
The Road to Accountable AI · 2026-04-23 · 39 min
Key moments - from our scoring
Substance score
70 / 100
Five dimensions, 20 points each
Henry Ajder, founder of Latent Space Advisory and a leading researcher on synthetic media, maps the dramatic transformation of the deepfake landscape over eight years. Since publishing his pioneering 2019 census, Ajder has tracked three critical dimensions: realism (now approaching indistinguishability from authentic content), efficiency (single images can now drive AI avatars), and accessibility (tools once exclusive to Hollywood studios now run on laptops and phones). The volume of synthetic content has grown exponentially - from 15,000 deepfakes online in 2019 to quantities generated daily by small content agencies.
Ajder identifies persistent harms spanning deception, doubt, and degradation, with non-consensual image abuse of women remaining the highest-impact category despite scale making precise measurement impossible. His work with governments across the UK, EU, and US, along with major tech companies, navigates the intractable challenge posed by open-source tools like TensorFlow-based implementations: restricting them is essentially "regulating mathematics." He explores what he calls "gray fakes" - ethically ambiguous applications (synthetic resurrection, avatar labor, satire, non-consensual voice cloning) that unsettle society but resist clear policy consensus. Recent momentum toward mandatory AI disclosure labeling across India, South Korea, Vietnam, the UK, and China suggests emerging international alignment, though jurisdictional boundaries and platform scale continue to complicate enforcement.
In 2019, 96% of deepfakes were non-consensual pornographic content targeting women. While the absolute scale makes comprehensive remapping impossible, Ajder believes non-consensual image abuse of women remains the highest-harm category by victim count, even as fraud and disinformation applications have grown substantially.
Most malicious deepfake tools are open-source implementations cobbled from libraries like Google's TensorFlow, not proprietary platforms. Restricting them would require regulating mathematics itself, making comprehensive technological prevention infeasible, especially as implementation happens across international jurisdictions.
In 2019, creating realistic deepfakes required hundreds of aligned and cropped images; now a single image can drive an entire AI-generated avatar. Computational requirements have plummeted, with many tools running on-device or in the cloud for cents on the dollar.
Gray fakes are ethically ambiguous applications (synthetic resurrection of people, non-consensual voice cloning, avatar labor) that fall between clearly harmful and pro-social uses. They unsettle society but resist easy policy consensus, making them critical for product and policy teams to navigate carefully.
India, South Korea, Vietnam, the UK, and China have begun implementing or hinting at mandatory labeling of AI-generated content. China's deep synthesis law was an early precedent, and the EU AI Act contains similar provisions, though enforcement across jurisdictional and platform boundaries remains challenging.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers concrete insights about deepfake evolution, technical metrics (realism, efficiency, accessibility), and policy responses. However, it contains padding through repetition (e.g., explaining three harm vectors multiple times) and Kevin's interview technique includes throat-clearing that dilutes density. The substantive material - distinctions between detection/watermarking/provenance limitations, the open-source problem, the three-metric framework - is genuinely useful but spread thin across 39 minutes.
realism has gone to a point where in most contexts with state-of-the-art models, it's basically a coin flip when it comes to human discrimination of AI generated and authentic outputs
you needed hundreds of neatly aligned and cropped images to train a model, to create a face swap that looks pretty nightmarish. We're now talking about one image being used to drive an entire AI generated avatar
Ajder offers genuine first-principles thinking on the problem space (the three metrics framework, the epistemic nihilism argument, the distinction between detection/watermarking/provenance) and names a 2019 report that predates the hype cycle. However, the core framing - deepfakes as a dual-use technology with legal/technical solutions - is now mainstream. The 'gray fakes' concept, though useful, is not widely known but also underdeveloped. Missing is contrarian pushback on whether detection/labeling actually works at scale.
what hasn't changed though, Kevin, is that fundamentally the dynamics by which harm are caused has remained the same
Don't worry because we've got these technological solutions that can help us... few problems. Detection whilst it can be useful is never going to be of the categorical confidence and reliability
Ajder is highly relevant: he has been researching deepfakes since before ChatGPT (2019 report), advises governments on legislation, consults with major tech companies, and advises a detection company. He operates at policy, product, and enforcement interfaces. His seniority is substantial in the narrow domain of synthetic media. However, he is a researcher/advisor rather than an operator who built a product or platform at scale, which limits caliber somewhat.
I describe my work broadly as kind of doing deepfake and synthetic media cartography, right? I've kind of been mapping this landscape more or less since it first emerged
I work with governments a lot, so I'm working a lot with organizations within governments or departments who are looking at legislation
Ajder provides specific data points (96% non-consensual pornography in 2019, deepfakes grew from 7,500 to 15,000 in 2018-2019, detection benchmarks around 90%) and names tools/platforms (StyleGAN, HeyGen, Syn ID, C2PA, Grok). However, he explicitly caveats that current scale is unmeasurable ('now it seems almost quaint... people are generating that much content a day'). He names some policy initiatives (India, South Korea, Vietnam, UK, EU AI Act, China's deep synthesis law) but lacks concrete deployment metrics or business impact examples.
the, the nu um, sorry, the amount of defects online had almost doubled. Um, and that's like, wow. Um, that doubling was from around seven and a half thousand to 15,000
If you benchmark and get somewhere in the region of 90%, that's a really good school. It also means that one in 10 pieces of media in, in the wild context might get flagged as a false positive or a false negative
Kevin asks solid setup questions that prompt Ajder to clarify the landscape and his current work. However, Kevin rarely presses on contradictions or challenges claims. When Ajder makes a strong statement ('you can't tell what's real or fake anymore at all'), Kevin responds sympathetically rather than testing the premise or pushing for nuance. Follow-ups are mostly clarifying rather than challenging. The conversation feels collaborative but lacks the friction that would deepen insight.
Kevin: given the way AI technology evolves, though it was a safe bet back then that the performance of these, uh, deep fake engines would improve. Uh, and these were risks that people, you know, including you were highlighting years ago, was there ever a moment where there was a real opportunity to severely mitigate
Kevin: Let's talk a little bit about those technological responses. There. There are a variety of standards and tools for content provenance and watermarking. And, and the two arguments that I always hear in response are
Computed from the transcript - who did the talking, and the words that came up most.
AI-generated deepfakes are exploding in volume and quality, posing frightening challenges for public discourse, security, safety, and more. My guest, Henry Ajder, has been mapping the deepfake landscape since before most people had heard the term. In this conversation, he describes the dramatic changes in realism, efficiency, accessibility, and functionality of synthetic media tools since he published the first comprehensive census of deepfakes in 2019. Ajder describes the current moment as one of "epistemic nihilism," where people cannot reliably distinguish real from synthetic content and the available technological responses are not yet at a level of categorical trust. He introduces a framework of "deception, doubt, and degradation" for understanding deepfake harms, and draws a distinction between the clearly malicious, the clearly beneficial, and a vast unsettling middle ground of uses that society has not yet figured out how to evaluate. On the response side, Ajder warns that media literacy advice is not just outdated but actively harmful, because it gives people false confidence in their ability to spot fakes.
Transcribed and scored by The B2B Podcast Index.
This file was generated by Descript Kevin: Hi, I'm Kevin Warbeck, professor of Legal Studies and Business Ethics at the Wharton School of the University of Pennsylvania. For decades, I've studied emerging technologies from broadband to blockchain. Today, AI is promising to transform our world, but AI needs accountability mechanisms to ensure it's developed and deployed in responsible, safe, and trustworthy ways. On this podcast, I speak with the experts leading the charge for accountable ai.
We are now beyond the point where you can be confident that any content you see or hear is real. How can governments and the private sector address the deepfake explosion? My guest on this episode is Henry Eider, one of the world's foremost experts on DeepFakes and synthetic media. We discuss the evolution of deep fakes efforts to address harmful activity, technical responses, and how organizations developing or deploying AI tools should act in light of these dangers.
Henry, welcome. Thank you so much for joining me on the Road to Accountable ai. Adjer: Thank you, Kevin. No, it's great to be with you today.
Kevin: Most people have only become aware of the magnitude of the deepfake problem in recent years, but you've been studying this for a long time. You published a report on DeepFakes in 2019, which was years before chat GPT came along. Can you give us a, just a general picture about how the, the landscape of DeepFakes has evolved over that period of time? Adjer: Yeah, sure.
I mean. You know, I describe my work broadly as kind of doing deepfake and synthetic media cartography, right? I've kind of been mapping this landscape more or less since it first emerged. As you mentioned, I published the first report really kind of providing something, almost a deepfake census as to how this technology was evolving, the quantity of, uh, deepfake content out there, who was targeting.
Um, and primarily that was really to try and actually kind of cut through the speculation. You know, in 2019, late 2018, there was a lot of speculations to the impact, but there wasn't much in a way of evidence to back up that speculation of its impact on elections or cybersecurity and so on. So yes, done a lot of work over the years, kind of mapping that landscape with, you know, different reports. Um, which primarily actually pointed to the fact that image abuse against women at the time was the biggest challenge.
Um. What has changed and what has not? I think this is one of the things that is really important for people to grasp, which is that the way I talk about DeepFakes is typically along three metrics. You could technically push it to four, but it's realism of the outputs that can be generated.
It's the efficiency of the models, both in terms of compute and data for generation and its accessibility of the tools in terms of how easy it is to actually use them and access them in the first place. Functionality would be a technical force in terms of what the models can now actually do, not just the realism of what they can generate as well, but, but that has changed dramatically, right? I mean, that has been. A real, um, frenetic space, particularly in the last two, three years, say, um, realism has gone to a point where in most contexts with state-of-the-art models, it's basically a coin flip when it comes to human discrimination of AI generated and authentic outputs.
That's across audio images and increasingly starting to become video as well. Um, the efficiency of these tools that used to be that you needed, you know, hundreds of neatly aligned and cropped images to train a model, to create a face swap that looks pretty nightmarish. We're now talking about one image being used to drive an entire AI generated avatar, which is incredibly realistic, right? Um, and the computational resources likewise have decreased.
Um, a lot of these can now, um, a lot of these tools for creating deface can now run on device or indeed on cloud for, you know, for. You know, pennies or cents on the dollar. Right. Um, and then accessibility.
I think that's the biggest factor that's dramatically changed is tools that, you know, six, seven years ago would've been the dream of Hollywood Studios to even begin to have access to somebody's capabilities. Right. Are now available on the laptop, on your desk, or the smartphone in your pocket. Um, so those areas have really dramatically changed.
Mm-hmm. The incidence of DeepFakes being used maliciously as well has also changed, um, in terms of the volume of attacks and the volume of, um, people being targeted. Um, so it used to be that we were talking about maybe hundreds of people, particularly in the fraud context and so on. C-suite top executives, politicians, um, figures in government.
It's now targeting private individuals, everyday people. Um, so the volume of attacks has grown and the efficacy of the attacks has also changed. It's no longer the case that it's quite as easy to catch them. Um, the three main vectors that I talk about is deception, doubt, and de uh, de degradation or, or degrading people.
Um, you know, the impact of that has. What hasn't changed though, Kevin, is that fundamentally the dynamics by which harm are caused has remained the same. It is those three same categories, and it is still about scamming people, humiliating people, scaring people, and deceiving people. Um, that hasn't changed.
Nor has the dynamic for how we tend to try and address them through things like detection, provenance of content, and watermarking. So lots has changed at the same time that the, the kind of, the core dynamics hasn't really changed that much. Kevin: I'm curious about that fourth potential category that you mentioned, functionality. Um, what might be changing in terms of what the models can do beyond just the caliber of the, the fidelity of the images and videos?
Adjer: Sure. So I mean, if you go back to say, 2019. The talk of the town was what were called style gans. Generative adversarial networks, GAN, um, style.
GaN was an algorithm developed by Nvidia and open source so anyone could functionally access it. It was on a commercial license, but bad actors don't tend to really care too much about commercial licenses. And, um, what this, uh, tool style GaN allowed you to do was to generate. Pretty realistic face images, portrait style images of non-existent people.
So some of your listeners may remember a website called this person does Not Exist. They may also be familiar with the kind of floods of fake LinkedIn profiles that kind of hit the platform at that time using these style GaN images as their profile picture. Um, I have many of them people saying, I'd love to join your network from clearly people that didn't exist. Um, likewise it also did creep into some of the kind of disinformation sphere.
Um, a, um, an account, um, uh, linked to the supposed Hunter Biden dossier. The person who leaked that, that was a style GaN image that was the picture of that person. This was something that had impact, but critically it was something that had a very narrow impact. This tool, as it had been trained, could only generate pictures of realistic human faces.
Now also, you, you get to see enough of them and immediately like style gall image. I know that look right. Um, but it was very narrow. Now we're talking about tools, uh, platforms like Hicks Field ai, for example, that contain just a multitude of really fine tuneable, um, tools that allow you to do things like, you know, change certain regions of images to animate them, you know, lip synchronization, entire face swapping, entire video generation character changing.
Driving images, um, or rather, sorry, driving videos based on real images. But with your facial movements, I mean, the amount of different tools that are being released, you know, weekly by Higgs field in particular is astonishing. So the functionality has just massively broadened. There is just so many more permutations of what you can now generate, um, compared to where we were before where you could get okay results, but they were very narrow.
Um, has really changed the game in terms of what we also now think of as possible. It's kind of bled out into many more aspects of media in the digital world. Mm-hmm. And Kevin: given the way AI technology evolves, though it was a safe bet back then that the performance of these, uh, deep fake engines, um, and image generation engines and so forth would improve.
Uh, and these were risks that people, you know, including you were highlighting years ago, wa was there ever a moment where there was a real opportunity to, uh. Severely mitigate the, the, you know, inappropriate and, and illegal and, and harmful uses of DeepFakes? Or, or was this sort of inevitable we get to this point? Adjer: Yeah, I, Kevin, I dunno what's kind of worse here?
It's either the fact that, you know, that, that there was and we missed it, or that there never was. And I think it's more the latter to be honest. I think, um, the dynamics that are in play when it comes to DeepFakes are really challenging. So one of the reasons it's challenging is that a lot of the tools that are used to create malicious DeepFakes are open source, right?
These are not proprietary closed tools, um, that are hosted via formal business operations and, um, and kind of play by the rules. These are tools like the original face swapping tool that. Term deep actually came from, was cobbled together from an open source library, from Google of software called TensorFlow. Um, and it was a weaponization of kind of disparate parts put together, so to speak.
The problem with this, right, is that if you're saying, well, look, we need to try and remove this content. We need to try and stop this stuff being created. It's a bit like saying we need to try and regulate mathematics or math as, as you guys say, right? Um, it's something where it's really, really hard to stop people from re-implementing and rebuilding systems.
To basically say anything that could potentially be weaponized now must be restricted for the open source community. That's something that, you know, just isn't feasible. It's something that the EU AI Act kind of attempted to try and bring in and got immediately shot down. So the open source component is really hard.
It's really hard to restrict and, um, and kind of govern that, that ecosystem. The second part is the, the, the kind of the way that the harm spreads, which is online, right? Primarily, um. Jurisdictions and kind of operating across, uh, international lines on the internet doesn't really make sense.
It doesn't really work in the same way. And so even if a country has really, really comprehensive and strict legislation prohibiting the sharing of certain content, making sure that labeling is put in place, for example, of anything to say AI generated, um, as is being discussed right now in India, South Korea, and so on, that's all well and good. But when content is being posted from a random account in Bulgaria or the UK or Mexico. You know, it is much, much harder to actually, uh, legislate for that.
Um, also the scale of content now being generated and shared means that the social platforms are also really struggling with it. So this is, this is my way of basically saying there hasn't really been a moment in my time, well, since the beginning of my time in this space, which is really the beginning of the space. It hasn't really been a moment where I've been like, we really missed the shot. Kevin: Mm-hmm.
Adjer: What we did do, as is always the case though, Kevin, is we acted too late. There was more we could have done in anticipation. I've been having conversations with international governments for years, and it has only been recently that they've started to act when I've been kind of trying to encourage 'em to do so, you know, for a long time before then. So there is still frustration about what could have been done, but I don't think what could have been done would've been, you know, definitive in, in solving or addressing a problem.
Kevin: And you mentioned, uh, a minute ago that, uh, when you looked at the space in 2019, uh, non-consensual pornography, other kinds of, uh, attacks on women were the largest category. I, I, I think is, is that still the case? Adjer: So it's really hard to give an answer to this with the same confidence that I did that research in 2019. The reason being, Kevin, that the landscape has, in some respects, in terms of the volume of content out there, is just, it is.
It is almost like the grain of sand on the beach of today in terms of where things were. Um, one of the key findings from my stated DeepFakes report 2019, which covered 2018 to 2019 in terms of the change in the landscape, was yes, that 96% of DeepFakes at that time were non-consensual pornographic content. Um, but another finding was that the, the nu um, sorry, the amount of defects online had almost doubled. Um, and that's like, wow.
Um, that doubling was from around seven and a half thousand to 15,000, right? I mean, now it seems almost quaint. Um, you know, people are generating that much content a day within a small business in some cases, right? If you're a content agency, I mean, um, the scale is just so different.
And so to say, I've exhaustedly or exhaustively mapped this landscape, and I can give you a definitive answer. Is basically impossible. And I think anyone who tells you that they can do that and they're not extrapolating from or approximating is, is not being honest with you. Um, that said, it is still my.
My perspective or my belief, um, the, the, the highest, um, harm level in terms of number of victims still remains in that non-consensual image view space. Mm-hmm. Part of the reason for that, Kevin, is that yes, a lot of this is being posted publicly. Obviously at the start of, uh, this year, 2026, we saw a scandal.
With Grok undressing, um, images of women on X. Again, I wrote the first report re investigating the commodification of ification apps on Telegram, on, on a similar kind of, um, platform, uh, back in 2020. Um, but obviously we've seen this in the public sphere, but it also happens at scale in the private world, it's about the people who are doing this to people on their phone and not sharing it as well. So it's still my deep belief that the, the vast, um, you know, the vast majority of victims of deep fake abuse.
Are predominantly women and it's predominantly of a non-consensual sexual nature. Having said that, the amount of people that are being targeted by the, um, fraud components or being targeted by, um, disinformation campaigns and are falling for AI generated content on their timelines in their daily life. Has radically changed as well. So depending on how you profile a victim and what degree of kind of engagement that they have with AI generated content, you know, that, that, that does have an impact.
But I think we can confidently say that. You know, the fake image abuse against women is still a huge challenge to date, irrespective of what the actual number is. Kevin: Mm-hmm. Well, so tell us about the work that you do now at, uh, with Latent Space Advisory, um, and more broadly in this space.
Adjer: Yeah, sure. So, I mean, my organization, latent Space Advisory is, is functionally just me. It is my vehicle for working with a variety of different stakeholders who are. Trying to navigate and then respond to this kind of new synthetic reality that we are all living in.
I say new, relatively new given the span of history. Um, although in the tech space, it feels like it's been a long, long time. I feel old given how, how, um, how these eight years have flown by. Um.
I work with governments a lot, so I'm working a lot with organizations within governments or departments who are looking at legislation, looking at what enforcement actions against malicious uses might look like. Um, looking at trying to get the balance right between understanding the. These tools are here to stay. And there's a lot of kind of exciting, creative applications that are out there whilst also recognizing the challenges I mentioned around weaponization and, um, and kind of good governance and, and responsible design.
Um, so a lot of work with, with, with, you know, the government side of things, um, particularly here in the uk but also in the eu and, and to some extent less of, of recent, but in the US too. Um, I do a lot of work with some of the bigger tech companies out there who are developing some of these systems, um, and trying to again, understand how to, how to best govern them, how to design them in the first place, what release strategies look like, what kinds of policies need to be put in place.
For example, if you're a platform as well as a provider of the tools, um. Big, big questions right now about things such as AI disclosure. How should you disclose or ought users, um, disclose content? What is deemed sufficiently deceptive?
How do we think about satire and critical art in the context of these platforms? And hyperrealistic AI generated content as well? Um, as well as looking at what is acceptable levels of kind of risk. And, um, and what are some of the kind of ethical gray areas that emerge?
Yeah. Um, I think one of the really interesting things in this space, Kevin and I wrote a piece on this back in 2019 with the pretty bad name, I called it, the rise of gray fakes really wasn't very catchy. I'm not surprised it didn't catch on, but, but the, the argument I was making at the time was, well, look, we've got all of these deep fakes, which are explicitly clearly bad. We've got non-consensual image abuse of women.
We've got cybersecurity. Ving attacks, you know, voice phishing, cloning voices, impersonating people. We've got state sponsored disinformation as well as just a general disinformation deception. Um, we've got people having their likeness stolen to perform in adverts and films and content they never wanted to.
Um, there's a lot of explicitly, quite bad. I think we can all kind of agree that that's not desirable. Then there's also some pro-social applications. I'm talking about, for example, the use of synthetic content in accessibility.
For example, cloning voices of people who've lost the ability to speak, um, avatars that can be generated in real time, that sign language, um, to help people with hearing impairments, right? Some stuff in there that's pretty, pretty uncontroversially good, but in the middle there's this huge swath of, of kind of applications, which, Kevin: yeah, Adjer: I think they unsettle us and they still unsettle us all these years later. And that unsettling feeling is often hard to understand.
Well, is this just future shock? Is this just something that's new and I'm not familiar with it and I don't like it because it's something different and it makes me uncomfortable? Or is it making me uncomfortable? 'cause there's a deeper kind of ethical intuition that's being disturbed, um, and that I'm realizing, no, this isn't just uncomfortable because it's new, it's uncomfortable because it's wrong or it's not, it's not okay.
And there's a huge amount of applications that fall into there. I'm thinking. Of, you know, the use of, um, synthetically resurrected people, kind of, um, ai, ai, um, uh, tere as I kind of call it. Um, you're talking about, you know, the use of, of kind of non-existent people, avatars in films.
You might have seen a kind of thing around this Tillian Norwood character. I think it's a bit of kind of empty hype at the moment, but I think the direction of travel is clear towards, you know, synthetic labor in audio visual contexts. Um. Again, the satire point.
You know, what is good faith and acceptable uses of this technology to clone people without consent? Um, you know, are there acceptable use cases? So there's loads of these. Situations where this technology has just opened up things that we just don't fully understand, both the longer term impact and how as a society we, we ought to feel about it or we, or do we do feel about it.
So a lot of my work kind of helps to, um, bring those issues to people who are invested in them, whether that's from a policy perspective, whether that's from a product perspective, whether that's from a media perspective, to help them better understand it and then make decisions, um, based on that better understanding. Kevin: Yeah, it's a really interesting point and you know, as you suggested, people have different intuitions and, and companies may have different cultures and policies and views on how to handle this even, even if we're just talking about.
Uh, just the image generation tools or the image modification tools and, you know, different communities feel differently about, uh, if I use an AI enhanced profile picture, uh, whether that, you know, it's not illegal, but is that legitimate or not? So given all of that range, uh, and, and, and the novelty of all these kinds of use cases. You know, what is the pathway or what are possible pathways to actually coming up with some measure of, uh, if not consensus, then some confidence of organizations to draw those lines.
Adjer: Yeah, it's a good question. So I think the consensus point is one that for a long time has been quite evasive. I think there's been a lot of hesitancy, understandably, from government in regulating with a heavy hand perhaps technologies, which, you know, many people believe will, will form the foundation of a new world order functionally, right? Um, and so from an economic perspective, there's hesitancy, but also from a kind of an overstepping perspective too.
Um, and likewise with the public, I mean, um, I'm sure Kevin, you, you find yourself in similar circles to me where you can end up in kind of AI echo chambers where everyone is, is just talking about how amazing this technology is and how, you know, this is gonna change the world for the better and they're so excited. Um. But you know, if you spend enough time in other spaces, you'll see just utter horror and um, and, uh, just disdain for what AI is doing to creative industries, to economic industries, to kind of slop ation of content and the way that we interact with each other.
Um, and so there, you know, lots of different viewpoints, that's not gonna change. There is not gonna be a point with this, um, where all of a sudden everyone reaches pure consensus, right. Um. Having said that, I do feel that I've seen over the last 18 months in particular, but particularly the last year, um, a real change in whose voices are pot potentially cutting through more.
Um, and I think that's. As some of the hype has started to fade, um, and as, um, discontent has started to grow louder, both because of the harms such as the, the use of gr to synthetically stripped women or the deep faking of, of various people in scams and fraud. Um, or just because people aren't happy with the fact that every email they read is clearly written by, by ai and it just sort of leads to a, a less enjoyable, um, and less kind of human experience of how you interact with each other.
Um, and the result of that I think, has been growing. Public backlash. Yes. But also there is started to become a more unified front internationally around.
Um, policy and legislation. So, um, this year we've seen already India, South Korea, I believe Vietnam as well, and the UK has started hinting at compulsory Montessori labeling, um, of AI generated content, um, with China. China, well, China. China were, yeah, exactly right.
China were actually the first to really do this. Yeah. Um, the deep synthesis law that they had. Couple of years back, um, closer to three now actually.
Um, which actually the EU is, uh, the EU AI Act was fairly closely aligned with, um, on those points, but yes, you're absolutely right. So, um, you're starting to see, you know, more and more com uh, countries moving towards this position of like, okay, kind of enough, enough, like we need to. Create some structure and some order here. Um, and for me, that's, that's critical.
That's how you maintain information integrity in the synthetic age. You need to mandate these kinds of actions. And then that leads to perhaps some of the technological solutions or solution approaches, um, which have been, you know, getting momentum, but not perhaps enough proportionate to the scale of the challenge that that leads to them. Then getting more attention and more resources and more adoption.
So, you know, I, I respect the, that there's differing views on AI regulation and, um, I'm certainly not one to say that it's a clear cut, you know, regulat it into the ground or let you know, let it all run free. Um, but I feel that these are issues which there's been enough case studies now, there are enough people who have felt it in their daily lives, uh, in terms of getting fooled. The, um, the, the, the unified front on legislation. Even if it's not the best for legislation, I think it's, you know, it is part of the process of iterating and, and getting to a better place.
So yes, we are starting to see more consensus on, on key issues, likewise with children and, you know, the use of, um, chatbots, um, as kind of romantic partners or as companions. Um, that's something that in the US for example, has had bipartisan support. Likewise with non-consensual image abuse and non-consensual pornography stuff. That was the bill that Melania Trump put her name to.
Right. Um, but was also spearheaded by, uh, A OC Alexandria Ocasio-Cortez. So, you know, there are key points where there is agreement, but um, there's a lot more that disagreement, but it is shifting towards, um, some kind of unified front. Kevin: Let's talk a little bit about those technological responses.
There. There are a variety of standards and tools for content provenance and watermarking. And, and the two arguments that I always hear in response are there, there's no technology that is perfectly robust against someone removing the watermark or, or, or otherwise. And you know, at some point if people are too credulous or they want to believe what they see or they don't trust anything.
It's all fake news. It really doesn't matter whether that technological capability is there. What's your sense, uh, and and and thoughts about that? Adjer: Yeah, it's, it is, it is, um, something that's taken up a huge amount of my, uh, my, uh, headspace at the moment and is one of the primary issues I'm working with from a government perspective in particular is precisely this question of, look where we are now.
We are in a world where you cannot. Say that a piece of media confidently is AI generated, um, or, or authentic, um, based on a naked eye or ear, particularly as a lay person. But increasingly, it's also difficult for, for experts, I guess, such as myself to do that kind of analysis. A lot of people talk about media literacy in this space and say, well, don't worry.
Here's the top five things that you can look out for. Like, look out for the blinking, look out for the fingers, look out for text in the background. Look out for. Um, you look, you know, look for disparities in detail between foreground and background, blah, blah, blah.
Um, this to me is not just, um, not helpful, but can be actively harmful because it gives people the wrong impression about their capabilities relative to the capabilities of the generating, uh, tools and those companies. So in good faith, we cannot tell people that their senses are any longer a reliable judge of whether content is. What do we tell them then? Because that's a really scary premise, right?
If I come to you and say, Hey, Kevin, I just wanted to let you know, mate, you can't tell what's real or fake anymore at all. Good luck. Um, that's quite unsettling. Kevin: Yeah.
But Adjer: it's the truth. It is the truth. It is the truth. Um, the consequences of that, and if this, if the conversation ended, there are effectively what I refer to as kind of epistemic nihilism, like just nihilism about what we can know and what we can't know.
And that quite rightly, as you said, I think leads to a sense of. There's no way I can know I'm gonna go with my gut. I don't like that politician. My friend would never say that.
Oh, she definitely would post a video like that, et cetera, et cetera. Right? Um, it leads to the biases rising to the surface, even in those people who really would like to know definitively what is real or not. So in response to this quite unsettling, uh, premise, we have a couple of things that we can say, well, we can say, well, look, you can't trust your eyes and ears anymore.
But, but don't worry because we've got these technological solutions that can help us. We've got deep fake detection tools that are basically able to spot things, um, based on artifacts that have been detected in AI generated versus authentic content in a way that the human. Eyes and ears cannot. We've got watermarking.
So we've got kind of good faith red flags planted in all of this content that kind of stick out and tell the detection systems that this is AI generated, or we've got kind of provenance systems, what we can talk about as digital nutrition labels, you know, the, um, the standard C two pa, um, which is a technical open standard for watermark, I'm sorry, watermarking for, for providing, uh, secure metadata about how a piece of media has been created and continues to be edited over time.
Right, so we can look at these and say, okay, don't worry. You may not be able to tell with your eyes and ears that these standards are gonna help us, or these technologies are gonna help us few problems. Detection whilst it can be useful is never going to be of the categorical confidence and reliability that I think most people would deem to be acceptable to make. CI if at commercial.
If you benchmark and get somewhere in the region of 90%, that's a really good school. That's a really good school. It also means that one in 10 pieces of media in, in the wild context might get flagged as a false positive or a false negative. And if you think about social media platforms where there's hundreds of thousands of pieces of content being uploaded, you know, potentially even by the hour, um, that's a lot of pieces of content being incorrectly flagged or allowed to slip through the net.
Um. The other thing with detection is of course, that it's an adversarial dynamic, right? It's a cat and mouse game. Um, and so it's not like when you benchmark your tool, you can pat yourself on the back and go away for six months and say, good job.
Our tool's at 90%. The next day something could be released, which technically could completely, um, undermine. Your detection system and the confidence that you've just communicated to people in its ability. Mm-hmm.
Um, I know, I, I, I advise a detection company who are doing really great work, um, and have humility to what their tools kind and can't do. They are useful, but they are useful in the hands of trained individuals. When you have people on x taking screenshots of free online detection systems, which spoiler alert don't work well 'cause they're free, um, that does more harm than good because again, it gives false confidence. So detection has limited, um, uh, usefulness when used by layperson, but can actually be harmful if not understood properly.
Watermarking, you know, yes. That's something that, for example, Google Syn ID has been really helpful for fact-checkers and for people doing forensic analysis. Um, those watermarks compared to some of the previous ones are much more robust so they can survive high levels of compression post-production, you know, cropping and changing of the size of the image, for example. Um, but they're not perfect.
Um, and what they often can't do is tell you necessarily how a piece of content might have been edited or generated, or if it has been generated. Let's say I generate a picture of a burning building. Um, and then in a very small part of the image I introduce what looks like an Israeli fighter jet or an American fighter jet or an Iranian fighter jet. Given the current ongoing situation, um, that we have in the Middle East, um, you know, some, some watermarks will persist.
In a way where you can introduce elements which won't be captured, um, or will be treated as authentic, even if it's only a small portion of the image being changed. Um, so again, not perfect useful, but not perfect. Also, at the moment, synth ID is only really being allowed to be used in Google products, so it's not that wide to spread. And then with content provenance, technically it's the most secure.
It's the one that is the most kind of, um, from an architecture perspective, it's the best designed in my opinion. Um, you know, if you try and change the metadata, you break the seal, you lose your digital nutrition label, you lose your content credentials, they're called, um. Problems with provenance though is explainability. So how can you meaningfully explain to someone how a piece of content has been edited and changed over time?
Um, think about, for example, the famous image of the shark on the highway, um, which is often posted in Flo around Florida hurricanes and stuff like this. Um, that's a really old image at this point. It's been shared reedited and changed a lot. And so the ledger, so to speak, of that piece of media is gonna be huge.
How do you distill that in a way that allows people to get the essence of what they need to know, um, in a moment? And the same goes for AI generated content. If I say, Kevin, this video you're watching of me right now is actually a deep fake, is AI generated? We might be saying, well, is it just the lip movements?
Is it the background? Is it my hair? You know, is it, is it my entire face? Is it my entire body?
Um, it can be really hard to communicate that effectively. So this is all to say that the solution approaches that we have in response to a difficult question are not perfect, and they aren't at a level of categorical trust that perhaps we are used to. And so that means that there are lots of people who, including myself, who don't feel that at the moment. We really have that satisfactory answer to the epistemic nihilism, to the uncertainty to provide reassurance.
So we're not in the best spot right now. My hope is that as people become more aware of how challenged our information systems now are, that there will be rising, uh, recognition of the need for more work, and we'll get to a better place with those solutions. Kevin: So that leads to my last question, given that we're not in an ideal spot, uh, with regard to all those elements, as you said, there's been a lot of activity by governments in around the world, but we, we still don't necessarily have the kind of legal frameworks we need for someone who is, um, involved in developing or deploying AI systems.
And let's, let's put aside the. The frontier model companies or the companies that are actually doing image generating tools. But you know, if you're someone who is just, uh, you know, thinking about the impact that this deepfake phenomenon has more broadly on you and on people's perception of ai, what's, what's the best thing for someone like that to do in this environ? Adjer: It is a good question.
I mean, I think one thing I'd start by saying is that I think in this space where there are so many people who, um, like to pretend that they're an expert on everything, um, when, when it comes to ai, um, who were experts on NFTs and crypto. Three years ago. Um, it's important for me to say that my focus really is on audio visual. I do cover some aspects of LLMs, um, um, and some aspects of age agentic systems.
That's a whole other issue, which we didn't get to around kind of, you know, judging authenticity in the age agentic kind of age. But, you know, I would focus on the, the audiovisual side of things. That's where my, my research is really focused. Um.
I think you can't understate the importance of doing things such as red teaming. You know, taking these tools and putting 'em in the hands of people who are just going to be able to forecast and foresee, um, weaponization approaches that you haven't imagined. If you can't afford red teaming, go look at places like four chan. Go look at places like Reddit in some communities.
Um, find some discord channels of people who are trying to jailbreak. AI tools and look at the techniques they're using, look at the kinds of content they're wanting to generate and do some reverse engineering based on basically the open source intelligence that you can gather without having to get someone professionally to red team your tools. But I think having, having a sense of the vulnerabilities. Um, and, um, and kind of what you need to, what you need to improve before you launch, I think is really important.
Often it's not the case. Um, and it really feeds into one of the most challenging dynamics, and it's another one I'm working on with governments, uh, at the moment, which is at the moment, Kevin, it's just not strategically smart to invest in safety over speed of development. Like from a, from an entrepreneurial perspective, it just doesn't make sense, like, um. If you are spending money and time waiting to release spending money that you could be spending on engineers or developers, um, on, on safety, testing your systems, um, you know, you might win the moral victory, but that's not ultimately the one that's gonna fund your next round.
Right? So there are big challenges. Aaron, I, I want to, you know, I want to be, uh, show awareness of that, that, that, this is a difficult one, but I think, you know, my hope is that we'll get to a point. Via carrot or stick, that, that kind of becomes a hard, a less of a difficult trade off to make.
But I think doing that red team and doing that safety testing is really critical. I think it sounds, it sounds almost obvious, but I think doing effectively, ethnography, doing like customer research, like truly understanding what is it the tool is for or who is it for and what is it trying to help them achieve. Um, so much of the backlash that I see around AI tools is by people saying. I don't want this, like, I didn't ask for this.
Um, and what's more, you're actually insulting my craft or my identity essence of what I see myself as. You know, we're all humans. We all have jobs. Our work is a big part of who we are.
Um, saying, you know, this is, this is, this is insulting, basically. So I think having an understanding of why you are developing the tool and who you're developing it for is, is critical and can often get, um, glazed over by excitement and sort of again, echo chambers. Um. And then I think the final thing I'd, I'd say is just don't over, um, don't underestimate how important authenticity now really is in a synthetic age, and that that doesn't just mean authenticity in the kind of social media sense of like, I had a really hard day and I just binge a, a whole packet of cookies to try and deal with it.
Right? Um, it's less to do with that. It's more about like, what is it that, what is it that your customers want to see and your, your users want to see from you in terms of. Saying what you do and don't know about how these tools work, admitting mistakes, um, just having that kind of honest perspective, I think with your users and with the people that you're ultimately trying to engage with.
Kevin: Mm-hmm. Adjer: Um. And about where these tools are designed to be used. You know, make it clear you're not trying to replace critical parts of, you know, the human experience.
I think these are all really powerful things to get that balance between, you know, safety market and, um, an audience I think is, you know, that, that's kind of some of the framing that I, I try to, uh, think about when I'm talking to these companies. Kevin: Henry, thank you so much for the conversation. Adjer: My pleasure. That's been great fun.
Thanks. Kevin: This has been the Road to Accountable ai. If you like what you're hearing, please give us a good review and check out my substack for more insights on AI accountability. Thank you for listening.
If you want to go deeper on AI governance, trust and responsibility with me. Another distinguished faculty of the world's top business school. Sign up for the next cohort of Wharton's Strategies for Accountable AI Online Executive education program, featuring live interaction with faculty expert interviews and custom designed asynchronous content. Join fellow business leaders to learn valuable skills you can put to work in your organization.
Visit exec ed.warden.upen.edu/acai for full details.
I hope to see you there.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.