dangerous instrumentality without adequate controls. Negligence-based provisions reach further still. Very likely. The securities laws incorporate common-law agency principles that hold principals accountable for acts of their agents within the scope of authority. Respondeat superior and apparent authority mean the firm remains on the hook even where no single human's state of mind can be proven. ======================================================================== # AI governance from the security chair: what the CISO owns URL: https://imadethisup.org/blog/ai-governance-from-the-security-chair Published: 2026-06-15 Summary: When an organisation adopts AI, governance lands on the security chair. The frameworks, controls, accountability lines, and board reporting involved. ======================================================================== AI governance increasingly lands on the security leader's desk. The remit is defined by three texts, the NIST AI Risk Management Framework, its Govern/Map/Measure/Manage functions being the spine, and is executed through three control families: logging, evaluation, and provenance. For public companies, board reporting on this risk is no longer discretionary. AI stopped being an experiment some time ago. It now sits inside identity workflows, alert triage, fraud scoring, and automated response, the exact systems a security organization runs every day. Once a model can shape a consequential decision, the question is no longer whether it is clever but whether it is governed: who authorized it, what it is allowed to do, how its behavior is measured, and who answers for it when it goes wrong. That question rarely has a clean owner. In practice it gravitates to the Chief Information Security Officer, because the CISO already owns the muscle memory, risk registers, control frameworks, incident response, and a standing reporting line to the board. The good news is that the security chair does not have to invent the discipline. Three reference points now define the field, and they are mutually reinforcing: a voluntary U.S. framework, an international management-system standard, and a binding European statute. Read together, they say the same thing in three dialects, AI governance is an operational program, not a one-time compliance attestation. ## The three texts that define the CISO's AI governance remit The most useful place to start is the NIST AI Risk Management Framework (AI RMF 1.0), published in January 2023. It is voluntary, sector-neutral, and organized around four functions a CISO will find familiar: Govern, Map, Measure, and Manage. Govern establishes accountability and policy; Map sets context and identifies risk for a specific system; Measure analyzes and monitors that risk with quantitative and qualitative methods; Manage allocates resources to treat it. The framework also names the properties of a trustworthy system, accountable and transparent, explainable and interpretable, privacy-enhanced, secure and resilient, and fair with harmful bias managed. In July 2024 NIST extended the framework with a Generative AI Profile (NIST-AI-600-1), which enumerates twelve risk categories unique to or amplified by generative models, among them confabulation, data privacy, information security, and, squarely relevant here, information integrity. The second text is ISO/IEC 42001:2023, the world's first AI management-system standard, published in December 2023. Where NIST gives you a vocabulary and a set of functions, ISO 42001 gives you a certifiable management system, requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System, including AI risk assessment and AI impact assessment across the lifecycle. For a CISO who has already lived through ISO/IEC 27001, the architecture is immediately legible: policy, objectives, controls, audit, improvement. The third is the only one with teeth. The EU AI Act (Regulation (EU) 2024/1689) takes a risk-based approach and imposes hard technical obligations on high-risk systems. Article 12 requires that high-risk AI systems be built to automatically record events, logs, over their lifetime, so that situations presenting risk can be identified and operation can be monitored after deployment. Article 26 then obliges deployers to retain those automatically generated logs for at least six months. Traceability, in other words, is no longer a nice-to-have; for in-scope systems it is the law, and full enforcement of the high-risk regime arrives in August 2026. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} THE GOVERNANCE STACK, security chair Board reporting risk posture · material incidents · oversight cadence Accountability layer named owners across vendor · builder · deployer · operator Control layer logging & retention · access · TEVV evaluation · provenance Risk-framework base NIST AI RMF · ISO/IEC 42001 · EU AI Act 2024/1689 GOVERN MAP MEASURE MANAGE AI RMF risk → control → accountability → report FIG. 1, The governance stack the security chair owns. Each layer rests on the one below; the NIST AI RMF functions run the full height. Controls: logging, evaluation, and provenance The control layer is where governance stops being a memo and becomes engineering. Three control families matter most for a security leader. The first is traceability. Explainability and event logging are not academic luxuries; they are the prerequisite for forensic readiness when an AI system has touched an access decision, an investigation, or an incident-response action. NIST treats interpretability as part of risk management, and the EU AI Act makes lifetime logging a technical requirement for high-risk systems.[1][4] If your model influenced who got in and who got locked out; you will eventually need to reconstruct why, and you cannot reconstruct what you never recorded. The second is test, evaluation, verification, and validation (TEVV). Governance depends on the ability to measure system behavior against stated objectives and constraints, and to keep measuring. NIST's companion Playbook frames this as continuous: monitoring for drift, emergent behavior, and shifts in deployment context, rather than a single pre-launch checkbox. A model that was fair and accurate at deployment can decay quietly; the control is the cadence, not the launch gate. The third is secure-by-design hygiene applied to the model itself. The joint guidance from CISA and the UK's NCSC, released in November 2023 and co-sealed by agencies across more than a dozen countries, organizes security around four lifecycle phases, secure design, secure development, secure deployment, and secure operation and maintenance, and treats AI systems as carrying novel vulnerabilities that sit alongside conventional cyber threats. For the CISO, the practical translation is that the remit expands from protecting data to protecting the integrity of automated logic. ## Accountability: refuse the diffusion The hardest governance problem is not technical. It is that responsibility dissolves. An AI capability is rarely built in one place, a vendor trains the model, an integrator wires it in, a business unit deploys it, an operator runs it. When something goes wrong, each party can point at the next. Automation does not erase responsibility; it concentrates it inside organizational process, which means someone has to be named. The security chair's job is to make the accountability map explicit before an incident, not after: who approved the use case, who owns the controls, who signs the risk acceptance, and who is accountable to the board. ISO/IEC 42001 gives this a home as a documented management responsibility; NIST's Govern function gives it a name.[1][3] ## The synthetic-media line item Deepfakes belong on the AI risk register, and the security chair owns them twice over. As a threat, synthetic voice and video now drive business-email-compromise and executive-impersonation fraud, a fabricated CFO on a video call authorizing a wire is a security incident, not a curiosity. As a governance matter, generative systems the organization itself deploys can produce convincing but false content; NIST's Generative AI Profile lists information integrity as a named risk category for exactly this reason. The defenses are the ones the security program already understands: out-of-band verification for high-value transactions, provenance and content-authenticity signals on media the organization produces, and detection tuned for impersonation. See the War Room for the incident-side playbook. ## Board reporting on AI risk: the part that is now mandatory For public companies, board-level reporting on this risk is no longer discretionary. The SEC's cybersecurity disclosure rules, adopted in July 2023, require disclosure of material cybersecurity incidents on Form 8-K (Item 1.05) within four business days of a materiality determination, and, through Item 106 of Regulation S-K, annual disclosure of how the company assesses, identifies, and manages material cyber risk, including the board's oversight role. An AI failure that compromises security, or a deepfake-driven fraud, can be a material cybersecurity incident. The reporting line a CISO already maintains to the board is therefore the same channel through which AI risk now flows, and the disclosure clock is short. The throughline across all of this is unglamorous and durable. Build governance now, frameworks at the base, controls in the middle, named accountability above them, board visibility at the top, and you reduce reactive remediation later. The security chair did not ask for AI governance, but it fits the chair better than any other in the building. The job is to treat it the way security has always treated risk: documented, measured, owned, and reported. Boards increasingly want the synthetic-media portion of that remit assessed by someone outside the reporting line. - Reg S-P's new baseline for smaller firms , the concrete regulatory floor under the governance - Agentic AI and accountability: who answers when an agent trades? , what happens when an autonomous system acts - From code to canvas: the copyright fight over generative-AI creations , who owns what the tools your programme authorises actually produce ## Sources ## Common questions on this topic The NIST AI Risk Management Framework (AI RMF 1.0), published January 2023. It is voluntary, sector-neutral, and organized around four functions a security leader will already recognize: Govern (accountability and policy), Map, Measure, and Manage. It lands there twice over. As a threat, synthetic voice and video now drive business-email-compromise and executive-impersonation fraud, a fabricated CFO authorizing a wire on a video call is a security incident. It is also an AI risk-register item in its own right. For public companies, yes. The SEC's cybersecurity disclosure rules adopted in July 2023 require disclosure of material cybersecurity incidents on Form 8-K (Item 1.05) within four business days of a materiality determination, plus governance disclosure through Item 106. ======================================================================== # AI tools and attorney-client privilege: keeping confidences confidential URL: https://imadethisup.org/blog/ai-tools-attorney-client-privilege Published: 2026-06-15 Summary: Feeding client data to a third-party AI model can risk confidentiality and privilege. ABA Rule 1.6, Opinion 512, FRE 502 waiver, and the controls. ======================================================================== Feeding client information to a third-party AI model implicates two distinct protections. ABA Model Rule 1.6 bars revealing information relating to the representation and requires reasonable efforts to prevent disclosure; separately, privilege protects only communications kept confidential, so voluntary disclosure to a third party outside the circle of representation generally waives it. The attorney-client privilege protects confidential communications between a lawyer and client made to obtain or provide legal advice. The Supreme Court has called it "the oldest of the privileges for confidential communications known to the common law," grounded in the idea that sound advice depends on the client being able to speak freely. The work-product doctrine, recognized in Hickman v. Taylor, runs alongside it, shielding the materials a lawyer prepares in anticipation of litigation, and giving heightened protection to a lawyer's mental impressions, conclusions, and legal theories. Both protections share a single load-bearing assumption: that the confidence stays inside the circle. Generative AI quietly tests that assumption thousands of times a day. When a lawyer or an in-house team pastes a draft contract, a witness memo, or a set of deposition notes into a consumer chatbot to "summarize this" or "tighten this argument," the confidential material may leave the firm's control entirely, flowing to a third-party provider that stores it, logs it, and in some product tiers uses it to train future models. The legal question is whether that disclosure breaks confidentiality, waives privilege, or both. ## The confidentiality duty under Model Rule 1.6 comes first Before privilege is ever litigated, the ethics rules impose a broader duty. ABA Model Rule 1.6 bars a lawyer from revealing "information relating to the representation of a client" absent informed consent or a recognized exception, and Rule 1.6(c) requires "reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to," that information. That duty is far wider than the privilege: it covers all information about the matter, whatever its source, not just confidential lawyer-client communications. A tool that ingests client information can implicate Rule 1.6 even where no privileged communication is involved at all. The competence rule reinforces the point. Comment 8 to Model Rule 1.1 requires lawyers to keep abreast of "the benefits and risks associated with relevant technology", the so-called duty of technological competence, now adopted in some form by a large majority of states. Using an AI tool without understanding where the data goes is not a neutral act; it is a competence question. ## What ABA Formal Opinion 512 actually says In July 2024 the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, its first comprehensive guidance on generative AI. On confidentiality the opinion is direct: because the duty under Rule 1.6 attaches to all information relating to the representation, a lawyer must evaluate the risk that a generative-AI tool will disclose or expose that information before inputting it. Self-learning tools that train on user inputs raise a particular hazard, client information fed in today could surface in an output generated for a different user, even an adverse party, tomorrow. The opinion's practical instructions are worth reading closely. Before entering client information into a tool, a lawyer should understand the tool's terms of use, privacy policy, and data-handling practices; should consider whether the tool retains or trains on inputs; and, critically, may need the client's informed consent, not mere boilerplate, before submitting that client's confidential information to a third-party model. The opinion also flags supervisory duties under Rules 5.1 and 5.3: a firm that adopts AI tools must train and oversee the lawyers and staff who use them. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} Confidential client data Rule 1.6 information PRIVILEGE GATE data handling reviewed? no-training / no-retention? informed consent on file? enterprise terms in place? PASS Input permitted confidence preserved FAIL Input blocked waiver / disclosure risk no gate = client confidence leaves the circle FIG. 1, A privilege-preservation gate. Client information should clear data-handling, consent, and contractual checks before it ever reaches a third-party model. A third-party AI tool as a privilege-waiver trigger Confidentiality and privilege overlap, but they are not the same, and privilege has its own unforgiving logic. The privilege protects only communications kept confidential, and voluntary disclosure to a third party outside the circle of representation generally waives it. That is why courts have repeatedly warned that a corporation cannot manufacture privilege simply by routing material through counsel, and why intermixing legal and business purposes invites a waiver fight in the first place. The same principle cuts the other way when client material is handed to an outside vendor. A consumer AI provider that stores inputs and reserves the right to use them to improve its products looks, doctrinally, a lot like any other third party. Not every disclosure to a service provider waives the privilege, courts have long recognized that agents who assist the lawyer in rendering legal advice can fall inside the circle, much as Upjohn extended the privilege beyond the corporate control group. But that protection depends on the provider acting as a confidential agent of the representation under terms that keep the information confidential, not as an open-ended data sink. The contractual posture, retention, training rights, sub-processing, breach exposure, is doing the legal work. ## Inadvertent disclosure and FRE 502 If confidential material does slip out through an AI tool, Federal Rule of Evidence 502 governs whether the leak waives privilege or work-product protection in federal proceedings. Rule 502(b) provides that an inadvertent disclosure does not operate as a waiver if the holder took reasonable steps to prevent disclosure and promptly took reasonable steps to rectify the error. The phrase that should focus every general counsel's attention is "reasonable steps to prevent." A firm that lets staff paste privileged documents into a public chatbot with no policy, no vendor diligence, and no training will struggle to show it took reasonable steps, and may forfeit the very protection 502 was written to preserve. Rule 502 is a safety net for accidents, not a cure for carelessness. ## Controls that protect privilege when counsel uses AI tools The doctrine here is not exotic; the discipline is. Several controls protect confidentiality and privilege regardless of which tool a team adopts: - Read the data-handling terms before, not after. Distinguish consumer tiers that train on inputs from enterprise agreements that contractually disable training, limit retention, and bind sub-processors. The contract, not the marketing page, defines the risk, exactly the diligence Formal Opinion 512 contemplates. - Get informed consent where the rules require it. When client confidential information will enter a third-party model, generic engagement-letter boilerplate may not be enough; consider specific, informed client consent and document it. - Write and enforce an AI-use policy. Define which tools are approved, what data may never be entered, and who supervises use under Rules 5.1 and 5.3. A policy on paper plus real training is the record that demonstrates "reasonable steps" under FRE 502(b). - Prefer architectures that keep data in the circle. Self-hosted, zero-retention, or enterprise deployments that do not train on inputs keep the confidence where the privilege requires it. See the War Room for incident-readiness resources. None of this requires abandoning AI; the competence rule arguably points the other way. It requires treating client confidences with the same care offline and online, recognizing that the easiest button in the interface can be the one that hands the oldest privilege in the common law to a stranger. The durable defense is the same one good practice has always demanded: keep the circle closed, and be able to prove you did. This article is general educational information about synthetic-media and technology risk, not legal advice. Rules of professional conduct vary by jurisdiction; consult counsel and your governing rules for any specific situation. Where a disclosure has already happened, the waiver analysis turns on technical specifics, what the model retained, and for how long, which is a question for a forensic examiner. - The hallucination tax: what unverified AI citations really cost , competence and confidentiality under the same opinion - Using AI in e-discovery: how to defend the review, not just run it , where client documents meet a review model Where the same inattention reaches a filing rather than a client file, courts have begun sanctioning it under the certification rules, and those orders are collected and summarised here. ## Sources ## Common questions on this topic Issued July 2024 as the ABA's first comprehensive generative-AI guidance; it is direct on confidentiality: because the Rule 1.6 duty attaches to all information relating to the representation, a lawyer must evaluate the tool before inputting client information. It can. Privilege protects only communications kept confidential, and voluntary disclosure to a third party outside the circle of representation generally waives it. That is the same logic courts have applied to other third-party disclosures, the tool being software changes nothing. Federal Rule of Evidence 502 governs. Rule 502(b) provides that an inadvertent disclosure does not operate as a waiver in federal proceedings if the holder took reasonable steps to prevent disclosure and reasonable steps to rectify the error. ======================================================================== # Authenticating AI-touched evidence: do we need a new rule? URL: https://imadethisup.org/blog/authenticating-ai-evidence-rule-901 Published: 2026-06-15 Summary: FRE 901 assumed seeing was believing. A look at Rule 901(b)(9), 902(13)-(14), proposed Rule 707, and what practitioners should be doing right now. ======================================================================== Federal Rule of Evidence 901(b)(9), evidence describing a process or system that produces an accurate result, is the workhorse for machine output, but its bar is low enough that a competent fake can clear it. Reform proposals would require a "valid and reliable" result, and a proposed Rule 707 would apply Rule 702 reliability standards to machine-generated evidence offered without a sponsoring expert. The Federal Rules of Evidence set a deliberately low bar for getting a photo, video, or audio file in front of a jury. Under Rule 901(a), the proponent need only "produce evidence sufficient to support a finding that the item is what the proponent claims it is." That is a screening standard, not a proof standard: the judge decides whether a reasonable juror could find the item genuine, and the jury decides whether it actually is. For a century that lenient gate worked, because fabricating convincing audiovisual evidence was hard, expensive, and usually detectable. Generative AI removes all three frictions at once. Realistic fakes are now cheap, fast, and, to a layperson and increasingly to experts, hard to distinguish from the real thing. The question consuming the Advisory Committee on Evidence Rules is whether a rule written for the analog era needs surgery, or whether judges already have the tools. ## How 901 and 902 actually work today Rule 901(b) supplies a non-exhaustive menu of ways to clear the bar. The provision most often invoked for machine output is 901(b)(9): "Evidence describing a process or system and showing that it produces an accurate result." This is the workhorse for surveillance footage, a custodian testifies that the camera system runs as described and is reliable, and the video comes in. Other subsections do the rest of the heavy lifting: a witness with personal knowledge under 901(b)(1), comparison by an expert or the trier of fact under 901(b)(3), or "distinctive characteristics" under 901(b)(4). Rule 902 goes further, making certain records self-authenticating so no live witness is needed. Two 2017 additions matter here: 902(13), covering "certified records generated by an electronic process or system," and 902(14), covering "certified data copied from an electronic device, storage medium, or file," authenticated by digital identification such as hash comparison. Notice the shared premise running through 901(b)(9), 902(13), and 902(14): a system that "produces an accurate result." That phrase assumes the system is faithfully recording reality. A generative model is engineered to do the opposite, to synthesize output that only looks like a recording of reality. ## The deepfake problem, and the liar's dividend The danger runs in two directions. The first is the obvious one: fabricated evidence that slips through a permissive gate. Because the 901(a) threshold is so low, a competent fake can satisfy it. The second is subtler and, so far, more common in real dockets, the "liar's dividend," a term popularized by law professors Bobby Chesney and Danielle Citron for the way pervasive awareness of deepfakes lets bad actors dismiss genuine evidence as fake. Courts are already seeing both. In Huang v. Tesla, lawyers for Elon Musk argued that an authentic, years-old recorded statement might be a deepfake; the judge rejected the gambit as "deeply troubling," refusing to let public figures hide behind the mere possibility of fakery. Running the other way, in Mendones v. Cushman & Wakefield (Alameda County Superior Court, 2025), the court suspected that summary-judgment exhibits were AI-generated, flagging looping video and absent facial expressions, ordered the plaintiffs to produce full metadata, and ultimately imposed terminating sanctions after concluding the videos were deepfakes. The lesson of Mendones is encouraging: a careful judge, asking for the right technical record, caught the fake. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} Proponent offers item 901(a): could a juror find it genuine? Opponent challenges as AI-fabricated more than a bare "it's a deepfake" Threshold showing made? evidence of fabrication / alteration NO Admit jury weighs authenticity YES Burden shifts to proponent reliability / probative-value test proposed 901(c) framework, not yet adopted FIG. 1, Burden-shifting gate under the proposed (not adopted) Rule 901(c). Today, a bare deepfake assertion does not shift the burden; the jury decides. The proposals on the table to amend Rule 901 Two reform tracks dominate the debate. The first, advanced by retired U.S. District Judge Paul W. Grimm and Dr. Maura R. Grossman, would amend 901(b)(9) so that a process or system must show it produces a "valid and reliable" result, not merely an "accurate" one, and would add a new 901(c) creating a burden-shifting test: once a challenger shows it is more likely than not that electronic evidence was fabricated or altered, the item is admissible only if its probative value outweighs its prejudicial effect. A parallel proposal from Professor Rebecca Delfino would likewise add a 901(c) but require the proponent to authenticate under 901(b) and prove reliability, relocating the call from the jury to the judge. The second track moved faster, but on different terrain. In June 2025 the Advisory Committee approved publication of an entirely new Rule 707, "Machine-Generated Evidence," which went out for public comment from August 15, 2025 through February 16, 2026. Rule 707 targets a distinct problem from deepfakes: machine output offered without a human expert, say, an algorithm's conclusion presented directly to the jury. It would subject that output to the same reliability scrutiny that Rule 702 applies to expert testimony. The Department of Justice, the lone dissenting vote, argued Rule 702 already reaches such evidence. Notably, the Committee declined for now to advance a deepfake-specific 901(c), concluding existing tools suffice given how few deepfake disputes have actually reached the courts, while keeping the draft on the shelf should that change. ## The argument for patience on new authentication rules There is a real case for the Committee's wait-and-see posture. In 2014 the same body considered, and rejected, special rules for authenticating emails, texts, and social-media posts, and in hindsight that restraint looks correct, because courts adapted 901's existing categories without much trouble. Critics such as Riana Pfefferkorn note that courts are "no stranger to doctored photographs" and have absorbed every prior wave of fakery without the sky falling. Rulemaking is slow, typically three years, and a rule drafted to today's model architecture could be obsolete before it takes effect. ## Three moves for practitioners, whether or not Rule 901 changes Whether or not the rules change, the practice has already changed. Three moves pay off regardless of how the rulemaking lands: - Build the authentication record at creation, not at trial. Capture and preserve hashes, signed provenance (C2PA-style Content Credentials), and full metadata. A 902(14) digital-identification certificate is worth far more than a witness's after-the-fact memory. See the Provenance guide. - Treat "it's a deepfake" as a claim that needs proof. Courts have rejected bare hacking and fakery assertions for years; a challenge should be backed by metadata, expert analysis, or visible artifacts, exactly the record the Mendones court demanded. - Budget for the expert, and for the access-to-justice gap. Forensic authentication of contested audiovisual evidence is expensive and qualified experts are scarce, which risks pricing out under-resourced litigants. Plan for it early. The honest answer to "do we need a new rule?" is: maybe, but not yet for deepfakes, and possibly soon for machine output. Either way, the durable defense is the same one provenance has always provided, evidence that can prove what it is, rather than evidence we are merely asked to believe. A Rule 901(b)(9) showing needs a witness who can describe the process that produced the output, which is the work a retained technical expert does. - Deepfakes and the integrity of evidence in family court , the doctrine applied where the liar’s dividend bites hardest - Forensic neutrals: who decides when digital evidence is contested? , what happens when authentication is contested - When the file lies about itself , the metadata problem underneath the rule Courts have not waited for a new rule to start answering this, and the decisions so far, including one state high court that found video unauthenticated and another that did not, are summarised in our collection of the authentication case law. ## Sources ## Common questions on this topic Rule 901(b) supplies a non-exhaustive menu, and 901(b)(9) is the provision most often invoked for machine output: "Evidence describing a process or system and showing that it produces an accurate result." It is the workhorse for surveillance footage and similar material. The subtler of the two dangers, and so far the more common in real dockets: because everyone now knows video can be fabricated, a party can dismiss genuine evidence as "probably a deepfake." The mere existence of the technology devalues authentic proof. Two reform tracks are live. Judge Paul W. Grimm and Dr. Maura R. Grossman would amend 901(b)(9) to require a "valid and reliable" result rather than merely an "accurate" one. Separately, a proposed Rule 707 would apply Rule 702's reliability requirements to machine-generated evidence. ======================================================================== # Building a deepfake incident-response plan for smaller firms URL: https://imadethisup.org/blog/deepfake-incident-response-plan Published: 2026-06-15 Summary: When a voice clone hits a small firm, the first hour decides everything. A checklist playbook built on NIST SP 800-61, FBI IC3, and CISA guidance. ======================================================================== A synthetic-media incident often leaves no technical footprint, no breached server, just a call or message that persuaded someone. Anchor the response to NIST SP 800-61 Revision 3 and run five steps: detect, contain, preserve, notify, recover. Containment means calling the bank's fraud line immediately, because wire-recovery windows are measured in hours, not days. Synthetic-media fraud has stopped being a problem only for the Fortune 500. The barrier to entry has collapsed: a usable voice clone can be built from a few seconds of audio scraped off a webinar or a voicemail greeting, and a convincing video of an executive can be assembled in an afternoon. In December 2024 the FBI's Internet Crime Complaint Center warned, in alert I-120324-PSA, that criminals are using generative AI to scale fraud, producing audio clips of a "loved one in a crisis situation" and impersonating leaders to authorize transfers. A month earlier, FinCEN told financial institutions the same thing from the other side of the counter: deepfake media is now being used to defeat identity verification at account opening, and banks were filing suspicious-activity reports about it. For a smaller organization, a law firm, a clinic, a family office, a regional nonprofit, the math is brutal. You hold concentrated, high-value information and authority, but you rarely have a dedicated security team standing by. The good news is that incident response is a discipline, not a budget line. A short, written plan that everyone has read beats an expensive tool that no one knows how to use at 4:55 p.m. on a Friday. ## Why deepfake incidents break the ordinary playbook Most incident-response plans assume an intrusion: malware, a phished credential, a ransomware note. A synthetic-media incident often leaves no technical footprint at all. There is no breached server; there is a phone call, a voicemail, a video meeting, or a forged message that persuaded a human being to act. NSA, FBI, and CISA flagged exactly this in their 2023 information sheet, Contextualizing Deepfake Threats to Organizations: the highest-impact abuses impersonate leaders and finance officers to authorize fraudulent transactions and to pry open access to networks. That means your plan has to treat a suspicious communication as a reportable event, route it the same way you would route a malware alert, and resist the instinct to quietly "sort it out" one-on-one. ## Anchor the plan to a recognized framework You do not need to invent a methodology. NIST's incident-handling guidance, refreshed as SP 800-61 Revision 3 in April 2025, organizes response around the Cybersecurity Framework 2.0 functions and supersedes the long-standing Revision 2. Borrow its spine and adapt it to a five-step flow any small team can run from memory: detect, contain, preserve, notify, recover. Write it down. Keep it to two pages. Name a person for each step, even if several names are the same person, and list one external backstop (outside counsel, an IT consultant, a forensic firm) you will call when the incident exceeds what you can handle alone. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:10.5px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} DEEPFAKE INCIDENT TIMELINE DETECT flag & report minute 0 CONTAIN halt transfer first hour PRESERVE capture files same day NOTIFY bank · IC3 · law ≤ 72 hours RECOVER harden · review days–weeks code words · callback verification · phishing-resistant MFA reduce the odds you ever reach CONTAIN accent boxes = steps where evidence is won or lost FIG. 1, A five-stage synthetic-media response timeline. Time windows are indicative, not legal deadlines; your actual notification clocks depend on the laws and contracts that apply to you. Detect: make reporting frictionless Detection in a deepfake incident is almost always a human noticing that something feels off, an unusual urgency, an off-channel request, a payment instruction that breaks the normal process. The single most valuable control is a verification habit your people use before acting: an agreed code word or a callback to a known number for any financial or credential request, exactly as the FBI recommends. Pair that with one obvious reporting path. Staff should know, without looking it up, who to message the instant they suspect a synthetic call or message, and they should know they will be thanked for a false alarm, never blamed. Phishing-resistant multi-factor authentication, which CISA calls the gold standard, blunts the credential-theft variant of these attacks before detection is even needed. ## Contain a deepfake incident: stop the money and the access Containment for synthetic-media fraud is mostly about speed on two fronts. First, the transaction: if a transfer has gone out, call the bank's fraud line immediately and request a recall, wire and push-payment recovery windows are measured in hours, not days. Second, the access: if the lure was aimed at a login, reset the affected credentials, revoke active sessions, and assume any account the target could reach may be compromised. Containment is also a communications act. Put a short, factual hold on the impersonated channel, "we have a suspected impersonation incident; verify any request from this person by callback", so the same fake cannot claim a second victim while you work. ## Preserve the deepfake evidence: the step everyone skips This is where small organizations most often lose. In the rush to fix the problem, people delete the voicemail, clear the call log, or close the video meeting without saving anything, and with it goes the evidence that investigators, insurers, and a possible civil claim all depend on. Preserve the artifact in its original form: the audio or video file, the message with full headers, the meeting recording and chat, and any platform metadata. Do not edit it; make working copies and keep the original untouched. Note who received it, when, and on which device, and record a hash of each file so its integrity can be shown later. This is the same provenance discipline that decides whether synthetic media holds up under scrutiny, see the Provenance guide and our War Room for the forensic side. ## Notify after the incident: know your clocks before the clock starts Notification is where a generic plan fails, because the obligations depend entirely on who you are. Build your list in advance: - Law enforcement and IC3. Report fraud and attempts to the FBI's Internet Crime Complaint Center at ic3.gov; speed materially improves the odds of clawing back funds. - CISA, where applicable. Critical-infrastructure entities will have mandatory reporting duties once CISA's CIRCIA final rule takes effect, and CISA already accepts voluntary incident reports from any organization, a 72-hour posture is a sound default to plan around. - Sector regulators. A non-banking financial institution under the FTC Safeguards Rule must notify the FTC of a qualifying breach as soon as possible and no later than 30 days after discovery. Financial institutions filing suspicious activity should reference the FinCEN deepfake alert key term in the SAR. - Intimate-image abuse. If the synthetic media is non-consensual intimate imagery, route victims to the right channel, NCMEC's CyberTipline and the Take It Down service for content involving minors, with the federal TAKE IT DOWN Act now requiring platforms to remove verified NCII within 48 hours. Add your own contractual and ethical clocks, client-notification duties, cyber-insurance reporting windows, and state breach-notice laws, next to each line so no deadline is discovered after it has passed. ## Recover from the incident: close the loop, then practice Recovery is more than restoring operations. Harden the path the attacker used: tighten payment-authorization rules so no single person can move funds on a verbal instruction, expand callback verification, and shore up MFA. Then do the part most teams omit, the post-incident review NIST builds into the lifecycle. Write down what was detected and when, what worked, what didn't, and which one change would most reduce the next incident's damage. Finally, rehearse. A 30-minute tabletop, "a cloned voice of the managing partner just told accounting to wire a deposit", surfaces the gaps in your two-page plan far more cheaply than the real thing will. None of this requires an enterprise budget. It requires deciding, in advance and on paper, who does what in the hour after a synthetic call lands, and practicing it once before you need it. That plan is the difference between an incident and a catastrophe. Smaller firms rarely hold this capability in-house, and the first hour is a poor time to start looking, worth deciding who you would call before you need them. - “Follow the money” is no longer enough , what recovery looks like once the money has moved - What the Arup deepfake actually proves, and what it doesn't , the case this plan is written against - Reg S-P's new baseline for smaller firms , the rule that makes a written plan mandatory ## Sources ## Common questions on this topic Most plans assume an intrusion, malware, a phished credential, a ransomware note. A synthetic-media incident often leaves no technical footprint at all. There is no breached server, only a phone call, voicemail, video meeting, or forged message that persuaded a person to act. NIST's incident-handling guidance, refreshed as SP 800-61 Revision 3 in April 2025, which organizes response around the Cybersecurity Framework 2.0 functions and supersedes Revision 2. Borrow its spine and adapt it to a five-step flow any small team can run. Preservation. In the rush to fix the problem people delete the voicemail, clear the call log, or close the video meeting without saving anything, and with it goes the evidence investigators, insurers, and any possible civil action will need. ======================================================================== # Deepfake defense for real-estate closings, at the process layer, not the model. URL: https://imadethisup.org/blog/deepfake-wire-fraud-real-estate Published: 2026-06-15 Summary: Voice and video impersonation is hitting title, escrow, and closing workflows. The break point is the missing callback on wiring instructions. ======================================================================== Voice and video impersonation now reaches title, escrow, and closing workflows, in September 2024 a Florida title company nearly wired roughly USD 250,000 to a fraudster who joined a Zoom call posing as the property owner. Detection is a useful layer but only a probability; the control that works is refusing to authorize funds without an out-of-band callback on the wiring instructions. A real-estate closing is a near-perfect target for synthetic-media fraud. The dollar amounts are large, the timelines are tight, and the authorization for a six-figure wire often rests on a voice on the phone or a face on a video call. The FBI's Internet Crime Complaint Center logged more than USD 275 million in real-estate-related fraud losses across at least 12,368 victims in 2025, up from roughly USD 173 million the prior year. Business email compromise, the broader category that swallows most closing-wire diversions, accounted for close to USD 2.8 billion in reported losses in 2024 alone. Generative tools don't create this exposure. They lower the cost of exploiting it. ## The deepfake reaches the closing table In September 2024, a Florida title company nearly wired roughly USD 250,000 to a fraudster who joined a Zoom call posing as the property owner. The impersonated identity was built around a woman who had been reported missing in 2018; the seller appeared on camera under a different name. The company didn't catch it with a detection model. It caught it with process: tax bills routed to a country that didn't match the seller's claimed residence, then a demand for proof of life that the fraudster could not satisfy. The synthetic face was convincing. The paperwork and the verification step were not survivable. That is the recurring shape of these incidents. The Arup Hong Kong case, fifteen wires totaling about USD 25 million, authorized after a video call where every other participant was AI-generated, is framed by independent analysts as a repeatable pattern, not a one-off feat of engineering. The systems were never breached. The approval workflow was. ## Why real estate is structurally exposed Four features of the transaction stack the odds for an attacker: - High value, high speed. Closings move on a clock, and parties are pressured to act before funds are due, the exact condition synthetic-media fraud depends on. - Fragmented channels. Buyers, sellers, agents, lenders, attorneys, and title officers coordinate across email, phone, and video. Every seam is a place to insert a convincing impostor. - Trust over protocol. Brokers and title agents run on established professional relationships. A cloned voice or face weaponizes that familiarity directly. - Last-minute instruction changes. The single most dangerous event in a closing is a change to wiring instructions near the deadline, and it is precisely what the impostor will manufacture. None of these is a technology gap. They are workflow assumptions, and that is good news: workflow is something you control. - OUT-OF-BAND CALLBACK number from file of record + pre-shared phrase MATCH RELEASE FUNDS after soft hold NO MATCH → STOP, ESCALATE FIG. 1, The checkpoint is the control. The impostor owns the inbound channel; it does not own the number on file or the phrase. The control that FinCEN and ALTA already name The defense is not novel and it is not proprietary. In November 2024, FinCEN issued an alert on generative-AI fraud schemes circumventing identity-verification controls at financial institutions, citing a rise in suspicious-activity reports involving deepfake media and pointing to phishing-resistant multi-factor authentication and live verification checks as mitigations. The American Land Title Association's wire-fraud guidance is blunter still: verify wiring instructions through an independent channel, and call the escrow or title company at a known, trusted number, never the number printed in the inbound email. Legitimate wiring instructions almost never change mid-transaction; treat any change as hostile until proven otherwise. The same protocol that protects a title file protects a corporate treasury. The Ferrari executive who foiled a 2024 voice-clone attempt asked the caller to name a book the CEO had personally recommended days earlier; the synthetic system had no answer. Different industry, identical mechanism, a question the channel can't answer, asked before money moves. What detection does and does not do Real-time deepfake detection, voice analysis against known voiceprints, frame-level video inspection, document and metadata checks, is a worthwhile layer, especially for remote notarization and virtual closings where there is no in-person fallback. But detection is a probability, and it sits inside a workflow that can override it. In every case above, the deciding factor was a procedural step the attacker could not pass: a callback to a number they didn't control, a phrase they didn't know, a proof they couldn't produce. Detection narrows the odds. Process closes the deal. What to put in the closing playbook this week Out-of-band callback on every wire and every instruction change. Use a number from the file of record or the corporate directory, not the inbound caller ID, not the email signature. This single step is what ALTA and the FBI both put first.[1][6] - Pre-shared verification detail with the client. Set it at engagement, never on camera, never in a shared document. A face or voice can be cloned; a fact agreed in advance cannot be guessed live. - Soft hold above a defined threshold. Build a short mandatory delay into high-value releases. Synthetic-media fraud runs on momentum; a hold breaks the clock the attacker is counting on. - A wire-fraud rapid-response plan. Know the recall path before you need it, the IC3 Recovery Asset Team reports a meaningful freeze rate when victims report fast. The model will keep getting better. The face will keep getting more convincing, the voice harder to distinguish. None of that changes the defense, because the defense was never about telling real from fake on the call. It was about refusing to authorize money on the strength of the call at all. See the War Room for the authentication card. Where funds have already moved, tracing and voice analysis both run on a short clock, and both typically require outside forensic capacity. - What the Arup deepfake actually proves, and what it doesn't , the same attack pattern at corporate scale - Building a deepfake incident-response plan for smaller firms , the callback protocol that defeats it ## Sources ## Common questions on this topic Yes. In September 2024 a Florida title company nearly wired roughly USD 250,000 to a fraudster who joined a Zoom call posing as the property owner. The impersonated identity was built around a woman who had been reported missing in 2018. Four structural features of the transaction stack the odds for an attacker, including large one-time transfers to parties who are often strangers, tight closing timelines, and remote or virtual closings where there is no in-person fallback for identity verification. Only partially. Real-time detection, voice analysis against known voiceprints, frame-level video inspection, document and metadata checks, is worthwhile, especially for remote notarization. But detection returns a probability and sits inside a workflow; the defense was never about telling real from fake on the call. ======================================================================== # Deepfakes and the integrity of evidence in family court. URL: https://imadethisup.org/blog/deepfakes-in-family-court-evidence Published: 2026-06-15 Summary: In custody fights a fabricated video does its damage before anyone proves it fake. The defense is authentication discipline, not better detection. ======================================================================== A fabricated video can do its damage in a custody dispute before anyone proves it fake. The remedy is not better detection but an authentication discipline the rules already support: Federal Rule of Evidence 901(a) has always required a proponent to produce evidence sufficient to support a finding that the item is what they claim it is. - CLIP A · signed at source capture hash custody admit CLIP B · no provenance ??? origin custody offered , break, Fig. 1, Authentication is a chain, not a verdict. A clip signed at source survives the walk to admission; a clip with no provenance breaks it. A custody hearing turns on credibility, and nothing wrecks credibility faster than a parent shown on screen screaming threats at a child. So picture the parent who never said those words. A short clip arrives in the file. It looks real, it sounds real, and it lands before anyone has tested where it came from. The damage is done at the moment of viewing. Unwinding it is slow, expensive, and uncertain. That is not a hypothetical. In a 2020 English family case, a mother used consumer software and online tutorials to doctor an audio recording so that the father appeared to make violent threats; the fabrication was caught only because his lawyers obtained the original file and examined its metadata. The case is now a fixture in legal commentary precisely because it shows how little skill the attack requires and how much luck the defense needed. The rules already contemplate this, most lawyers just don't invoke them The instinct is to treat deepfakes as a gap in the law. They aren't. Federal Rule of Evidence 901(a) has always required a proponent to "produce evidence sufficient to support a finding that the item is what the proponent claims it is." That standard does not assume good faith. It assumes nothing. A video is not self-proving merely because it plays. Rule 901(b)(9) is the underused tool here. It authenticates an item by "evidence describing a process or system and showing that it produces an accurate result." Applied to a phone video; that means the proponent should be able to account for the device, the capture, and the unbroken path from recording to exhibit, not just assert that the clip is genuine. The companion self-authentication rules, 902(13) and 902(14), let a qualified person certify that an electronic record is the accurate output of a system, or that a copied file matches its source by hash value. Used affirmatively, they reward the party who can show provenance and quietly expose the party who can't. The burden of proof is the battlefield in family court In practice the fight is rarely about whether deepfakes exist. It is about who has to prove what, and at whose cost. When a clip with no provenance is offered, the targeted parent is pushed into proving a negative, that an event never happened, which usually means retaining a digital-forensics expert to analyze compression artifacts, metadata, and edit history. Few family-court litigants can afford that, and the supply of qualified examiners is thin. The corrective is to keep the burden where Rule 901 puts it. A court that demands a genuine foundation before a video is shown, source, custody, and a process account, does more to protect a custody record than any detector. Authentication is a threshold the proponent must clear, not a defense the respondent must fund. The liar's dividend cuts against real evidence too There is a second hazard, and it is the mirror image of the first. Once everyone knows video can be faked, the guilty parent can wave away a real recording as "probably a deepfake." Legal scholars call this the liar's dividend: the mere existence of synthetic media lets bad actors discredit authentic evidence. A custody court that grows reflexively skeptical of all video does not become safer. It becomes blind in both directions, admitting fakes and discarding truth. This is why provenance beats suspicion. A clip that was signed at capture and carried through an intact chain of custody can be credited with confidence. A clip with no such record gets the scrutiny it has earned. The goal is not to distrust video. It is to distrust unverifiable video. Proposed Rule 707, and what to do now The Advisory Committee on Evidence Rules has published a proposed Rule 707, which would subject machine-generated evidence offered without a sponsoring expert to the reliability requirements of Rule 702, closing the gap where a party tries to launder an algorithm's output past the standards a human expert would have to meet. The proposal went out for public comment through February 2026, with the committee's review continuing this year. Separately, states have moved fast on synthetic media: the National Conference of State Legislatures tracks dozens of deepfake bills, with deceptive audio and visual media among the most active categories. The statutory frame is forming around the courts even as the rules catch up. None of that helps the parent in next week's hearing. Three habits do, and they are available today: Demand a foundation before the clip plays. Under Rule 901(a), make the proponent account for source and custody first. A video that cannot survive that question should not be shown to the finder of fact. - Preserve and pull the original. The 2020 UK father was saved by metadata on the original file. The exported, re-compressed copy a party hands over is not the evidence, the source file is. - Use provenance affirmatively. Where your own evidence is signed at capture or hashable to its source, certify it under 902(13)/(14) and let the contrast with the unverifiable clip speak. The lesson is procedural, not technical. The technology that fabricates a custody video will keep improving; the discipline that keeps it out of a child's case is older than the technology, and it is already written into the rules. Authentication discipline in a custody matter usually means putting the file in front of an examiner who can testify to what it is before it is argued over. - Authenticating AI-touched evidence: do we need a new rule? , the authentication standard this venue applies - What the TAKE IT DOWN Act actually changes, and what it doesn't , the takedown route available alongside the proceeding The New York Court of Appeals reached this question directly in February 2026 and divided four to three on it, over two dissents arguing the deepfake theory had arrived for the first time on appeal, which is set out with the other decisions in what courts have actually held about deepfake evidence. ## Sources ## Common questions on this topic Yes. The instinct is to treat deepfakes as a gap in the law, but Federal Rule of Evidence 901(a) has always required a proponent to "produce evidence sufficient to support a finding that the item is what the proponent claims it is." Most lawyers simply do not invoke it. Because when a clip with no provenance is offered, the targeted parent is pushed into proving a negative, that an event never happened, at their own cost. The fight is rarely about whether deepfakes exist; it is about who must prove what. Yes, and it is the mirror image of the first hazard. Once everyone knows video can be faked, a guilty parent can wave away a genuine recording as "probably a deepfake." Scholars call this the liar's dividend. ======================================================================== # Deepfakes are reshaping workplace sexual harassment. URL: https://imadethisup.org/blog/deepfakes-workplace-harassment Published: 2026-06-15 Summary: Synthetic intimate imagery makes harassment remote and scalable. Title VII liability does not require the conduct to happen at work, what HR should do. ======================================================================== Synthetic intimate imagery of a coworker turns harassment into a remote, repeatable act, and Title VII of the Civil Rights Act of 1964 does not require the conduct to occur at the office. Harassment becomes the employer's problem when it is severe or pervasive enough to affect the terms and conditions of employment, wherever the image was made. For most of its history, workplace sexual harassment was bounded by physical proximity and authentic conduct, a comment, a touch, a message that actually came from the person who sent it. Synthetic media removes both boundaries. A harasser no longer needs access to a victim, only to a few public photographs, and the result can be fabricated, convincing, and impossible to fully recall once it spreads. The overwhelming majority of malicious deepfakes are sexually explicit and nonconsensual, and they fall disproportionately on women. This is a sensitive subject, and it deserves to be handled as one. The point here is not the imagery; it is the harm done to a real person and the duty an employer owes them. What follows is a practical map of where that duty comes from and what a prepared organization does about it. ## Why synthetic harassment lands on the employer The instinctive objection is that a fabricated image made on someone's home computer, at night, has nothing to do with work. Title VII of the Civil Rights Act of 1964 does not draw the line there. Harassment becomes the employer's problem when it is severe or pervasive enough to alter the conditions of employment and create a hostile work environment, and conduct that originates off-premises can still permeate the workplace once coworkers see it, talk about it, or use it to intimidate. A synthetic image of an employee circulating on a team channel is not a private matter that happens to involve staff; it is a workplace event. The standard for what counts as actionable has also moved in the employee's favor. In Muldrow v. City of St. Louis (2024), the Supreme Court rejected the heightened "significant harm" bar that many lower courts had imposed on Title VII claims, holding that an employee need only show some harm to a term or condition of employment. That recalibration makes it easier, not harder, for a targeted worker to get past early dismissal, and it raises the cost of an employer that treats a synthetic-harassment complaint as someone else's problem. ## The EEOC guidance moved, then moved again For a brief window the federal enforcement posture was unusually explicit. The EEOC's 2024 Enforcement Guidance on Harassment in the Workplace, its first comprehensive harassment guidance since 1999, listed the sharing of "sexually demeaning depictions of people, including AI-generated and deepfake images and videos" among its examples of harassing conduct. For the first time, the agency had named synthetic intimate imagery directly. That guidance is no longer in force. In January 2026 the Commission voted to rescind the 2024 document. It is worth being precise about what that does and does not change. Rescinding a guidance document does not repeal Title VII, narrow the definition of a hostile work environment, or make deepfake harassment lawful. The statute and the case law, including Muldrow, remain exactly where they were. What changed is the loss of an agency-blessed example employers could point to. The underlying exposure did not move; the roadmap did. Employers should plan around the durable law, not the document of the moment. ## The takedown side of the ledger: the TAKE IT DOWN Act and state law Liability is only half the story. A targeted employee usually wants one thing first: the image gone. The federal TAKE IT DOWN Act, enacted in May 2025, criminalizes the nonconsensual publication of intimate visual depictions, including AI-generated "digital forgeries", and requires covered platforms to remove reported content within 48 hours of a valid request. State law fills in around it: a clear majority of states now have statutes reaching nonconsensual intimate imagery or sexually explicit deepfakes, with wide variation in criminal penalties and civil remedies. An employer cannot file these requests for an employee, but it can know they exist, point the person to them quickly, and avoid the trap of telling a victim to simply wait it out. ## The HR investigation reflex that now backfires For decades, HR and legal teams operated on a quiet assumption: a photo, a recording, or a video of misconduct was real, and the burden sat with whoever denied it. Synthetic media inverts that reflex. The same skepticism applies in both directions, an image purporting to show an employee behaving badly may be fabricated, and an image purporting to be an employee may be fabricated too. Treating either as self-authenticating is now a way to reach the wrong conclusion and absorb liability for it. Where authenticity is genuinely in dispute, a forensic, provenance-aware review, not a gut call, is what protects everyone, including the accused. ## An escalation path for a synthetic-harassment report, before you need one The figure below is the shape most defensible responses take. The worst outcomes in this area rarely come from the incident itself; they come from improvisation, a delayed response that reads as indifference, a public statement that gets ahead of the facts, an insurance policy with an AI exclusion nobody read until the claim. 1 · INTAKE report received, no judgment 2 · PRESERVE + ASSESS capture source, chain of custody 3 · AUTHENTIC? forensic / provenance TAKEDOWN TRACK TAKE IT DOWN / state law platform removal, 48 hr INVESTIGATION TRACK scope, witnesses, no presumption of authenticity 4 · ACT + SUPPORT discipline, accommodate, document the timeline LIABILITY ATTACHES → delay reads as indifference silence can ratify the conduct FIG · A synthetic-harassment response does two jobs at once: get the content removed, and resolve the conduct without presuming any image is real. Exposure tends to grow in the gaps between steps, not inside them. Three policy changes to make before a deepfake incident, not during one Three changes carry most of the weight, and none of them require a standing crisis team: - Name synthetic media in the policy. Most handbooks define harassment in terms that assume the conduct is real. Add language that the creation or circulation of fabricated or manipulated intimate content about a colleague is serious misconduct, regardless of where or when it was made. - Write the response plan in calm weather. Decide in advance who triages a report, how content is preserved, when authenticity gets a forensic look, and who speaks publicly. A plan on paper is the difference between a measured response and a damaging improvisation. - Read the insurance before the claim. Employment-practices and cyber policies written before generative AI may carry exclusions or ambiguities around synthetic and third-party content. Find out now whether you are covered. None of this makes the underlying harm smaller. What it does is put the employer on the right side of the only question a court, and the affected employee, will ultimately ask: when you knew, what did you do? For the verification side of that answer, see the Safety Suite. Investigations of this kind turn on whether the imagery can be attributed, which is a technical question rather than an HR one. - What the TAKE IT DOWN Act actually changes, and what it doesn't , the 48-hour takedown duty this post relies on - Building a deepfake incident-response plan for smaller firms , the employer-side response procedure ## Sources ## Common questions on this topic Potentially, yes. The instinctive objection is that an image fabricated on someone's home computer has nothing to do with work, but Title VII does not draw the line there. What matters is whether the harassment is severe or pervasive enough to affect employment conditions. The EEOC's 2024 Enforcement Guidance on Harassment in the Workplace, its first comprehensive harassment guidance since 1999, listed the sharing of "sexually demeaning depictions of people, including AI-generated and deepfake images" among covered conduct. The federal enforcement posture has since shifted. The federal TAKE IT DOWN Act, enacted in May 2025, criminalizes nonconsensual publication of intimate visual depictions, including AI-generated "digital forgeries", and requires covered platforms to act on valid removal requests. Liability is only half the story; removal is usually the first thing a target wants. ======================================================================== # Forensic neutrals: who decides when digital evidence is contested? URL: https://imadethisup.org/blog/forensic-neutrals-digital-evidence Published: 2026-06-15 Summary: When parties cannot agree that evidence is authentic, courts can appoint a neutral. FRCP 53 special masters, FRE 706 experts, and why it matters. ======================================================================== When adversaries cannot agree whether a file or an AI-generated artifact is authentic, courts have an underused option: appoint a neutral. Federal practice offers two doors, a court-appointed expert under Federal Rule of Evidence 706, and a special master under Rule 53, with the master's independence enforced by the same disqualification standard that applies to judges. Litigation is built on adversaries. Each side hires its own expert, and the trier of fact watches them disagree. That design works tolerably well when the disputed question is one of judgment, how to read a contract, whether a design infringes. It works far less well when the disputed question is a matter of physical fact buried inside a computer system: does Company A's source code actually appear on Company B's servers? Was this video file generated by a camera or by a model? Did the deleted data ever really get deleted? On questions like those, two paid experts pointing at the same drive and reaching opposite conclusions does not clarify anything. It produces a stalemate the judge is poorly equipped to break. For exactly these moments, the rules give courts a different tool: a neutral. Instead of two partisans, a single technically qualified person, appointed by and answerable to the court, examines the evidence and reports what it shows. As synthetic media and ever-larger data sets push authenticity disputes into more cases, this neutral-authority model is worth understanding precisely because it is so often overlooked. ## Two ways a court appoints a neutral: Rule 706 and Rule 53 Federal practice offers two distinct mechanisms, and the distinction matters. The first is the court-appointed expert under Federal Rule of Evidence 706. The rule lets a court appoint an expert the parties agree on, or one of its own choosing, to give an opinion, and that expert may be deposed, called by any party, and cross-examined like any other witness. Rule 706 exists to break the "dueling experts" deadlock by adding a voice the jury knows is not on anyone's payroll. Tellingly, courts have invoked it sparingly in the decades since its enactment, wary of appearing to put a thumb on the scale. The second door is broader. Federal Rule of Civil Procedure 53 lets a court appoint a master, historically a "special master," though in current practice the term "neutral" is increasingly used. Rule 53(a)(1) permits appointment to perform duties the parties consent to; to hold trial proceedings and recommend findings of fact in a non-jury matter where an exceptional condition, an accounting, or a difficult damages computation warrants it; or to address pretrial and posttrial matters that cannot be effectively and timely handled by an available district or magistrate judge. That last category is the workhorse for discovery disputes. A master is not merely a witness who opines; the master can be empowered to manage a protocol, examine systems directly, and report findings back to the court. ## Why a neutral, and not just another expert The decisive feature of the neutral is independence enforced by rule. Before appointing a master, the court must give the parties notice and an opportunity to be heard, and the master must satisfy the same disqualification standard that applies to judges under 28 U.S.C. § 455, unless the parties, after disclosure, consent to a known conflict. The appointing order must spell out the master's duties, the limits of authority, the standards by which the court will review the master's rulings, and the terms of compensation. In other words, the neutral's mandate is documented, bounded, and reviewable in a way a retained party expert's never is. This structure solves a problem that adversarial expertise cannot. When authenticity is genuinely contested, not as rhetoric but as a factual question about what is on a device, someone has to actually look. And often neither side can be the one to look. Consider the recurring trade-secret pattern: employees leave one technology company for a rival, and a product with suspiciously similar functionality soon appears. The answer lies in the source code and in whether one company's documents sit on the other's systems. But the plaintiff cannot be handed access to a competitor's code, and the defendant cannot be handed the plaintiff's. A neutral with no stake in either business can be granted access to both, examine the systems, and report only what the court needs to know, resolving the impasse without forcing either party to expose its crown jewels to the other. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} .dsh{stroke:#3a423a;stroke-width:1.4;fill:none;stroke-dasharray:5 5} The Court defines mandate · reviews findings FRCP 53 / FRE 706 Forensic neutral no ties to either party Party A own expert systems & source code Party B own expert systems & source code access access no direct access neutral bridges the gap each party refuses to cross FIG. 1, The neutral sits between adversaries who cannot be given access to each other's systems, examines both, and reports findings up to the court under a defined mandate. What a forensic neutral actually does The job blends technical and legal work, which is what separates a forensic neutral from an ordinary subject-matter expert. In a large data-driven dispute, the neutral may draft and police a forensic collection protocol; determine the existence and authenticity of digital evidence; supervise or perform a court-ordered purge of misappropriated data and validate that it is truly gone; analyze deleted or corrupted files for signs of spoliation; and audit a system for compliance with a court order. Because the neutral can both interpret what a protective order technically requires and carry out the examination, a single appointment can replace rounds of motion practice over what is feasible and what was done. This dual competence is especially valuable where speed matters, for example, when a party seeks an injunction or an ex parte seizure of data. Those remedies demand highly technical collections and deletions executed under time pressure, with little room for error and high risk of overreach. A neutral with both the forensic skill and the procedural judgment to act fairly can deliver that relief without either side's partisan expert running the operation. ## The provenance dimension Synthetic media sharpens the case for neutral authority. When a party claims a video, image, or audio file is a fabrication, or insists a real one is genuine, the dispute is no longer about credibility alone; it is about artifacts, metadata, hashes, and generation signatures that require examination, not argument. A neutral can take custody of the original file and its provenance record, run the analysis once, and report whether the technical indicators support authenticity. That is a far cleaner path than asking a jury to choose between two retained experts who never touched the same copy of the file. The same provenance discipline we advocate at the point of creation, preserved hashes, signed Content Credentials, full metadata, is what gives a neutral something concrete to verify. See the Provenance guide. ## The limits of appointing a forensic neutral Neutral appointment is not a default, and it should not be. Rule 53 treats a reference to a master as the exception, and the court must weigh the fairness of imposing the cost on the parties and guard against unreasonable expense or delay. A neutral adds a fee that the litigants usually share, which can burden the less-resourced side. There is also a legitimate institutional caution: appointing a single authoritative voice risks displacing the adversarial testing that ordinarily exposes weak analysis. Commentators tracing the intersection of the modern Rule 53 and the e-discovery rules have urged courts to reserve neutrals for the matters that genuinely need them, the complex, the technical, the gridlocked, rather than as a routine offload of judicial work. The Sedona Conference's long-running work on electronically stored information makes the same point from the other direction: most ESI disputes should be resolved through proportionality and cooperation between the parties, with a neutral reserved for where that cooperation breaks down. Used well, though, the forensic neutral answers a question the adversarial system answers badly: when authenticity itself is the fight, who does the looking? The durable answer is someone the court trusts and neither party owns, a technical authority whose only client is the record. Courts appointing under FRCP 53 or FRE 706 need a candidate with the relevant technical background, and parties often propose a neutral with synthetic-media experience. - Authenticating AI-touched evidence: do we need a new rule? , the rule a neutral is appointed to resolve - When the dispute is about AI: arbitration's new rules for AI discovery and evidence , the arbitration analogue of a court-appointed neutral The Louisiana Supreme Court took a similar view of surveillance video offered mid-trial in 2025, holding that the balancing it requires cannot be done without an in camera review, one of the decisions summarised in our case-law collection. ## Sources ## Common questions on this topic Federal practice offers two distinct doors. The first is a court-appointed expert under Federal Rule of Evidence 706, which lets a court appoint an expert the parties agree on or one of its own choosing. The second is a special master under Rule 53. Independence enforced by rule. Before appointing a master the court must give the parties notice and an opportunity to be heard, and the master must satisfy the same disqualification standard that applies to judges under 28 U.S.C. § 455. It is not a default and should not be. Rule 53 treats a reference to a master as the exception; the court must weigh the fairness of imposing cost on the parties and guard against unreasonable expense or delay. ======================================================================== # From code to canvas: the copyright fight over generative-AI creations. URL: https://imadethisup.org/blog/generative-ai-copyright-canvas Published: 2026-06-15 Summary: Who owns what a model makes? The human-authorship rule, Thaler, the Copyright Office’s 2025 reports, and the training-data suits, for creators and counsel. ======================================================================== Generative AI raises two separate copyright questions with two different answers. On the output side the law is settled: copyright protects human authorship, so purely machine-generated elements are not protectable and must be disclaimed on registration. On the input side, whether training on copyrighted works is fair use, the law is genuinely unsettled. Imagine a model drafts a novel, intricate plot, vivid characters, a bestseller. Who holds the copyright? The developer who built the model? The user who typed the prompt? Or no one, because the law sees no human at the keyboard of authorship? The intuition pump is fun, but the answer is now reasonably settled at one end and genuinely contested at the other. Untangling generative-AI intellectual property means separating two distinct fights: whether AI output can be copyrighted, and whether AI training infringed the works fed into it. They run on different statutes and they are moving at different speeds. ## The output side: copyright needs a human author U.S. copyright protects "original works of authorship fixed in any tangible medium of expression." Courts and the Copyright Office have long read "authorship" to mean a human being, a thread that runs from a nineteenth-century photography case through monkey-selfie litigation to today. The generative-AI test case is Thaler v. Perlmutter. Computer scientist Stephen Thaler sought to register an image, "A Recent Entrance to Paradise," that he said was generated autonomously by his "Creativity Machine," which he listed as the sole author. The Office refused; in March 2025 the D.C. Circuit affirmed, holding that the Copyright Act requires a human author and that a machine cannot be one. The Supreme Court declined to hear the case in March 2026, leaving that holding in place. It is important to read Thaler narrowly. It answers only whether a machine can be named as the author. It does not say that anything touched by AI is uncopyrightable. The harder, fact-specific question, how much human creative control is enough, is where most real disputes will live. ## How much human input is "enough" for copyright registration? The Copyright Office has been filling that gap. Its 2023 registration guidance told applicants that works may be registered when they contain sufficient human authorship, that purely machine-generated elements are not protected, and that applicants must disclose AI-generated material and disclaim it. In January 2025 the Office published Part 2 of its AI report, on copyrightability, concluding that existing law is flexible enough to handle generative AI and that no new statutory category is needed. Its line: prompts alone, however elaborate, generally do not make the user an author, because the user does not control how the system turns the prompt into expression. Protection attaches where a human contributes perceptible expressive choices, selecting, arranging, editing, or combining outputs with human-authored material, judged case by case. For a working creator that is a practical instruction, not an abstraction. The copyrightable layer is the human one: the curation, the composition, the edits, the way generated pieces are assembled into something a person shaped. Keep records of that contribution. The generated raw material in the middle may sit in a gray zone or outside protection entirely. - COPYRIGHT LINE HUMAN-AUTHORED selection · arrangement · edits AI-ASSISTED human shapes the output MACHINE-GENERATED prompt only · not protected FIG. 1, Protection tracks human expressive contribution. The right of the dashed line, output driven by prompts alone, generally falls outside copyright; the protected zone is the human layer. The input side: the training-data copyright suits The second fight has nothing to do with who owns the output. It asks whether building the model, ingesting billions of copyrighted works as training data, was itself infringement, or whether it is fair use. Here the law is genuinely unsettled, and the cases are still in motion. In Andersen v. Stability AI, a group of visual artists sued over images allegedly scraped into training sets. In August 2024 the court let the core direct and induced copyright-infringement claims proceed while dismissing certain DMCA claims; as of 2026 the case remains in active litigation and discovery. In The New York Times v. OpenAI, the publisher alleges its articles were used to train models that can reproduce its content; in April 2025 the court denied OpenAI's motion to dismiss the central copyright claim, allowing the case to move forward. Both remain pending, no merits verdict on whether training is fair use has issued in these cases. Abroad, the picture diverges. In Getty Images v. Stability AI, the English High Court ruled in November 2025; after Getty dropped its primary copyright claims at trial, the court rejected the remaining secondary-infringement claim and made only narrow trademark findings. It is a UK judgment on UK law, useful context, not U.S. precedent. What the Copyright Office says about training In May 2025 the Office issued a pre-publication Part 3 of its AI report, on generative-AI training. It declined to create a new exception and said fair use must be assessed case by case under the existing four-factor test. Notably, it suggested that using vast troves of copyrighted works to produce content that competes in the same markets, particularly where access was unlawful, can fall outside fair use. The report is guidance, not binding law, and the courts will have the final word. But it signals where the analysis is heading. What creators and counsel should know A few durable takeaways survive the churn: Document the human layer. If you want registrable rights, preserve evidence of your creative choices, selection, arrangement, edits, and disclaim the purely AI-generated material when you register. - Don't assume prompts confer authorship. Under current Office guidance, prompts alone generally aren't enough. - Training liability is unresolved. Whether ingestion is fair use is being litigated, not settled; treat confident claims in either direction with caution.[5][6] - Provenance is a control, not just an aesthetic. Keep your generation logs, model versions, and source records; they are the evidence both registration and litigation will turn on. - Jurisdiction matters. A UK or EU ruling does not bind a U.S. court, and the reverse is equally true. The romantic question, can a machine be an author?, already has an answer in U.S. law: no. The interesting questions are quieter and more consequential. How much of you has to be in the work for the law to protect it, and was it lawful to feed the work to the machine in the first place? Those are being decided right now, one motion at a time. Where authorship itself is contested, the evidentiary question is what the model was given and what it returned, a matter for technical examination. - AI tools and attorney-client privilege: keeping confidences confidential , the confidentiality cost of the same act of putting material into a model - AI governance from the security chair: what the CISO owns , where ownership of AI output stops being a legal question and becomes a policy someone has to write ## Sources ## Common questions on this topic Not the machine-generated parts. U.S. copyright protects "original works of authorship," and courts and the Copyright Office have long read authorship to mean a human being, a thread running from a nineteenth-century photography case through monkey-selfie litigation to today. The Copyright Office's 2023 registration guidance says works may be registered when they contain sufficient human authorship, that purely machine-generated elements are not protected, and that applicants must disclose AI-generated material and disclaim it. Further guidance followed in January 2025. Unsettled. In May 2025 the Copyright Office issued a pre-publication Part 3 of its AI report on generative-AI training. It declined to create a new exception and said fair use must be assessed case by case under the existing four-factor test. ======================================================================== # Investigating white-collar fraud when the evidence can be fake URL: https://imadethisup.org/blog/white-collar-fraud-investigation Published: 2026-06-15 Summary: Generative AI lets fraudsters fabricate documents and voices, and lets investigators be misled by fluent forgeries. How rigor keeps an inquiry honest. ======================================================================== Complex frauds surface as friction, a variance that will not reconcile, a vendor whose invoices follow a suspicious pattern. In the AI era the documents explaining that friction may themselves be synthetic, so authenticity becomes a separate line of inquiry rather than an assumption, and the dataset an investigator is offered is not the dataset that exists. Occupational fraud is not a rounding error. The Association of Certified Fraud Examiners estimates that the typical organization loses roughly five percent of revenue to fraud each year, with a median loss per case of about $145,000 across the 1,921 cases in its 2024 global study. Those numbers describe schemes that were eventually detected. The cases that matter most to an investigator are the ones still hiding behind a plausible explanation, and the presenting issue is almost never the whole problem. It is the symptom that happens to be visible from where the company stands when it begins to look. Closing the gap between what is presenting and what is actually occurring is the work of curiosity, not just process. Procedural rigor, technical capability, and broad data access are all necessary; none of them, on its own, forces an investigator to keep asking why a fact pattern exists after a plausible answer has already been offered. Generative AI raises the stakes on both halves of that sentence. It gives fraudsters cheaper ways to fabricate the documents, invoices, and voices an investigation relies on, and it gives the investigator a fluent assistant that will confirm almost any theory it is asked to confirm. ## The first theory is the most dangerous moment in a fraud investigation Investigations run under cost pressure, time pressure, and a structural temptation to close. The team that scopes tightly to the presenting issue can deliver a report on schedule; the team that follows an open question into adjacent systems and unanticipated counterparties cannot promise when the work will end. The economics favor the first team. The outcomes do not. Confirmation bias here is not a beginner's mistake; it is the failing of a working theory that becomes too useful too early. An investigator forms a hypothesis in the first days because it is necessary to organize the work: which custodians to image, which transactions to sample, which interviews to prioritize. The hypothesis is a tool. The discipline lies in remembering that it is a tool, not a finding. A better framing than "does the evidence support the theory that this executive directed the misstatement?" is "what would I expect to see if someone else directed it, and are those indicators present, absent, or simply not yet examined?" The first question can be answered with the data already collected. The second usually cannot, and that gap is where investigations either deepen or quietly close. A large language model turns that asymmetry into a trap. Ask a model whether the evidence supports a theory and it returns a fluent, well-organized answer that supports it. Pose the inverse and it returns an equally fluent answer for the inverse. The model is not validating anything; it is performing the task it was given, in the register requested. Treating that output as confirmation rather than as a hypothesis to be tested is the working theory tested against itself, with better grammar. ## In a fraud investigation, the dataset you are offered is not the dataset that exists Skepticism about the working theory is owed to the data as well. Custodian lists are negotiated, sometimes by people whose visibility into the conduct is partial by design. Sources are omitted because they are administratively inconvenient or technically unfamiliar, encrypted messaging apps, collaboration platforms, voice and video systems with retention windows measured in days, personal devices used for work. Most collection workflows were built around email, so everything else is under-collected by default. AI adds a layer that did not exist a few years ago: the prompts, retrieval traces, intermediate outputs, and agent action logs generated by the systems employees now use to draft, summarize, code, and decide. When the conduct involves those systems, the relevant evidence is not only the resulting document but the interaction history behind it. The curious investigator asks where that history is stored, who has rights to it, and what its retention period is, and asks early enough that the answers still exist. A defensible methodology matters precisely because it keeps that question from depending on the instincts of the most experienced person in the room. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} CLAIM document · invoice · recording CORROBORATE independent records · third parties AUTHENTICATE AI-artifact checkpoint: metadata · provenance CLEAN ADMIT into the record SYNTHETIC QUARANTINE re-scope · widen collection loop: a quarantined artifact reopens the working theory FIG. 1, Claim → corroborate → authenticate, with an AI-artifact checkpoint. A synthetic finding is not an endpoint; it widens the collection and reopens the theory. Authenticity of the evidence is now a separate inquiry The risk of fabricated evidence is no longer hypothetical. The FBI's Internet Crime Complaint Center has warned that criminals are using generative AI to facilitate financial fraud, fabricating text, images, audio, and video to make schemes more believable while reducing the effort required to deceive. Voice cloning now takes only seconds of source audio. In late 2024 the Financial Crimes Enforcement Network issued a dedicated alert on fraud schemes that use deepfake media to defeat the identity-verification, authentication, and due-diligence controls banks rely on, describing falsified documents, photographs, and videos created with generative tools. Synthetic documents, AI-generated invoices, and voice-cloned audio are within the operational reach of mid-sophistication actors, and they turn up in matters that begin as ordinary commercial disputes. That changes the investigator's posture toward every artifact. Accepting that a document is authentic because it looks authentic is no longer a defensible default. Authenticity has become a distinct inquiry, corroborate the claim against independent records, then check the artifact itself for provenance, metadata, and synthetic markers, and it has to be contemplated from the outset rather than discovered on cross-examination. Where it exists, signed provenance such as C2PA Content Credentials does more work than any after-the-fact recollection; see the Provenance guide. ## Why a curious interview beats a checklist in fraud investigations Interviews are where curiosity produces the highest return, and where synthetic risk meets human behavior. An interview run as a checklist confirms what the interviewer already suspects: the questions come from the working theory, and the theory exits slightly more confirmed than it entered. A curious interview proceeds differently. The interviewer notices when a witness answers a different question than the one posed, which topics the witness steers toward unprompted, and which names appear in the answer that were not in the question. None of those is decisive alone. Each is a thread, and the willingness to pull on threads is what separates an interview that confirms from one that opens. Silence is the most useful instrument in the room. A prepared answer is short; an unprepared one is longer, and a witness invited to fill a pause will often fill it with something that was not in the rehearsed response. A name mentioned in passing in the third interview, untethered to anything the investigator was looking for, sometimes turns out to organize the whole matter when it reappears in the seventh. ## Curiosity is not license: scope and privilege limits on a fraud investigation None of this means following every interesting question off the books. A forensic investigator works within a scope set by counsel, a privilege framework that protects the work product, proportionality limits on discovery, and an authorized budget. The professional discipline is recognizing when an unanswered question calls for a conversation with counsel about scope, rather than a quiet exploration that produces a record nobody can defend. The hobbyist follows curiosity wherever it leads; the professional follows it to the edge of authorization and stops there, with a memo. A defensible record of what was asked, pursued, deferred, and why is what lets curiosity operate without becoming undisciplined. Regulators are watching that shape. The Department of Justice's 2024 update to its Evaluation of Corporate Compliance Programs asks prosecutors whether a company is vulnerable to schemes enabled by new technology, including false approvals and documentation generated by AI, and whether it has controls to identify and mitigate those risks. A prosecutor, agent, or successor regulator who later evaluates an internal investigation does so with full compulsory process and an internal benchmark: what a thorough independent inquiry into the same conduct would have produced. An investigation that never asks whether AI tools served as a vector, for the conduct, for its concealment, or for misidentifying who did what, is increasingly exposed. A report that looks scoped to avoid finding the larger problem does not earn credit for its conclusions, and the company ends up defending the conduct twice: once on the merits, once on the credibility of its own inquiry. Curiosity, in this discipline, is not temperament. It is a methodological commitment, that the working theory is the thing most in need of testing, that the dataset offered is not the dataset that exists, that the interview is the answers rather than the questions, and that an artifact's authenticity is something to prove rather than assume. The tools have changed; AI expands both the volume of relevant material and the number of ways it can be misread. The discipline has not. The investigations that close cleanly tend to be the ones that ask the additional question. The difference is rarely visible at the time. It is almost always visible afterward. Once fabricated documents are in the evidence set, the investigation needs someone who can test the artifacts themselves, a forensic examiner alongside the financial team. - “Follow the money” is no longer enough , where the money goes once it leaves - Forensic neutrals: who decides when digital evidence is contested? , who examines the evidence when both sides distrust it Authenticity challenges of this kind are reaching appellate courts, and how they have actually been resolved, rather than how they are argued, is set out in our summaries of the decided cases. ## Sources ## Common questions on this topic The first theory. Investigations run under cost pressure, time pressure, and a structural temptation to close. A team that scopes tightly to the presenting issue can deliver on schedule; a team that follows an open question into adjacent systems cannot promise when it will finish. Because custodian lists are negotiated, sometimes by people whose visibility into the conduct is partial by design. Sources get omitted for being administratively inconvenient or technically unfamiliar, encrypted messaging apps, collaboration platforms, voice and video systems. Yes. The FBI's Internet Crime Complaint Center has warned that criminals are using generative AI to facilitate financial fraud, fabricating text, images, audio, and video to make schemes more believable while reducing the effort required to deceive. ======================================================================== # Reg S-P's new baseline for smaller firms URL: https://imadethisup.org/blog/reg-s-p-small-firm-data-security Published: 2026-06-15 Summary: The SEC’s amended Regulation S-P demands written incident response, 30-day breach notice, and vendor oversight, and it blunts AI-enabled fraud too. ======================================================================== As of June 3, 2026, smaller SEC-registered advisers and broker-dealers must comply with the amended Regulation S-P. Three obligations apply: a written incident-response program, notification of affected customers as soon as practicable and no later than 30 days, and service-provider oversight requiring vendors to report breaches within 72 hours. Outsourcing the data does not outsource the duty. For a quarter century, Regulation S-P was the SEC's quiet privacy rule. Adopted in 2000 to implement the Gramm-Leach-Bliley Act, it required broker-dealers, investment companies, and registered investment advisers to mail a privacy notice and to adopt "reasonable" written safeguards for customer records. Most firms treated it as a compliance formality: a policy in a binder, reviewed once a year. The 2024 amendments ended that era. Reg S-P is now, in substance, a cybersecurity rule with deadlines and teeth. On May 16, 2024, the Commission adopted sweeping amendments to Reg S-P in Release No. 34-100155, published in the Federal Register on June 3, 2024. The headline change is a federal customer-breach-notification obligation where none existed before. But the deeper shift is operational: the rule now prescribes how a firm must detect, respond to, and recover from an intrusion, and it expects documented proof, not paper intentions. ## Three new obligations the amended Reg S-P imposes The amended rule layers three new obligations on top of the existing safeguards and disposal requirements. First, every covered institution must maintain a written incident-response program "reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information," including procedures to assess the nature and scope of an incident and to contain it. Second, and this is the part that changes day-to-day reality, the program must include customer notification. When sensitive customer information has been, or is reasonably likely to have been, accessed or used without authorization, the firm must notify each affected individual "as soon as practicable, but not later than 30 days" after becoming aware of the incident. "Sensitive customer information" is defined broadly: any information whose compromise could create a reasonably likely risk of substantial harm or inconvenience, Social Security numbers, biometric records, and account credentials being the obvious examples. The notice must describe the incident, the data involved, and what the customer can do to protect themselves. Third, the rule imposes service-provider oversight. Firms must adopt written policies to oversee their vendors through due diligence and monitoring, and to obtain assurance that a service provider will take appropriate measures and notify the firm as soon as possible, but no later than 72 hours after discovering a breach of customer information in its custody. Critically, outsourcing the data does not outsource the duty: the registered firm still owns the customer-notification obligation even when the breach happens inside a vendor's systems. Rounding out the package are recordkeeping requirements, firms must document their program, their incidents, and their service-provider oversight, and an expansion of the safeguards and disposal rules to cover a broader universe of customer information, including information a firm receives about another institution's customers. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} .axis{stroke:#3a423a;stroke-width:1.4} REG S-P, THE NOTIFICATION CLOCK T0 · awareness +72 hours +30 days (outer limit) Firm becomes aware trigger: unauthorized access Vendor reports breach ≤ 72 hrs to the firm Notify customers as soon as practicable Duty stays with the registered firm, even when the breach is the vendor's. FIG. 1, Reg S-P incident clock under Release No. 34-100155: vendor reporting within 72 hours; customer notice as soon as practicable, no later than 30 days. Why smaller firms feel it hardest The amendments phase in by size. Larger entities, registered advisers with $1.5 billion or more under management, and broker-dealers and fund complexes above the corresponding thresholds, had to comply by December 3, 2025. Everyone else, the "smaller entities," had until June 3, 2026. That deadline is now here, and it lands on the firms least equipped to meet it. Larger broker-dealers have run formal incident-response playbooks for years. A two-person advisory shop typically has no in-house security team, leans on third-party custodians and SaaS vendors for nearly every core function, and has never run a tabletop exercise. The SEC declined to prescribe specific technical controls, which sounds like flexibility but functions as a burden: each firm must make risk-based judgments about what is "reasonably designed" for its size and business, and then defend those judgments to an examiner who will ask for evidence the controls actually work. ## The security baseline that also stops AI fraud It is tempting to read Reg S-P as a documentation chore. That misreads the moment. The controls the rule effectively requires, multi-factor authentication, encryption in transit and at rest, role-based access, centralized logging with secure retention, and a rehearsed response plan, are the same controls that defend against the fastest-growing threat to financial firms: AI-enabled social engineering. Synthetic media has industrialized the impersonation attack. In one widely reported 2024 incident, an employee at the engineering firm Arup was tricked into transferring roughly $25 million after joining a video call populated entirely by deepfaked colleagues, including a fabricated chief financial officer. The FBI has warned that criminals are using generative AI to clone voices and faces for exactly this kind of fraud and account takeover. A wealth-management client's voice is now a trivial thing to fake; a wire-authorization "call from the founder" can be wholly synthetic. The defenses are unglamorous and overlapping with Reg S-P's text. Out-of-band verification before moving funds defeats the deepfake call. Strong access controls and logging shrink the blast radius of stolen credentials and make the incident-response program's containment and assessment steps actually executable. A tested response plan is the difference between a 30-day notification met calmly and a scramble that misses the clock. Reg S-P, in other words, forces firms to build the muscle that synthetic-media fraud is designed to exploit. ## Reg S-P in context: it is not alone Reg S-P now rhymes with the broader federal trend. The FTC's Safeguards Rule under the same Gramm-Leach-Bliley Act was amended in 2023 to require non-banking financial institutions to notify the FTC of a breach affecting 500 or more consumers as soon as possible and no later than 30 days after discovery, effective May 2024. Different regulator, different trigger, same direction: written programs, fixed clocks, documented proof. A firm that builds one defensible program is well along toward satisfying the others, and toward surviving an examination cycle in which examiners now expect operational compliance, not intent. ## What to do now to close the remaining Reg S-P gaps For firms that started early, the work now is closing gaps, stress-testing the incident-response plan through a tabletop, and assembling an exam-ready documentation package. For firms that have not started, the priority is blunt: begin. Inventory and classify customer data, paper the vendor relationships with breach-notification obligations, stand up MFA and encryption, turn on logging you can actually retrieve, and write, then rehearse, the response plan. The deadline arrives whether the binder is ready or not. The durable lesson is the one this project keeps returning to: in an era where a voice, a face, or a video can be conjured on demand, the firms that survive are the ones that can prove what happened and respond on a clock, not the ones merely asked to trust what they see. For more on defending against synthetic-media fraud, see the War Room. Smaller firms often need the written incident-response program assessed against the amended rule by someone independent of the vendor who drafted it. - Building a deepfake incident-response plan for smaller firms , the written plan Reg S-P requires, drafted - AI governance from the security chair: what the CISO owns , who owns this at board level ## Sources ## Common questions on this topic Three new obligations on top of existing safeguards and disposal rules: a written incident-response program reasonably designed to detect, respond to, and recover from unauthorized access to customer information; customer breach notification; and written service-provider oversight policies. When sensitive customer information has been, or is reasonably likely to have been, accessed without authorization, the firm must notify each affected individual as soon as practicable but not later than 30 days after becoming aware of the incident. June 3, 2026. The amendments phase in by size, larger entities, including registered advisers with $1.5 billion or more under management, had to comply by December 3, 2025. Everyone else, the "smaller entities," had until June 3, 2026. ======================================================================== # The hallucination tax: what unverified AI citations really cost URL: https://imadethisup.org/blog/ai-hallucination-tax-arbitration Published: 2026-06-15 Summary: Fabricated AI citations are a breach of the duty of competence, not a glitch. Mata, Park v. Kim, ABA Opinion 512, FRCP 11, and the JAMS AI rules. ======================================================================== A fabricated AI citation is not a software glitch but a breach of the duty of competence, and it levies a real cost, sanctions, wasted hours, forfeited credibility. ABA Model Rule 1.1 Comment 8 already requires lawyers to understand the risks of relevant technology; no rule change was needed to make verification mandatory. There is a tidy excuse making the rounds whenever a brief turns up citing cases that do not exist: the AI did it. The model "hallucinated," the black box misled me, the technology is new and imperfect. It is a comforting story, and it is wrong. Large language models are probabilistic text engines, not search tools, they predict the most plausible-looking sequence of words, which means a fabricated citation is not a malfunction but the expected behavior of a system asked to do something it was never built to do. A lawyer who treats a general-purpose chatbot as a legal database has not been ambushed by a glitch. They have skipped the one step the profession has always required: reading the authority before signing the filing. That failure has a price, and someone always pays it. We call it the hallucination tax, the real, compounding cost that unchecked AI output imposes on litigation and, increasingly, on arbitration. It is paid in monetary sanctions, in the billable hours of opposing counsel and the tribunal, in delay, and most durably in lost credibility. None of it is recoverable from the model. ## The duty of competence did not change; AI tooling did Nothing in the rules of professional conduct treats AI as a special case, because nothing needs to. ABA Model Rule 1.1 requires competent representation, and Comment 8, added in 2012, directs lawyers to keep abreast of "the benefits and risks associated with relevant technology." Rule 5.3, retitled the same year to cover nonlawyer assistance rather than merely assistants, extends a supervising lawyer's responsibility to non-human help, which now plainly includes generative tools. In July 2024 the ABA made the point explicit in Formal Opinion 512: a lawyer's "uncritical reliance on" AI output without "an appropriate degree of independent verification or review" can breach the duties of competence and candor. Federal Rule of Civil Procedure 11 says the same thing in older language. By signing a paper, an attorney certifies that the legal contentions are warranted by existing law, after an inquiry "reasonable under the circumstances." Citing a case you never read, because a model invented it, is the textbook failure of reasonable inquiry. The gatekeeping obligation is non-delegable. You cannot hand it to a summer associate, and you certainly cannot hand it to a chatbot. ## The case law of consequence, from Mata v. Avianca onward The jurisprudence matured fast, from cautionary tale to hard penalty. The origin point is Mata v. Avianca, Inc., where plaintiff's counsel filed a brief citing multiple nonexistent opinions generated by ChatGPT, then, when challenged, submitted fabricated "copies" of the phantom decisions. Judge Castel imposed a $5,000 sanction, but the holding's value is in its framing: "there is nothing inherently improper about using a reliable artificial intelligence tool for assistance," the court wrote, while stressing that "existing rules impose a gatekeeping role on attorneys to ensure the accuracy of their filings." The wrong was not the tool. It was abandoning the gate. If Mata was a warning, Park v. Kim showed the appellate teeth. There the Second Circuit confronted an attorney whose reply brief cited a case she admitted was generated by ChatGPT and that did not exist; the court referred her to its grievance panel. And the costs are no longer symbolic. In Lacey v. State Farm General Insurance Co. (C.D. Cal. 2025), a special master who candidly admitted he "almost" adopted the fake citations into an order imposed roughly $31,000 in sanctions, about $26,000 for the work of reviewing the briefs and holding the hearing, plus $5,000 to reimburse opposing counsel. Even where courts decline to punish, the spectacle lingers: when former attorney Michael Cohen's submission carried fake cases produced by Google Bard, Judge Furman declined sanctions but memorialized that, "[a]s far as the Court can tell, none of these cases exist." Surviving sanctions is not the same as surviving the record. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} One unverified AI citation filed without reading the source Opposing counsel hours hunting a phantom case Tribunal / court billable hours to verify non-existence Satellite litigation show-cause / sanctions motion Credibility collapse every other assertion now suspect Sanctions · delay · enforcement risk a poison pill in the client's own award the hallucination tax, paid by everyone except the model FIG. 1, Cost cascade of a single unverified AI citation. The fabricated cite is cheap to produce and expensive for everyone downstream, none of it recoverable from the tool. Why arbitration pays the tax twice The economics bite harder in arbitration than in court. A tribunal is paid by the hour, so every hour spent chasing a citation that does not exist is billed straight to the parties. Worse, arbitration's defining promise, speed, economy, finality, runs on trust. The first fake case an arbitrator catches converts a sympathetic reader into a forensic skeptic who now distrusts every factual assertion in the brief. Under a loser-pays regime, submitting hallucinations is close to writing your opponent a blank check for the cost of catching them. Then there is enforcement. If a tribunal relies, even inadvertently, on a fabricated legal principle, the resulting award becomes vulnerable: a losing party can argue it was unable to present its case against fictitious law, or that the award offends public policy, grounds that echo the New York Convention's narrow but real bases for refusing enforcement. A hallucinated brief is a poison pill in your own client's victory, handing the loser a fresh argument for years of post-award litigation. The institutions have noticed. JAMS issued dedicated Artificial Intelligence Disputes Rules effective April 2024, the first comprehensive ADR framework for AI matters. The AAA-ICDR followed with March 2025 guidance on arbitrators' use of AI tools, updated later that year, instructing that AI outputs be critically evaluated and cross-referenced against primary sources, with independent decision-making retained and material AI use disclosed. The throughline is unmistakable: AI is a permitted assistant, never a substitute for verification. ## Verify AI-assisted citations before you file The defense against the tax is unglamorous and entirely within the filer's control. Three habits do most of the work: - Ground the research, then click through. Use general-purpose chatbots for brainstorming and drafting prose, never for generating citations. Reserve citation work for tools tied to primary law, and let no authority into a filing until someone has opened the actual source and confirmed the case exists, the pin cite is right, and the opinion says what the brief claims. - Keep a verification log. A short record showing that every authority was independently checked is cheap insurance, it both prevents the error and rebuts any later charge of bad faith. See the Research Lab. - Run the table of authorities before filing. Push every cite through a traditional database; anything that fails to resolve or flags as unrecognized halts the filing until it is manually retrieved or removed. The black box is, in the end, a mirror. When it produces garbage and that garbage gets filed, what shows up in the record is not the model's unreliability but the filer's. The mandate for the AI era is the oldest one in the practice, only more so: trust, but verify. Anything less is not innovation; it is the hallucination tax, and the client pays it. Once a fabricated citation is already in a filing, the question becomes how it got there, a reconstruction that generally calls for an independent examiner. - AI tools and attorney-client privilege: keeping confidences confidential , the confidentiality duty alongside the competence one - Authenticating AI-touched evidence: do we need a new rule? , what an unverified citation costs in evidence The sanctions orders that followed are now numerous enough to compare against each other, running from ten thousand dollars against counsel personally to a disciplinary referral carrying no fine at all, and each is summarised in the case-law collection. ## Sources ## Common questions on this topic No, because nothing needs to. ABA Model Rule 1.1 requires competent representation, and Comment 8, added in 2012, directs lawyers to keep abreast of the benefits and risks associated with relevant technology. The duty did not change; only the tooling did. Mata v. Avianca, Inc., where plaintiff's counsel filed a brief citing multiple nonexistent opinions generated by ChatGPT and then submitted fabricated "copies" of the phantom decisions when challenged. The jurisprudence matured quickly from cautionary tale to hard penalty. The economics bite twice. A tribunal is paid by the hour, so every hour spent chasing a citation that does not exist is billed straight to the parties. And arbitration's defining promise, speed, economy, finality, runs on trust that fabrications erode. ======================================================================== # Using AI in e-discovery: how to defend the review, not just run it URL: https://imadethisup.org/blog/ai-ediscovery-in-arbitration Published: 2026-06-15 Summary: Using TAR and generative-AI review in litigation: defensibility, proportionality under FRCP 26, validation by recall and precision, and Rule 26(g). ======================================================================== Courts settled the threshold question over a decade ago: technology-assisted review is an acceptable way to search for relevant ESI. What gets challenged now is validation, whether the producing party can demonstrate the result was adequate, typically through recall and precision measures, and whether a human attorney can certify the response under FRCP 26(g). The volume problem in modern disputes is old news: a mid-size commercial arbitration can carry hundreds of gigabytes of email, chat, and file shares, and the cost of reviewing all of it by hand is the single largest line item in most discovery budgets. Technology-assisted review (TAR), the family of supervised-learning methods also called predictive coding, was the legal profession's first encounter with machine learning as a production workflow, and courts approved it years ago. The newer entrants are generative-AI review tools that draft issue summaries, propose relevance calls, and answer natural-language questions across a corpus. The technology has changed; the governing question has not. It is not may I use AI? It is can I defend the process I used? That distinction matters because e-discovery is governed by a process standard, not an outcome standard. No review, human or machine, finds every relevant document. What a producing party owes is a reasonable, proportional, and good-faith effort, and the ability to show its work if challenged. AI changes the tooling inside that obligation. It does not change the obligation. ## The case law settled the threshold question about TAR Judicial acceptance of TAR is not new or contested. In 2012, Magistrate Judge Andrew Peck issued the first opinion approving computer-assisted review, holding that it "is an acceptable way to search for relevant ESI in appropriate cases." Three years later, in Rio Tinto PLC v. Vale S.A., the same judge went further, writing that "the case law has developed to the point that it is now black letter law that where the producing party wants to utilize TAR for document review, courts will permit it." The empirical case had been made even earlier: a widely cited 2011 study by Maura Grossman and Gordon Cormack found that TAR could achieve recall and precision at least comparable to, and often better than, exhaustive manual review, at a fraction of the cost. There is an important limit on the other side. In Hyles v. City of New York, Judge Peck declined to force a responding party to use TAR over its preference for keyword search, invoking Sedona Principle 6: the responding party is generally best positioned to choose the tools for producing its own ESI. The producing party owns the methodology, and therefore owns the burden of defending it. ## Proportionality under FRCP 26(b)(1) is the frame, not a footnote In federal practice, the analysis starts with FRCP 26(b)(1): discovery must be relevant and proportional to the needs of the case, weighing the amount in controversy, the parties' resources, the importance of the issues, and whether the burden outweighs the likely benefit. Proportionality is the strongest argument for AI review and, paradoxically, a constraint on it. A six-figure manual review in a dispute worth a few hundred thousand dollars is hard to justify; TAR is the proportionate answer. But the same logic cuts against gold-plating an AI validation protocol beyond what the stakes warrant. Arbitration sharpens this. The whole premise of ADR is a faster, cheaper, more party-controlled process, and providers expect discovery to be tailored, not litigation-grade by default. That makes AI review a natural fit, and makes the parties' agreement, or the arbitrator's procedural order, the real source of the rules. JAMS, for its part, has published dedicated rules for disputes involving AI systems, built around default protective orders and disclosure of the systems at issue, signaling that ADR institutions now treat AI as a first-class procedural subject rather than an afterthought. Practitioners should assume that how they used AI in review may itself become a disclosable, negotiable term. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} Human-coded seed set attorney relevance calls Model ranks corpus TAR / GenAI scoring Validation on control sample measure recall & precision Human-validation gate metrics meet target? sample QC? NO, retrain YES Certify & produce 26(g) signature · documented protocol the algorithm proposes; a human certifies FIG. 1, A defensible AI review loop. The model ranks; a validation sample measures recall and precision; a human gate decides whether to certify or keep training. Output never reaches production without the gate. Validation of the TAR result: the part that actually gets challenged When TAR disputes reach the courts, they rarely turn on whether AI was permissible. They turn on validation, whether the producing party can show the result was adequate. The Sedona Conference's TAR Case Law Primer tracks exactly this shift, noting that the unsettled questions are now about methodology, metrics, and validation rather than basic acceptability. Two metrics dominate. Recall measures completeness, the share of truly relevant documents the process actually found. Precision measures discipline, the share of documents the process flagged that were in fact relevant. They trade off against each other, and the defensible posture is a documented recall target, a statistically valid control sample to estimate it, and a record of where the process landed. The generative-AI layer raises the validation bar rather than lowering it. A large language model can produce a fluent relevance rationale that is confidently wrong, and its calls can drift as prompts or model versions change. None of that is fatal, but it means the same empirical discipline applies: sample the model's output, measure it against human judgment, log the prompt and model configuration, and be ready to explain it. Treat a generative tool's output as a proposal to be validated, not a conclusion to be trusted. ## The human-in-the-loop is a legal requirement, not a courtesy Under FRCP 26(g), an attorney's signature on a discovery response certifies that, after a reasonable inquiry, the response is complete and correct. That certification cannot be delegated to a model. A lawyer signs; a lawyer must therefore understand and stand behind the process. Practically, the human-in-the-loop does the work the rule assumes: coding the seed set, reviewing the model's edge cases, running the validation sample, and deciding when the metrics are good enough to certify. The arbitration variant adds an ethical overlay, the duty of competence reaches the technology a lawyer deploys, and candor with the tribunal and opposing party about the use of AI review tools protects the process from a later integrity challenge. A second human-judgment point is bias. A skewed seed set can teach the model to systematically miss a category of documents, producing an under-inclusive result that looks clean on its face. That is precisely the kind of defect a validation sample is designed to catch, and precisely why a reviewer, not the algorithm, has to own the final call. ## Build the e-discovery record before the dispute, not during it Defensibility is built into the workflow or it is not built at all. Four moves pay off regardless of which tool you run: - Document the protocol contemporaneously. Record the tool and version, the seed-set methodology, the recall target, the validation sampling plan, and the metrics achieved. Reconstructing this after a challenge is far weaker than a record made as you went. - Negotiate the methodology up front. In both arbitration and litigation, transparency about the approach, the cooperative posture the early TAR opinions rewarded, converts a potential motion into an agreed protocol. - Keep the human gate explicit. Identify who reviews edge cases, who runs validation, and who signs under 26(g). Make the certification a deliberate step, not a formality. - Validate generative output like any other measurement. Sample it, measure recall and precision against human calls, and log the prompts and configuration. See the Research Lab. The honest summary is that AI in e-discovery is no longer a frontier question; it is a competence expectation. The tools will keep improving, and generative review will keep absorbing tasks that used to be manual. What endures is the standard underneath: a reasonable, proportional, documented process, validated by numbers, certified by a human who understands it. Defend the process, and the technology takes care of itself. Validation is the part that gets challenged, and recall and precision figures are easier to defend when they were produced by someone independent of the review team. - When the dispute is about AI: arbitration's new rules for AI discovery and evidence , the evidence rules that govern the same proceeding - AI tools and attorney-client privilege: keeping confidences confidential , the confidentiality question review models raise The parallel fight over authenticating electronically stored evidence has produced its own appellate law, including a reversal turning in part on a refusal to let a party authenticate its own software, which is summarised with the other decisions on electronic evidence. ## Sources ## Common questions on this topic Yes. In 2012 Magistrate Judge Andrew Peck issued the first opinion approving computer-assisted review, holding it "is an acceptable way to search for relevant ESI in appropriate cases." Rio Tinto PLC v. Vale S.A. reinforced it three years later. Judicial acceptance of TAR is neither new nor contested. Validation, not permissibility. Disputes turn on whether the producing party can show the result was adequate. The Sedona Conference's TAR Case Law Primer tracks exactly this shift, the unsettled questions are about measuring and demonstrating recall, not about whether the algorithm was allowed. No. Under FRCP 26(g), an attorney's signature certifies that after a reasonable inquiry the discovery response is complete and correct. That certification cannot be delegated to a model, a lawyer signs, so a lawyer must understand and stand behind the process. ======================================================================== # When the dispute is about AI: arbitration's new rules for AI discovery and evidence URL: https://imadethisup.org/blog/jams-ai-rules-discovery Published: 2026-06-15 Summary: The JAMS AI Disputes Rules rework discovery when AI is the evidence: secured access to models and training data, disclosure duties, and proportionality. ======================================================================== The JAMS AI Disputes Rules answer a problem litigation rules were not built for: how to take discovery of a model that learns and drifts. The signature move is to take the experts to the model rather than the model to the parties, proprietary hardware, software, models, and training data are made available to experts rather than handed over. When a dispute centers on what an artificial-intelligence system did and why, the evidence is no longer a tidy stack of emails. It is a model with millions of parameters, the data it trained on, the configuration that shaped its behavior, and outputs that may have shifted between the disputed event and the day a complaint was filed. Ordinary discovery tools strain against that target. A model is a moving, opaque, and often proprietary artifact, and the conventional answer of "produce the relevant documents" does not map cleanly onto it. Arbitration providers reached this problem before the federal rulemakers did. In April 2024, JAMS published the first set of arbitration rules built specifically for disputes involving AI systems, the JAMS Rules Governing Disputes Involving Artificial Intelligence Systems, accompanied by a model clause and a form protective order. The rules are worth studying not because arbitration governs most AI cases (it does not), but because they are a real-world laboratory for three questions every forum will eventually have to answer: how to disclose AI use, how to handle the authenticity of AI-touched evidence, and how to keep AI discovery from swallowing the case. ## The core move: take the experts to the model, not the model to the parties The signature provision of the JAMS framework addresses the proprietary, high-stakes nature of model evidence directly. Rather than ordering a party to hand over its hardware, software, models, and training data, the rules direct that those materials be made available to one or more experts in a secured environment established by the disclosing party, and the experts may not transmit or remove any produced materials from that environment. Where the parties jointly request it, the arbitrator can appoint neutral experts from a JAMS-maintained roster, with costs ordinarily split between the parties. This is a genuinely different posture from traditional production. It treats the model as something to be examined in place, under controlled conditions, rather than copied and circulated. That design solves several problems at once: it protects trade secrets and the integrity of the system, it keeps sensitive training data, which may itself contain personal information regulated under laws such as the GDPR or CCPA, from spreading, and it routes interpretation through people equipped to read it. A backing protective order governs the handling of everything disclosed. ## Disclosure of AI use as a procedural duty The JAMS rules answer one slice of the disclosure question, disclosure of the AI system at issue. A second, faster-moving slice is disclosure of AI use in the conduct of the proceeding itself: briefs drafted with generative tools, exhibits touched by AI, analyses produced by an algorithm. Here the AAA-ICDR's March 2025 Guidance on Arbitrators' Use of AI Tools is the cleaner reference point. It tells arbitrators to make reasonable inquiries about any AI tool before relying on it, to cross-check AI output against primary sources, and, critically, recognizes that the tribunal may require disclosure of AI use where that use could affect the proceeding. Read together, the two instruments sketch an emerging norm: AI is not invisible infrastructure to be used silently. When it shapes the evidence or the decision, its use becomes a fact the forum is entitled to know. That norm tracks what courts are independently demanding, that a party asserting an exhibit is AI-generated, or defending one that is, put the technical record on the table rather than leaving authenticity to assertion. .box{fill:none;stroke:#2a312a;stroke-width:1.4} .acc{stroke:#00b341} .lbl{fill:#d6dbd6;font-size:13px} .mut{fill:#8a938a;font-size:11px} .grn{fill:#00b341;font-size:11px;letter-spacing:.04em} .ln{stroke:#3a423a;stroke-width:1.4;fill:none} AI-touched evidence offered model · training data · output Arbitrator screens scope relevance · burden · proportionality disproportionate Limit / deny narrow or exclude request Secured-environment review experts examine in place · no export Reliability + provenance test how was output produced? reliable Admit / weigh on the merits protective order governs all disclosed materials throughout FIG. 1, How an arbitrator gates AI evidence under the JAMS AI Disputes Rules: scope first, then in-place expert examination under a protective order, then a reliability and provenance check before the evidence is weighed. Authenticity becomes a provenance question AI-related disputes scramble the usual authenticity inquiry. The hard question is not only "is this exhibit genuine?" but "how was this output produced, and can that be reconstructed?" Models that learn continuously change their parameters and their behavior over time, so the system that generated a disputed output in March may no longer exist by discovery, a preservation and spoliation problem with no clean analog in paper litigation. Without a snapshot or an audit trail, recreating the state of the system at the moment in question can be impossible. The secured-environment model helps here too, because it lets experts examine the architecture, configuration, and available training data rather than accept a litigant's characterization of them. This mirrors how the Federal Rules of Evidence already treat machine output: authenticity under Rule 901(a) requires evidence sufficient to support a finding that an item is what its proponent claims, and the workhorse for system output, Rule 901(b)(9), turns on showing that the process or system "produces an accurate result." For a generative or adaptive system, satisfying that standard demands exactly the technical record the JAMS process is designed to surface. The same logic animates proposed Federal Rule of Evidence 707, published for comment in 2025, which would subject machine-generated output offered without a human expert to Rule 702-style reliability scrutiny. ## How the JAMS rules contain the cost of AI discovery AI discovery is expensive precisely because the data is voluminous, unstructured, and hard to interpret. The JAMS rules lean on two levers to contain that cost. The first is proportionality: document requests are confined to material directly relevant to the dispute, e-discovery is generally limited to ordinary business sources, and the arbitrator may deny requests where the costs and burdens are disproportionate to the nature of the dispute or the amount in controversy. That standard is a close cousin of Federal Rule of Civil Procedure 26(b)(1), which since 2015 has limited discovery to matter that is relevant and proportional to the needs of the case, weighing burden against likely benefit. The second lever is competence at the top. Arbitration lets the parties choose a decision-maker, or a discovery referee, who already understands model architecture, training pipelines, and search-term mechanics. A neutral fluent in the technology can resolve scope, sampling, and proportionality fights faster and more accurately than a generalist forced to learn the domain mid-case, and can craft reliability rulings in an area where binding precedent is still thin. That expertise is the quiet engine behind the efficiency the rules promise. ## What practitioners should take from this Arbitration is not the destination for most AI disputes, but its rules are a preview. Three lessons travel to any forum. First, treat the model and its provenance as the evidence: preserve snapshots, configurations, and audit trails the moment a dispute is foreseeable, because an adaptive system will not wait for discovery. Second, plan for in-place, expert-mediated examination rather than wholesale production, it protects trade secrets and regulated data while still letting the truth be tested. Third, build the authentication and disclosure record early; the forum that asks "how was this produced?" rewards parties who can answer with a verifiable trail rather than an assurance. The durable advantage, as always, belongs to evidence that can prove what it is. See the Provenance guide. Secured-environment inspection of a model or its training data is not something counsel can run unaided; it generally requires a technical expert working inside the protective order. - Using AI in e-discovery: how to defend the review, not just run it , the review-defensibility half of AI in arbitration - Forensic neutrals: who decides when digital evidence is contested? , who resolves a contested exhibit ## Sources ## Common questions on this topic Rather than ordering a party to hand over its hardware, software, models, and training data, the rules direct that those materials be made available to one or more experts. It addresses the proprietary, high-stakes nature of model evidence directly. Because the question is no longer only "is this exhibit genuine?" but "how was this output produced, and can that be reconstructed?" Models that learn continuously change their parameters and behavior over time, so the system that generated an output may no longer exist. Through two levers. Proportionality confines document requests to material directly relevant to the dispute and generally limits e-discovery. Technical competence in the tribunal is the second, AI discovery is expensive precisely because the data is voluminous, unstructured, and hard to interpret. ======================================================================== # When the file lies about itself. URL: https://imadethisup.org/blog/ai-metadata-hallucination Published: 2026-06-15 Summary: Generative tools can write false author, date, and provenance metadata into files. Why that is a discovery risk, and how to verify with hashes. ======================================================================== Generative tools can write false author, date, and provenance values into the files they produce. Because metadata is treated as evidence in discovery and authenticity disputes, a fabricated Author or Created field can mislead at two depths: the ordinary Properties pane a reviewer reads, and the deeper fields forensic tools parse. Verify provenance; do not trust it. Most coverage of AI "hallucination" concerns the visible content of a document: a fabricated citation, an imaginary statute, a precedent that never existed. A quieter failure mode has drawn far less attention. Generative systems can also fabricate the metadata, the embedded, largely invisible layer that records who authored a file, what organization produced it, and when it was created or last modified. When that layer is wrong, the consequences are different in kind, because metadata is precisely the data we reach for when we want to know whether the visible content can be trusted. ## Metadata is evidence, not trivia Metadata is often described as "data about data": the hidden information embedded in every digital file, organized into fields such as Author, Company, Created, and Last Modified. For the file types most people handle daily, Office documents, PDFs, images, metadata can reveal the author and organization, the creation and modification dates, version history and tracked changes, and embedded comments. Critically, these fields have historically been written automatically by the software and operating system as a user creates, saves, and shares a file, not typed in by hand. That provenance is exactly why metadata has been treated as a quiet, trustworthy audit trail. In litigation that trust is formalized. Courts and counsel rely on metadata to authenticate documents, establish a chain of custody, and prove when and by whom a file was created. The Federal Rules of Evidence allow electronic records to be self-authenticated: Rule 902(13) covers a record "generated by an electronic process or system that produces an accurate result," and Rule 902(14) covers data identified "by a process of digital identification", in practice, a matching hash value. The Sedona Conference, the leading vendor-neutral authority on electronically stored information, treats metadata as a central pillar of ESI admissibility. The whole edifice assumes the fields mean what they say. ## Why a model would invent a provenance Metadata hallucination follows from how large language models work. They do not "know" facts; they predict the most probable next token from patterns in training data. Recent OpenAI research argues that hallucination is not a mysterious glitch but a predictable product of training and evaluation regimes that "reward guessing over acknowledging uncertainty", models are optimized to be confident test-takers, and a confident guess scores better than an admission of ignorance. That pressure does not stop at the visible text. When a system assembles a document, a "complete" file of that type is expected to carry author, date, and history fields. Faced with no real value to place there, a model does what it was trained to do: it produces something plausible. The output looks like a normal author name or timestamp, and is entirely invented. The danger is structural: these guesses live in the hidden layer, where almost no one looks. ## Two places hallucinated metadata misleads you The risk operates at two depths. At the surface, fabricated values surface in a file's ordinary Properties pane, the Author or Company a lawyer or reviewer reads with a couple of clicks and reasonably presumes to be authoritative. Deeper down, forensic and e-discovery tools report whatever is embedded in the file as ground truth. Those tools are built to surface what the file contains, not to adjudicate whether the contained values are true. So a hallucinated timestamp or author can pass through forensic review wearing the authority of forensic review. The figure below states the core problem: the claimed provenance a file asserts about itself is not the same thing as a cryptographic fact about that file. The first can be guessed, copied, or invented. The second can only be verified. CLAIMED · WHAT THE FILE SAYS report.docx Author“John Milton” ? Created2025-02-30 ? SHA-256embedded ? cannot be trusted VERIFIED · WHAT CAN BE PROVEN 1 · Hash the bytes → compare values 2 · Check signed Content Credential 3 · Reconcile to chain of custody PROVENANCE ESTABLISHED A field a model can guess is not evidence. A value that can be recomputed is. Fig. 1, Claimed metadata vs. cryptographic truth: a three-step verification flow. How to verify provenance instead of trusting it The remedy is to stop treating self-asserted metadata as proof and start treating it as a claim to be tested. Three layers, in order, move a file from "claimed" to "verified." - Hash the bytes. A cryptographic hash (SHA-256) is computed from the file's actual content, so any change, including a doctored field, produces a different value. NIST's guidance on integrating forensic techniques into incident response builds its collection and integrity model on exactly this property: hashing and documented handling preserve evidence so it stays admissible. A matching hash is the digital identification that Rule 902(14) contemplates. - Check for a signed Content Credential. The C2PA standard, the open specification behind Content Credentials, binds provenance to an asset in a tamper-evident, cryptographically signed manifest. If the content or its credential is altered after signing, verification fails and says so. Unlike an ordinary Author field, a signed credential cannot be silently guessed into existence by a model. - Reconcile to a chain of custody. Cross-check the file's asserted dates and authorship against independent records, collection logs, system timestamps, custodian interviews. The Sedona Conference frames metadata authenticity as a question answered by corroboration, not by reading a field at face value. None of these steps is exotic, and that is the point. The arrival of generative tools does not break provenance; it removes the luxury of assuming provenance. A field that a model can invent is not evidence. A value that can be recomputed from the bytes, or verified against a signature, is. The discipline that distinguishes the two has existed for years, see the Provenance guide for the full verification toolkit. Where a file’s own metadata is the disputed fact, the hashing and provenance checks have to be run by someone who can later testify to how they were done. - What Content Credentials establish, and what they do not , signed provenance as the remedy this post implies - Authenticating AI-touched evidence: do we need a new rule? , what happens when fabricated metadata reaches a filing ## Sources ## Common questions on this topic Metadata hallucination follows from how large language models work: they do not know facts, they predict the most probable next token from training patterns. Recent OpenAI research argues hallucination is not a mysterious glitch but a predictable product of training and evaluation. Yes. Metadata is the hidden information embedded in every digital file, fields such as Author, Company, Created, and Last Modified. For Office documents, PDFs, and images it can reveal authorship and timing that parties rely on in discovery and authenticity disputes. Stop treating self-asserted metadata as proof and start treating it as a claim to be tested. Three layers, applied in order, move a file from "claimed" to "verified", with cryptographic hashing and C2PA Content Credentials doing the work self-reported fields cannot. ======================================================================== # What the Arup deepfake actually proves, and what it doesn't. URL: https://imadethisup.org/blog/arup-deepfake-what-it-proves Published: 2026-04-27 Summary: The break point in the $25M Arup Hong Kong deepfake fraud was not the model. It was the missing out-of-band callback above the transfer threshold. ======================================================================== The Arup Hong Kong fraud succeeded because a video call could substitute for payment authorization, not because the deepfake was undetectable. Arup's CIO stated no systems were compromised and no data was affected; it was "technology-enhanced social engineering." The break point was the payment-approval workflow, and the missing control was an out-of-band callback. The Arup Hong Kong fraud is the most-cited synthetic-media incident of the last two years, and rightly so; it is the first widely reported case in which a multi-million-dollar transfer was authorized after a video conference where every other participant was an AI-generated deepfake. A finance employee made fifteen wire transfers totaling roughly USD 25 million to five accounts controlled by the perpetrators. The incident was reported to Hong Kong police in January 2024 and confirmed publicly by Arup in May. ## The Arup lesson is operational, not technical Arup's CIO Rob Greig framed it explicitly: "None of our systems were compromised and there was no data affected... this was technology-enhanced social engineering." Every Arup system was intact. The break point was the company's payment-approval workflow, specifically, that a video call could substitute for an out-of-band callback above the wire-transfer threshold. This is the part most coverage understates. The story is rarely "an AI fooled a person." The story is almost always "a control was missing." In the Arup case, several missing controls compounded: - No out-of-band callback to a number stored in the corporate directory. - No challenge phrase known only to the real CFO. - No soft hold on payments above a defined threshold. - No requirement to verify a signed Content Credential on imagery shared in the meeting. Add any one of those and the attack does not net the perpetrators $25 million. Add three of the four and it does not net them anything. ## What the Arup case does not prove It does not prove that deepfake-detection technology has failed; there was no detection technology in the path. It does not prove that video conferencing is unsafe, the protocol is. It does not prove that the perpetrators were unusually sophisticated. The same tooling is now within budget for ordinary fraud crews; an independent World Economic Forum analysis frames the Arup case as a repeatable pattern, not a one-off. It also does not prove that detection is unimportant. Detection remains the only signal you have for content that wasn't signed at source. But for the specific class of attack that hit Arup, authorization fraud during a live conference, process controls dominate detection at the margin. ## The same verification protocol foiled the Ferrari and LastPass attempts The Ferrari executive who foiled a 2024 voice-clone attempt did so by asking the caller to name the title of a book CEO Benedetto Vigna had personally recommended a few days earlier. The synthetic system did not have the answer. The LastPass employee who foiled an April 2024 deepfake voicemail of CEO Karim Toubba did so by recognizing the channel choice (WhatsApp, outside normal company communications) and the forced urgency as social-engineering hallmarks. Both are versions of the same protocol that would have stopped Arup. Adopt the lot, see the War Room for the six-step authentication card. ## Harden the payment-approval workflow against deepfakes this week If you have any control over a payment-approval workflow, three changes pay back disproportionately: - Out-of-band callback above $X. Pick a threshold that fits your finance posture. Confirm the number from your directory, not the inbound caller ID. - Pre-shared challenge phrase, rotated quarterly. Never spoken on camera or stored in a shared document. Drill it. - Thirty-minute soft hold above $X. Most synthetic-media frauds depend on momentum. Arup's wires cleared in about four minutes per transfer. After an incident of this shape, the reconstruction that matters is which control was missing rather than which model was used, a post-incident review worth commissioning independently. - Why deepfake impersonation works, and what stops it , why the attack worked on a person rather than on a detector - Deepfake defense for real-estate closings, at the process layer, not the model , the same control failing in a second industry - Building a deepfake incident-response plan for smaller firms , the procedure that would have stopped it ## Sources ## Common questions on this topic No. Arup's CIO Rob Greig framed it explicitly: "None of our systems were compromised and there was no data affected... this was technology-enhanced social engineering." Every Arup system was intact. The failure was in the payment-approval workflow, not the infrastructure. No; there was no detection technology in the path to fail. It also does not prove video conferencing is unsafe; the protocol was. Nor does it prove unusual sophistication on the attackers' part, since the same tooling is widely available. An out-of-band verification the synthetic system cannot satisfy. A Ferrari executive foiled a 2024 voice-clone attempt by asking the caller to name a book the CEO had recently recommended; the synthetic system did not have the answer. A LastPass employee foiled a similar attempt. ======================================================================== # What the TAKE IT DOWN Act actually changes, and what it doesn't. URL: https://imadethisup.org/blog/take-it-down-act-explained Published: 2026-04-27 Summary: A practical reading of S.146 for survivors, platforms, and counsel: a federal prohibition on non-consensual intimate imagery and a 48-hour takedown duty. ======================================================================== The TAKE IT DOWN Act (S.146) prohibits knowingly publishing, without consent, intimate visual depictions of minors or non-consenting adults, and deepfakes intended to cause harm. The criminal prohibition took effect on enactment. It gives survivors a federal floor for platform takedown speed, 48 hours, but does not amend Section 230. The TAKE IT DOWN Act (S.146, 119th Congress) was signed into law on 19 May 2025. It is the first federal statute to combine a criminal prohibition on non-consensual intimate imagery with an affirmative platform-removal obligation. The combination matters more than either piece in isolation. Here is what it actually does, and the gaps it leaves. ## What the TAKE IT DOWN Act changes It criminalises distribution. The Act prohibits any person from knowingly publishing, without consent, intimate visual depictions of minors or non-consenting adults, and any deepfakes (whether intimate depictions or not) intended to cause harm. The criminal prohibition was effective on enactment. It puts a 48-hour clock on platforms. Covered platforms, public websites, online services, and applications that either primarily host user-generated content or are primarily designed to publish non-consensual intimate visual depictions, must provide a notice-and-removal process and remove valid reports within 48 hours. Platforms had one year (to 19 May 2026) to set up the process. It applies to deepfakes, not just authentic captures. The statutory definition of intimate visual depiction explicitly covers AI-generated and AI-altered content. This closes a gap that left earlier state NCII laws ambiguous when the imagery was synthetic. ## What the TAKE IT DOWN Act leaves untouched Section 230 protection survives. The Act does not amend Section 230, it adds a notice-and-removal duty, violations of which can be enforced by the FTC, but it does not make platforms generally liable for user content. This is a deliberate design choice and a contested one; commentators have argued that it limits the meaningful enforcement window to platforms that fail to set up the process, not to ones that set it up and miss the window in individual cases. It does not preempt state law. If your state has a stronger statute, and roughly thirty states have specific deepfake-NCII laws as of mid-2025, that statute continues to apply alongside the federal regime. File under both where applicable. It is not a civil remedy. Civil claims under state NCII / right-of-publicity / IIED law are available now in many jurisdictions. A federal civil cause of action would come from the DEFIANCE Act, $150,000+ liquidated damages, 10-year statute of limitations, but that bill is still pending in Congress. S.3696 (118th Cong.) passed the Senate by unanimous consent in July 2024 but did not pass the House. Reintroduced as S.1837 (119th Cong.), it passed the Senate again by unanimous consent in January 2026, where it remains stuck. Until DEFIANCE clears the House, the federal regime in this space is criminal-only, TAKE IT DOWN, plus the FCC's TCPA AI-voice rule and the standard wire-fraud statutes. Survivors should not rely on TAKE IT DOWN alone to do civil-remedy work. ## The TAKE IT DOWN Act in practice If you are a survivor: you now have a federal floor for platform takedown speed. If a covered platform receives a valid report and does not remove the content within 48 hours, that is now a federal compliance failure, not just a customer- service complaint. Combine the federal notice with a hash submission to StopNCII.org (adults) or NCMEC Take It Down (under-18 content); a copyright report where you hold rights in the underlying image; and a civil claim under existing state law (or DEFIANCE if and when it becomes federal law) if the economic and emotional harm warrants it. If you are counsel: read the statute itself (link below), the Congressional Research Service's Legal Sidebar (LSB11314) is a useful one-page primer. Note the interaction with state law and Section 230. If you operate a covered platform: the notice-and-removal process must accept reports from any user, must act within 48 hours of a valid report, and must be navigable without specialised legal knowledge. The independent audit by Qiwei et al. (arXiv 2024) found that on at least one major platform, copyright reports cleared in 25 hours while NCII reports cleared in zero days over three weeks. The new statute makes that asymmetry compliance-relevant, not just policy-embarrassing. Where a platform disputes that the imagery is synthetic, a takedown request may need a technical opinion attached before it moves. - Deepfakes are reshaping workplace sexual harassment , the same imagery where Title VII adds liability the Act does not reach - Deepfakes and the integrity of evidence in family court , the evidentiary side of the same harm - Reporting non-consensual imagery: what one audit found , what research measures about how platform reporting routes actually perform How criminal statutes reach wholly synthetic imagery is being worked out in the appellate courts now, including a 2026 federal decision on possession, and those cases are summarised in what the courts have held so far. ## Sources ## Common questions on this topic It prohibits any person from knowingly publishing, without consent, intimate visual depictions of minors or non-consenting adults, and any deepfakes, whether intimate depictions or not, intended to cause harm. The criminal prohibition was effective on enactment. No. Section 230 protection survives. The Act adds a notice-and-removal duty enforceable by the FTC, but it does not make platforms generally liable for user content. That is a deliberate design choice. A federal floor for platform takedown speed. If a covered platform receives a valid report and does not remove the content within 48 hours; that is now a federal compliance failure rather than merely a customer-service complaint. ======================================================================== # Why deepfake detectors fail on new generators. URL: https://imadethisup.org/blog/why-detectors-fail-on-new-generators Published: 2026-04-27 Summary: A tour of the cross-generator generalization gap: why a detector trained on one model fails on another, and what the current research says to do. ======================================================================== Deepfake detectors fail on unfamiliar generators because they learn an architecture's fingerprint rather than synthesis itself. Frank et al. (ICML 2020) showed GAN-generated images carry severe frequency-domain artifacts caused by upsampling operations, so a detector trained on them is really learning the upsampling signature of one family of decoders, and it does not transfer. The most-cited deepfake-detection result of the last six years is arguably this one: with careful preprocessing and augmentation, a standard image classifier trained on outputs from a single CNN generator (ProGAN) generalized surprisingly well to ten unseen architectures, including StyleGAN2. The 2020 paper by Wang, Wang, Zhang, Owens, and Efros, "CNN-Generated Images Are Surprisingly Easy to Spot... for Now", is the source of the cautious optimism that runs through much of the popular coverage of deepfake detection. The phrase to dwell on is "for now." Five years later, generators are diffusion-dominant. Detectors trained on GAN-family outputs frequently fail on diffusion-family outputs and vice versa, and accuracy drops further on compressed, recompressed, or screen-recorded media. This is the cross-generator generalization gap, and it is the discipline's central open problem. ## Why cross-generator failure happens Frank et al. (ICML 2020) gave the field its cleanest mechanistic account: GAN-generated images carry severe artifacts in the frequency domain, caused by upsampling operations common across architectures. A detector that learns those artifacts is implicitly learning the upsampling fingerprint of one family of decoders. Diffusion models do not share that fingerprint exactly, their decoders leak differently. The detector's overfit generalizes within a family, but not across. It gets worse on the audio side. ASVspoof 2021, the canonical anti-spoofing benchmark, reports that countermeasures developed for the new deepfake-speech track "lack generalization across different source datasets," even after the codec-distortion augmentations the challenge specifically introduced. The audio version of the same gap. ## What about watermarking? If detection always trails generation, the natural response is to sign the output instead. Two strong proposals exist: Fernandez et al.'s Stable Signature (ICCV 2023), which fine-tunes a latent-diffusion generator to embed a recoverable signature in every output; and Google DeepMind's SynthID-Image, which has been used to watermark over ten billion images and video frames at internet scale. Both work, for cooperating actors. Saberi et al. (arXiv 2023) showed a fundamental trade-off between watermark evasion error and spoofing error for low-perturbation methods, and demonstrated that high-perturbation methods are vulnerable to model-substitution attacks. Watermarking is a useful production signal; it is not a closed defense against motivated adversaries who don't sign their work. ## Three mitigations for cross-generator detector failure Three threads worth following: - Train across families. Augment training data with samples from multiple generators, including diffusion-family outputs even when the deployment target is GAN-family (and vice versa). This is the operationally cheapest mitigation. - Lean on biosignal and semantic features that are not architecture-specific. PPG-derived heart-rate signals (Ciftci et al., IEEE TPAMI 2020) and inter-eye specular-highlight symmetry (Wang, Tondi, Barni, Frontiers 2022) are robust to a generator change in a way that frequency residuals are not.[7][8] - Stack provenance underneath detection. Cooperating actors sign with C2PA (see the Provenance guide); uncooperating actors get the detection stack. The two play different positions. The honest summary is that no single approach has closed the gap. The 2020 cautious optimism was correct for the GAN era. We are not in the GAN era anymore. Read every published in-distribution AUC with this in mind, and read /research-lab for the longer version. Detector output alone rarely survives cross-examination, which is why contested matters generally pair it with an examiner who can explain its limits. - Detector results on deepfakes found in the wild , the same failure measured on deepfakes that were actually circulating - When audio deepfake detectors fail on new voice generators , the identical problem in audio, which this post does not cover - What a deepfake detector score does not tell you , what that means for quoting a detector score in a report ## Sources ## Common questions on this topic Frank et al. (ICML 2020) gave the cleanest mechanistic account: GAN-generated images carry severe artifacts in the frequency domain caused by upsampling operations common across architectures. A detector that learns those artifacts is implicitly learning the upsampling fingerprint of one family of decoders. It is the natural response if detection always trails generation, sign the output rather than detect it. Two strong proposals exist: Fernandez et al.'s Stable Signature (ICCV 2023), which fine-tunes a latent-diffusion generator to embed a recoverable signature, and Google DeepMind's SynthID-Image. The field's central open problem: a detector trained on outputs from one generator architecture performs far worse on outputs from an unfamiliar one, because what it actually learned was that architecture's artifacts rather than a general signature of synthesis.