Our weekly Briefing is free, but you should upgrade to access all of our reporting, resources, and a monthly workshop.
This week on Indicator
Corporate investigator Dan Greenberg detailed five ways AI can assist with investigative due diligence, including examples from real world cases. He also shared guidance to make sure you don’t take things too far with AI.
Craig shared the video, transcript, and slides from our July members-only workshop. He showed how to apply our new guide, “The Indicator Framework: How to tell what your digital evidence is actually worth,” in order to weigh the strengths and weaknesses of digital indicators.
Paid members should check out a special beta preview of Data Navigator, a new Indicator tool that lets you query public datasets to assist with investigations. It’s part of our partnership with Tom Vaillant of Buried Signals.

Minnesota’s state capitol (Photo by: Michael Siluk via Getty Images)
Musk sues Minnesota instead of putting guardrails on Grok
On Monday, lawyers for xAI filed a lawsuit challenging a new Minnesota law targeting AI services that allow the generation of deepfake nudes. Unlike the federal Take It Down Act that criminalizes the dissemination of deepfake nudes, HF1606 puts the responsibility on the people who enable their generation.
Enter Elon Musk. According to his lawyers, the bill “imposes an overbroad, content-based ban on free speech and the tools of visual expression.” xAI said that because of the bill, it “has no practical choice but to restrict Grok Imagine’s image-editing features in various ways” and that “protected speech freely available before the law takes effect will thus be chilled.”
xAI cares as much about free speech as I do about cream in carbonara. The company is trying to avoid the $500,000 fines that it could face for each deepfake nude of an identifiable person generated with Grok. Musk’s image generator enabled the creation of millions of sexualized images earlier this year; Wired found it was still hosting these kinds of images as recently as June. The company could easily be on the hook for millions of dollars in fines unless it places major new guardrails on Grok.
And it’s not just X. Indicator’s reporting has shown how all kinds of platforms have failed to tackle generators of synthetic nonconsensual intimate imagery (SYNCII). To date, their efforts haven’t made a significant dent in the creation, distribution, and monetization of this form of sexual abuse.
But let’s set aside the brazen and self-serving nature of xAI’s lawsuit and the failures of tech platforms in general. Does Minnesota’s law go too far?
Riana Pfefferkorn of Stanford’s Institute for Human-Centered Artificial Intelligence certainly thinks so. She called the law “ridiculously unconstitutional,” arguing that it “clumsily tries to target deepfake ‘nudify’ sites but ends up outlawing a broad swath of legal speech.” Pfefferkorn said that the law also doesn’t mention the question of consent, making it a de facto ban on porn.
I value Pfefferkorn’s expert opinion, but I started off skeptical of her argument. I have spent several years analyzing this industry of abuse and have yet to stumble on a convincing consensual use case for nudifier apps. If you want someone’s nude and they’re OK with you having it, you don’t need AI to generate it for you.
So I emailed Pfefferkorn, who raised the hypothetical of closeted trans individuals who want to explore what their body might look like if they transitioned, or the documented instances of sex workers sharing Grok-generated nudes of themselves on X. Lawyer Kathryn Tewson provided several more examples in a Bluesky thread worth reading in its entirety.
These are all, to me, edge cases. I worry that by repealing laws targeting tools that are 99% abusive just so that we can protect unlikely use cases we are throwing out the baby with the bathwater.
Pfefferkorn told me in an email the lawmakers could have done a whole range of things to avoid these concerns, including “specify that it’s limited to nonconsensual conduct, include knowledge and intent requirements, and include carve-outs for protected speech. Minnesota lawmakers know how to write that language: they did so in the state’s revenge porn law, which is why it survived a constitutional challenge.”
“If you want to outlaw nonconsensual deepfake porn, which I wholly agree is almost all deepfake porn,” Pfefferkorn said, “then have the law actually say that!”
Beyond the issue of consent, there are other carveouts that the lawmakers could have considered. Some of these are mentioned in the lawsuit itself, like this post depicting Chris Christie and JB Pritzker as sumo wrestlers. Because it represents intimate parts not in the original image, it could run afoul of HF1606. While crass, this type of political humor is certainly not the main harm of ‘nudification’ technology.

Mike Masnick of Techdirt raised similar concerns, arguing that the law doesn’t pass the “strict scrutiny” test used to assess laws limiting First Amendment rights. This requires laws to take “the least restrictive means” necessary to meet their objective.
In that sense, if the goal of HF1606 is to prevent abusive deepfake nudes, it should have included clear exemptions for consensual use cases and parody.
I got similar feedback from my favorite internet lawyer, James Grimmelmann of Cornell Tech. He said that xAI’s complaint “makes some valid points about the breadth of the law. Its definitions cover services that could be used to generate consensual nude images, to generate nude images with scientific or political value, or to generate images that aren't actually nudes. At the very least, this raises genuine questions about how narrowly tailored the law is and whether there are less restrictive alternatives.”
Still, Grimmelmann added that “Minnesota has a plausible argument that banning the apps at this level of generality is necessary to prevent misuse, but it's a question requiring actual arguments on both sides.”
He emailed me later in the day noting that “the more I read, the more I think xAI has strong arguments.”
And so we turn to the court system. For now, the law is set to go into effect tomorrow. But it’s possible that a federal judge puts it on hold while the arguments are heard. Minnesota seems ready to fight, with governor Tim Walz responding to Musk’s lawsuit by tweeting “see you in court, creep.”
Minnesota is not the only battleground in the legal pushback against this industry of abuse. The EU is all set to ban AI nudifiers, while California’s AB 621 makes digital service providers liable if they knowingly provide services to these tools of abuse. — Alexios
Deception in the News

📍 LinkedIn launched a reporting option called — I kid you not — “Seems like AI slop.” This feels like a bit of a desperate reaction to the recent news articles driven by this Pangram analysis claiming the platform was inundated in synthetic posts. The sloppy rollout (it looks like media reporting may have forced the company to post about it), the choice of a term that’s hard to define in a menu of otherwise pretty straightforward options, and the fact that this doesn’t seem to have been rolled out globally suggests to me this was a test that got caught rather than a fully-baked product launch. — Alexios
📍 Brazil’s former president Jair Bolsonaro is under house arrest and cannot communicate publicly in support of his son Flávio’s presidential campaign. So Flávio used an AI avatar of his dad at a rally on Saturday. The opposition has presented a legal challenge.
📍 It’s a big week for AI transparency as regulations go into effect in California on Saturday and the EU on Sunday. Among other measures, both laws will eventually require AI companies to embed machine-readable provenance data in content generated with their tools and large social media platforms to display that information to users. In March we showed that some companies were still behind on implementation. Expect more audits from us in this space.
📍 AI text detector Pangram raised another $9 million in funding and has expanded to synthetic image detection. The company continues to serve as a high-profile proxy for the field as a whole. Princeton’s Arvind Narayanan ran some tests on Pangram and posted that he is now less skeptical of text detection, while blogger Freddie deBoer called the tool “brittle” after it implausibly flagged excerpts of his essay as AI-generated while rating the full text a 100% human-written.
📍 Meta launched Facebook Verified, a feature that uses facial recognition to match an uploaded video selfie with a user’s profile pictures. The company claims this free service will validate that there is a human behind a verified account.
📍 Australian doctors say that social media misinformation is leading more parents to resist administering vitamin K to their newborns. One influencer called the shot, which helps with blood clotting, a “murder weapon.”
📍 US Senator Adam Schiff introduced two bills related to transparency in online political speech. One proposal requires influencers to disclose any posts paid for by a political committee, while the other prohibits “AI-generated fraudulent advertising which uses the likeness or voices of candidates to misrepresent their positions, campaigns, or causes, or otherwise misrepresents a candidate’s point of view.”
📍 Top record companies want to disqualify AI-generated music from charts of the most popular songs unless there was a substantial human contribution. Meanwhile, fans of human music are creating databases of likely synthetic tunes.
📍 Futurism reports that the defunct website for Cambridge Analytica has been resurrected as an AI slop content farm.
📍 An article falsely claiming French presidential hopeful Édouard Philippe has dementia got more than 1.2 million views across 82 posts on X, per NewsGuard. The tactic matches known Russian propaganda efforts.
Tools & Tips

The Institute for Strategic Dialogue launched a new version of the Authoritarian Interference Tracker. It’s a free, open-source database “that catalogs publicly documented incidents of state-sponsored interference carried out by Russia, China, and Iran in Europe and North America.”
The Tracker offers a variety of visualizations and ways to filter the data, which currently reflects incidents since 2022. You can sort by the state actor (China, Iran, Russia) and by the type of incident (cyber operations, information operations, malign finance etc.).
It also displays a list of incidents sorted by most recent:

📍 RecentReborn offers the ability to see recent Instagram posts, reels, TikToks and YouTube videos. It has a limited free tier. (via Cyber Detective)
📍 Lighthouse Reports and the Data and Research Center released a freely searchable dataset of documents from 239 lawsuits filed by food and beverage companies across six countries. The files were gathered as part of Lighthouse’s Big Food vs. The People investigation.
📍 MailAccess is a “Self-hostable OSINT platform for investigating email addresses.” Saad Sarraj said it’s useful because it “analyzes multiple sources and builds an identity graph showing why certain accounts are likely connected.”
📍 Google added image generation capabilities to Google Earth. I’ll say it again: you can now use the Nano Banana model to alter the real imagery in Google Earth.
Henk van Ess spotted the Google announcement and took the feature for a test drive. He said it will “lead to governments, factions fighting infowars, trolls etc.”
Why make it easy to manipulate satellite imagery? Here’s what Google Earth product manager Bryan Horowitz said in the announcement:
Have you ever looked at an empty lot in your neighborhood and imagined a community garden, or wondered what your city looked like a century ago? Now Nano Banana 2’s image generation capabilities in Google Earth can show you both — and so much more.
He cited use cases such as creating “custom infographics,” helping students “visualize the past instead of just reading about it,” and “professional real estate plans.”
Blake Spendley, the head of OSINT at Hunterbrook who runs the @OSINTtechnical account on X, summed up the reaction from the community: “Unbelievably irresponsible and does immediate, catastrophic damage to the credibility of satellite imagery.”
The bottom line is that, after spending years building up a trustworthy, free repository of satellite imagery, Google just made it trivially easy to generate convincing fakes. — Craig
📍 Bellingcat published a video, “Monitoring Wildfires Using Open Source Tools.” It covers using NASA FIRMS, Satellite imagery, social media verification, and more. Watch it here:
Events & Learning
📍 UserSearch.com is hosting a free webinar on Aug. 4, “How to Investigate a Suspect Online: A Live Walkthrough.” Register here.
Reports & Research
📍 A new study in Science Advances contains results from a unique research effort that studied misinformation on Facebook and Instagram during the 2020 election.
The paper has three main findings. First, a minority of users consumed the vast majority of content published by untrustworthy sources. (Sources were categorized as “untrustworthy” if they were debunked at least twice by a verified signatory of the International Fact-Checking Network’s code of principles.)

Second, even though Meta reduced amplification of some of the sources as part of its fact-checking program, the researchers tested an additional intervention that removed the content from some users' feeds entirely. It led to a 70% reduction in their reach.
Finally, and probably most consequentially, this reduction in exposure did not appear to have a substantive effect on the tested population’s belief in false claims or trust in news media. The researchers caution that their findings “provide limited guidance about the effects of removing third-party fact-checking altogether.” (The nuanced discussion section is worth reading in full).
I have a lot of half-baked thoughts about the paper that I will likely return to but it is certainly not a resounding endorsement of combating clickbaity social media misinformation by reducing its reach at the source level. — Alexios

📍 AI-generated doctors and healers peddling questionable wellness hacks and shady supplements are thriving on Instagram and TikTok according to separate investigations by Maldita and 404 Media.
📍 The Tech Transparency Project found that GatherOne, “one of roughly a dozen Chinese ad agency firms authorized by Meta to place ads on behalf of Chinese clients,” was behind at least 7,600 ads for AI nudifiers that ran on the platform. The company won several awards at a summit held by Meta in January.
📍 AI Forensics found that a majority of image generating “Spaces” on Hugging Face, including 7 of the 9 top-ranked ones, had no guardrails preventing the generation of nonconsensual deepfake nudes. The organization then created a dummy image generating space of its own — that did not actually produce any outputs — and found that 60.6% of the roughly 1,000 requests were for nonconsensual deepfake nudes.
📍 In a preprint, researchers at the University of Southern California profiled the “counter-misinformation ecosystem” on Twitter in 2020-2021 around COVID-19. They found corrective responses were typically more negative in tone and came from more established users.
Want more studies on digital deception? Paid subscribers get access to our Academic Library with 75 categorized and summarized studies:
One More Thing
You don’t need to be a geography whiz to spot issues with a map of Africa that was displayed by the US State Department at an international AIDS conference in Rio de Janeiro.
Reuters writes that the map, which gets both the location and the shape of highlighted countries wrong, “contained an artificial intelligence watermark that signals it was made with OpenAI tools.” (h/t Brian Dolan).

Indicator is a reader-funded publication.
Please upgrade to access all of our content, including our how-to guides and Academic Library, and to our live monthly workshops.


