Likeness Attestation · Triodian

Solution · At the point images are released

Every image checked for a real face, with proof, before release.

Appliances sit inline at the emission boundary, beyond the operator's reach. Each detected face is resolved against a public reverse-image corpus; a match to a real person withholds the token and blocks release. Cleared assets carry the token embedded inside them, so anyone downstream can verify it later.

Discuss a deployment → How verification works ↓

The governance app

Live likeness screening, watched at the emission boundary.

Screen Console, live likeness screening at the Grok facility emission boundary: appliance pool, sampled asset stream, disposition plane and per-face panel

Screen Console · governance read-only · illustrative data

How this is an embodiment of the Semantic Enforcement Suite

The same Suite, re-pointed to a new choke point.

The Aggregate Drift suite answers "has the set of an optimiser's instructions drifted out of the declared appetite?" This suite answers a sibling question at a different choke point: "Did this generated image or video depict a real, identifiable person, and can an outside party verify that the check ran before the asset left the building?"

The same inversion the whole family sells. We do not ask the image model to promise it will not produce real-person likenesses; instead a cluster of Semantic Enforcement Appliances sits inline at the emission boundary, outside the model operator's software reach.

The Engine's verdict logic is re-pointed: instead of allow/redact/deflect/block on a chat output, the Engine screens each asset, faces detected, each face resolved against a public reverse-image corpus, any face resolving to a real person is a gate event: the compliance token is withheld and the asset cannot be released.

The Appliance is the same deployed unit: default state blocking; no token, no release; the check declared in advance, run deterministically before actuation, recorded verifiably, the same three guarantees the meaning check makes everywhere else.

Same constituent apps, re-skinned: Likeness Report (↔ Oversight/Aggregate Drift Report), LK Concepts (↔ Semantic Library), Screen Console (↔ the governed-application seat), Attestation / Token Record / Interlock / Hardware / Provenance Ledger / Triage (unchanged mechanics), plus two new surfaces the oracle lane demands: Oracle and Consent Registry, and a public Verify page.

Built on the Semantic Enforcement Suite →

Why this deployment, why now

The exposure is at the door, and the law now asks for proof.

The exposure is at the emission boundary, not in the model

Guardrails lower the rate of real-person likeness generation; they cannot reduce it to zero or say which outputs were the exceptions.

The regulatory surface has hardened

US TAKE IT DOWN Act, state NCII and digital-replica statutes, EU AI Act Art. 50, AU Criminal Code deepfake amendments all converge on one operational question: can the operator prove, per asset, that a real-person screen ran?

The check cannot live inside the operator's software

Logs are testimony from the accused; the appliance sits beneath the software, at the boundary where output becomes a released asset.

The rules it enforces, LK (Likeness)

Six controls the appliance checks every asset against.

IDControlTier
LK-001Resolved-likeness prohibition, no asset with a face resolving to a real person gets a token, absent a consent match.Semantic + oracle lane
LK-002Consent-registry release, a resolved face releases only against a valid, unexpired, scope-matching consent artefact.Rules
LK-003Minor-likeness absolute bar, any face classified minor is an unconditional gate event; no consent, no override, no appeal on the appliance.Rules + semantic
LK-004Composite-reconstruction drift, a session whose passing outputs converge toward one real identity is a set-level gate event even though every asset passed.Set-level (Aggregate Drift)
LK-005Attestation completeness, every released asset carries a verifiable embedded attestation; an unattested asset at the edge is a reconciliation event.Rules
LK-006Oracle-health floor, tokens issue only while the oracle lane holds its certified operating point; degradation demotes the tier, never fails open.Rules

LK-002/-005/-006 are rules-tier (decidable); LK-001 is a detection lane with an external oracle (certified miss-rate, not a proof); LK-004 runs on the unmodified Aggregate Drift Service; LK-003 combines a rules gate with abstention discipline.

What's different about this one

The distinctive machinery.

Placement, a separate enforcement enclosure

An N+1 pool of SEA-2800-P cards (SEA-GRK-01…04) in a physically and logically separate cage, its own rack, management network, signing keys, measured boot, no operator credentials. The operator's stack sees only an API and a yes/no. Inline, single-pass, fail-closed: the only route from render farm to CDN traverses the enclosure.

The five-layer identity pipeline

Adapter → identity evidence → evidence normalisation → identity decision → governance decision. The split isolates the one probabilistic link (the identity decision, bounded by a calibration certificate) from the deterministic governance decision above and the untrusted oracle below.

The oracle, governed as evidence not as a trusted party

The reverse-image corpus is reached only through an OracleAdapter contract: the adapter proposes, the card disposes. Swapping the corpus is a configuration-and-certification event. Each adapter loads only with its own non-transferable calibration certificate; adapter disagreement abstains to review, never averages into a pass.

Certified miss-rate, not a tuned threshold

τ_id is calibrated via distribution-free risk control over a labelled corpus, yielding a certified miss-rate α at confidence δ, with an honest effective sample size and a stated adversarial scope limit.

Fallback ladder

Nominal → reduced-oracle → hold-and-queue → rules-only refusal. Every rung attested; no rung lets a face pass unscreened. Outage degrades throughput, never assurance.

The token, embedded in the asset (two bindings)

Hard binding: a C2PA-conformant manifest whose claim signature is the on-card HSM signature, the operator cannot mint it because it never holds the keys. Soft binding: an imperceptible watermark carrying the token_id, robust to a declared transform budget, so a stripped asset still resolves via the Attestation Lookup service.

The later check ("Verify")

A public endpoint + reference CLI/SDK: validate the C2PA chain to the Foundation root, recompute hashes, fall back to watermark lookup, check the ledger anchor, return the verdict card, "screened against <oracle_lineage> on <date> under LK envelope <versions>, calibration α/δ, chain ✓."

Set-level control (LK-004)

The unmodified Aggregate Drift Service runs over the identity-embedding stream per session: convergence toward a single external identity gates the session's token issuance even though every individual asset passed, the Sorites blind spot the platform exists to name.

See it running

A six-surface demonstration suite, who sees what.

The suite screens generated images and video for resolved real-person likeness at the emission boundary and records a verifiable disposition. It does not author, edit, or remediate content, and makes no claim that no real person is depicted, corpus coverage is bounded and stated on the token.

Governance

Screen Console

Live sampled stream, per-face verdicts, drift plane.

Governance

Likeness Library

Concept cards, consent registry, oracle adapters.

Governance

Enforcement Engine

Attestation ledger, tokens & hardware interlock.

Governed application

Generation Studio

The generation endpoint, the enforcement point.

Oversight · regulator

Regulator Oversight

Cross-endpoint roll-up & obligation map.

Inspector · public

Verify

Public downstream check, drop an asset, royalty-free, no sign-in.

The Sorites payoff

Every asset passed the per-face screen. The set did not. Steps 1–2 pass and release; step 3 resolves to a real person and is withheld at the boundary; step 4's twenty individually-passing variations trip the set-level LK-004 control and the session token is HELD. The appliance never authored anything, a blocked asset is the operator's problem upstream.

The demonstration console uses an instrument palette by design, this is the operator/regulator seat, not marketing. The detection lane is a calibrated signal with a certified miss-rate, never a proof of correctness.

What the proof does and doesn't say

Honest boundaries.

Claimed

The declared screen ran, in hardware, before release; its result gated the token; the named oracle/envelope/calibration/registry versions are exactly those; the asset bytes are exactly those hashed; the record is anchored in a tamper-evident ledger; no facility software could suppress or reorder it.

Not claimed

That no real person is depicted (every corpus is incomplete; a private individual with no indexed imagery cannot resolve); robustness against a white-box adversary beyond the stated budget; soft-binding survival beyond the declared transform budget; any judgement about content other than resolved likeness.

Screen at the emission boundary.

Discuss a deployment →
Built on the Suite High-Security Operational Assurance
Demonstration scenario

The deployment described, a generative-media provider's data centre referred to as "the Grok facility", is a hypothetical reference deployment for specification purposes. No affiliation with xAI, Google, or any real organisation is implied. Google Images is referenced as the canonical example of a public reverse-image corpus; the oracle interface is defined generically.