Most platforms can detect harmful AI-generated content. Far fewer can trace where it came from, document what happened next, or prove any of it to a regulator—and that gap is where compliance exposure becomes enforcement liability.
Key takeaways
- Detection identifies potential violations, but it doesn’t explain where content originated, whether it was altered, or provide the audit trail enforcement and regulatory compliance required.
- Human-in-the-loop governance turns AI detection into consistent, defensible enforcement by applying context, policy judgment, and oversight where automation alone falls short.
- A focused pilot combining provenance technology with human review workflows allows organizations to validate the approach, measure operational impact, and scale with confidence.
AI-generated content has fundamentally changed trust and safety. The volume is higher, the harm is harder to trace, and the regulatory clock is ticking. For executives accountable for platform integrity, the pressure to act—and to prove it—has never been greater.
Counterfeit and pirated goods that infringe intellectual property rights account for an estimated $467 billion in global imports annually—roughly 2.3% of worldwide imports. More than 700 million downloads of AI nudification apps have been recorded, and one in eight teens knows someone who has been targeted by AI-generated deepfakes. These aren’t edge cases. They’re a systemic risk that existing tooling wasn’t built to handle at today’s scale.
The risk landscape has shifted
The categories of harm have expanded, and so has the liability that follows them. Non-consensual intimate imagery (NCII), AI-generated deepfakes, brand impersonation, and synthetic advertising are proliferating across platforms and forums. Generative AI tools make this content fast, convincing, and cheap to produce. As volume grows, so does enforcement complexity.
Regulatory pressure is accelerating at the same time. The Take It Down Act mandates a 48-hour response window for NCII and deepfake takedown requests. The EU AI Act introduces new transparency requirements for AI-generated and manipulated content, while the Digital Services Act imposes additional obligations on the largest online platforms operating in the EU.
Organizations that fall behind aren’t only facing reputational risk. They’re facing compliance exposure with hard regulatory deadlines attached.
Detection is necessary, but not sufficient
Most platforms have detection in place. The problem is that detection only tells you something may be wrong. It doesn’t answer the questions that actually drive enforcement: Where did this content originate? Who created it? Was it shared with consent? Has it been altered?
Without those answers, investigators work blind. False positives rise. Edge cases stall. And when regulators ask for an audit trail, there often isn’t one. Fragmented tooling compounds the issue. Detection, policy, escalation, enforcement, and reporting often operate in separate systems with misaligned data. That fragmentation creates blind spots and slows decisions at exactly the moment speed matters most.
In an environment with a 48-hour takedown window, detection without provenance creates liability.
Companies are going to start to get more accountable for how their technology enables harms on their platform.
Melanie QuandtSenior Director, Trust & Safety
Highspring
How provenance changes the equation
The attribution problem that detection can’t solve alone is what content provenance addresses. SASHA embeds an invisible, 128-bit cryptographic signature at the pixel level when content is created or published. That signature survives the transformations that defeat traditional watermarking: screenshots, crops, compression, and format changes. It can be decoded from any copy of the content found anywhere on the web.
The result is complete traceability. If an image appears in a fake ad, on a forum, or across a social platform, teams can identify where it originated, how it traveled, and whether it was altered. Think of it as a passport for content. It doesn’t just flag a problem—it tells the full story behind it. That’s what enforcement actually requires.
At the core of it all, what we are trying to do is answer two questions for every image that’s on the internet: one, where did it come from, and what was the intent behind which it was shared?
Shiva KumarDirector of Enterprise
SASHA
Operationalizing enforcement at scale
Provenance creates the foundation. Human governance turns that foundation into defensible outcomes. Highspring structures its human-in-the-loop (HITL) model across four phases that take a violation from signal to resolution.
Detect. Automated systems identify risk and correlate signals across tools and evidence sources at scale.
Investigate. Human specialists review context, intent, and severity, identifying patterns and escalating high-risk cases that require policy or legal judgment.
Decide. Human experts evaluate edge cases, apply policy nuance, and produce decisions that can withstand regulatory scrutiny.
Resolve. Execute governance by removing, remediating, or reporting as appropriate. Insights from each resolved case feed back into models and policies to improve future detection accuracy.
This structure isn’t just a moderation framework. It’s the operational accountability regulators expect when they ask how a violation was handled and whether an organization can prove it.
Fundamentally the human becomes the QA, the human becomes the force multiplier for a lot of these AI things.
Carson AftDirector of AI and Analytics
Highspring
A practical path forward
For organizations looking to close the gap, the starting point doesn’t have to be a full-scale transformation. A 30-to-60-day pilot scoped around a single use case—IP protection, brand protection, NCII response, or content authenticity—is enough to generate real results. SASHA’s provenance encoding and Highspring’s HITL review workflows are deployed together, with success metrics defined upfront: time-to-resolution, false positive rate, and takedown completion within regulatory windows.
That structure produces three things: proof of concept, operational confidence, and a repeatable model ready to scale. The most common mistake organizations make is trying to solve every trust and safety problem at once. A focused pilot generates the evidence needed to build an internal case for broader deployment and to demonstrate compliance readiness to regulators, partners, and legal teams.
How Highspring and SASHA can help
SASHA provides the cryptographic provenance and content authentication infrastructure. Highspring provides the human-at-the-helm operations, policy enforcement, and governance workflows. Together, they deliver continuous platform monitoring, policy mapping across IP, DMCA, and NCII categories, legal escalation, and audit-ready reporting.
If your team is ready to start the conversation, contact Highspring today.
Related insights
Watch From Detection to Enforcement: Protecting People and Brands in the Age of AI, where Highspring’s Melanie Quandt and Carson Aft are joined by SASHA’s Shiva Kumar for a full walkthrough of real-world workflows, a live demo, and a closer look at how a focused pilot can deliver measurable results.



