Faking Is Free: The Rising Price of Proving You Are Real

A pug flying an aeroplane. That was the image, generated with an off-the-shelf model by a photographer who posts under the handle Horshack, and in September 2025 he persuaded a Nikon Z6III to certify it as a photograph.

The method was not sophisticated. He encoded the synthetic image into Nikon's raw NEF container, then used the camera's multiple exposure mode to graft it onto the skeleton of a legitimate capture. The camera, running firmware version 2.00 released on 27 August 2025, duly wrapped the result in a cryptographic manifest conforming to the specification published by the Coalition for Content Provenance and Authenticity. Anyone inspecting the file would have found a valid signature attesting that a real Nikon camera had recorded the scene. Nikon confirmed the fault on 4 September, suspended its Authenticity Service, and later notified users that every certificate it had issued would be revoked. Early adopters who had spent the fortnight signing their work found their proofs retrospectively voided.

The more instructive part came next. Horshack pointed out that Nikon could not fully fix this alone, because the default behaviour of the widely used C2PA validation tools is not to check whether a signing certificate has been revoked. The revocation-checking code exists in the software development kit; it is simply not switched on by default. He filed a GitHub issue asking that the reference command-line tool change that. Until it does, a revoked certificate and a valid one look identical to most software that inspects them.

Hold that sequence in mind, because it contains the whole argument in miniature. Manufacturing a convincing fake cost one person an afternoon and no money. Certifying that something is real required a camera manufacturer, a firmware pipeline, a certificate authority, an industry consortium, a specification, a conformance programme and a public trust list — and it failed anyway, in a way only the consortium could repair.

This is the asymmetry that will define the next decade of the internet, and almost every optimistic account of the “trust economy” walks straight past it.

The Statistic Everyone Cites Cannot Prove Its Own Provenance

Writing in Modern Diplomacy on 16 August 2026, Yang Xite, a research fellow at ANBOUND, set out the case with unusual clarity. “Information used to be scarce, and access to it was a source of power,” he wrote. “Today, the problem is almost the opposite; there is too much information floating online.” His conclusion: “As the cost of producing information approaches zero, the value of finding, checking, filtering, and trusting information rises. The scarce resource is no longer content itself. It is confidence in the content.” And therefore: “In a market where consumers and businesses are increasingly exposed to fraud, proof of authenticity can itself become a product.”

That is correct as far as it goes. The trouble starts with the number recruited to support it.

You will have seen the claim that ninety per cent of online content will be AI-generated by 2026. It appears in policy briefings, keynotes and vendor decks, usually attributed to Europol, whose 2022 report Facing reality? Law enforcement and the challenge of deepfakes states that “experts estimate that as much as 90% of online content may be synthetically generated by 2026”.

In January 2023, Jesse Walker at Reason traced the chain. Europol's “experts” resolve to a single citation: Nina Schick's 2020 book Deepfakes: The Coming Infocalypse. Schick's source was one named individual — Victor Riparbelli, chief executive of Synthesia, a company that sells synthetic video. What Riparbelli said was that synthetic video may account for up to ninety per cent of all video content in as little as three to five years. A forecast about one medium, made by a vendor with a direct commercial interest in that medium's growth, generalised into a claim about the entire internet, laundered through a book into a police agency report and from there into the newspaper of record.

The most widely cited datum about information pollution is itself a specimen of information pollution. It is not a measurement. It never was.

The measurements that do exist tell a duller, more useful story. In October 2025 the search analytics firm Graphite published an analysis by Gregory Druck, Jose Luis Paredes, Bevin Benson and Ethan Smith covering forty-three thousand English-language URLs drawn from CommonCrawl between January 2020 and May 2025. They reported their error rates: a 4.2 per cent false positive rate against pre-ChatGPT articles, and a 0.6 per cent false negative rate against known GPT-4o output. AI-written articles overtook human-written ones in November 2024 and stood at just over half the sample by May 2025. Crucially, the proportion has been broadly stable for about a year. The wave crested; it did not keep rising toward ninety.

Graphite also noted something that cuts against the panic: these articles largely do not surface in Google or ChatGPT results. NewsGuard, tracking the sharper end of the phenomenon, had identified 3,749 AI content farm sites across sixteen languages as of 23 June 2026, more than double its count a year earlier. A real and growing problem. Not ninety per cent of the internet.

This matters beyond pedantry. Build a verification regime on the premise that nearly everything is fake and you will build something that treats unverified as guilty by default. Which is exactly what is being built.

What the Economics Paper Actually Says Is Worse

The arXiv paper usually invoked alongside the ninety per cent figure does not contain it. “The Economics of Information Pollution in the Age of AI: General Equilibrium, Welfare, and Policy Design”, submitted by Yukun Zhang and Tianyang Zhang on 17 September 2025 and revised on 4 January 2026, is a theoretical model rather than an empirical survey. It contains no census of what fraction of the web is synthetic.

What it does contain is a sharper claim. The authors argue that large language models represent “a fundamental shock to the economics of information production” because they collapse the marginal cost of generation asymmetrically — driving the cost of low-quality synthetic content towards zero while leaving high-quality production costly. Formally, AI substitutes for labour in low-quality output but complements it in high-quality creation. From this they derive a unique “Polluted Information Equilibrium”, and attribute its inefficiency to a threefold market failure: a production externality, a platform governance failure, and an information commons externality.

That framework explains something a raw percentage cannot. The problem is not the volume of synthetic content. It is that the cost gap between producing a plausible lie and producing a verified truth has widened, and every actor's incentives now point downhill. Zhang and Zhang propose an Information Pollution Index and an adaptive governance regime keyed to real-time readings — a proposal presupposing an instrument nobody operates.

“AI, Digital Platforms, and the New Systemic Risk” by Philipp Hacker, Lilian Edwards and Atoosa Kasirzadeh, submitted on 22 September 2025 and revised on 23 May 2026, comes at the same territory from the governance side. Drawing on finance, complex systems theory, climate science and cybersecurity, the authors argue that recent European legislation invokes systemic risk while relying on narrow or ambiguous characterisations of it. The Digital Services Act, they find, identifies systemic risk better than the more recent AI Act, and harms such as discrimination at scale and systematic hallucinations “may not fall under current legal definitions, given the AI Act's focus on frontier model capabilities”.

Put the two together and the diagnosis is precise. Generation has become cheap in a way structurally biased towards the low-quality end, and the legal instruments built to respond target frontier model capabilities rather than population-level degradation of the information commons. Neither paper says ninety per cent of the internet is fake. Both say something more troubling: the machinery for noticing and pricing the damage does not exist.

Seeing Stopped Being Enough Somewhere Around Last March

The abstraction becomes concrete fastest in medicine, where the readers are the most highly trained image analysts in the world.

On 24 March 2026, Radiology published a study led by Mickael Tordjman, a post-doctoral fellow at the Icahn School of Medicine at Mount Sinai, testing whether radiologists could distinguish synthetic X-rays from real ones. Seventeen radiologists at twelve centres across six countries assessed 264 radiographs, half authentic and half generated, using both a general-purpose commercial model and RoentGen, a diffusion model built at Stanford for chest radiography.

When the radiologists did not know the study's true purpose, only forty-one per cent spontaneously flagged the synthetic images. Told explicitly that the dataset was half fake, their mean accuracy reached seventy-five per cent, with individual performance ranging from fifty-eight to ninety-two per cent. Experience made no difference: the researchers found no correlation between years in practice and detection accuracy.

Read that again. Specialists, forewarned, missed roughly a quarter of fabricated medical images. The clinical implications are obvious — fraudulent insurance claims, manufactured litigation evidence, falsified trial data — but the epistemic implication is larger. A chest X-ray was, until recently, close to a paradigm case of self-authenticating evidence. It is not any more, and no amount of professional training closes the gap.

The financial sector has the loss figures. On 7 April 2026 the FBI's Internet Crime Complaint Center published its 2025 report: 20.9 billion dollars in reported losses, up twenty-six per cent from 16.6 billion, across 1,008,597 complaints — the first time annual complaints have exceeded one million in the centre's twenty-five year history. People aged sixty and over filed 201,266 complaints and accounted for roughly 7.7 billion dollars of the losses. For the first time, the report carried a section on AI-facilitated fraud: more than twenty-two thousand complaints and nearly 893 million dollars.

The archetypal case remains the engineering firm Arup, whose Hong Kong finance employee authorised fifteen transfers totalling roughly 25.6 million dollars in a single day after a video conference in which every executive on the call was a deepfake assembled from publicly available footage. Hong Kong police disclosed the incident in February 2024; Arup confirmed itself as the victim in May. Deloitte's Center for Financial Services, in an analysis published on 29 May 2024 by Satish Lalchand, Val Srinivas, Brendan Maggiore and Joshua Henderson, projected that generative AI could push United States fraud losses to forty billion dollars by 2027, from 12.3 billion in 2023. That last figure is a projection and should be read as one. The IC3 numbers are not.

Detection Is the Losing Side of an Arms Race It Cannot Leave

The instinctive response is to build a detector. The evidence says this will not work, and the best evidence is a benchmark designed specifically to test the claim.

Deepfake-Eval-2024, assembled by Nuria Alina Chandra, Oren Etzioni and eleven colleagues and first posted in March 2025, collected deepfakes actually circulating in the wild during 2024 — forty-five hours of video, 56.5 hours of audio and 1,975 images, drawn from eighty-eight different websites in fifty-two languages. The team then ran state-of-the-art open-source detectors against it.

Performance collapsed. Against the academic benchmarks on which these models report their headline accuracy, the area under the curve fell by fifty per cent for video, forty-eight per cent for audio and forty-five per cent for images. Commercial detectors and fine-tuned models did better, but still did not match human forensic analysts. The authors' conclusion is blunt: academic benchmarks are out of date and unrepresentative of real-world deepfakes.

This is not a temporary engineering shortfall. Detection is structurally the trailing party. A detector is trained on generators that already exist, and any published detector becomes a differentiable objective for the next generation to optimise against. Compression, re-encoding, screenshotting and platform transcoding degrade exactly the statistical residue detectors look for. Every step of ordinary internet distribution is, incidentally, an evasion technique.

Which means the question cannot be answered by looking harder at the artefact. You have to ask where it came from. And the moment you do, you have changed the subject from what is true to who is vouching — and created a market.

Provenance Changes the Question From What Is True to Who Signed

The Coalition for Content Provenance and Authenticity is the serious attempt at that change. Its output, Content Credentials, is a cryptographically signed manifest travelling with a file, recording what device or software produced it and what edits were applied. The specification reached version 2.3 in January 2026 and is progressing through ISO as draft standard 22144.

The steering committee is the tell. It comprises Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic — the world's largest advertising conglomerate, the dominant mobile and desktop platform vendors, the two largest generative model providers, three major distribution platforms, one public service broadcaster and one verification vendor. A reasonable roster for building an interoperable standard. Also a list of the organisations that will decide what counts as authentic.

Before assessing who should hold that power, be precise about what the technology proves. It proves that a manifest was signed by a key traceable to a listed certificate, and that the file has not changed since. It does not prove the manifest's assertions are true. Photograph an AI-generated image displayed on a screen using a C2PA-enabled Leica and you get a cryptographically impeccable credential attesting that a real camera captured a real scene, which it did — the scene was a monitor. Nor does provenance say anything about context: an authentic photograph from one conflict, correctly signed, remains authentic when captioned as coming from another.

The independent security assessment is worse than the conceptual critique. On 27 April 2026, Enis Golaszewski, Neal Krawetz, Alan T. Sherman, Edward Zieglar and seven colleagues published what they describe as the first comprehensive independent security analysis of C2PA, including the first formal-methods analysis of its core protocols. Their finding: “the current C2PA specifications fail to achieve their claimed security goals”. Their recommendation is stark. C2PA “should not yet be relied upon for high-stakes uses such as financial disclosures, journalism, or legal evidence” — a fairly comprehensive list of the uses for which it is being promoted.

The Certificate Authority Is the Chokepoint

Here the asymmetry stops being conceptual and becomes an access-control list.

To emit a Content Credential validators will trust, you need a signing certificate from a certification authority on the C2PA Trust List. To obtain one, your product must have passed the C2PA Conformance Program, which assesses it against the specification, a certificate policy and a set of security requirements. The interim trust list that held the ecosystem together in its early years was frozen on 1 January 2026; the formal programme replacing it opened in mid-2025 and remains in early enrolment.

Consider what this means in practice. SSL.com, a conformant certification authority, introduced a free tier in June 2026 offering one Level 1 claim signing certificate valid for a year plus ten thousand trusted timestamps. Generous — except that applicants must present “a valid C2PA conformance record ID”. The certificate is free; eligibility to hold one is not something an individual can obtain at all. Conformance is a process applied to products and organisations, with legal agreements, security assessments and identity validation attached. A freelance photographer in Nairobi cannot pass it. A witness with a phone cannot pass it.

The World Privacy Forum, in a technical review published on 3 September 2025 by Kate Kaye and Pam Dixon, put the governance objection with precision: “the criteria used for inclusion on these lists, or who the arbiters deciding which entities are considered known, and by extension, trustworthy have not been made public”. The same review noted that C2PA's own harms modelling documentation concedes that “loss of control over personal information and enforced suppression of speech are possible through use of C2PA”, and that identity specifications were moved out of the core standard into a separate working group in January 2024, with identity claims aggregators now bridging government and commercial identity systems into provenance workflows.

So the architecture, stated plainly: generating a convincing fake requires a consumer graphics card or a free web account. Generating a credential that a verifier will honour requires membership of, or accreditation by, a consortium whose selection criteria are not published. One of those capabilities has been democratised. The other has been enclosed.

Every Platform Reads the Evidence and Then Deletes It

Even for the accredited, the infrastructure does not currently deliver.

In October 2025 the Washington Post ran a test that ought to be better known. Reporters produced an AI-generated video carrying Content Credentials and uploaded it to eight major social platforms. Only YouTube surfaced any warning, and that disclosure sat inside a description attached to the clip rather than on the video itself. No platform preserved the Content Credentials data in a form users could access.

The mechanism is mundane. Platforms re-encode nearly every image and video at upload — for file size, for format normalisation, and to strip EXIF data that routinely contains GPS coordinates and device identifiers. Metadata not deliberately carried through the transcode does not survive it. Some platforms do read the manifest before discarding it: TikTok began reading C2PA data in 2024 and applies its own “AI-generated” labels on that basis, adding an invisible watermark in November 2025 precisely because, in its own account, C2PA metadata can be removed when content is re-uploaded or edited.

That is the settled state of affairs. The provenance record is read by the platform, used for the platform's own labelling decision, and deleted from the file that everyone actually sees. Users receive a conclusion, not evidence. Whether to believe the label is a question about the platform, which is where we started.

The proposed remedy is “durable” credentials — soft bindings such as invisible watermarks and perceptual fingerprints that allow a stripped manifest to be recovered from a cloud registry. C2PA's own FAQ describes the approach. It also relocates verification from the file in your hand to a lookup against a database somebody else operates, and makes every verification a queryable event. Google's SynthID, embedded by default across Gemini, Imagen, Lyria and Veo, had marked more than ten billion pieces of content by Google's own account. Detection runs through Google's detector portal and the Gemini app. The watermark is Google's, the detector is Google's, and the answer to “is this real” is a request to Google.

Brussels Set a Deadline and It Lands on the Compliant

Two weeks ago, on 2 August 2026, Article 50 of the EU AI Act became enforceable. Providers of systems generating synthetic audio, image, video or text must now mark outputs with “effective, reliable, robust and interoperable machine-readable marks”. Deployers of deepfakes must disclose them with a visible or audible label a person can understand without any detection tool — a hidden machine-readable mark does not satisfy the deployer obligation. Systems already on the market have until 2 December 2026 to comply with the marking requirement, and content generated before 2 August 2026 needs no retrospective labelling. Non-compliance carries fines of up to fifteen million euros or three per cent of worldwide annual turnover, whichever is higher.

This survived a serious attempt to slow the whole regime. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and deferred the high-risk obligations under Annex III to 2 December 2027 and those for product-embedded systems to 2 August 2028. It did not delay Article 50. Spain has gone further, creating a dedicated supervisory agency, AESIA, and legislating penalties of up to thirty-five million euros or seven per cent of global turnover for failure to label.

Now apply the asymmetry. Article 50 binds providers placing systems on the EU market and deployers operating within its jurisdiction — companies with legal departments, European entities and revenue worth three per cent of. It binds OpenAI, Google, Adobe and Meta. It does not bind an open-weight model running on a laptop in a jurisdiction with no equivalent statute, which is where a growing share of genuinely harmful material is produced. The fraudsters who took 893 million dollars from Americans last year were not weighing their exposure to European administrative fines.

The predictable effect is that compliant, well-resourced, largely benign generation becomes marked, while non-compliant, adversarial generation stays unmarked. Over time that inverts the signal. If the honest are labelled and the dishonest are not, then “unmarked” ceases to mean “probably human” and starts to mean “outside the regime” — a category containing both the criminal and the ordinary person with a phone and no accreditation.

Hacker, Edwards and Kasirzadeh anticipated the structural version of this. Their framework identifies four levels of AI-related systemic risk and warns that the AI Act's orientation towards frontier model capabilities leaves population-level harms outside its definitions. Marking obligations regulate the emitter. The pollution they were meant to address is a property of the commons.

Ten Dollars a Title Is What Being Believed Now Costs

The optimistic version of the trust economy holds that a premium will emerge on genuinely human work. It is worth looking at what such a premium looks like once someone actually builds one.

The Authors Guild operates a certification called Human Authored. A book qualifies if its text was written by one or more humans, with an exception for spelling and grammar tools; using AI for research, brainstorming or indexing does not disqualify a title. The programme opened to Guild members in 2025 and, as of March 2026, to any author published in the United States. Certification costs ten dollars per title for non-members and requires identity verification through a third-party service. Both the fee and the identity check are waived for Guild members.

Two features deserve attention. First, the Guild does not vet manuscripts for AI content before certifying them, and says so, on the reasonable grounds that no reliable detection method exists. Enforcement rests on self-certification, a licensing agreement and community reporting. What is certified is not that a human wrote the book. It is that an identified person has made a contractual assertion and is exposed to consequences if it is false. That is accountability, which is genuinely valuable — and a different product from truth.

Second, look at the price structure. Ten dollars and an identity check for outsiders; free and no identity check for members. That is a small, benign, entirely defensible example of exactly the mechanism at issue. Membership confers the presumption of good faith. Non-membership must purchase it, and surrender identifying data to do so.

Scale that logic to every claim anyone makes online and the phrase “authenticity premium” reveals what it describes. A premium is a price. Someone pays it and someone collects it. Yang Xite's suggestion that “people with established reputations, professional track records, and a history of making reliable judgments may become more valuable precisely because they are accountable for what they say” is almost certainly right, and not obviously good news. It describes a market in which credibility accrues to those who already have standing, and everyone else must buy accreditation from an intermediary or be discounted. A premium on being believed is, in distributional terms, a tax on being doubted. It falls hardest on those least able to pay it and with the weakest prior reputation to trade on — which is to say, most people.

Proof of Personhood Turns Out to Be a Subscription Business

The same shape appears in identity infrastructure, at greater scale and with fewer safeguards.

World, the network built by Tools for Humanity and co-founded by Sam Altman, verifies humanness by scanning irises with a device called the Orb, issuing a World ID that lets a person prove uniqueness without revealing identity. By April 2026, nearly eighteen million people had verified at an Orb. During 2026 the company has pivoted towards enterprise, expanding verification points into retail and introducing fees for applications that check a user's humanity, while keeping verification free for the end user. Reported partners include Tinder and Reddit.

Read that business model carefully. Users supply biometrics free of charge; relying parties pay for the right to trust them. The asset being monetised is the population of verified humans, and the revenue accrues to whoever operates the verification layer. This is not a criticism of the cryptography, which is thoughtful. It is an observation about who ends up holding the register of real people, and on what terms.

The public-sector alternative is further along than most people realise and less far along than its deadline requires. Under the revised eIDAS regulation, all twenty-seven EU member states must make a European Digital Identity Wallet available to citizens by 24 December 2026. France, Austria and Italy have launched national implementations; Germany has said its state-issued wallet will arrive on 2 January 2027, after the deadline. Fewer than a third of member states currently meet the readiness benchmark. A wallet issued by a state is a materially better arrangement than one issued by a venture-funded company, and it is arriving late into a vacuum commercial providers are filling now.

Meanwhile the enforcement apparatus for synthetic commercial speech is thin. The Federal Trade Commission's rule on consumer reviews and testimonials took effect on 21 October 2024, expressly covering AI-generated reviews, with civil penalties per violation running to tens of thousands of dollars. In December 2025 the agency sent warning letters, later posted publicly, and in January 2026 established a dedicated AI enforcement unit. Set that against NewsGuard's 3,749 content farms and the scale problem answers itself. Enforcement is retail; generation is wholesale.

Absence of Proof Is Becoming Proof of Absence

Everything above converges on a single failure mode, and the World Privacy Forum named it before it arrived.

Provenance systems classify. Content carrying a valid signature is marked as such; content without one is rendered “unknown” or “invalid”. In an interface, on a phone, glanced at for a second and a half, those categories collapse into one: not verified, therefore suspect.

Consider who is systematically unverified. A protester filming police conduct on a five-year-old handset with no provenance capability. A whistleblower who must strip metadata to survive. A journalist in an authoritarian state for whom a cryptographic link between a file and a device is a targeting package. A photographer in a country with no conformant certificate authority. The World Privacy Forum found precisely this risk: that the trust model penalises creators lacking C2PA adoption and disadvantages marginalised and at-risk communities — the very groups the technology's designers set out to protect.

There is a second-order effect. When authenticity becomes a live question, real evidence loses force. The liar's dividend — dismissing genuine recordings as fabricated — is available to anyone whose accuser lacks a certificate, and that accuser is usually the one with less money. Provenance infrastructure does not merely fail to help such people. It hands their opponents a rhetorical instrument: where are the credentials?

Nor is the burden evenly distributed geographically. The conformance programme, the certificate authorities, the steering committee and the standards process are concentrated in the United States, western Europe and Japan. The trust list is the operative boundary of the verifiable internet, and it was drawn by eleven organisations, none accountable to an electorate, according to criteria that have not been published.

What Would Actually Redistribute the Burden

None of this argues for abandoning provenance. Content Credentials are useful, and a signed chain of custody from a wire agency's camera to a newspaper's front page beats nothing. The argument is that provenance as currently constituted transfers the cost of doubt onto the people least able to bear it, and that this is a design choice rather than a law of nature.

Four changes would alter the distribution.

Make absence neutral by design. Interfaces should be prohibited from rendering unsigned content as suspect. The presence of a credential is information; its absence is not. This is a user-experience rule with constitutional weight, and the cheapest intervention available.

Open the trust list. If the conformance criteria and the identity of the arbiters remain unpublished, a private consortium is exercising a public function without accountability. Publishing the criteria, the appeals process and the removal grounds costs nothing. An individual pathway to signing — accreditation of persons, not only products and organisations, with the cost borne publicly — is the harder and more necessary step.

Fix revocation before scaling. The Nikon episode was contained because Horshack disclosed it, and could not be fully remediated because validators do not check revocation by default. A provenance ecosystem in which a revoked certificate validates is worse than no ecosystem, because it manufactures unearned confidence. Golaszewski and colleagues have supplied the formal analysis; the specification should be treated as pre-deployment until their findings are addressed.

Regulate the reader, not only the writer. Article 50 obliges emitters to mark. It says nothing about the platforms that strip those marks in transit. A distribution-side duty to preserve and display provenance data, enforceable against very large platforms under the Digital Services Act, would make the marking obligation meaningful. At present the EU compels the creation of evidence and permits its destruction seconds later.

The pug flying the aeroplane was never really about Nikon. It was about the discovery that the certificate and the thing certified had come apart, and that only the certifier could put them back together. That is the position ordinary people are being moved into across every domain where truth must now be demonstrated rather than observed. The ability to fabricate has been handed to everybody. The ability to be believed is being metered, priced and administered by a small number of hardware manufacturers, platforms, model providers and identity vendors, on terms they have not published, with an appeals process that does not exist.

Confidence is indeed becoming the scarce resource. Whether that is a market opportunity or a civil liberties emergency turns not on whether verification gets built, but on whether the people who cannot afford it are treated as unproven or as liars.

References

  1. Yang Xite, “Information Pollution and the Rise of the Trust Economy,” Modern Diplomacy, 16 August 2026. https://moderndiplomacy.eu/2026/08/16/information-pollution-and-the-rise-of-the-trust-economy/
  2. Yukun Zhang and Tianyang Zhang, “The Economics of Information Pollution in the Age of AI: General Equilibrium, Welfare, and Policy Design,” arXiv:2509.13729, 17 September 2025, revised 4 January 2026. https://arxiv.org/abs/2509.13729
  3. Philipp Hacker, Lilian Edwards and Atoosa Kasirzadeh, “AI, Digital Platforms, and the New Systemic Risk,” arXiv:2509.17878, 22 September 2025, revised 23 May 2026. https://arxiv.org/abs/2509.17878
  4. Jeremy Gray, “Nikon Can't Fully Solve the Z6 III's C2PA Problems Alone,” PetaPixel, 22 September 2025. https://petapixel.com/2025/09/22/nikon-cant-fully-solve-the-z6-iiis-c2pa-problems-alone/
  5. Europol Innovation Lab, “Facing reality? Law enforcement and the challenge of deepfakes,” Europol, 2022. https://www.europol.europa.eu/cms/sites/default/files/documents/Europol_Innovation_Lab_Facing_Reality_Law_Enforcement_And_The_Challenge_Of_Deepfakes.pdf
  6. Jesse Walker, “That time we tried to make sense of a statistic in a 'New York Times' story on deepfakes,” Reason, 27 January 2023. https://reason.com/2023/01/27/that-time-we-tried-to-make-sense-of-a-statistic-in-a-new-york-times-story-on-deepfakes/
  7. Gregory Druck, Jose Luis Paredes, Bevin Benson and Ethan Smith, “More Articles Are Now Created by AI Than Humans,” Graphite, October 2025. https://graphite.io/five-percent/more-articles-are-now-created-by-ai-than-humans
  8. NewsGuard, “Tracking AI-enabled Misinformation: 3,749 AI Content Farm sites (and Counting),” NewsGuard AI Tracking Center, 23 June 2026. https://www.newsguardtech.com/special-reports/ai-tracking-center/
  9. Mickael Tordjman et al., “The Rise of Deepfake Medical Imaging: Radiologists' Diagnostic Accuracy in Detecting ChatGPT-generated Radiographs,” Radiology, 24 March 2026. https://pubs.rsna.org/doi/10.1148/radiol.252094
  10. Federal Bureau of Investigation, “2025 Internet Crime Report,” Internet Crime Complaint Center, 7 April 2026. https://www.fbi.gov/file-repository/2025_ic3report.pdf/view
  11. Heather Chen and Kathleen Magramo, “Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee,” CNN Business, 16 May 2024. https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
  12. Satish Lalchand, Val Srinivas, Brendan Maggiore and Joshua Henderson, “Generative AI is expected to magnify the risk of deepfakes and other fraud in banking,” Deloitte Center for Financial Services, 29 May 2024. https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html
  13. Nuria Alina Chandra, Hannah Lee, Ryan Murtfeldt, Lin Qiu, Arnab Karmakar, Emmanuel Tanumihardja, Kevin Farhat, Ben Caffee, Changyeon Lee, Jongwook Choi, Sejin Paik, Aerin Kim and Oren Etzioni, “Deepfake-Eval-2024: A Multi-Modal In-the-Wild Benchmark of Deepfakes Circulated in 2024,” arXiv:2503.02857, 4 March 2025, revised 27 May 2026. https://arxiv.org/abs/2503.02857
  14. Coalition for Content Provenance and Authenticity, “C2PA,” c2pa.org, accessed 16 August 2026. https://c2pa.org/
  15. Enis Golaszewski, Neal Krawetz, Alan T. Sherman, Edward Zieglar, Sai K. Matukumalli, Roberto Yus, Carson L. Kegley, Michael Barthel, William Bowman, Bharg Barot and Kaur Kullman, “Verifying Provenance of Digital Media: Why the C2PA Specifications Fall Short,” arXiv:2604.24890, 27 April 2026. https://arxiv.org/abs/2604.24890
  16. Kate Kaye and Pam Dixon, “Privacy, Identity and Trust in C2PA: A Technical Review and Analysis of the C2PA Digital Media Provenance Framework,” World Privacy Forum, 3 September 2025. https://worldprivacyforum.org/posts/privacy-identity-and-trust-in-c2pa/
  17. SSL.com, “C2PA Certificates for Media Authenticity,” ssl.com, accessed 16 August 2026. https://www.ssl.com/products/content-authenticity/content-credentials/c2pa/
  18. Washington Post, “Tests show top social platforms don't disclose markers on AI videos,” 22 October 2025. https://www.washingtonpost.com/technology/2025/10/22/ai-deepfake-sora-platforms-c2pa/
  19. Google DeepMind, “SynthID,” deepmind.google, accessed 16 August 2026. https://deepmind.google/models/synthid/
  20. European Commission, “Transparency obligations under Article 50 of the AI Act,” Shaping Europe's Digital Future, 2026. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
  21. Gibson Dunn, “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes,” gibsondunn.com, 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
  22. The Authors Guild, “Human Authored Certification,” authorsguild.org, accessed 16 August 2026. https://authorsguild.org/human-authored/
  23. Biometric Update, “World shifts from crypto identity experiment to enterprise proof-of-humanity,” biometricupdate.com, June 2026. https://www.biometricupdate.com/202606/world-shifts-from-crypto-identity-experiment-to-enterprise-proof-of-humanity
  24. European Commission, “European Digital Identity Wallet,” ec.europa.eu, accessed 16 August 2026. https://ec.europa.eu/digital-building-blocks/sites/display/EUDIGITALIDENTITYWALLET/EU+Digital+Identity+Wallet+Home
  25. DLA Piper, “FTC's 2026 enforcement approach to fake reviews takes shape: Takeaways for companies,” dlapiper.com, July 2026. https://www.dlapiper.com/en-us/insights/publications/2026/07/ftcs-2026-enforcement-approach-to-fake-reviews-takes-shape-takeaways-for-companies

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...