If Anyone Can Generate Your Likeness, What Is the Correction Path for Synthetic Visuals?

This article was AI-generated as part of an experimental historical-content project. The date reflects the period being analyzed rather than the date the article was originally written.

Almost every reputation correction process starts with an address. A defamatory article has a URL. A fake profile has a handle. A Wikipedia error has a page and a talk page. The playbook, whether it ends in a polite email, a platform report or a lawyer’s letter, assumes there is somewhere the problem lives.

Synthetic images increasingly do not live anywhere.

What changed in the last three weeks

On March 25 OpenAI built image generation directly into GPT-4o, and by the end of the month it was available to all ChatGPT users. The model is very good at photorealism and, unusually, at rendering legible text inside an image. That second skill matters more than it sounds. Within days, people were posting realistic receipts for real restaurants. TechCrunch reported that it could produce one for an Applebee’s in San Francisco, with a couple of giveaways a fraudster could easily fix.

OpenAI’s system card addendum is candid about its choices. At launch, it is “not blocking the capability to generate adult public figures,” relying instead on safeguards against things like violent or sexual content, and public figures “who wish for their depiction not to be generated can opt out.” It also says all generated assets carry C2PA metadata, the industry standard for recording where a file came from.

So the question for a communications team is a practical one. If a convincing image of your CEO, your storefront or your product appears, where do you go to correct it?

Reasoning through the options

The generator. The public-figure opt-out is real, but it is prospective and it covers one company’s product. It does nothing about an image already made, or one made with another tool.

The metadata. C2PA credentials help when the original file is what circulates. Google said last year that its “About this image” feature would show when an image’s C2PA data indicates it was created or edited with AI. But a screenshot is a new file, and the credentials do not come along. Images forwarded in group chats or reposted as screenshots arrive with their history stripped.

The host. Platform reporting works once an image lands on a platform with a policy that covers it. Much of the early life of a fake happens in private messages, where there is no public post to report and no one to report it to.

The record. If a fake spreads far enough, someone writes about it. At that point the correction path reappears, because now there is a page. But the page is about the incident, and it may rank for your name for years.

That is the uncomfortable conclusion. For synthetic visuals, the conventional correction path often only becomes available after the damage has a URL.

What an identity team can prepare instead

If you cannot reliably remove the image, the realistic goal is to make the answer to “is this real?” easy to find. A few steps follow from that.

Keep an official, dated source for the visuals people might fake: executive headshots, store formats, packaging, sample documents such as receipts or invoices. A journalist or customer comparing a suspicious image needs a reference to compare it with.

Decide in advance who confirms or denies an image, how quickly, and where that statement will live so it can be indexed and linked.

Use reverse image search, including Lens, as part of monitoring, since fakes are often found by people searching the image rather than the name.

And ask your executives directly whether they want to use opt-outs where vendors offer them. It will not solve the problem, but it is one of the few preventive tools available.

In 2023 I argued that provenance was becoming the product in generative search. The same logic now applies to images, with a twist: when the fake has no provenance, yours has to be easy to find.