Artificial intelligence (AI) generated content has created a new hurdle for establishing authenticity in nearly all digital media formats. An article, photo, voice clip or video can now be easily created or modified using affordable, easy to access, and relatively fast software tools.
The obvious allure here is to locate a detection tool, upload your digital material and have some percentage tell you if it's real or fake. But this approach is too simplistic. Establishing authenticity is not simply based upon context, origin, history of creation, evidence of technology used and reliability of the detecting tool(s).
A better method considers the process of verifying digital content to be an investigative procedure rather than a simple yes/no question. To start, identify exactly what you want to verify. Collect multiple independent indicators which can either support or refute the claim. When evaluating written materials this may include reviewing previous drafts or versions of the document. Evaluating images may require examining metadata, as well as determining the image's origins. Video and audio evaluation often rely equally on the sources of the recorded items, chain of custody and physical/technical evaluations.
As technology evolves at such a rapid pace, the best methods for verifying digital content today do not ensure the best methods tomorrow.
1. Start With the Authenticity Claim
The first mistake in content verification is asking a question that is too broad.
“Is This AI?” is typically a simple question, however, in practice it can have multiple meanings. In reality, you may be seeking to know if a person authored the content without the use of AI; if an image represents a true event; if an image has been manipulated; or if a publication contains the original version of a submitted file.
Each type of inquiry will need different types of evidence.
To illustrate, assume that an employee completes a project report and that your organization allows its employees to utilize AI for ideas generation, but they are required to draft their own reports. A tool designed to detect AI would likely detect statistical patterns indicative of generated writing, but it would not be able to determine if the employee utilized AI to create brainstormed ideas, rewritten individual sentences, or if the employee generated the complete report.
Much more relevant information could be provided by the revision history of the document, research materials prepared while drafting the document, drafts of the document and statements from the employee regarding how he/she completed the report.
In regard to visual content, when an individual provides photographs as evidence of an event, the most significant concern may not necessarily be “Did this image originate from AI?” The primary issue is whether this photograph was taken at the claimed time and location?
Determining what constitutes the claim first will help prevent you from selecting a tool based on an appealing result.
The Forum.AIContentAuthenticity.com Forum examines the topic as a general authentication problem, including text, images, video, audio, tools/methods, origin/creation/preservation, research and policy. They do not limit authenticity to a single detection method.
2. Treat Detection Results as Evidence
Detection tools can be useful, but they should rarely be treated as final arbiters.
A detector is generally making an inference based on characteristics of the content. It is not observing the complete creation process. That distinction becomes critical when the consequences of a false accusation are significant.
Consider AI-generated text. A detector may identify patterns associated with predictable language, sentence structure, or token distribution. Yet human writing can naturally contain those characteristics, particularly when the author is writing technical, academic, or highly structured material.
The reverse problem also exists. AI-generated text can be edited, paraphrased, translated, or combined with human writing. The final product may no longer resemble the output that a particular detector was designed to recognize.
Image detection presents similar difficulties. Community testing discussed on the forum found substantial variation between tools, including cases where genuine photographs were incorrectly flagged and generated images escaped detection. Compression and other transformations can make the task harder still. (Forum.AIContentAuthenticity.com)
That means a useful verification process should ask:
What exactly did the detector measure?
Was the tool independently evaluated?
Was the content altered before testing?
Does the tool work well for this particular medium?
What evidence exists outside the detector?
A score should change your level of attention, not automatically determine your conclusion.
3. Look for Creation History
When available, creation history can be more informative than surface-level analysis.
For most documents, useful evidence for establishing the authorship would include:
drafts
revision timestamps
research notes
source materials (e.g., pictures, graphs, charts)
editing history
comments on collaborations
previous examples of the author’s writing
Evidence like this is helpful as it allows reviewers to understand how the end product was developed.
If an example of an essay appears with unusual polish and a plagiarism detector alerts you, this could cause you to consider further reviewing. However, if in addition to polishing there are also weeks’ worth of revision history; substantial changes to the structure of the paper; extensive research notes; and feedback comments from the student or employee regarding their own drafts then your initial reaction to reviewing the paper might become more tempered. This doesn’t necessarily mean that Artificial Intelligence wasn’t used; but it does provide reasons why the detection results should never be evaluated alone.
Creating processes that allow organizations to collect evidence as part of the normal workflow will help. Employees or students do not need to go back through forensic type work, if they have already saved shared documentation; if they use version control for their projects; if they implement a structured review system; and/or keep all of their source documentation. The same reasoning applies to creative teams. If employees save original project files and not just final export versions of those files, then reviewers will have much more data at hand if a conflict arises over ownership or authenticity.
4. Use Provenance and Metadata
Detection tries to infer what happened.
Provenance attempts to document what happened.
That difference is becoming increasingly important.
Metadata can include timestamps, camera information, software details, GPS information, file histories, hashes, and other technical records. More advanced provenance systems can provide cryptographically verifiable information about a file's origin and subsequent modifications.
C2PA and Content Credentials are prominent examples of this approach. Instead of asking whether an image “looks AI-generated,” a provenance system can potentially provide information about how the asset was created and what happened to it afterward.
However, provenance is not magic.
The forum's discussions about C2PA repeatedly highlight the gap between technical capability and widespread adoption. Credentials can be useful, but platforms may strip metadata, fail to display credentials, or preserve information without exposing it to ordinary users. (Forum.AIContentAuthenticity.com)
That creates an important rule:
The absence of provenance is not automatically evidence of manipulation.
A photograph uploaded to a platform may lose metadata during processing even though the original file contained useful information. Conversely, the presence of provenance does not necessarily prove every claim associated with the content.
Think of provenance as a documented chain rather than a universal authenticity certificate.
When it exists, preserve it. When it does not, use other evidence.
5. Verify Images With Multiple Signals
Images often create an especially difficult verification problem because modern generative systems can produce convincing details while traditional visual artifacts are becoming less obvious.
Start with the original file whenever possible.
A screenshot or compressed social-media copy may contain much less information than the original. If you have access to the source, preserve it before performing additional transformations.
Then examine several categories of evidence.
Technical information
Check available metadata, creation information, software history, and provenance credentials.
Visual consistency
Look at lighting, reflections, shadows, perspective, geometry, repeated patterns, typography, hands, faces, and object boundaries. None of these is definitive by itself, but inconsistencies can justify closer examination.
Source history
Determine where the image first appeared. Reverse-image searching can help establish whether the same photograph existed before the claimed event or whether it has been repeatedly reposted with different descriptions.
Context
Ask whether the surrounding claim makes sense. A technically authentic photograph can still be presented with a false caption, date, location, or explanation.
That last point is easy to miss. Authenticity of the file and authenticity of the claim are separate questions.
A real photograph can be used to support a completely fabricated story.
6. Treat Video and Audio as Context Problems Too
Deepfake detection is particularly challenging because modern synthetic video can eliminate many of the obvious visual artifacts that earlier systems relied upon.
Traditional checks can still be useful. Look for inconsistent lip synchronization, unusual facial motion, lighting changes, temporal flickering, abrupt transitions, or unexplained edits.
But don't stop with the pixels.
Ask where the video came from, who recorded it, whether an earlier version exists, whether the full recording is available, and whether the file has a credible chain of custody.
The forum's discussions on current deepfake detection point toward a broader shift from passive detection toward active verification, including signed capture, challenge-response mechanisms, and provenance chains for high-stakes situations. (Forum.AIContentAuthenticity.com)
Audio requires a similar mindset.
Voice cloning can produce remarkably convincing speech, so analyzing vocal artifacts alone may not provide enough confidence. Source records, original files, timestamps, surrounding communications, and independent confirmation can be much more valuable.
For a supposedly important phone recording, for example, you should not rely solely on whether a voice “sounds like” the person.
7. Build a Verification Checklist
A repeatable checklist is more reliable than asking reviewers to trust intuition.
For written content, a practical workflow could include:
Identify the authenticity claim.
Preserve the original document.
Review available revision history.
Check cited sources.
Compare the work with previous samples where appropriate.
Use detection tools as an additional signal.
Record contradictory evidence.
Escalate only when multiple signals justify further investigation.
For images:
Obtain the original file.
Preserve available metadata.
Check provenance or Content Credentials.
Inspect visual inconsistencies.
Search for earlier appearances.
Verify the claimed context.
Record the evidence and limitations.
Source verification, editing analysis, and chain-of-custody should be added to video and audio. The main issue here is consistency. It would be ideal that two reviewers are using an almost identical method in reviewing the material instead of being influenced by their own subjective opinions. A similar method was proposed for editorial teams on the forum content authenticity workflow that recommends the same layer-based method to use when working with editorial teams, including revision history, sources, previous work, image-source verification, and detection tools in combination rather than focusing solely on detector scores. (Forum.AIContentAuthenticity.com)
8. Use Escalation Instead of Automatic Accusations
One of the most important design choices is deciding what happens after a suspicious result.
A detector should generally trigger a review rather than an automatic penalty.
You can create simple levels:
Low concern: The available evidence is consistent with the stated origin.
Review recommended: One signal is unusual or contradictory, so additional evidence should be collected.
Substantial concern: Multiple independent signals conflict with the claimed origin.
Unable to verify: The evidence is insufficient to reach a responsible conclusion.
That last category is essential.
There will be cases where you simply cannot determine what happened. Saying “unable to verify” is more defensible than forcing every artifact into a real-or-fake category.
This is particularly important in education and employment, where a false positive can affect someone's reputation or opportunities.
The forum's discussion of AI detection and student attempts to bypass detection tools also raises a broader concern: when detection becomes a high-stakes punishment mechanism, users may spend more effort avoiding detection than demonstrating genuine understanding. Participants suggest that process portfolios, oral examinations, and assignments requiring personal analysis can sometimes provide stronger evidence than detection alone. (Forum.AIContentAuthenticity.com)
In other words, better verification can sometimes mean changing the workflow rather than buying another detector.
9. Match Verification Effort to Risk
Not every piece of content deserves the same level of investigation.
A casual social post and a video being used as evidence in a legal proceeding should not pass through identical verification procedures.
Use the potential cost of being wrong to determine how much evidence you need.
For routine marketing content, a source check and editorial review may be enough. For investigative journalism, financial authorization, legal evidence, identity verification, or safety-critical communication, you may need original files, provenance, independent confirmation, and human review.
This also prevents verification systems from becoming so burdensome that people stop using them.
A good system has a lightweight path for ordinary content and an escalation path for high-risk material.
The goal is not maximum scrutiny everywhere. It is appropriate scrutiny where it matters.
10. Keep Updating the Method
AI authenticity is not a solved problem.
The technologies used to generate synthetic content are constantly evolving. As this evolves so do the methods for detecting it. New standards on provenance will continue to emerge. More and more platforms are treating metadata differently; users are finding increasingly innovative ways to alter or "edit" their content.
Therefore, a verification system that functions well now will likely not function nearly as effectively in a year.
This is why regular testing is an absolute necessity. Keep your repository of both authentic (real) and synthetic (fake) samples up to date, and continually evaluate your tools using these examples. Track false positives and false negatives from your tests. Check if your workflow continues to align with emerging technology.
When considering the marketing claims from vendors of detection services, look closely at any percentages given, such as "99% accurate." This number means very little without information about the type(s) of data used during testing; types of model(s) used to create synthetic examples; method of conducting tests; and whether the benchmark is similar to the content you use in your daily operations.
Provenance systems need to be evaluated using the exact same practical approach. Ask yourself/your team if the credentials will persist through your normal publishing workflow? Will the platforms where you publish preserve these credentials? Can end-users view, understand, and utilize these credentials?
The goal is not to identify one long-term solution to solving the authenticity issue.
Conclusion: Authenticity Is an Evidence Problem
The most reliable approach to Forum.AIContentAuthenticity.com is not to search for a single perfect detector.You are to create an evidentiary chain (a chain of evidence).
To start with, define what you have to verify; preserve the source documents and their record of origin. Verify all possible metadata about items. For any item which provides valuable information use specialized discovery tools. When appropriate evaluate the reliability of the sources and contextualize them. Wherever possible compare independent indicators. Document any doubts. If the implications warrant escalate as needed.
Above all, do NOT allow yourself to convert one data point into a decision.
Content verification will likely be composed of some form of detection, metadata/origin tracking, transparency in processes/workflows, and a degree of human judgment. Detection will probably be good at discovering potential suspect content. Provenance, if a reliable origin story can be developed through that method, could offer greater assurance. However neither technique has applicability in every case.
Build your process based on evidence -- not labels -- and you'll be able to make better choices regardless of how much technology changes beneath you. ultimately what effective authenticity verification should accomplish: not perfect certainty, but a disciplined and defensible way to determine what you can—and cannot—reasonably prove.
Top comments (0)