technology
The AI Authenticity Policy a Brand Can Actually Enforce
A concrete policy model for approved AI uses, prohibited synthetic media, review levels, evidence retention, vendor controls, disclosures, and corrections.
Published ; updated

An authenticity policy fails when it says “use AI responsibly” but never tells a campaign manager what can ship. An enforceable policy names covered people and channels, sorts uses by risk, assigns approval authority, specifies required evidence, and gives the organization a way to stop or correct distribution. The model below is a governance starting point for brand and editorial operations. It is not a ready made legal policy. Organizations should adapt it to their products, workforce, jurisdictions, contracts, regulated activities, and risk tolerance. NIST describes its Generative AI Profile as voluntary guidance for managing generative AI risk; it is useful for structuring controls, but adopting it does not by itself establish legal compliance. Policy Statement and Scope Policy objective: The organization will not publish AI generated or AI manipulated content that materially misleads an audience about the identity of a speaker, the origin of media, a person's experience, the existence of evidence, or the basis for an objective claim. AI assisted work remains subject to the same accuracy, substantiation, rights, privacy, security, accessibility, and records requirements as other work. Covered people: The policy applies to employees, contractors, agencies, creators, influencers, and vendors acting for the organization. Contracts should require these parties to follow the applicable controls, disclose their use of AI to the organization, preserve required records, and cooperate with corrections or takedowns. Covered output: Include advertising, social posts, articles, newsletters, customer support scripts, product pages, presentations, audio, video, images, translations, code that produces public content, and personalized variants. Internal brainstorming may be lower risk, but confidential information and personal data still need approved handling. Accountability: A named business owner is responsible for each published asset. A central policy owner maintains the rules, approved tools, training, exceptions, and audit process. Legal, privacy, security, and subject matter reviewers retain authority in their domains. Approved, Conditional, and Prohibited Uses Approved with ordinary review: Low risk assistance may include spelling, formatting, ideation, transcript preparation, or summarization of material the reviewer is authorized to use. The human publisher must inspect the result. Approved status is attached to a defined workflow and data classification, not to a tool brand in every possible configuration. Conditional with enhanced review: AI drafted claims, translations, personalized marketing, generated illustrations, altered product imagery, synthetic narration, and realistic depictions require a documented reviewer, source or reference checks, rights review, and an audience disclosure when the policy or applicable duty calls for one. Regulated, safety critical, financial, health, legal, employment, or public interest content should route to qualified reviewers. Prohibited: Ban fabrication of testimonials, reviews, endorsements, documentary evidence, credentials, quotations, or research. Ban imitation of a real person's face, voice, signature, or distinctive identity without documented authority and approval. Ban removal or falsification of provenance records, undisclosed substitution of synthetic media for evidence, and prompts containing protected data in unapproved services. Disclosure does not override a prohibition. The FTC's advertising guidance provides an important legal baseline for United States marketing: advertising must be truthful and non deceptive, and objective claims need evidence before the ad runs. Therefore, an AI label cannot cure a false product claim. The policy should send endorsements, testimonials, paid creator relationships, and native advertising through their separate disclosure and substantiation checks. Review Levels and Release Authority Create three release levels with named approvers. Level A covers low risk internal assistance and routine public work where AI has no material effect on meaning or authenticity; the normal content owner approves. Level B covers materially AI drafted or generated public content; a trained editor or brand reviewer approves after checking sources, rights, disclosure, and final media. Level C covers realistic synthetic people, high consequence claims, crisis communications, public interest material, or novel uses; legal or another designated specialist joins the approval. For each level, define a service target and an escalation route. Teams bypass policies that offer no timely path for legitimate work. An exception should identify the requester, asset, reason, compensating controls, approver, expiry date, and distribution limits. It should not silently become a permanent permission. NIST's Generative AI Profile recommends actions across governance, content provenance, pre deployment testing, incident disclosure, and third party risk. Use those categories to test whether a release process covers the whole lifecycle rather than only the prompt and final caption. The profile is a risk management resource, so the organization still has to choose controls appropriate to its context. Disclosure and Provenance Rules The policy should define disclosure triggers in concrete terms. Require a reader facing label when AI materially generated or altered what the audience could reasonably treat as a person's words, a real scene, a demonstration, evidence, or an independent endorsement. Put the disclosure where the affected content is encountered, not only on a distant policy page. Specify wording by media type and provide an accessibility equivalent disclosure for audio or visual formats. Keep legal analysis separate. The European Commission's Article 50 guidance describes EU AI Act obligations for particular providers and deployers and covered outputs, including certain deepfakes and generated or manipulated content. It also addresses exceptions. A brand should map whether it is acting as a provider or deployer and obtain advice for the actual use; its voluntary disclosure table should not be represented as universal compliance. Use C2PA Content Credentials where supported to retain tamper evident provenance assertions across an asset's history. The C2PA explainer expressly limits what this proves: credentials convey provenance and support validation, but they do not decide whether the content or assertions are true. Preserve a visible label and internal source record because platforms may strip or fail to display metadata. Evidence, Vendors, and Data Handling For Level B and C work, retain the final prompt or production instruction when appropriate, model and version information available to the team, source assets, licenses, consent or talent releases, substantiation for claims, reviewer identity, approval date, disclosure text, provenance status, and final distributed files. Set retention periods through the organization's records and privacy process. Do not collect sensitive prompts merely to prove that a log exists. Maintain an approved service register describing allowed data classes, account type, retention settings, training or reuse terms, security review, and permitted output types. Reassess material changes. A general approval for text ideation should not automatically authorize voice cloning or uploads of customer records. Vendor and agency agreements should address permitted tools, confidential data, subcontractors, rights in inputs and outputs, disclosure of synthetic elements, record delivery, incident notice, correction cooperation, and audit evidence. The brand owner must still review the delivered asset; outsourcing production does not outsource the public claim. Correction, Incident, and Audit Procedure Anyone who discovers an undisclosed synthetic element, fabricated source, missing consent, false claim, or broken provenance chain should have a clear reporting route. The incident owner should pause scheduled distribution, preserve relevant evidence, assess live copies and paid placements, notify responsible functions, and decide whether to label, correct, replace, retract, or remove the asset. Where a legal, contractual, platform, or regulatory notice is required, follow the applicable process. A public correction should identify the affected content and material change without repeating harmful media unnecessarily. Update copies under the organization's control and contact partners holding distributed versions. Record why the original controls failed and change the workflow, permission, training, or vendor requirement that allowed it. Audit a sample of work by risk level, channel, team, and supplier. Measure whether approvals exist, evidence supports claims, disclosures remain attached, and exceptions expired as intended. Do not score success by the number of AI labels. The policy succeeds when audiences are not materially misled, reviewers can reconstruct consequential decisions, and the organization can correct failures across every distribution path. Sources Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile https://www.nist.gov/publications/artificial intelligence risk management framework generative artificial intelligence Advertising FAQ's: A Guide for Small Business https://www.ftc.gov/business guidance/resources/advertising faqs guide small business Guidelines on Transparency of AI Generated Content https://digital strategy.ec.europa.eu/en/policies/guidelines transparency ai generated content C2PA and Content Credentials Explainer https://spec.c2pa.org/specifications/specifications/2.3/explainer/Explainer.html Cover image credit Cover image by NASA Headquarters / NASA/Bill Ingalls , made available under Public domain in the United States NASA work . WIKIVISE cropped and converted the source image.
Evidence and review
Sources
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, National Institute of Standards and Technology
- Advertising FAQ's: A Guide for Small Business, Federal Trade Commission
- Guidelines on Transparency of AI-Generated Content, European Commission
- C2PA and Content Credentials Explainer, Coalition for Content Provenance and Authenticity