By Alex Laurie, GTM CTO, Ping Identity
Generative AI has made content creation effortless, but establishing where content originates – and whether it can be trusted – remains a critical security challenge. While AI vendors are introducing digital watermarking to improve visibility, provenance and trust are not the same thing. Knowing an image or document was generated by AI reveals its origin, but it tells us nothing about its accuracy, intent, or authorisation.
Watermarking alone is an incomplete defense. Digital watermarks have existed for decades, and bad actors have consistently found ways to strip, alter, or spoof them. As AI safeguards evolve, so will the techniques designed to bypass them. Maintaining digital trust requires adaptable controls rather than static markers.
The limits of watermarking AI content
The fundamental flaw in relying solely on watermarking is treating origin as verification. A watermark cannot confirm that content is accurate, approved, or compliant.
In an enterprise environment, basic cyber hygiene principles must extend to synthetic content. Just as security teams train employees to scrutinise suspicious links and emails, AI outputs must be systematically validated. Where automated tasks involve critical risk, automated execution must escalate to human oversight.
Why clear standards matter in the fight against misinformation
This doesn’t mean watermarking is pointless – it is simply insufficient on its own. AI companies are right to experiment with ways of making AI-generated content more identifiable, but there are measures that can make these approaches more effective.
For example, attaching tamper-evident metadata to AI content effectively provides a record of who or what created it, when and using what system. That origin story automatically improves AI provenance, particularly when combined with clear policies and organisational standards that establish how AI-generated content should be handled and verified.
However, vendor-specific labeling is only a baseline. To build resilient defenses against AI-driven misinformation and deepfakes, organisations must combine content origin signals with continuous identity assurance. This requires enforcing contextual verification, treating synthetic assets and autonomous AI agents as managed identities with explicitly defined boundaries and runtime behavioural monitoring. Crucially, maintaining human-in-the-loop safeguards ensures that human accountability is retained for verifying high-stakes data and authorising sensitive actions.
Why transparency alone won’t be enough
The introduction of watermarking is an important development in how the technology industry is responding to the challenges created by AI-generated misinformation. Some AI companies are already taking the lead, with others likely to follow as they look for practical and responsible ways to give users greater visibility into AI-generated content. However, watermarking should be viewed as one part of a broader approach rather than a definitive solution.
As watermarking techniques become more sophisticated, so too will the methods used to circumvent them. Organisations need to be able to combine information about a piece of content’s origin and creation with other methods for identifying and validating AI-generated content. This will become increasingly important as synthetic content becomes harder to distinguish from material created by people. For example, every time I present my work, I now take the time to let the audience know which parts of my presentation were AI-generated and which parts human-generated. By being so up-front about my use of AI content, I get an improved level of engagement and trust.
The longer-term challenge is establishing the conditions in which people can make informed decisions about what they see and share. This requires clear standards for identifying AI-generated material and safeguards that can adapt as new methods of circumvention emerge.
Ultimately, provenance can provide valuable context, but it should not be treated as proof. Building confidence in AI-generated content will depend on technology working alongside human oversight, with people retaining responsibility for verifying information and deciding whether it can be trusted. As AI becomes more embedded in how content is produced and distributed, that combination of transparency, evolving safeguards and human accountability will be essential to maintaining trust over the long term.

