Authenticity
Photo authenticity in the age of AI
Telling a real photo from a generated one by eye is a losing battle. The only workable route is to invert the problem: prove the origin of what is authentic.
Until recently a photograph enjoyed an implicit presumption: it depicted something that had happened. That presumption no longer holds. And the consequence is not mainly for those producing fakes — it is for anyone holding a genuine photo who has to prove it.
The collateral damage: the liar's dividend
Much is said about synthetic images used to deceive. Far less about the side effect, which in litigation is both more common and more insidious: the existence of fakes makes the genuine contestable.
Nobody needs to argue that a photo was retouched any more. It is enough to observe that anything can be generated today, and the burden of proving authenticity returns to whoever produced it. That objection costs nothing to raise and a great deal to dismantle.
The problem is not only that fakes become believable. It is that the truth becomes deniable.
Why detectors do not solve it
Tools that analyse an image to decide whether it was generated work by hunting for artefacts typical of generative models. The limit is structural: they are trained on what existed yesterday. Each model generation reduces the artefacts detectors rely on, and recompression or a crop is often enough to degrade their effectiveness.
They also give probabilistic answers — «likely synthetic» — which carry limited weight where something must be demonstrated. Useful as an indication. Not a foundation to build on.
Inverting the problem: provenance
The approach that holds is the opposite. Instead of asking «is this image fake?», it puts whoever captured the genuine image in a position to prove where it came from: which device, which instant, which place, and that it has not changed since.
The practical difference is stark. A detector ages; a cryptographic chain of custody does not, because it never looks at the image: it looks at the path. If the fingerprint computed at capture matches, and a third party's timestamp attests that fingerprint already existed, the fact that perfect images can now be generated is irrelevant — that image has a documented history.
Regulation is moving the same way
The European legislator has taken the route of transparency about origin rather than detection. Regulation (EU) 2024/1689 (the AI Act) introduces transparency obligations for synthetic content, requiring in particular that artificially generated or manipulated content be marked in a machine-readable format and detectable as such. The transparency provisions apply from August 2026.
The design confirms the direction: declared, verifiable origin becomes the thing under discussion, far more than after-the-fact pixel analysis. Anyone documenting facts verifiably is ahead of that curve.
How LOCUS handles it — and what it declares it does not do
The authoritative layer is the one described in the other guides: cryptographic fingerprints, signed manifest, dual RFC 3161 timestamps, sealed BagIt package. That is what holds, and it is verifiable with standard tools.
On top of that, LOCUS embeds a provenance information block in the media — inside the JPEG for photos, in a dedicated container box for video. Maximum clarity is needed here, because it is easy to be misread:
- The format is inspired by C2PA and JUMBF, but it is not standard C2PA.
- Consequently it is not readable with Content Credentials ecosystem tools: anyone opening it with those will find nothing, and that is not a defect of the bundle.
- It is an additional, self-asserted layer. The real guarantees remain the signed manifest, the timestamp and the hashes.
- For audio no block is embedded in the media: the track is raw and the box would alter it.
Saying so openly is a choice. «C2PA compliant» would sell better, but it would be false, and it would be found out at exactly the worst moment: when a technically competent opposing party opens the file and does not find what they expected.
The underlying limit no technology overcomes
This must be stated precisely, because the credibility of everything else rests on it. A chain of custody proves that those bytes existed at that instant and have not been touched since. It does not prove the scene in frame was real.
Whoever controls the device before sealing can photograph a staged scene — or, in principle, film a screen. The seal will faithfully certify that capture. No cryptography solves this: context, the coherence of the supporting data (position, time, sequence) and the operator's accountability do.
What is gained remains decisive nonetheless: you move from «believe me» to «check it». In an age when any image can be generated, being able to prove the history of yours is the one defence that does not age.
Continue with how to prove a photograph has not been edited and the chain of custody.