The Future of Trust Isn’t Detecting Deepfakes. It’s Proving Authenticity

You can audit the threat landscape in your own organization and ask whether any of your incident response playbooks assume that video evidence is reliable.
One important milestone came in 2024, when Microsoft Research Asia published its VASA-1 paper, which demonstrated how a single image and an audio track could be used to generate lifelike talking faces. The significance of that research was not limited to one model. It illustrated how little source material could be required to create footage that appears authentic.
Web representations of digitally signed content close the loop for public-facing distribution. Technology such as Open Badges enables web content, including video, to display a visible indicator that it has been signed by an accountable, identified human being. This is not a watermark that can be copied. The badge is cryptographically bound to the signature. Stripping or spoofing it breaks the verification chain.
What the situation calls for, in this view, is not only better detection after the fact, but a provenance framework applied before distribution. That means returning to the cryptographic infrastructure that, as Kussmaul notes, has been available for decades.
What has been absent is coordinated deployment across the organizations, media companies, social platforms, legal institutions, and identity providers that would need to recognize and honor the framework together. A signed video is only useful if the systems people use to view and share it can interpret and display the signature status.
AI-generated video has advanced from an interesting research problem to a practical trust challenge. Systems can now produce increasingly convincing footage of real people appearing to say things they never said. Not a rough approximation. Not necessarily a forgery that flickers at the edges. In many cases, the output can pass the baseline threshold of believability for ordinary viewers.

The Problem With Waiting for Better Detection

The technology exists. That point is worth holding. The cryptographic primitives are mature. PKI infrastructure has been deployed in financial and government contexts for years. NIST’s identity assurance framework has been published for years. None of the five components above requires a research breakthrough.
Measurable reliability of identity claims addresses how rigorously an identity has been verified. NIST has published identity assurance guidance addressing these questions. It involves vetting evidence of identity, what practitioners call EOI, through a labor-intensive process. That process includes demonstrating to an attestation officer that you can authenticate to an online bank account, corroborating employee credentials, and producing other account-level evidence. The resulting reliability score is graduated rather than a simple pass or fail, which means relying parties can make proportional trust decisions based on the strength of vetting rather than treating all certificate holders as equivalent.
The proposed counter-architecture rests on five components, each addressing a distinct layer of the trust problem.

How Digital Signatures and Professional Licensing Can Defeat Deepfakes

There is a familiar response to deepfake threats: build better detectors. Train classifiers on synthetic artifacts. Flag anomalies in facial geometry. This response treats the problem as a signal-detection challenge, which is a reasonable framing until the signals become difficult to distinguish from authentic footage. The more convincing synthetic media becomes, the more it strains the detection arms race, because improvements in generation can outpace improvements in detection.
The same logic applies to video content. A licensed professional, or a sufficiently well-identified private individual, who digitally signs a video and attests that it contains no fabricated elements creates a chain of accountability that a deepfaker cannot replicate without committing fraud under their own verified identity.
Professional licensing is the fourth layer. Kussmaul describes it as a “generally superior alternative to government regulation.” The mechanism works because it distributes accountability across practitioners who have skin in the game. Consider how a building earns its certificate of occupancy: an architect attests to the structural design, an engineer to the load calculations, a contractor to the build quality, and a building inspector to code compliance. Each professional stakes their license and livelihood on that attestation. The building does not become habitable by regulatory decree alone. It becomes habitable because multiple accountable individuals have put their names on it.
This is not a marginal improvement on prior deepfake technology. It reflects a broader shift in which synthetic video is becoming more convincing, more accessible, and more difficult to evaluate through visual inspection alone. An actor with access to a photograph and an audio track may be able to synthesize footage that appears credible enough to influence an ordinary viewer.
PKI digital identity certificates solve the next problem: whose private key is this? For a public key to carry a meaningful identity claim, a trusted authority must digitally sign that claim, producing a certificate. A certificate, in the most direct definition, is an authority’s attestation to a claim. Without this layer, a deepfaker could simply generate their own key pair and sign fraudulent content under it.
True digital signatures are the foundation. These are distinguished from the “electronic signatures” that populate contract-signing platforms. An electronic signature may use cryptographic technology, but carries no requirement that the signature be tied to a verified, specific human being. A fraudster’s signature can validate just as cleanly as a legitimate one. That distinction is not semantic. It is the gap between a security control and security theater.
A true digital signature is produced by a large private number, the private key, that is mathematically bound to a corresponding public key. The private key never leaves the owner’s device. The public key can be shared freely. When a file is signed with the private key, any subsequent alteration to that file, even a change of a single bit, causes the signature to fail. The file announces its own corruption. Applied to video, this means a signed recording cannot be silently modified. Any deepfake substitution would invalidate the signature immediately.
The specific danger here is not aesthetic. It is testimonial. Wes Kussmaul, writing on the problem, frames it plainly: AI-generated video can let someone “mold testimonial reality into whatever you want it to be.” What that means in practice is that video evidence, a format that courts, journalists, security teams, and corporate boards have often treated as authoritative, loses its presumption of authenticity. Every recording becomes a hypothesis rather than a fact.

The Coordination Problem

That gap has narrowed considerably.
For years, the deepfake video problem was easier to warn about than to demonstrate. Journalists wrote the warnings. Legislators drafted policy frameworks. Security researchers ran the simulations. And yet, despite the genuine technical threat, the forgeries themselves often remained unconvincing enough that public alarm failed to catch hold. The faces were wrong, the lip movements stiff, the audio out of sync in ways that trained eyes could catch quickly. That gap between the theoretical danger and the visible evidence kept urgency at bay.
An effort to build that coordination is underway. Whether it achieves the cross-sector adoption that would make signed video a norm rather than an exception is a question the technology alone cannot answer.

Similar Posts