Emerging Tech Horizons: What's Next After Today's AIPhysical constraints and digital trust · Lesson 11 of 16

Synthetic media, deepfakes and content provenance

Article · 7 min · 8 min lecture

Video lecture

Synthetic media, deepfakes and content provenance

15 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 15

Synthetic media and provenance

  • Opportunity and risk
  • Provenance: C2PA
  • Watermarks and detection
  • Rules and policy

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

When seeing is no longer believing

AI can now generate photorealistic images, convincing voices and increasingly realistic video in minutes. This creates huge creative and commercial opportunity (product imagery, localisation, dubbing, personalised video) and serious risks: impersonation scams, fake endorsements, election disinformation, non-consensual imagery and eroding trust in genuine content. The response is developing on three fronts: provenance (proving where content came from), detection and watermarking, and regulation and platform policy.

Provenance: C2PA and Content Credentials

The Coalition for Content Provenance and Authenticity (C2PA) publishes an open technical standard for attaching cryptographically signed manifests to media. A manifest can record who created the content, with what tool or device, and what edits were made, including whether AI was used. Consumer-facing, these are known as Content Credentials, often shown with a small "CR" icon.

Adoption has grown across the pipeline:

  • Capture: some cameras and phones sign images at capture. Google's Pixel 10 phones, for example, attach Content Credentials to photos taken with the Pixel Camera app, and other manufacturers have announced or shipped support.
  • Creation tools: major image and design tools add credentials to AI-generated or edited outputs, and several AI image generators attach them by default.
  • Distribution: some platforms read credentials to show labels; however, many platforms and messaging apps strip metadata on upload, so credentials do not always survive.

Provenance proves origin and history of content that carries credentials. It cannot prove that content without credentials is fake, and it does not stop bad actors who never add credentials. It is one layer, not a silver bullet.

Watermarking and detection

  • Invisible watermarks embedded in AI outputs (for example Google DeepMind's SynthID for images, audio, video and text from Google's models) can be detected by the provider's tools even after some edits.
  • Detection classifiers try to spot AI-generated content without a watermark. They produce probabilities, can be fooled, and have false positives; do not use them alone for high-stakes decisions (such as accusing someone of fakery).

Regulation and platform policy

  • EU AI Act, Article 50 (applies from 2 August 2026): providers of generative AI systems must ensure outputs are marked in a machine-readable format as artificially generated, and deployers who publish deepfakes must disclose that the content is artificially generated or manipulated, with some exceptions (for example, evidently artistic or satirical works, with lighter obligations). A Code of Practice on marking and labelling supports implementation.
  • Platforms: major social and video platforms require creators to label realistic AI-generated or altered content and apply their own labels, especially for ads and political content.
  • Advertising rules: regulators such as the UK's ASA and the US FTC apply existing rules on misleading advertising to AI content; fake testimonials and undisclosed AI endorsements are risky.
  • Impersonation and fraud: many jurisdictions have or are developing laws on non-consensual deepfakes and voice cloning. Always get written consent before cloning a real person's voice or likeness.

A practical synthetic-media policy

  1. Consent: written consent for any real person's likeness or voice; rights to training inputs.
  2. Disclosure: label AI-generated or materially altered realistic content; follow platform and ad rules.
  3. Provenance: preserve Content Credentials in your pipeline; enable them in tools that support it; publish originals where possible.
  4. Verification: before sharing or reacting to viral or sensitive media, check provenance and source; use call-back procedures for voice or video requests involving money.
  5. Incident response: a plan for deepfakes of your executives or brand: monitoring, platform reporting, statement templates, legal contacts.

Hands-on: inspect Content Credentials

Use the open-source c2patool command-line tool from the Content Authenticity Initiative (check its README for current install instructions), or the public verification site at contentcredentials.org.

# Install via Rust's package manager (one option; prebuilt binaries are also published)
cargo install c2patool

# Print the C2PA manifest (if any) attached to an image
c2patool photo.jpg

# Save a detailed report to a file for your records
c2patool photo.jpg --detailed > photo-manifest.json

Inspect: the signer, the claim generator (tool or device), the actions recorded (created, edited, AI-generated), and any ingredients (source files). No manifest does not mean fake; it means no provenance information is available.

Worked example: a Dubai bank and voice-clone fraud

A bank's finance team in Dubai received a voice message apparently from the CFO asking for an urgent transfer. Policy required a call-back on a known number and a second approver for transfers above a threshold; the call-back revealed the fraud. The bank then trained staff on voice-clone scams, added a code-word process for urgent requests, and prepared a deepfake response plan for its executives' public images and voices.

Pitfalls

  • Relying on AI detectors as proof.
  • Stripping Content Credentials in your own asset pipeline.
  • Cloning voices or likenesses without documented consent.

How to measure success

Share of published AI content correctly labelled, credentials preserved through your pipeline, staff completion of verification training, and time to respond to deepfake incidents.

Key takeaways

  • Synthetic media brings creative value and risks such as impersonation, fake endorsements and eroded trust.
  • C2PA Content Credentials attach signed provenance manifests; they prove history when present but cannot prove unlabelled content is fake.
  • Watermarks such as SynthID help identify AI outputs; detection classifiers are probabilistic and should not be used alone.
  • EU AI Act Article 50 applies from 2 August 2026; combine consent, disclosure, provenance, verification and incident response.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. An image has no Content Credentials. What can you conclude?
  2. A detector says a video is 87% likely AI-generated. How should you use this?
  3. A finance team receives an urgent voice request from the CEO to transfer funds. What is the best control?

Put it into practice

Inspect three images with c2patool or the Content Credentials verify site, then draft a one-page synthetic-media policy covering consent, disclosure, provenance, verification and incidents.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.