cd /news/ai-safety/stop-detecting-ai-content-start-sign… · home › topics › ai-safety › article
[ARTICLE · art-145838] src=dev.to ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Stop detecting AI content. Start signing it at the source

A developer argues that cryptographically signing AI-generated content at the source is a more tractable problem than trying to detect it after the fact, since watermarks and detectors degrade under paraphrasing, cropping, and re-encoding. The proposed approach hashes the output, signs the hash with a producer-controlled key, and ships a small manifest alongside the file, so any edit breaks the signature and verification is possible with a public key. The author notes standards like C2PA already define richer manifests for media, but warns that key management — rotation and keeping keys out of application code — is the real work.

by read2 min views1 publishedOct 6, 2026

Every few months someone ships a new way to detect AI-generated text or images, and every few months someone else shows how to strip it. Paraphrase the text, crop or re-encode the image, and the hidden signal gets weaker or disappears. Detection is a cat and mouse game, and the mouse only needs to win once.

There is a calmer way to think about this. Instead of asking "can I prove this was made by AI?", ask "can I prove where this came from and that nobody changed it since?" That is provenance, and it is a much easier problem to engineer.

Watermark / detector Signed provenance
Where it lives hidden inside the content a small record next to the content
What it claims "this probably came from model X" "this exact file came from source Y at time T"
Survives edits? degrades with paraphrase, crops, re-encoding any edit breaks the signature, which is the point
Failure mode silent false negatives and false positives missing or invalid signature, clearly visible
Who can check usually only the vendor anyone with the public key

A watermark tries to make the content itself carry the evidence. Provenance keeps the evidence outside the content and makes it cryptographically checkable. When the content changes, you do not get a fuzzy score, you get a clear "this is not the file that was signed".

You do not need a platform to try this. Hash the output, sign the hash with a key the producer controls, and ship a tiny manifest with it.

import hashlib, json, time
from nacl.signing import SigningKey  # pip install pynacl

key = SigningKey.generate()          # keep this secret, publish key.verify_key
content = open("report.txt", "rb").read()

manifest = {
    "sha256": hashlib.sha256(content).hexdigest(),
    "producer": "summarizer-v3",
    "model": "model-name-and-version",
    "created": int(time.time()),
}
payload = json.dumps(manifest, sort_keys=True).encode()
signature = key.sign(payload).signature.hex()

Verification is the reverse: recompute the hash of the file you received, rebuild the manifest bytes, and check the signature with the public key. If one character changed, the hash will not match.

Provenance does not tell you whether content is true, only who vouches for it and whether it changed. Unsigned content stays unknown, so adoption matters. And key management is the real work: a leaked signing key lets anyone sign anything, so rotate keys and keep them out of app code.

Standards like C2PA already define richer manifests for media. But the core habit is simple enough to start today: sign at the source, verify at the edge, and treat "unsigned" as a fact rather than an accusation.

Would you rather verify where content came from, or keep trying to detect what made it? I am curious which one people think scales.

I wrote a longer, free paper on verifiable claims for public and AI systems, if you want the deeper version: Proof, not promises.

── more in #ai-safety 4 stories · sorted by recency
── more on @c2pa 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/stop-detecting-ai-co…] indexed:0 read:2min 2026-10-06 · —