XDRIPACADEMY
Sign in

Curriculum·F111 AI-Era Threats and Verification·60 min

Verifying anything in the AI era

By the end of this lesson you can

  • Run the four-step trace procedure on any claim that would change what you do with money
  • Show why two sources only reduce your error rate when they are genuinely independent, and compute the difference
  • Identify the trust signals that have been decoupled from the thing they used to certify
  • Use an AI assistant as a lead generator and a skeptic without treating its output as a source
AutopsyThe Pentagon explosion image, 22 May 2023no measured loss, an intraday dip of about 0.3 percent that recovered within minutes

On the morning of 22 May 2023 an image circulated showing smoke rising near the Pentagon. It appeared to have been generated by an AI tool. It was amplified by accounts carrying paid blue checks, one of which presented itself as "Bloomberg Feed" and had nothing to do with the news organisation.

Shortly after 10am New York time the S&P 500 dropped about 0.3 percent to a session low, then rebounded as the hoax was identified. Arlington police and fire officials confirmed no explosion had taken place.

The claim was refutable by a single phone call to a fire department. The image itself had visible inconsistencies. Nobody went upstream.

The decision point has two parts, and the second is the one that generalises. People leaned on a badge that had recently stopped certifying identity and started certifying a subscription. And they read repetition as corroboration, when every one of those accounts was copying the same single origin.

Primary source

There was a time when producing something that looked authoritative took effort. A real-looking article, a believable screenshot, footage of a known person saying something: each needed skill, tools and time. That friction did quiet work for all of us. It meant most of what we saw had passed through somebody's hands.

The friction is gone. The result is not that everything is fake. It is that looking real no longer carries information.

That sounds like a loss and it is mostly a reallocation. The weight moves off "does this look legitimate" and onto "can I trace this to somewhere I already trust". The second question is a learnable procedure, and this lesson is the procedure.

Your instincts are calibrated for a world that ended

For most of your life, polish was a reasonable proxy for legitimacy. Clean design, fluent writing, a plausible quote, footage matching the story. Your brain learned to relax when those were present.

Every one of those signals is now free to manufacture. So the instinct that says "this looks professional, it is probably real" is actively working against you. Fakes are specifically strong at the surface, because the surface is the cheap part.

The same thing happened to the badge in the autopsy. A blue check once meant an institution had checked who you were. Then it meant a payment had cleared. The symbol did not change and the meaning underneath it did, which is the most dangerous kind of change, because nobody has to notice for it to stop protecting them.

Ask this about any trust signal you rely on: what, specifically, does the party issuing this signal verify, and when did they last change that? Domain names, verified badges, app store listings, "official" support handles, and lock icons in a browser bar have all shifted in what they certify. F104's autopsy is a fake Ledger Live that came through the official Mac App Store, which is the same failure wearing different clothes.

The procedure: trace, do not trust

When something matters enough to act on, and especially when it touches money, accounts, or anything you cannot undo, run this. Under a minute once it is a habit.

1. Find the original source, not the messenger. A screenshot of an announcement is not the announcement. A clip is not the press release. Go to the origin: the project's own site, the official account, the primary document, the filing. If a claim cannot be traced to a real origin, that absence is your answer.

2. Confirm it somewhere genuinely independent. One source can be wrong or fabricated. Two independent credible sources reporting the same thing is a different level of confidence. Independence is the load-bearing word, and the arithmetic below is why.

3. Reach sensitive destinations through your own door. For anything asking you to log in, send funds, or connect a wallet, the address is the identity and the page is just paint. Type it yourself or use a bookmark you saved earlier. Never arrive at a sensitive destination via a link you were handed.

4. Ask what the source gains from your speed. Every message has a motive. Someone urging you to buy now, move now, or act before a deadline has an interest in your haste. That interest is information. Slow down in proportion to how hard you are being pushed.

Worked example
Why 'two sources' is not a count

Suppose any single source you consult has a 10 percent chance of being wrong on a given claim.

Two genuinely independent sources. Independent means the second did not learn it from the first: a different reporter, a different method, a different origin. The chance they are both wrong is:

0.10 x 0.10 = 0.01 = 1 percent

Your error rate fell by a factor of ten.

Two dependent sources. The second copied the first. If the first is wrong, the second is wrong with near certainty. So:

P(both wrong) = P(first wrong) = 10 percent

You consulted twice and learned nothing. The number of sources went from one to two and your error rate did not move at all.

Now extend it, because this is what actually happens online. Ten accounts, all repeating one origin:

P(all wrong) = 10 percent, unchanged, whatever the number of accounts

The confidence you feel scales with the count. The information does not scale at all. In the autopsy that gap between felt corroboration and actual corroboration is the entire failure, and it is worth more than any visual detection skill you could learn.

The practical version: before you count a second source, ask where it got the claim. If the answer is the first source, it is not a second source. It is an echo.

A screenshot is not evidence

Screenshots of messages, balances, endorsements and news are among the easiest things to fabricate, and they spread fastest because they feel like proof. Treat any screenshot as a claim to be checked at its origin, never as the check itself. This applies with special force to screenshots of profits.

Using AI to check AI, carefully

An assistant can help you verify, but only if you hold it in the right role. It can state something false with complete confidence, produce a real-sounding citation that does not exist, and be out of date. It is a research assistant, not a witness.

Three uses that hold up.

As a lead generator. Ask where an official announcement would live, or what the real address of a service is, then go and confirm that yourself at the origin.

As a skeptic. Paste a suspicious message and ask what techniques it uses and what it is trying to get you to do. Models are good at naming the pattern, and naming the pattern breaks the spell of a convincing one.

As a translator. Ask it to put a confusing term in plain language so you can judge a claim on its merits rather than being excluded by vocabulary.

What you never do is treat its answer as the fact. The model points at sources; the sources, checked at their origin, are what you trust. And be aware that the assistant itself can be fed instructions by the content it reads, which is the whole subject of F111-05.

Common misconception

I can just use a deepfake or AI-content detector.

Detectors exist and some are useful in forensic contexts with the original file, a chain of custody, and an expert reading the output. That is not your situation.

Consumer-facing detectors produce both false negatives and false positives at rates that make a single verdict unsafe to act on, and their performance degrades against each new generation of tools while yours does not improve. Worse, a "probably authentic" verdict actively harms you, because it manufactures confidence where you previously had appropriate doubt.

Trace the claim instead. It works on a real image, a fake image, and an image nobody can classify.

Make it a reflex, not a policy

You will not run a four-step audit on every post you scroll past, and you should not try. The procedure is for the moments that matter: a message about your money, an account warning, an opportunity that needs a decision today, a video that would change your behaviour if it were true.

For those, the reflex is short enough to hold under pressure. Trace it to the origin, confirm it somewhere independent, and reach anything sensitive through your own door.

Practise it on things that do not matter, so it is automatic on the one that does.

Key takeaway

Looking real stopped carrying information, so verification moved from perception to procedure: trace the claim to its origin, confirm it somewhere genuinely independent, reach any login or payment through an address you typed yourself, and read urgency as a motive. Independence is the word that does the work, because ten accounts repeating one origin leave your error rate exactly where it started. Check what your trust signals actually certify, because several of them quietly changed. And treat an AI assistant as a thing that points at sources, never as one.

These come back later

State the four-step trace procedure.
Find the original source rather than the messenger. Confirm it somewhere genuinely independent. Reach anything sensitive through a door you opened yourself. Ask what the source gains from your speed.
Why is 'two sources' not automatically better than one?
Because ten accounts repeating one origin is still one source. The error reduction comes from independence, not from count. Two dependent sources leave your error rate exactly where it was.
What does 'this looks professional' tell you now?
Almost nothing. Polish is the cheap part and it is the part generation is best at. The only durable signal is whether the claim traces back to an origin you already had reason to trust.

Sources and review

Confidence high·Volatility medium·Reviewed 2026-08-05·Owner unassigned

Contested

The image is described as AI-generated by most reporting on the basis of visual analysis, not on a recovered provenance record. It has never been definitively attributed. Say 'apparently generated', and note that the lesson does not depend on how it was made.

The 0.3 percent move is a reported intraday dip that recovered within minutes. It is not a measured loss and no dollar figure should be derived from it. Do not turn it into a headline number.

Track your progress

Create a free account to mark lessons complete and pick up where you left off.