Trust and law: who accepts a digital file, and who answers for an agent?
This is a live Practicum page for Volume 3. Verified: 2026-08-18. The field changes quickly, so check the date. The book explains the principle. The status of laws and standards can change within months, so it belongs here.
Discipline: this is not legal advice. Check effective dates, thresholds, and exact wording in primary sources such as laws and regulator websites. Verify disputed points yourself.
In a dispute, your best protection is not spotting a fake by eye. It is provenance, meaning where a file came from, a procedure such as a second channel and a pause, and a verifiable trail. Regulation is catching up. This page shows its current direction.
The page covers five situations. If you are going to a bank, newsroom, or court, start with "Three doors." For the status of labeling laws, use "Jurisdictions." To check another person's file, sign your own material, or sign in without a password, use "Content provenance." If an agent spent your money, read "Who answers for an agent's mistake?" If fake reviews target a business, use "Where to report fake reviews and extortion."
Russia-specific free protections, including the credit self-ban, "second hand" service, and cooling-off period, have a separate page, written for readers in Russia: protections you can turn on there.
Three doors: what each institution will ask
| Where you go | What the institution needs | What to prepare before you contact it |
|---|---|---|
| Bank | The transaction trail in the bank's system, device, confirmation, recipient, and time you reported the incident. A call recording gives context but does not replace the transaction log. | statement, receipt, original recording, messages, and case number; report the incident without delay |
| Newsroom | File provenance, the original rather than a forwarded copy, context, and independent confirmation | original file, metadata, full message history, and contact details for a second source; disclose any enhancement separately |
| Court | Authentication, integrity, admissibility, and evidentiary weight under the rules of that procedure | untouched original, transfer log, checksum, and independent traces; ask a specialist before processing the file |
This is a map of questions, not a promise of a result. A bank, newsroom, and court may examine the same file and reach three different answers because they make different decisions.
Practical worksheets: the first day with an important file and an evidence package before a dispute.
Jurisdictions: the current response
| Jurisdiction | Rule | Status, verified 2026-08-18 |
|---|---|---|
| European Union | Article 50 of the AI Act requires machine-readable marking for some AI content and visible disclosure for deepfakes and certain public-interest texts. | Now in force. The AI Office and national authorities began enforcing these duties on Aug 2, 2026. Penalties reach €15M or 3% of worldwide annual turnover. Systems placed on the market before that date have until Dec 2026 to meet the marking obligation. |
| China | Explicit and hidden labels are required. A platform labels material when it detects signs of synthetic content that the user did not disclose. | In force since Sep 1, 2025, and past the paper stage: audits began Oct 2025 and the first enforcement actions were expected from Jan 2026. |
| Russia | A user has the right to add a label, and a large platform must provide that option. | The law was signed and published Jul 26, 2026. Labeling provisions are scheduled to apply from Mar 1, 2027. |
| United States | Still no general federal labeling rule; sector rules and state laws apply. But one federal law does bind platforms: the TAKE IT DOWN Act, signed May 19, 2025, criminalizes non-consensual intimate images including AI-generated ones and required platform takedown processes by May 19, 2026, a deadline that has now passed. | Rule 707 did not move forward in May 2026. A broader AI Labeling Act was introduced in 2026 but is a bill, not law. Do not plan around it. |
| Japan | The national approach currently uses updated business guidance and risk management. | METI published AI Guidelines for Business 1.2 in Mar 2026. It is soft law: it creates no enforceable duties and works through voluntary compliance. It applies to foreign companies operating in Japan, and it is not a presumption that a file is admissible or authentic. |
| India | The IT Rules require platforms to use clear labels and traceable metadata for permitted synthetic content. | Notified Feb 10, 2026 and effective Feb 20, 2026, giving platforms about ten days. Removal duties are broader and faster than labeling: three hours for flagged unlawful content. Further amendments proposed in Apr 2026 would require the label to stay visible for the whole duration of a piece of content. |
What changed since the last check. This is the first review after the EU rules stopped being a future date. Until Aug 2026 the honest answer to "is AI content labeled by law anywhere that matters to me" was "not yet in Europe." That answer is now different, and it comes with a supervisor and a fine attached. The Commission is also running a Code of Practice on marking and labelling AI-generated content, which is where the practical detail is being settled.
Do not over-read it either. A rule in force is not the same as a rule that is being enforced against anyone yet, and the marking grace period runs to Dec 2026 for anything already on the market.
Reader's conclusion: labels help, but honest people apply them and fraudsters may not. Do not rely on whether a label is present. Use the verification procedure in the Personal Trust Perimeter.
Content provenance: Content Credentials and C2PA
This approach signs authentic material instead of trying to catch every fake. A file carries a signed history of how it was captured and edited.
- Signature at capture is supported by some cameras from Leica, Sony, Nikon, and Canon, as well as flagship phones. Verified: 2026-07; the list is growing.
- Signature during editing is supported in Adobe Photoshop, Lightroom, and Premiere, which can read and write Content Credentials.
- Platforms: some social and video platforms display a provenance label. Verified: 2026-07.
- Honest limit: the signature reaches viewers only part of the time, and a missing signature does not prove a fake. Provenance supports reputation and procedure. It does not replace them.
Route: check someone else's file
Five steps work even when today's popular service changes:
- Ask for the original, not a forwarded copy. A forwarded video, screenshot, or file saved from chat loses much of the useful evidence: metadata, edit history, and sometimes the image quality needed for inspection.
- Read what the file can tell you. Where Content Credentials are supported, the record may show the capture device and edits. No label means "unknown," not "fake."
- Check where else it appears. Find the first publication, date of first appearance, and the same frame in another context. The most common fake is not synthetic. It is a real file with a false caption.
- Change the question. Instead of asking "Is it fake?", ask "What exactly does it prove?" Use the table in Section 5 of the Evidence Package.
- For an expensive decision, leave the file. Confirm through a channel you knew before the incident. The Personal Trust Perimeter has the procedure.
A person's signature: passkey instead of password
Provenance signs a file. A passkey authenticates a person. The cryptographic key stays on your device and is not sent to the service. A caller, email, or fake page cannot persuade you to hand over something that never leaves the device.
- Microsoft has made new accounts passwordless by default since May 1, 2025. Existing users are offered a move to the new method. Verified: 2026-07-29.
- For a Volume 3 reader, the practical value is that a passkey removes an entire class of attacks based on phishing or asking for an SMS code.
- Honest limit: a passkey protects access, not a decision. It cannot stop someone who personally approves a transfer. That requires a limit and a second channel.
Route: sign your own work
Make your material cheap to verify and a fake in your name cheap to identify. The six settings for one evening are in Step 4 of the Trust Footprint Map.
Who answers for an agent's mistake?
Legal practice is younger than the technology. A general frame is emerging: when you act through an agent, the action is treated as yours. Buyer protection comes from limits and the right to dispute a payment, not from the protocol alone.
| What happened | Outcome | What it suggests |
|---|---|---|
| An airline chatbot gave a passenger incorrect discount terms. | The British Columbia Civil Resolution Tribunal held Air Canada responsible and awarded CAD 812.02 in Moffatt v. Air Canada, 2024 BCCRT 149, Feb 14, 2024. | A company answers for what its chatbot says. "It was not a person" is not a defense. |
| A user made a car dealer's chatbot "sell" a car for $1. | The dealer did not complete the sale. This was a public incident, not a court precedent, listed as AI Incident Database No. 622 in Dec 2023. | A bot's promise does not automatically create a contract, but it can still create reputation cost. |
| Amazon challenged Perplexity's agentic shopping browser. | A preliminary injunction was issued Mar 10, 2026 in the Northern District of California, then stayed in the Ninth Circuit. As of Jul 25, 2026, there was no written decision after the June hearings. | An agent's right to act on another company's storefront remains an open question. |
What already protects a buyer, based on status in 2026-07:
- Payment networks are building agent modes around tokenized payment details and conditions set by the customer. Visa announced Intelligent Commerce on Apr 30, 2025.
- Payment providers describe payments limited to a specific purchase or a preapproved amount. Stripe published the Machine Payments Protocol in 2026.
- Consent protocols create a signed trail of intent, cart contents, and payment. Google announced AP2 in Sep 2025. This can prove what you authorized, but not that you understood it.
- Agent identification is developing separately from authority. Skyfire Know Your Agent and Experian Agent Trust are examples from 2025-2026. A signature answers "Who is this?" It does not answer "What may it do?"
Honest conclusion: none of these layers replaces two settings at home. Put a limit on the card and keep a way back, such as a card payment with dispute rights instead of an irreversible transfer. Complete the table in Section 5 of the Family Trust Protocol.
Another source of failure is instruction substitution rather than malicious intent. Text on a third-party website or in a file can change the behavior of an agent that has access to data and tools. OWASP calls this LLM01:2025 Prompt Injection. From the point of view of your wallet, "the agent made a mistake" and "someone tricked the agent" can have the same outcome.
Where to report fake reviews and extortion
Platform forms and rules change, so use the current support section:
- Map and directory services such as Google, Yandex, and 2GIS, marketplaces such as Ozon and Wildberries, and Avito provide routes for reporting a review or extortion.
- The United States has had an FTC rule against fake reviews since 2024. Russia uses general extortion provisions.
- Section 5 of the Personal Trust Perimeter covers the first steps during an attack.
Sources (verified 2026-08-18)
- European Commission guidance on Article 50 of the AI Act
- The Commission on enforcement and the new transparency requirements from Aug 2, 2026
- Code of Practice on Transparency of AI-generated Content
- Cyberspace Administration of China labeling measures
- Official Russian legal-information portal, Russian law
- U.S. Courts committee report on Rule 707, May 2026
- METI, AI Guidelines for Business 1.2
- Government of India amendments to the IT Rules for synthetic content
Responsibility for an agent's actions:
- American Bar Association analysis of Moffatt v. Air Canada, verified Jul 25, 2026.
- AI Incident Database, incident No. 622, verified Jul 25, 2026.
- Justia appeal docket for Amazon v. Perplexity, verified Jul 25, 2026.
- Visa Intelligent Commerce, verified Jul 25, 2026.
- Stripe Machine Payments Protocol, verified Jul 25, 2026.
- Google Developers Blog on agent protocols and AP2, verified Jul 25, 2026.
- OWASP LLM01:2025 Prompt Injection, verified Jul 25, 2026.
A person's signature:
- FIDO Alliance on Microsoft making new accounts passwordless by default, effective May 1, 2025; verified 2026-07-29.
Review this page once a quarter or after a material change in law. The full source catalog for the volume is here.