Our weekly Briefing is free, but you should upgrade to access all of our reporting, resources, and a monthly workshop.
This week on Indicator
We revealed that a network of over 150 automated TikTok accounts stole content from Sydney Towle, a cancer patient with more than a million followers. TikTok said it would remove all accounts as a result of the reporting by EJ Gibney. Sadly, Towle passed away Aug. 5.
Alexios teamed up with Bruna Santos and Jacobo Castellanos from WITNESS to audit the detection tools California and EU laws now require AI companies to build. They found detectors for six out of 13 companies, and successfully fooled all but one detector.
We also sent a beta edition of the OSINT Tools Radar to paid members. This is a weekly roundup of the tools added to the OSINT Navigator, our app that helps you find the right digital tool for your investigation. Give Navigator a try.

It’s raining labels
I’m a big fan of labeling as a digital safety intervention. Adding context about the author or content of a post can be pro-social and pro-speech. Besides informing users, labels serve as an infrastructure for algorithmic interventions to boost, segment, downrank, or hide content.
This week brought more evidence that labeling has become the go-to path for platforms (and regulators) scrambling to tackle an avalanche of AI content.
On Tuesday, Spotify announced that it will soon add an “AI Persona” badge to artists who self-declare as AI-generated and to those the platform determines to be synthetic. (This is done via unspecified signals in the text or imagery of the account.) By default, AI Personas will not be recommended to users.
Anthropic overshadowed Spotify’s labeling news — at least on LinkedIn, the mecca of Claude-generated banalities — by announcing it will watermark text generated with its newer models and add C2PA metadata to images. While its synthetic text will contain a machine-readable watermark rather than a visible warning, this could also be used by downstream platforms to affix labels on it. (Predictably, someone already built a skill that claims to strip the watermark by re-writing the text.)
Finally, Apple-watchers spotted language in beta code that suggests the company will soon allow users to embed provenance data into photos taken with their iPhone. This is complementary to labeling AI-generated content; it provides evidence that a photo was taken IRL.
Apple apparently chose not to use C2PA. This led Andrew Jenks, former chair of the industry coalition overseeing the standard, to call the move “stupid” because “provenance only works when the biggest players agree to speak the same language. When one of them decides to invent a new dialect — and a worse one — everyone else pays the cost.”
Sam Gregory, outgoing executive director of WITNESS, was cautiously optimistic. He wrote that being able to get the label on demand “makes sense” because it’s not always clear when you need to prove that an image is demonstrably real. And he said that while not adopting C2PA was “a missed opportunity (but very Apple-like),” the proposed iPhone feature was still promising “for the core use cases of journalism, human rights and critical content.”
To track shifting platform labeling policies, check out the Indicator guide to AI labels, which was freshly updated. — Alexios
Deception in the News
📍 Meta, TikTok, and the European Union activated crisis protocols under the bloc’s code of conduct on disinformation, following the mass crossings into the Spanish exclave of Ceuta. The voluntary mechanism gives fact-checkers a direct line to flag emerging false claims to the platforms, which then decide what to act on. Clara Jiménez Cruz, CEO of participating fact-checker Maldita.es, told Indicator that she views this as “a means to prevent harmful disinformation that can end up in deaths like the over 140 that took place after the first crossing.”
📍 A US federal court sanctioned Meta for failing to preserve information about scam ads using mining magnate Andrew Forrest in an ongoing lawsuit against the company.
📍 Fact-checkers Aos Fatos, investigative outlet Agência Pública, and two other publications launched a collaborative effort to cover electoral disinformation ahead of Brazil’s October presidential vote.
📍 In the first six months of 2026, the nonprofit British Internet Watch Foundation received 420 reports from children who say explicit images of them were generated without their consent. That’s already more than the 397 received in all of 2025. (via Henry Ajder).
📍 South Korean legislators are considering expanding a law banning deepfake porn to include explicit AI content of fictional characters. (If I understand the law correctly, it seems to go too far. — Alexios)
📍 An Australian man asked OpenClaw to book him a gym class, only for the AI agent to find a vulnerability in the gym’s booking software and kick someone else off the waitlist.
Tools & Tips
The US Treasury made a major decision on ultimate beneficial ownership data, with direct consequences for investigators.
This week it announced a rule that “permanently removes the requirement for U.S. companies and U.S. persons to report beneficial ownership information.” Even more surprising, the Treasury’s Financial Crimes Enforcement Network (FinCEN) said it would delete the beneficial ownership reports collected from US persons.
The move bucks the trend in the EU, UK, and elsewhere towards creating beneficial ownership registries, and in some cases making the data open to the public or to journalists and others with a “legitimate interest.” (See my recent guide to finding the true owner of a company, which details the state of UBO initiatives and how to access the data.)
UBO registries are a key weapon in the fight against financial crime. Even if not made publicly accessible (which is incredibly useful for OSINT), such registries provide governments and law enforcement with critical information about who actually owns an entity. The Treasury’s decision makes the US an outlier among its peers. (The department argues that banks' existing customer due diligence obligations fill the gap.)
Even if the Trump administration didn’t want to collect additional UBO information or to make it public, it’s surprising that a key financial crime enforcement agency plans to destroy existing, lawfully collected data.
The legality of Treasury’s new rule is up for debate. The Corporate Transparency Act, passed by Congress in January 2021 over Trump's veto, required companies formed in the US (as well as foreign companies registered to do business there) to disclose their owners to FinCEN.
Some legislators who passed the law aren’t happy:
This could get duked out in court.— Craig
📍 A couple of people shared useful tips for working with Overpass Turbo. Precious Vincent posted a short video walkthrough of how to use it for OSINT, and Hackers Arise published “Locating Hidden Security Cameras with Overpass Turbo.”
📍 OpenSanctions released an initial version of Funes, an open-source tool that “turns the internet into lists of politicians.” The description says it “orchestrates web capture (via the in-process Pravda async library), LLM extraction, and JSONL output to pull political position holders out of web pages.” (Via Open Journalism)
📍 Benjamin Strick published the latest edition of his monthly Field Notes newsletter. He dug into questions including “how a flight-tracking system (that we all use) really captures its data, what sits behind the glass of a watch? Who is behind a Facebook page? Who owns an aircraft flying through Sudan?” He also broke down the methodology he used to investigate 42 Facebook pages and four Facebook groups managed from Sri Lanka that falsely present themselves “Australian, British, French, Canadian, Mexican and American local community outlets.”
📍 Jeremy Hsu of Ars Technica detailed how the European Space Agency’s Copernicus Browser added a “wildfires” visualization layer. “Anyone clicking on this layer while looking at a wildfire location can see active fires in white or yellow, burning vegetation in red, and burned landscapes in dark brown or black.,” Hsu wrote.
📍 The OSINT Newsletter wrote a guide to the Library of Leaks, “a web-based search engine that indexes hundreds of publicly available breach and leak datasets so you can search masses of exposed records from a single, simple interface.” (It’s maintained by Distributed Denial of Secrets.)
📍 Oxana Korzun wrote, “Phone Numbers Talk, If You Listen.”
Events & Learning
📍 SANS is hosting a free webinar on Aug. 26, “Modern OSINT Investigations: From Website Analysis to AI-Powered Threat Intelligence.” Register here.
📍 The Association of Corporate Investigators is hosting a free webinar on Sept. 2, “Follow the Money - Using AML Laws to Smash Illegal Wildlife Syndicates.” Register here.
Reports & Research

📍 Really great investigation into the AI slop MDs of YouTube by Cody Sumter, a former product manager at several tech platforms. Sumter identified several AI-generated doctors making inaccurate or unsourced medical claims targeting seniors. He also exposed the side-hustlers who encourage people to create this type of content, did a great job scraping and coding the claims in the videos, and came up with a novel way to test if the fake docs’ names were AI-generated, which helped him find additional accounts. His reporting also highlighted a very sad series of comments by a man who ignored his wife and his (real) doctor’s guidance in favor of the fake “Dr Claire.” A must read. (via Paree Z)
📍 This preprint claims that “60.0% of reputable sites disallow at least one AI crawler, compared to just 9.1% of misinformation sites in their robots.txt files. Reputable sites forbid an average of 15.5 AI user agents, while misinformation sites prohibit fewer than one.” While the research relies on Media Bias/Fact Check to categorize sources — a methodology with known limitations — it offers evidence that AI agents may be fed a heavier diet of low-quality content.
📍 A Brennan Center audit of major chatbots and disinformation about the US election process was a net positive, concluding that “the chatbots we tested consistently pushed back against the false tropes that have been central to election disinformation campaigns. They even did so in the face of persistent questioning.“ Still, the analysis found the tools were often inaccurate and happy to assist in generating misleading imagery.
📍 A joint report by Type Investigation and MIT Technology Review details how dismantling the so-called “Censorship Industrial Complex” (aka standard content moderation practices) shifted from a fringe idea to official policy in the second Trump administration.
📍 A new analysis of AI-generated political content by Lupa found that in 20 cases, the same image or video got conflicting verdicts on whether it was synthetic or not when tested on four different AI detectors (Undetectable AI, Deepware, TruthScan, AI Image Detector and Gemini).
Want more studies on digital deception? Paid subscribers get access to our Academic Library with 75 categorized and summarized studies:
One More Thing
Indicator is a reader-funded publication.
Please upgrade to access all of our content, including our how-to guides and Academic Library, and to our live monthly workshops.






