A detector score is not an authenticity conclusion. Images, audio and video can be generated, edited, recompressed, stripped of metadata or presented with a false story. Examination works best when it combines the original file, provenance records, technical characteristics and independent context.
Get as close to the source as possible
Ask for the original file and the device, account or system that created or received it. A copy downloaded from a social platform may have new encoding, dimensions, timestamps and metadata. That copy can still be examined, but its history is shorter and the conclusion must reflect the loss.
Document who provided each item, how it was transferred and whether any application processed it. Preserve the supplied file before creating working copies. Record cryptographic hashes so later analysis can be tied to the same bytes.
Test several evidence layers
- Container and metadata: file structure, codec, timestamps, device fields, edit history and inconsistencies.
- Signal characteristics: compression, noise, lighting, motion, acoustic environment, spectral patterns and discontinuities.
- Content continuity: geometry, reflections, shadows, lip synchronization, object interaction and temporal coherence.
- Provenance: signed assertions about origin and edits, including Content Credentials where present.
- External context: other recordings, device records, location information, witness accounts and known event timing.
No single layer decides every case. Metadata can be missing or altered. Recompression can obscure signal clues. A real recording can be paired with a false caption. A synthetic element can be inserted into otherwise genuine footage.
Understand what provenance can prove
The Coalition for Content Provenance and Authenticity publishes the C2PA technical specification for cryptographically bound content credentials. When present and valid, a credential can help establish that certain assertions are associated with a file and have not been altered outside the stated history.
That is valuable, but it is not a truth verdict. A credential depends on the signer, capture process and trust model. Content without a credential is not automatically false, and signed content can still be misleading in context. Report the trust chain, the assertions and the verification result separately from the broader authenticity opinion.
Treat AI detection as one test, not the answer
Detection systems can fail when media is cropped, transcoded, filtered or produced by a model outside the detector’s training. False positives also matter. A responsible examination records the detector version, settings, input preparation and score, then looks for corroboration through other methods.
NIST’s 2025 evaluation of systems intended to detect AI-generated deepfakes found meaningful limits across analytic approaches. Its Guardians of Forensic Evidence report is a useful reminder that tool performance must be measured against representative material and realistic transformations.
Write a conclusion with boundaries
State exactly what was examined. Distinguish “no evidence of editing was identified” from “the file is authentic.” Explain whether the available copy was original, whether provenance was present, which tests were performed and what could not be tested.
- Identify the proposition that needs support or challenge.
- Preserve the best available source and its transfer history.
- Examine independent technical layers.
- Validate important tool results and record tool versions.
- Compare the media with external evidence.
- Report confidence, alternatives and limitations in direct language.
Evidence limit: Media-authentication conclusions depend on the item supplied and the question asked. A low-quality derivative may support a narrower opinion than an original file with a documented capture history.