A photograph used to be reasonably good evidence that something had happened. A familiar voice on the phone usually belonged to the person you thought you were speaking to. If someone appeared on camera during a video call, you could at least be fairly confident there was a real person sitting on the other side.

None of those assumptions were perfect. People have been editing photographs, impersonating each other and lying on the internet for as long as the technology has existed. What’s changing is how cheaply, quickly and convincingly those things can now be done.

And it isn’t only the content we see that’s changing. According to Thales’ 2026 Bad Bot Report, bots accounted for 53 per cent of all internet traffic during 2025, compared with 47 per cent generated by humans. AI-enabled bot attacks also increased 12.5 times year on year. The internet is becoming an environment where people, traditional automation and AI agents increasingly operate alongside one another, sometimes in ways that look remarkably similar.

em360tech image

For organisations, this creates a much bigger internet verification problem than simply figuring out whether an image was generated by AI. They increasingly need to know who or what they’re interacting with, where information came from, whether it has been changed and whether the actor behind a request actually has the authority to make it.

For a long time, much of that was inferred from context. Now we’re reaching the point where authenticity increasingly needs evidence.

The Internet Wasn't Built To Prove Everything Is Real

The internet was designed to make it easier for systems and people to connect and exchange information. It has been spectacularly successful at doing exactly that. What it wasn’t designed to do was independently prove the authenticity of everything moving across it.

Instead, we built up a collection of practical shortcuts. We recognise a company domain. We see someone’s photograph beside a profile. A document has the right logo. A video looks professionally produced. The voice sounds right. Several pieces of information line up with what we already know.

None of these things necessarily proves anything by itself, but for most everyday interactions they’ve historically been good enough. Generative AI changes the economics behind that arrangement. A convincing fake photograph no longer requires somebody with strong editing skills and several hours to spare. 

Synthetic audio, video, documents, websites and identities can all be produced faster, then reproduced or modified at scale. The problem isn’t that AI somehow made the internet untrustworthy overnight. It has made the gap between something looking authentic and being independently verifiable much easier to exploit.

That gap becomes harder to ignore once organisations start making real decisions based on what crosses it.

AI Is Changing What Organisations Need To Verify

Entrust’s 2026 Identity Fraud Report analysed more than one billion identity verification attempts across 195 countries and over 30 industries. It found that deepfakes now account for around one in five biometric fraud attempts, while deepfaked selfie attempts increased 58 per cent during 2025. 

Injection attacks, where manipulated media is fed directly into a verification system rather than captured normally, rose 40 per cent. That gives us one version of the problem: can you prove that the person presenting an identity is really that person? But digital verification now has several layers:

  • There’s the content itself. Did this photograph, document, recording or message actually come from the claimed source, and has anything happened to it since?
  • Then there’s identity. Is the person, business or organisation what it claims to be?
  • There’s also the interaction. Are you communicating with a person, a traditional bot or an AI agent acting on someone’s behalf?
  • And finally, there’s authority. Even if you know exactly who or what you’re dealing with, is it actually allowed to make this request or take this action?

A July 2026 warning from the FBI’s Internet Crime Complaint Center shows how these problems can combine. Scammers impersonating the IC3 created fake social media personas, spoofed government websites and AI-generated videos showing FBI personnel. One fake website even issued reference numbers after victims submitted information, making the process look more convincing.

Any one clue might have raised suspicion. Put them together and you get something much more persuasive because every fake element appears to confirm the others. Which is why becoming better at spotting individual fakes will only take organisations so far.

Verification Is Moving From Detection To Provenance

For years, much of the response to synthetic media has centred on detection. Find the visual glitch. Identify the strange movement. Analyse whether a voice sounds artificial. Build an AI detector sophisticated enough to recognise what another AI has produced. There’s still value in that. But it creates an uncomfortable race between generation and detection, where both technologies keep getting better.

A different approach starts by asking what we can positively establish about where something came from. Content provenance is evidence about the origin and history of digital content, including information about how it was created and what happened to it afterwards. 

The Coalition for Content Provenance and Authenticity (C2PA) has been developing an open standard called Content Credentials that allows this information to be recorded in tamper-evident, cryptographically signed records associated with an asset. Its latest Version 2.4 specification was published in April 2026, followed by new implementation guidance in July.

Google is already pushing this idea into products ordinary internet users interact with every day. In May 2026, it said SynthID had watermarked more than 100 billion AI-generated images and videos and 60,000 years of audio. It also began expanding SynthID and C2PA verification across Search, Gemini and Chrome.

Identity systems are moving in a similar direction. The latest NIST Digital Identity Guidelines explicitly address digital injection and forged media attacks. They require remote identity proofing systems to analyse submitted media for possible manipulation and include controls designed to increase confidence that images and video came from genuine capture devices rather than virtual cameras or other manipulated sources.

Regulation is following. The transparency requirements in Article 50 of the EU AI Act became applicable on 2 August 2026, covering the marking and detection of AI-generated content along with disclosure requirements for deepfakes and certain AI-generated publications.

Different parts of the digital ecosystem are effectively solving variations of the same problem: how do you give people and systems better evidence about what they’re dealing with?

There is an important limit, though. Content Credentials can help prove where something came from or whether its recorded history has been tampered with. C2PA is explicit that this doesn’t prove the content itself is truthful. A genuine photograph can still be misleading. A verified person can still lie.

Which means verification only becomes useful when you’re clear about exactly what you’re trying to prove.

Verification Doesn't Mean The Same Thing Everywhere

There’s an obvious response to a growing verification problem: verify more. Unfortunately, applied without context, that could turn every digital interaction into the online equivalent of airport security. Not every interaction needs the same level of assurance. 

Reading a public document carries very different consequences from approving a payment, onboarding a customer or giving an AI agent access to production systems. And no single control answers every question anyway. 

  • Digital identity verification can give you confidence that someone is who they claim to be. It doesn’t prove their intentions.
  • Content provenance can provide evidence of origin and modification history. It doesn’t prove factual accuracy.
  • Authentication can confirm that somebody has the required credentials. It doesn’t automatically mean every action performed afterwards is appropriate.
  • Even human review has limits when the evidence being reviewed can itself be convincingly manufactured.

A more useful approach is therefore to match the strength of verification to the consequence of getting the decision wrong. NIST uses a similar risk principle for digital identity, requiring organisations to select assurance levels based on the potential impact of failures rather than applying identical controls everywhere.

For enterprises, that turns verification from a blanket security measure into a design decision.

Build A Chain Of Evidence, Not A Single Trust Signal

If one piece of evidence can only answer one part of the problem, important decisions may need several pieces working together. That doesn’t mean adding another authentication prompt every time someone clicks something. It means being clearer about the questions the organisation needs answered before a consequential action goes ahead.

What is it?

Start with the actor or information itself. Is this a human user, an organisation, a machine identity, an automated bot, an AI agent or a piece of digital content? As agentic systems become more common, assuming that something human-looking necessarily has a human behind it will become less useful.

Thales already describes AI agents as a third category that complicates the old distinction between good and bad bots because legitimate and malicious automation can perform many of the same actions.

Where did it come from?

Next comes origin. 

Are you enjoying the content so far?
  • What created the information? 
  • Is its source known? 
  • Does trustworthy digital provenance exist? 
  • Has it moved through other platforms or tools, and is there evidence that it has been altered along the way?

The stronger the consequence of accepting that information, the less comfortable organisations should be with origin being an assumption.

What is it allowed to do?

Knowing what something is still doesn’t tell you what it’s entitled to do. A verified employee may be authorised to access one system but not approve a particular transaction. An AI agent may legitimately act for a user without having unlimited authority on their behalf.

This separation between identity and authorisation becomes increasingly important as automated actors begin doing more than retrieving information.

What happens if we're wrong?

This is where the other questions come together. If accepting the wrong content would have almost no consequence, heavy verification creates unnecessary friction. If getting it wrong could move money, expose sensitive information, trigger an operational change or create regulatory consequences, the evidence threshold should rise accordingly.

The goal isn't perfect certainty. It’s enough confidence for the decision being made.

Verification Is Becoming An Operational Capability

Once you look at verification this way, it stops fitting neatly inside one security function. Customer onboarding teams already care about identity. Fraud teams care about whether transactions make sense. Communications teams increasingly need to think about content authenticity

AI governance teams need to understand what autonomous systems can act on and who has authorised them. Security teams need reliable evidence across all of those interactions. If each function develops its own answers independently, organisations can end up demanding strong proof in one workflow while another equally consequential process still relies on assumptions nobody has revisited for years.

A useful starting point is to identify where important business decisions depend on identity, origin or authority being correct. Then ask what evidence those workflows currently use, what each piece actually proves and what would happen if it turned out to be wrong. That turns enterprise verification into something designed around business consequence rather than suspicious activity alone. 

And the need for that capability is likely to grow. INTERPOL’s 2026 Global Financial Fraud Threat Assessment says AI-enhanced financial fraud is estimated to be 4.5 times more profitable than non-AI-enhanced tactics, partly because AI lets criminals target more people while making individual interactions more convincing.

As the economics of deception improve, the economics of verification have to change with them.

Final Thoughts: Trust Increasingly Needs Evidence

The internet hasn’t suddenly stopped being useful or trustworthy because generative AI arrived. What AI has done is make some of the shortcuts we've used to judge online authenticity much less dependable on their own. 

A familiar face can be generated. A voice can be cloned. A convincing identity may belong to nobody. A human-looking interaction may come from an agent. Even several apparently independent clues can be manufactured to support the same fiction.

That doesn’t mean organisations need to prove everything they encounter online beyond all doubt. They need to understand what they actually need to know before allowing an interaction or piece of information to influence a consequential decision, then demand evidence proportionate to that consequence.

For years, much of the internet worked because appearance and context gave us enough confidence to keep moving. As synthetic identities, AI agents and generated media become ordinary parts of that environment, confidence will increasingly have to come from something stronger.

The organisations best prepared for that future probably won't be the ones that become perfect at spotting every fake. They'll be the ones that know what they need to prove before they act.

As identity, AI, security and governance continue converging around that question, EM360Tech will keep following the technologies and operating models reshaping what digital trust looks like when assumption is no longer enough.