That Damning Video of Your Coworker? Don't Believe It Until 3 Things Happen.
Two students at a Pennsylvania high school allegedly used AI tools to generate hundreds of sexually explicit fake images of their female classmates. School officials reportedly knew about it for months before law enforcement got involved. And when the lawsuits landed, the school wasn't just on the hook for what the students did — it was on the hook for what administrators failed to do after they found out.
That's the part nobody talks about. Not the deepfake. The silence that followed it.
A suspicious image or video is not evidence until someone checks where it came from, whether the surrounding facts support it, and whether every step was written down — in that order, before anyone gets fired or expelled.
We are entering a moment where fake images of real people can appear anywhere — work Slack channels, school group chats, HR inboxes — and look genuinely convincing. Most organizations have no plan for what to do in the next ten minutes after that happens. And that gap, it turns out, is its own kind of liability.
A Shocking Image Is Not Evidence. Yet.
Here's the thing about outrage: it moves fast. Evidence moves slow. And in the age of AI-generated media, the distance between those two speeds is where careers get destroyed.
When a damaging photo or video surfaces at work — one that appears to show an employee doing something terrible — the human instinct is to treat it as proof. It looks real. It feels real. Shouldn't that be enough?
No. And here's why.
According to The National Law Review, responsible investigators are now expected to run three gates before any image becomes the basis for a personnel decision: source verification, contextual corroboration, and documented chain of custody. Skip any one of those, and you don't just risk firing the wrong person — you risk the organization becoming legally responsible for the outcome either way.
That's a genuinely new situation. And most workplaces aren't ready for it. This article is part of a series — start with Identity Verification App Signup Face Scan What You Should K.
Gate One: Where Did This Thing Actually Come From?
The first question isn't "does this look real?" It's "can we trace exactly how this file got here?"
Every digital image carries invisible luggage — metadata (think of it as the image's travel diary: when it was created, what device made it, whether it's been edited, and sometimes even where the camera was standing). Forensic analysts read that diary to spot inconsistencies. A photo that claims to be from a Tuesday but whose file properties say Saturday is already suspicious. A video that shows no compression history — meaning it appears to have sprung into existence fully formed — is a serious red flag.
But here's the twist that makes this genuinely hard: the people who create deepfakes know this. They strip or falsify that metadata on purpose. So according to forensic researchers cited in Legal Desire, the absence of metadata isn't proof of a deepfake — but it IS proof that the chain of custody is broken. You can't verify the origin. Which means you don't have evidence. You have a file.
This is why forensic teams always want the highest-quality version of a file available — ideally straight from the device that recorded it, not a screenshot of a screenshot that was downloaded from a group chat, emailed to HR, and then re-uploaded to an investigation folder. Every time a file moves through someone's hands without being logged, and every time it gets re-compressed (squeezed smaller to send faster), forensic signals get erased. Permanently. You can't get them back.
"Control over evidence begins immediately a file is received, not subsequently." — Article's Ledge, on chain-of-custody requirements in deepfake investigations
Translation: the moment a suspicious image enters the building, stop passing it around. Log it. Preserve it. Assign someone to own it. The clock starts the second it arrives — not after you've decided it's real.
Gate Two: Does the Rest of the Story Hold Up?
Source verification tells you about the file. Context verification asks: does the file make sense alongside everything else you know?
Was the employee supposedly in that location on that date? Do their access logs, calendar, or travel records support it? Does anyone else corroborate the situation — or does the image appear, fully formed, with no other witnesses and no surrounding facts that fit?
This is where investigators start cross-referencing, the same way a good detective doesn't just look at one clue. A real incident leaves traces in multiple places. A fabricated one often doesn't.
None of this means the image is automatically fake if context is thin. Sometimes real incidents lack witnesses. But thin context is a reason to slow down — not speed up. Previously in this series: That App Wants Your Whole Id It Only Needs One Fact.
That number deserves a moment. A detector with 95% accuracy — which sounds excellent — still produces roughly five bad calls per hundred images. In a workplace investigation, one of those five bad calls could mean firing a person who did absolutely nothing wrong, based entirely on an AI's confidence score. That's not a rounding error. That's a lawsuit.
The Misconception That Gets Organizations in Trouble
Here's what most people assume: if a detection tool says the image is fake — or real — that settles it.
It doesn't. Not even close.
It's an easy mistake to make, honestly. These tools sound authoritative. "92% confidence: synthetic." That feels like a verdict. But according to forensic standards cited by Honeybadger Solutions, a detector output is the beginning of an investigation, not the end of one. Courts require authentication under rules like Federal Rules of Evidence 901 — which basically means a human expert has to stand up and explain, step by step, why a piece of media is what someone claims it is. No algorithm testifies. No confidence score speaks for itself in front of a judge.
Think of it this way. Imagine a fingerprint is found at a crime scene. The fingerprint is real. But if nobody documented who collected it, when, how it was stored, and who had access to it between then and now — that fingerprint is worthless in court. Not because the fingerprint is fake, but because the chain of custody (the documented record of every hand the evidence passed through) is broken.
With deepfakes, the "fingerprint" is the metadata, the compression history, and the subtle pixel artifacts that AI-generated faces leave behind. Every time the image gets forwarded in Slack, downloaded twice, and re-uploaded to a shared drive, another smudge gets wiped off that fingerprint. By the time legal gets involved, the evidence that could have proven authenticity — or fakery — is gone.
Detection tools are valuable. They're just not sufficient on their own. The research published through ArXiv on multi-modal deepfake forensics makes clear that even the best detection systems — trained across image, video, and temporal signals simultaneously — are meant to flag candidates for further investigation, not deliver final verdicts.
What You Just Learned
- 🧠 Metadata is the image's travel diary — and when it's missing or falsified, the evidence trail is already broken before you start
- 🔬 Re-sharing destroys forensic signals — every time a suspect image moves through a chat or email without being logged, permanent evidence is erased
- ⚖️ AI confidence scores are not verdicts — they're the first step in a documented process, not a substitute for one
- 📋 Inaction after receiving a report is also a liability — the Lancaster case showed that knowing and doing nothing is legally dangerous for institutions
Gate Three: Who Decided What, and When?
Documentation is the gate most organizations forget entirely — until a lawyer asks for it. Up next: That New App Wants Your Face Before Youve Even Used It.
Every decision made during an investigation involving suspicious media needs to be written down as it happens. Who first received the image? Who reviewed it? What tool was used to analyze it, and what did that tool actually say — not the paraphrase, the actual output? Who made the call to escalate? Who authorized the personnel action?
This isn't bureaucratic busywork. It's the difference between an organization that can defend its process and one that cannot. Courts don't just ask whether the right decision was made — they ask whether the decision was made the right way, with appropriate diligence, at every step.
The Lancaster Country Day School case is instructive precisely because the failure wasn't just about what happened — it was about the gap between when officials learned about the situation and when anything was done. That gap, undocumented and unaddressed, became evidence of institutional negligence. Being horrified by a deepfake is not a response. A documented, deliberate, time-stamped response is a response.
At CaraComp, this principle maps directly onto how we think about facial recognition evidence: a match result is the start of a verification process, not the end of one. Whether the question is "is this face the same person?" or "is this video even real?", the methodology for answering it — and the documentation of every step — matters as much as the answer itself.
A shocking image at work is not evidence until three things are documented: where it came from, whether the surrounding facts support it, and who touched it and when. Skipping that process doesn't save time — it creates liability in both directions, whether the image is real or fake.
So here's the question worth sitting with: if a damaging video of a coworker showed up in your company chat tomorrow, who in your organization would be allowed to decide whether it's "real enough" to act on? Is there a written answer to that question anywhere?
If the answer is "whoever sees it first" — that's the policy gap that ends careers and starts lawsuits. The organizations that will handle this well aren't the ones with the best detection tools. They're the ones that decided, before anything happened, exactly who asks the questions, in what order, with what documentation.
A shocking image is not evidence yet. Three questions make it one — or prove it never was.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
That "Urgent" Video From Your Boss? Watch the Mouth, Not the Face
A deepfake detector isn't asking "does this look real?" — it's running two separate checks on your face and your voice, then seeing if they agree. Here's why that timing gap is the real tell.
digital-forensicsThat Urgent Video From Your Boss? Your Eyes Can't Tell It's Fake Anymore.
Deepfake detection has outgrown "spot the glitch." Learn how the real defense works in three layers — and why your eyes are the last thing you should trust.
digital-forensicsThat "Too Perfect" Video? 4 Hidden Clues It's Fake
A deepfake detector doesn't just ask "real or fake" — it weighs four independent clues: eye blinks, lip timing, pixel artifacts, and frame drift. Learn why multiple clues beat any single perfect signal, and why a video that looks flawless should actually make you more suspicious, not less.
