DAI Methodology v1.4
Date: 2026-07-20 Status: Consolidated master methodology Audience: external technical reviewers, forensic researchers, and serious journalists Scope: image authenticity investigations in a current DAI implementation
0. Core Principle
Confidence is earned through the systematic reduction of relevant uncertainty.
DAI is not AI detection. It is not a real/fake classifier. It is an evidence interpretation discipline for digital media. A DAI system collects structured evidence from multiple provider families, evaluates that evidence through rules, and reports what the evidence most strongly supports.
The output is claim-relative. DAI does not certify truth, guarantee authenticity, prove all media origin, detect all fakes, or treat missing credentials as proof of falsity. It also does not treat a credential, publication page, or reverse-search match as proof that the surrounding caption, article, or claim is true.
Every assessment must preserve the difference between what was measured, what was inferred, and what remains unresolved. When a DAI system can make a supported finding, it states the finding and its public confidence as High, Moderate, or Low. When a DAI system cannot responsibly assess a proposition, it does not invent a confidence level. It reports a status such as Not established, Not determined, Insufficient evidence, or Unresolved.
The discipline is deliberately bounded. A low AI-generation score weakens an AI-generation explanation; it does not establish real-world capture. Camera metadata can support real-world capture; it does not by itself prove that the published claim is true. Online copies can document circulation or publication; they do not establish original release, capture origin, or independent corroboration.
The case record functions as jurisprudence. The 49ers AI image, Case 002 recycled protest photo, Case 003 fabricated image, the NYT Carroll photo, The Onion satire case, and the McConnell proof-of-life case each forged rules below because each exposed a failure mode that generic authenticity language would miss.
1. Evidence Collection
A DAI system collects evidence from provider families. Each family is a distinct class of observation, but provider output is not accepted as a verdict. Provider evidence becomes useful only after it is characterized, bounded, deduplicated, and compared against the claim under investigation.
The current image evidence families are:
- Metadata forensics: embedded metadata such as EXIF/XMP when present, including WebP EXIF extraction through RIFF chunk parsing. Absence of readable metadata is reported as absence of readable metadata, not as evidence of falsity.
- Reverse image search: exact and related matches, candidate source pages, candidate image URLs, and Known History evidence. Exact copies and verified source pages are treated differently.
- Reference comparison: structural comparison between the submitted specimen and retrieved copies when copies are available.
- AI and manipulation detection: current synthetic-generation and face/deepfake classifier signals. Same-vendor signals count once for corroboration.
- Pixel and file forensics: ELA, noise analysis, processing indicators, and localized compression anomaly detection. Lossless formats and platform-recompressed derivatives are interpreted with format- and degradation-aware limits.
- C2PA presence detection: current capability detects embedded C2PA/JUMBF manifest presence only, and labels it unverified.
The instance-set investigation model changes the unit of investigation from the uploaded file to the instance set. The submitted file remains important because it is the claim-bearing instance: the specimen the user was shown or asked about. But it is only one instance of the asset. Discovered instances may include exact-match images found through reverse search, direct image copies, or verified source-page copies.
For each instance that a DAI system can acquire, the Instance Map records the role, source URL or domain when available, retrieval status, storage record, SHA-256 hash when fetched, dimensions, format, file size, and metadata presence. Candidate hashes remain unknown until retrieval succeeds; failed acquisition is recorded rather than hidden. The purpose is custody and comparability, not a claim that the copy is original.
Claim-bearing and discovered instances must not be collapsed. A submitted screenshot, a CDN WebP derivative, and a publisher JPEG can all depict the same visual asset while carrying different forensic value. A DAI system therefore records which specimen supports each finding. The Instance Map exists to prevent report language from confusing "this was uploaded" with "this was found online" or "this was measured."
Cross-instance comparison is a first-class evidence operation. It can produce framing divergence, content divergence, and overlay divergence. Framing divergence means that one instance contains regions cropped from another; Case 002 used this pattern when a wider protest image exposed the claim-defeating "SHERIFF" context. Content divergence means localized structural difference inside the overlapping region above re-encoding noise; Case 003 used this rule when details such as epaulettes and belts varied between purported renditions of the same moment. Overlay divergence means added text, watermarks, or stamps; those are lineage evidence and must not be confused with content fabrication by themselves.
2. Forensics on Best Evidence
The submitted file is often the worst specimen. Platform recompression, screenshots, CDN resizing, social reposts, and local re-encoding can launder the signals that forensic tools need. A null result on a degraded derivative can be an expected consequence of degradation rather than evidence against manipulation or generation.
Version 1.3 therefore adopts a best-evidence rule: a DAI system analyzes the strongest stored copy available for the relevant measurement and always names the specimen measured. The strongest copy is not called original. It is the least-degraded retained specimen according to available information such as effective pixel area, retained byte density, format, and URL-native-size hints that reveal enlarged derivatives.
The McConnell proof-of-life case forged this rule. The submitted file was a 713 x 660 WebP derivative of about 220 KB. A richer 3000 x 2777 JPEG from CNN's image CDN was already stored. Running AI and face-manipulation analysis on the small submitted derivative while leaving the CNN JPEG unanalyzed created a false impression of evidentiary completeness. The corrected report named the 3000 x 2777 analyzed specimen and reported 0.1% AI-generation and 1% face-manipulation scores in bounded language.
Best-evidence analysis does not make detection conclusive. In McConnell, low generation and face-manipulation scores weakened the AI and identity-level face-modification explanations. They did not establish capture origin, scene authenticity, the truth of the surrounding proof-of-life claim, or absence of subtle retouching or alterations outside the measured face signal.
Submitted-file and matched-copy measurements of the same signal are deduplicated. If a richer matched copy supplies a valid measurement, stale or lower-quality submitted-file findings must not appear to contradict it or inflate the evidence count. The most informative valid measurement governs, and the report displays the measured specimen.
This rule is currently implemented for the AI-generation and face-manipulation best-copy path. The methodology requires the same specimen-labeling discipline for every provider family as best-evidence routing expands.
2.1 Coverage and Validation
Coverage is not "the control ran." Adequate coverage means the required controls ran on suitable specimens, passed their quality gates, and produced interpretable results for the proposition being evaluated. A detector that completes on a degraded file and returns nothing diagnostic has not covered that vector. Every assessment therefore declares what was examined, at what quality, and what could not be examined.
A coverage limitation is never a finding. "No readable metadata" describes what could not be examined; it is not evidence of editing, and must never be presented alongside findings as if it were suspicion.
Validation is a precondition, not a formality. Bounded language does not substitute for empirical performance. No DAI deployment may be presented as reliable for a decision context without internal measurement of sensitivity, false negatives, false alarms, per-subgroup performance, and drift — measured per use-case profile and reviewed on a defined cycle. A discipline that reports "reasons to escalate" without measuring how often it misses them is making a promise, not a measurement.
3. Dating and Backtracing
DAI uses dates as bounds. The public phrase is "circulating since at least [date]" or "earliest documented occurrence: [date]." The date is never an origin claim, creation date, capture date, or first-publication claim.
Backtracing attempts to date each instance with a method and reliability class. Reliable dating can resolve claim context even when other evidence is limited. Case 002 was resolved by a prior occurrence: the image was already online years before the current claim. Case 003 showed the opposite kind of temporal evidence: after wide circulation, a DAI system did not find a pre-claim instance, which weakened specific origin narratives without proving the asset's true origin.
Date display is UTC date-only for public reporting. This avoids shifting a publisher URL-path date such as July 12 to July 11 for readers in western time zones. The McConnell report made this rule concrete: URL-path and Known History dates had to remain July 12 in the public report.
The current dating methods are:
- Platform ID decode: high reliability when the platform ID encodes a timestamp and the decode method is known.
- Wayback first capture: high reliability for "documented by archive no later than this capture."
- Page-declared date: medium reliability when a page presents an article, post, or publication date.
- Publisher URL-path date: medium reliability when an independently discovered copy or page URL contains a date path such as
/YYYY/MM/DD/.
URL-path dating is applied to independently discovered copies, not to the submitted file. A submitted filename or URL context supplied by the user does not become Known History evidence.
Recirculation requires a meaningful temporal gap. The REC-1 framing "Circulating since [date] - predates the current claim" requires the earliest documented occurrence to predate the claim reference date by at least 14 days. A current-event image published one or two days before investigation is not recycled media merely because it appeared elsewhere first.
4. Known History and Distribution Analysis
Known History documents what a DAI system found about circulation and publication. It does not answer authenticity by itself.
A DAI system distinguishes exact copies, verified source pages, related pages, page-less exact image copies, and unstable or login-dependent results. Page-only or category results are related pages, not confirmed prior appearances. Facebook group-post URLs are not displayed as verified exact-match source pages when they are volatile, login-dependent, or no longer show the searched image, even if reverse search reports an exact image match.
Verified exact source pages can support a publication-history finding. The NYT Carroll photo forged the PUB-1 scenario: exact matches tied to verified source pages should not collapse to "source and authenticity could not be established" merely because capture origin remains unresolved or an AI detector is unavailable. The bounded headline is "Published copy documented online." It does not confirm camera capture, rule out AI generation or alteration, prove article context, or establish capture origin.
For contemporary clusters, broad republication is not independent corroboration. The McConnell case showed that many copies can trace to one release window. DAI therefore uses a Single-Release Distribution Pattern: when at least two dated exact copies fall within 72 hours and no earlier occurrence is found, Known History may state that all N dated copies trace to one publication window. Republication by multiple outlets does not establish independent corroboration or capture origin.
When at least two exact copies exist, no exact-match source page is verified, at least two discovered copies carry dates, and the earliest and latest dated copies are no more than 72 hours apart, a DAI system may report a clustered release-window finding. Undated copies are never assigned to the window. The finding does not claim an original source, official source, common ownership, independence among publishers, or authenticity.
Durable Known History matters because search results can fluctuate. If a DAI system already fetched and stored safe discovered instances tied to verified exact source pages, a later reverse-search run that omits those pages should not erase that evidence, so long as the current run still finds exact copies. Current provider results remain first; persisted verified pages fill gaps and are deduplicated.
Hard bound: DAI never claims an original, official, or first source, and never identifies or speculates about the releasing party or its interests. It can say what publication or republication evidence documents. It cannot turn distribution into motive, authorship, or capture origin.
5. Verdict Construction
DAI constructs verdicts from scenarios, not free-form impressions. The controlled nomenclature appears in Appendix A. Scenario families include RWC, SYN, ALT, UNV, QAI, REC, PUB, PRC, FRM, and CON. Scenario selection is claim-relative and bounded by the available evidence.
The corroboration gate protects consequential findings. Public High confidence for AI-generated media or digital manipulation requires at least two independent evidence families. A single vendor classifier, even a strong one, may support a finding but is capped at Moderate unless independently corroborated. Same-vendor signals count once. Absence signals such as no EXIF or no reverse-search match do not corroborate generation or manipulation. Smooth regions and generic processing/compression artifacts do not become manipulation evidence by themselves.
The 49ers AI image calibrated the edge case. A 99% synthetic classifier score can support the direct headline "AI-generated media," but without an independent family such as an AI tool signature or content declaration, public confidence remains Moderate. Lower strong uncorroborated scores use "Possible AI-generated media."
Material modification follows the same discipline. Processing/export/compression artifacts are not the same as digital manipulation. Possible digital manipulation is not the same as confirmed alteration. Localized compression anomaly can support possible manipulation when calibrated conditions are met, but documented gaps remain for small patches and media resampled before reaching a DAI system.
Rule A7 governs synthesis precedence. Lineage stability may never serve as the primary assessment while capture origin is undetermined. Case 003 forged this rule when a fabricated image whose file matched circulating copies received a headline that read like authenticity clearance. "No content changes found since circulation" answers whether the copies changed after discovery; it does not answer whether the depiction reflects reality.
Recirculation requires a real time gap. The "predates the current claim" framing (REC-1) applies only when the earliest documented occurrence precedes the claim date by at least 14 days. Current-event media questioned within days of its release is not recycled media, even though its occurrence technically predates a question asked today. The McConnell proof-of-life case forged this rule.
Question-focused response is mandatory. When the user submits a direct question, the primary headline answers that question first, within evidence limits. McConnell's "Is this photo AI?" required an answer about AI-generation and face-manipulation evidence before generic publication history. The corrected QAI-1 response weakened the AI explanation while keeping source authenticity unresolved.
Claim verifiability is part of verdict construction. A sub-claim can be media-resolvable, context-resolvable, or structurally unverifiable. False and unverifiable are different outcomes. A claim about an unarchived deletion or private transmission may require evidence that does not exist; the report must say so rather than converting unverifiability into falsity.
Obviousness is not evidence. Visual self-evidence cannot substitute for evidence families. Case 003 stayed below a stronger conclusion until continuity failure across renditions supplied independent support. Genuine photographic series of the same moment preserve physical detail; independent generative renditions often reinvent unspecified details. Continuity failure is therefore an evidence family when multiple renditions claim to depict the same moment.
6. Communication Rules
> Operational annex. These rules are elaborated into an enforceable reporting layer — > prohibited terms, canonical output states, coverage definitions, reason-code taxonomy, > and per-use-case coverage profiles — in the TRST Reporting and Decision Guidance Standard > (Evidence-Based Escalation, v1.2, release candidate; internal). Where the annex is more > specific, it governs how a finding is expressed; it never changes what the evidence > supports.
Status is not confidence. Public confidence is only High, Moderate, or Low. What cannot be assessed receives an explicit status. "Indeterminate" may exist internally as a synthesis state, but it is never presented publicly as a confidence level.
An assessment is decision support, never permission. DAI reports what the completed controls found, bounded by what could actually be examined; it never issues an instruction to proceed, reject, pay, publish, or approve. Absence of a triggered control is not a certification of authenticity, and a coverage limitation is never presented as a finding.
Every verdict carries a "does not claim" statement. Bounded language is not optional; it is how DAI prevents evidence from being overread. Prohibited public terms for backtracing include "original," "created," and "first published." Preferred terms include "earliest documented occurrence," "documented online as of," "published copy documented online," and "circulating since at least."
The public headline and body must agree. A headline that says "could not establish" must not be paired with a confidence pill. A headline that says "published copy documented online" must not imply capture origin. A headline that answers an AI question must not let low AI evidence become real-world capture.
Publisher context labels are display context only. The Onion satire case forged this rule. A known satire/parody label can inform readers that a publisher is a known satire outlet, but it does not move the DAI assessment. Publisher labels are not NewsGuard-style ratings, source credibility scores, or authenticity evidence.
Submitted source context never feeds Known History. User-provided source context can help define the claim, but it does not establish independent circulation. Known History depends on independently discovered and characterized evidence.
Reports separate the Investigation Brief from the Full Investigation. The brief states the primary assessment, confidence or status, dimension summaries, Known History, and why the assessment follows. The full section can expose provider findings and instance details, but provider details do not decide the public wording by themselves.
7. Provenance and C2PA
DAI is complementary to C2PA and Content Credentials. Content Credentials can help establish provenance. DAI helps interpret what the total evidence supports.
The current C2PA capability is manifest presence detection only. A current DAI implementation detects embedded C2PA/JUMBF manifest presence and reports it as unverified. It does not currently perform cryptographic verification, trust-list validation, certificate-chain reporting, or trusted-vs-valid distinction. Absence of a manifest is not evidence about authenticity.
Phase 2 is cryptographic verification using industry-standard open-source tooling. Phase 2 must distinguish valid from trusted. A signature can verify cryptographically against an issuer that is not trusted for the relevant purpose, including test certificates. A DAI system will say exactly that rather than collapsing validity into trust.
Durable credentials are the eventual answer to screenshot and re-encode laundering. The McConnell case demonstrated the ceiling of detection without provenance: best-copy classifier results can weaken specific synthetic explanations, but they cannot establish capture origin or the underlying event. Provenance evidence can document a file or credential chain; distribution evidence can document copies; independent corroboration is still required for the event claim.
8. Calibration and the Case Record
The case record is not marketing collateral. It is jurisprudence and an acceptance-test suite. Each case records a rule that must survive future development.
The 49ers AI case calibrated single-classifier dominance: strong classifier evidence can support a direct finding, but High confidence needs independent corroboration. Case 002 calibrated temporal bounding and framing divergence: the decisive evidence was not a classifier but an older, wider instance. Case 003 calibrated Rule A7, continuity analysis, degradation-aware nulls, and the difference between fabrication, lineage stability, and unverifiable deletion narratives. The NYT Carroll photo calibrated publication-history nomenclature and page-less exact-copy handling. The Onion satire case calibrated publisher labels as display-only context. The McConnell proof-of-life case calibrated best-evidence forensics, QAI-1 question focus, the 14-day REC-1 gap, UTC date-only display, durable Known History, and the single-release distribution pattern.
User feedback feeds the calibration record. A report that is useful, partly right, or wrong is evidence about the methodology. The correct response is not to patch language around a single output; it is to decide whether the case exposes a general rule, add that rule to methodology, and add regression coverage where an implementation can enforce it.
Appendix A. Scenario Nomenclature Table
| ID | Headline | Bands / status | Does not claim |
|---|---|---|---|
| RWC-1 | Consistent with a camera photograph | High / Moderate | Does not prove the caption, event context, or absence of all later edits. |
| RWC-2 | Camera-capture characteristics with digital alteration | Moderate | Does not identify the editor, motive, original source, or truth of the surrounding claim. |
| RWC-3 | Camera-capture characteristics with later processing | Moderate | Does not establish content-level alteration or prove the image is unmodified. |
| RWC-4 | Consistent with camera capture; possible alteration not confirmed | Low / Moderate | Does not confirm alteration or clear the file of subtle edits. |
| SYN-1 | AI-generated media | High / Moderate | Does not identify the tool, prompt, creator, or publication origin unless separately evidenced. |
| SYN-2 | Possible AI-generated media | Moderate | Does not establish machine generation; it reports an uncorroborated generation signal. |
| ALT-1 | Digitally altered; source not established | Moderate | Does not establish who altered it, why, or where the altered version originated. |
| ALT-2 | Possible digital alteration; source not established | Low | Does not confirm alteration; signals remain inconclusive. |
| UNV-1 | Source and authenticity could not be established | Status: Not established | Does not prove authenticity, falsity, AI generation, or alteration. |
| UNV-2 | Insufficient evidence to assess | Status: Insufficient evidence | Does not imply the media is authentic or inauthentic. |
| QAI-1 | Little evidence of AI generation or face manipulation; source authenticity not established | Status: Not established | Does not establish capture origin, scene authenticity, surrounding claim truth, or absence of subtle/shared prior edits. |
| REC-1 | Circulating since [date] - predates the current claim | High / Moderate | Does not identify the original source, creator, capture date, or first publication. |
| PUB-1 | Published copy documented online | High / Moderate | Does not confirm camera capture, rule out AI generation or alteration, prove article context, or establish capture origin. |
| PRC-1 | Processed digital media; source not established | Moderate / Low | Does not establish content-level manipulation or source authenticity. |
| FRM-1 | Screenshot of digital content | Moderate | Does not authenticate the underlying displayed content. |
| FRM-2 | Designed digital image | Moderate | Does not assess whether the designed message, logo, or promotional claim is true. |
| FRM-3 | Image of a document | Moderate | Assesses the media file, not the underlying document's legal or factual authenticity. |
| FRM-4 | Capture of existing media | Moderate | Does not authenticate the underlying print, screen, artwork, or media object. |
| CON-1 | Conflicting evidence about source | Status: Unresolved | Does not prove any single source explanation. |
Appendix B. Dating Methods and Reliability
| Method | Reliability | What it supports | Does not claim |
|---|---|---|---|
| Platform ID decode | High | A platform-derived timestamp bound when the ID scheme is known. | Does not prove capture time, creator, or first publication outside that platform record. |
| Wayback first capture | High | The page or asset was archived no later than the capture date. | Does not prove the asset first appeared on that date. |
| Page-declared date | Medium | A page itself declares a publication or post date. | Does not prove the media was created or first published then. |
| Publisher URL-path date | Medium | An independently discovered page or asset URL contains a publisher date path. | Does not prove capture time or first publication; not applied to submitted-file context. |
| Reverse-search exact-copy count | Contextual, not a date by itself | Distribution breadth and possible candidates for dating. | Does not establish independent corroboration, origin, authenticity, or release party. |
| Submitted source context | Not Known History evidence | Helps define what the user is asking. | Does not independently document circulation. |
All public dates are rendered as UTC date-only values. Public wording must use bounded language such as "since at least" or "documented online as of."
Appendix C. Methodology Version History
| Version | Date | Summary |
|---|---|---|
| v1.0 baseline | Before 2026-07-02 | Established DAI as evidence-based image authenticity assessment with deterministic confidence synthesis, provider-family evidence, and bounded public reporting. |
| v1.1 calibration | 2026-07-02 to 2026-07-07 | Added the corroboration gate for consequential findings, media-form calibration, processing-vs-manipulation separation, localized compression anomaly, and Instance Map Phase A for the instance-set model. |
| v1.2 Rule A7 | 2026-07-08 | Founder-approved change proposal codified instance-set investigation, cross-instance comparison, temporal bounding, claim verifiability, degradation-aware diagnosticity, narrative genealogy, corroborator quality, and no exonerating lineage headlines while capture origin is undetermined. |
| v1.3 consolidation | 2026-07-15 | Consolidates v1.2, the primary-assessment nomenclature, current confidence/status rules, Known History distribution rules, best-evidence forensics from the McConnell case, C2PA presence-only boundaries, and methodology-bearing changelog entries through 2026-07-15. |
| v1.4 decision-support boundary | 2026-07-20 | Removes the "real-world capture" overclaim from the nomenclature (RWC-2/3/4 now describe camera-capture characteristics, not that the depicted scene occurred). Adds the decision-support boundary: an assessment reports what the completed controls found and never issues an instruction to proceed, reject, pay, publish, or approve. Defines adequate coverage as controls run on suitable specimens that pass quality gates and yield interpretable results, forbids presenting a coverage limitation as a finding, and makes quantitative validation (sensitivity, false negatives, false alarms, per-subgroup performance, drift) a precondition for presenting DAI as reliable in a decision context. Introduces the operational reporting annex. |