cd /news/ai-safety/at-last-apple-joins-the-war-against-… · home topics ai-safety article
[ARTICLE · art-125671] src=fastcompany.com ↗ pub= topic=ai-safety verified=true sentiment=↑ positive

At last, Apple joins the war against fake AI images

Apple has introduced Apple Reference Image, a sensor-level cryptographic signing feature debuting on the iPhone 18 Pro that signs every pixel the camera captures and stores an "unalterable reference image" alongside the editable photo, according to Apple. The feature, switched off by default and revealed through analyses of iOS 27 beta code, performs signing inside the Secure Enclave and verifies images via Apple's Private Cloud Compute, which can retroactively revoke authentications from sensors flagged as compromised. Apple's implementation follows an ETH Zurich laboratory prototype sensor chip built in March that embeds hashing and signing circuitry in the same silicon as the pixels; ETH Zurich researcher Fernando Cardes said forging such data would require a physical attack costly enough that "the mass generation of manipulated content for social media platforms would be practically impossible.

by read6 min views1 publishedSep 10, 2026

Reality is crumbling at the hands of generative AI users, to the point where most people don’t trust what they see online anymore.

Apple has come up with a technology to fix that: Apple Reference Image. It comes with the new iPhone 18 Pro models, and when enabled, it lets the camera’s new sensor cryptographically sign “every pixel it sees” when you take a photo, according to Apple.

When you shoot in the new Reference mode, the iPhone’s camera sensor cryptographically signs each pixel in the image—something no other phone or camera on the market does. Apple’s secure servers then develop that signed sensor data into what the company calls an “unalterable reference image” that lives next to your editable picture, “like a digital negative,” in the company’s words.

It can create the necessary pressure for the entire industry to protect reality at the hardware level rather than guessing at fakes with unreliable AI detectors. And that could be the key to reclaiming our trust in images on a global scale.

Back in March, researchers at ETH Zurich built a working prototype of a sensor chip that does the same and then some, stamping a similar cryptographic signature the instant data is captured. The design places the hashing and signing circuitry inside the same piece of silicon as the pixels themselves, so the data carries its signature from the moment it comes into existence—there is no gap in which it can be tampered with. That is the same property Apple now claims for its new sensor.

“If data is signed the moment it is captured, any later manipulation leaves traces,” explained ETH Zurich researcher Fernando Cardes, when the invention was introduced. He noted that forging it would require a physical attack on the chip so costly that “the mass generation of manipulated content for social media platforms would be practically impossible.”

ETH Zurich’s chip remains a laboratory prototype (a patent application has been filed, but it is not yet commercialized). Meanwhile, Apple’s is the first real-world commercial implementation of sensor-level security at this scale, from a company that sells hundreds of millions of cameras every year.

When you turn Apple Reference Image on—it is switched off by default and requires a trip to the camera settings, sadly—and shoot in Reference mode, the shutter triggers a cryptographic process that signs the raw sensor data together with unique hardware identifiers tied to the actual camera module.

According to analyses of the iOS 27 beta code that revealed the feature, this happens inside the Secure Enclave (the iPhone’s dedicated security chip) before the image leaves the camera pipeline. Nothing else touches it. No app. No external process. It all happens in an instant, and it is, in theory, untouchable.

The check starts when you tap the badge on an image in Photos or a compatible app: The iPhone sends the raw frame, the sensor signatures, the capture timing, and a file hash to Private Cloud Compute over an encrypted channel. PCC is Apple’s secure cloud infrastructure, built on custom Apple silicon, that processes your data and retains nothing once the request is answered. Think of it as a notary.

According to the beta analyses, PCC cross-checks the signatures against its database of valid hardware and can reject the authentication if a sensor or key has been flagged as compromised—even retroactively revoking authentications from tampered sensors. If everything checks out, the device gets an all-clear: Yes, this photo came from that camera, and it has not been altered.

According to iOS beta testers, an authenticated photo can travel by AirDrop or Messages with its proof attached, and the person receiving it can verify it on their own device. There is no need for a new trip to Apple’s servers, and Cupertino never learns which photos are being checked. Apple’s APIs across iOS, iPadOS, and macOS 27 will let other apps—newsroom verification tools, for example—display reference images and see how a photo has been manipulated since capture.

Now compare that to what other phones do. Google’s Pixel 10 signs every single photo its stock camera app produces, using C2PA Content Credentials—an open standard also used by Leica, Sony, and Canon—with signing keys stored in the Titan M2 security chip. But under today’s C2PA implementations, the cryptographic seal is applied by the device’s main processor, after the sensor’s data has already crossed its internal wiring to reach it.

That seal is a hash covering every pixel, so any later edit breaks it—but the gap before the seal exists is exactly the vulnerability the ETH researchers identified. In theory, a capable attacker could tap that path and substitute an AI-generated feed for the real one, and the processor, with no way to tell the difference, would end up certifying a fabrication as genuine. Apple is betting on sensor-level proof rather than file-level proof.

Unfortunately, Apple has not built this on an open standard. The company’s C2PA support covers AI-generated and AI-edited images, not this capture proof. (We have sent Apple a note asking about it, and we will report back with any info we receive.)

In ETH’s design, each sensor’s public key would live in a public, append-only register—ETH floats a blockchain as one option—allowing independent verification by anyone, without having to trust any single company.

In such a model, “it is barely of any relevance whether a person or the technology involved in data processing and transmission is trustworthy,” said Felix Franke, another ETH Zurich researcher who worked on the project.

Apple’s version routes verification through its own servers. The proof is strong, but Apple is the notary, and the notary sits behind a closed gate in Cupertino. Should we depend on a private company to certify what’s real and what’s not?

Both visions, though, share one big hairy “but”: These signatures will matter only if everyone on the internet can read them. Social networks, messaging apps, browsers, and every photo and video player must surface the badge that tells you, in effect, This is real. Perhaps a small lock icon—the same visual shorthand a browser uses to vouch for a secure connection to your bank—marking a recording as one that a real camera captured and that nothing has altered.

Sure, newsrooms will now be able to certify that an image shot in Reference mode by some random person in some random war is real and not AI-generated. That’s one step. But we need to wall off the fakes behind a huge barbed-wire-and-titanium barrier of certified imagery. Unless that happens, nothing changes, and every image will stay under permanent suspicion.

Let’s hope that Apple’s new technology, backed by the company’s market gravitas, is just the first step toward repairing our shared reality once and for all.

── more in #ai-safety 4 stories · sorted by recency
── more on @apple 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/at-last-apple-joins-…] indexed:0 read:6min 2026-09-10 ·