AIG-057 Inbound Synthetic Media Detection
Description
A documented assessment names each point at which a system relies on audio, image or video supplied by a user or received from an external source as evidence of a person's identity, of the provenance of an artefact or of a real-world event and names the decision each point feeds. Each named intake point runs a detection step for synthetic or manipulated media before the content is relied on. The detection method for each point is recorded with its measured detection rate and false positive rate against a named evaluation set and the threshold at which content is blocked or referred. Any provenance credential the content carries is verified as part of the step. Content that fails the step is blocked or routed to a human check rather than accepted; the outcome is recorded against the intake event. The evaluation is repeated at defined intervals and after a change to the method. The method is updated from confirmed cases and from the evaluation results.
Rationale
The risk lands where a forged artefact is accepted as fact: a face or voice presented at identity verification, a document or recording submitted as evidence of an event, a piece of media assessed at moderation. The assessment is the first artefact because an organisation cannot say the control does not apply until it has looked at where its systems believe what they are given; an assessment that finds no such point is a complete answer. Three neighbours run the other way. AIG-016 marks the organisation's own generated output and discloses it; this control checks media coming in before it is believed. AIG-031 detects misuse of the service by a user; a forged artefact is not misuse of the service but an attack on the decision behind it. AIG-029 governs content that reaches a model prompt; media at an intake point may never reach a prompt. Detection approaches include classifiers trained to separate real from generated content, checks for artefacts such as inconsistent lighting, audio mismatches or unnatural facial movement, liveness signals such as blinking and micro-expressions and verification of a signed provenance credential where the source supplies one. A measured rate matters more than a named technique, because detectors decay as generators improve, which is why the evaluation is repeated. Provider seat for a product feature, deployer seat where the deployer runs the intake against its own process (ADR-031).
Applicability (9 profiles)
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16). A deployer that runs an identity, claims or evidence intake on a provider's product relies on the provider's detection step and records its rates from the provider's evaluation.
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
Required on the base as well since the S13 benchmark (ADR-049 amendment, 2026-09-16); stated here because a public body's intake points are where a forged artefact produces an adverse decision about a person: identity evidence for a benefit or a permit, media submitted as evidence in a proceeding and, under Annex III point 1, biometric identification. The documented assessment the control opens with is the row's first artefact; a body whose assessment finds no intake point that relies on inbound media as evidence records that finding and the detection limb has nothing to attach to. Both seats: the assessment and the record of each disposition are the deployer's, the detection method and its measured rates come from the provider where the intake runs on a provider's product (AIG-034). The code is core rather than role-duty because no article imposes the detection on the seat; the row is an assurance judgement about where the harm lands.
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
Framework Mappings (4)
| AML.M0034 | Deepfake Detection | full |
| MP-2.3-004 | Scientific Integrity and Testing Considerations | MP-2.3-004 | full |
| MS-1.1-002 | AI Risk Measurement Approach Selection | MS-1.1-002 | partial |
| ASI09 | Human-Agent Trust Exploitation | informative |
Evidence (3)
The intake-point assessment: each point at which a system relies on user-supplied or externally sourced audio, image or video as evidence of identity, provenance or a real-world event, the decision that point feeds, the detection method assigned to it, the threshold at which content is blocked or referred and the review date.
Example: Inbound media intake assessment version 3, reviewed 20 August 2026, covering the onboarding identity check, the claims evidence upload and the moderation queue.
Test: Verify: (1) every feature in the system inventory that accepts media from a user or an external source and relies on it as evidence appears in the assessment, tested by walking the inventory rather than the assessment, (2) each intake point names its detection method and its block or referral threshold, (3) each point names the decision it feeds and who receives a referral, (4) the assessment was reviewed within the interval it states and after each change to a method, (5) where the assessment concludes that no such intake point exists, the conclusion is dated and signed.
The evaluation results for each detection method: the named and versioned evaluation set, the measured detection rate and false positive rate, the threshold in force and the date of the run, with the previous run for comparison.
Example: Deepfake detector evaluation run of 2 September 2026 against evaluation set faces-v7, with the run of 3 June 2026 alongside.
Test: Verify: (1) the evaluation set is named and versioned and contains both generated and genuine samples, (2) the detection rate and the false positive rate are recorded for the threshold in force, (3) the threshold configured in production equals the threshold the evaluation was run at, (4) the run is dated within the interval the assessment states or after the most recent change to the method, (5) a rate that fell below the level the previous run recorded carries a recorded decision on the method.
Intake event log for each named intake point showing, per event, the detection result, the provenance credential check where a credential was present, the disposition (accepted, blocked or referred to a human check) and, for a referral, the human decision.
Example: Identity verification intake log for 1 to 31 August 2026, filtered to events with a detection score above the referral threshold.
Test: Verify: (1) every event at a named intake point carries a detection result, (2) no event whose result exceeded the block threshold was accepted, (3) every referred event carries a human decision, (4) confirmed synthetic cases in the period appear in the record of updates to the detection method, (5) an event carrying a provenance credential shows the verification result.
Questions (3)
Does each point where your systems rely on user-supplied or external audio, image or video as evidence of identity, provenance or a real-world event run a detection step for synthetic or manipulated media before the content is relied on?
Identity verification, onboarding checks, evidence uploads and moderation queues are the usual intake points. A step that runs after the decision has been made, or that only logs a score, is not a detection step in this sense. Where a documented assessment concludes that no system relies on inbound media in this way, answer on that assessment.
Which of the following are in place for inbound media at those points?
Options run from the assessment to the step, from the step to the outcome and from the outcome back to the method. The rates item asks for numbers measured on a set the organisation can name, not a vendor's published figure.
What happens to inbound media that fails the synthetic media detection step?
Options run from the strongest disposition to the weakest. Answer for the behaviour of the system in production at the intake point with the highest-impact decision.