An editor pauses to watch a sequence. A sound designer repeats a section. A colourist changes several settings in quick succession. None of these patterns, on their own, tells you whether a person or a piece of software did the work. Good verification needs the context of the creative tool and the evidence available for that session.
DigiBridge Labs is our research agenda for strengthening that distinction. Its purpose is to bring security expertise, data science and production knowledge to the same question: how can we make evidence of human creative work more useful, harder to manipulate and fairer to review?
A convincing answer is not enough.
An AI verification agent can help connect observations and explain why activity needs attention. A confident explanation is still not a substitute for the observations themselves. Our direction is to make each finding traceable to permitted evidence, the relevant rule and the limits of what was recorded.
NIST’s Generative AI Profile warns that testing under laboratory conditions or narrow benchmarks may not reflect real use. For creative verification, the implication is practical: evaluate the actual workflow. An editing session, a long render and a collaboration handover need different expectations, even within the same production.
Challenge the verifier as well as the activity.
The research agenda includes attempts to misrepresent recorded activity, reuse an old record, attach evidence to the wrong version or influence an AI reviewer. These are different failure cases. Testing should identify which control is expected to stop each one and what remains uncertain if that control cannot decide.
MITRE ATLAS provides a public knowledge base of attacks involving AI systems. OWASP identifies prompt injection as a risk when supplied information changes a model’s behaviour. These resources inform useful questions for DigiBridge: can review material be mistaken for an instruction, can a model exceed its role, and can an explanation conceal missing evidence?
The design principle is straightforward. A model should analyse only its permitted evidence and return a bounded finding. It should not change the source record, grant itself access or impose a programme penalty. Independent access and publication rules must hold even when an AI response is wrong.
Measure the mistakes that matter to creators.
Finding attempted abuse is only part of the task. We also need to understand when ordinary work is flagged incorrectly. The Labs agenda prioritises comparison between permitted creative actions, prohibited software control and activity for which the evidence is incomplete.
Useful evaluation should report the tool, workflow and conditions tested. It should count incorrect warnings and missed cases, explain coverage gaps, and test whether a result still holds when the software or operating system changes. One headline accuracy figure cannot describe every creator’s working day.
Production specialists can explain why a workflow looks unusual. Security researchers can challenge the controls. Data scientists can test whether a pattern holds beyond the examples used to design it. Bringing those perspectives together is the collaboration we want Labs to support.
Better research does not require your private footage.
DigiBridge’s evidence boundary excludes source footage, creative project files and typed content. The research direction starts with isolated test projects and controlled examples, with a clear purpose for any additional data. Permission to record a session does not automatically give permission to train a model or reuse private evidence for research.
The same care applies to vulnerability testing. Tests should have an agreed scope and a route for responsible reporting, using accounts and records created for that purpose. CISA’s vulnerability disclosure guidance illustrates why clear reporting and coordination matter. A useful research programme gives specialists a defined way to contribute while protecting the people and systems outside the agreed test.
A strict standard needs a fair review.
Our goal is to give creators evidence they can stand behind and reviewers a defensible basis for their decisions. Under the human creation programme, the first confirmed incident holds the affected recording or version. Three distinct confirmed incidents make the project ineligible for directory publication. A warning, gap or uncertain AI result alone is not an incident.
Labs sets the direction for improving the methods behind that standard. It is an invitation to discuss research, production knowledge and carefully scoped testing. Findings deserve published methods and clear limits before they become broad claims about what a system can detect.
“Protecting human creation means testing the system, not just judging the creator.
How DigiBridge helps
Research that earns the creator’s trust.
These research priorities guide how DigiBridge Labs should evaluate verification methods and work with specialists. Conclusions need clear methods, test conditions and limits. Any use of private evidence for research or model training requires its own informed permission.
In the strict human creation programme, permitted device, operating system and creative tool evidence feeds layered checks and an AI verification agent. These detect prohibited AI assistance and software control, warn creators with supporting evidence, and inform publishing decisions after confirmation and review. A warning or uncertain result alone does not count as an incident.
Read the human creation standardSources and further reading
Primary and authoritative sources reviewed for this article. Statistics remain attributed to the organization that published them.
- 01Generative AI ProfileNISTPublished July 2024. Discusses evaluation, real use conditions and risks of generative AI.
- 02AI Risk Management Framework PlaybookNISTVoluntary framework guidance. Page updated 10 June 2026; reviewed 30 September 2026.
- 03ATLASMITRELiving knowledge base of threats involving AI, including observed attacks and controlled demonstrations. Reviewed 30 September 2026.
- 04Prompt InjectionOWASP Gen AI Security Project2025 risk guidance on untrusted inputs, constrained access and testing. Reviewed 30 September 2026.
- 05Vulnerability disclosure policy directiveCISAPublished 2 September 2020 and revised 24 January 2022. Federal guidance cited for reporting and coordination principles, not as a certification of DigiBridge.
Continue reading
Browse all insights