I approve this message. Prove it.
American political advertising has required a named human to take personal responsibility for the message since 2002. The requirement assumed the voice saying the words belonged to the person claiming them. That assumption broke in January 2024, and the law has not caught up.
The call that arrived two days before the primary
On 21 January 2024, phones rang across New Hampshire. The voice on the line was familiar. It had the cadence, the pauses, the particular way of leaning into a phrase. It told the person who answered that voting in Tuesday's primary would not help, that they should save their vote for November.
The voice belonged to nobody. It was a synthetic imitation of President Biden, generated with commercially available tools, dialled out through ordinary telephony infrastructure to registered voters in a state that was about to hold a presidential primary. The Federal Communications Commission subsequently pursued enforcement against the political consultant behind the calls, issuing a forfeiture order that reporting put at six million dollars, and a separate court proceeding produced a much smaller judgment of twenty two thousand five hundred dollars, which reporting indicates went unpaid.
Here is the part that should bother you more than the fine. Every voter who picked up that phone had, in principle, a way to evaluate the call. American political messages carry disclosure. Broadcast ads for federal candidates include a spoken statement in which the candidate identifies themselves and says they approved the message. Print and digital carry a "paid for by" line naming the committee. This is not decoration. It is a statutory scheme, built deliberately, precisely so that a named human being stands behind political speech and can be held accountable for it.
The scheme has one unstated dependency. It assumes that a voter hearing a candidate say "I approve this message" can tell that it is the candidate saying it. For twenty two years that assumption held, not because anyone verified it, but because faking a recognisable politician's voice convincingly enough to fool a voter was expensive, slow, and required skills that were rare. The disclosure requirement outsourced verification to the human ear.
The human ear is no longer up to the job, and it is not going to get better.
Voters cannot currently verify that a political message was approved by the candidate. The spoken disclaimer is a claim, not a proof, and anyone who can clone a voice can clone the claim along with it. The only thing that would let a voter, broadcaster, or platform check is a signature from the committee over the specific file, published so it can be verified without asking anyone.
Why does "I approve this message" exist at all?
The requirement came from the Bipartisan Campaign Reform Act of 2002, in a provision usually called "stand by your ad." The reasoning behind it is worth understanding, because it explains what the mechanism was actually for.
Before 2002, a candidate could run a brutal attack ad and keep a comfortable distance from it. The ad existed, the damage landed, and the candidate could shrug. The theory of stand by your ad was that if you force the candidate to appear on camera, in their own voice, personally claiming ownership of the message, two things happen. Voters learn who is responsible. And candidates, knowing they will have to say the words themselves, moderate their worst instincts.
Whether it achieved the second goal is debatable and has been debated at length. What matters here is the first. The Federal Election Commission's disclaimer rules, at 11 CFR 110.11, set out who must include what, on which kinds of communication. The design is an accountability mechanism resting on identity: this message belongs to this named person, who has said so.
The mechanism was a social one, not a technical one
Notice what the law did not do. It did not create a registry of approved messages. It did not require broadcasters to check anything. It did not give voters a way to confirm the claim. It required the claim to be made, and then relied on the practical difficulty of impersonating a public figure to keep the claim honest.
That is a perfectly sensible design for 2002. Security controls always rest on some assumption about what an adversary can afford to do, and in 2002 the cost of a convincing fake was high enough that the assumption was sound. What has happened since is not that the law was repealed or weakened. It is that the assumption underneath it quietly stopped being true, and nobody rewrote the law, because the law still reads fine.
This pattern shows up throughout the Identity Failure Map. A control works for years, the cost of defeating it collapses, and the control keeps operating with the same words and none of the effect. The disclaimer is a particularly clean example because the words are literally a claim of authorisation, and there has never been anything behind them.
What does a disclaimer actually establish?
Almost nothing, once you look closely.
A spoken approval in an ad is audio. If an adversary can synthesise the candidate's voice for the body of the message, they can synthesise it for the approval statement. The statement is not a separate channel with separate security. It is the same audio stream, produced by the same process, and it costs the forger nothing additional.
The "paid for by" line is text overlaid on video or printed on a mailer. Text is trivially forgeable and always has been. What has historically constrained it is not technical difficulty but the traceability of the printing and mailing supply chain, and the fact that a real committee will notice and complain. Neither constraint applies to a robocall placed from anywhere.
So the disclosure regime is doing something real, which is telling honest actors how to identify themselves, and something imaginary, which is preventing dishonest actors from claiming an identity that is not theirs. It was always the first. We only mistook it for the second because the second used to be hard for unrelated reasons.
Why can't detection solve political deepfakes?
The obvious response is to build a detector. Analyse the audio, spot the artefacts, flag the synthetic ones. Platforms have deployed variants of this, and vendors sell it energetically.
We have written at length about why this class of control loses in Detection debt, and political media is one of the worst domains for it, for three compounding reasons.
The timeline is wrong
A robocall placed two days before an election has done its work within hours. Detection, review, and enforcement operate over weeks and months. The FCC's action in the New Hampshire case came after the primary. Every element of the enforcement response was correct and none of it un-rang the bell. When the harm window is measured in hours and the response window in months, a detector that eventually reaches the right answer is a historical record, not a control.
The false positive cost is intolerable
In most domains a false positive is an annoyance. In political speech, a platform incorrectly labelling a genuine candidate's ad as synthetic is itself an interference in an election, and would be treated as such, correctly, by the affected campaign and by a great many observers. That pressure pushes every operator to set thresholds conservatively, which means catching less. The detector's operating point is set by liability rather than by accuracy.
The adversary picks the ground
Generation improves faster than detection because generation has more people working on it, more money behind it, and a much easier problem. A political operator only needs one call that passes. A detector needs to catch everything, forever, including techniques that did not exist when it was trained.
Doesn't caller ID authentication already fix robocalls?
It fixes a different problem, and the distinction matters enough to be worth stating precisely.
The STIR and SHAKEN framework lets an originating carrier cryptographically sign the calling number and assert how confident it is in the caller's right to use that number. A terminating carrier verifies the signature. Full attestation means the originating carrier authenticated its customer and confirmed they are entitled to the number in question. This is real cryptography doing real work, and it has measurably reduced crude number spoofing.
What it establishes is that a particular carrier vouches for a particular customer's use of a particular number. What it does not establish, and does not claim to establish, is anything about the content of the call or the identity of whoever is speaking. A political operator who lawfully obtains numbers from a compliant provider receives full attestation on every call they place, including calls carrying a cloned voice. The framework is behaving exactly as specified.
This is the recurring shape of the problem. A standard authenticates one layer with genuine rigour, the fraud moves to a layer the standard was never about, and observers conclude the standard is broken when it is simply answering a different question. The same analysis applies to voice deepfakes reaching contact centres, where carrier level authentication passes and the impersonation succeeds anyway.
What about content credentials and provenance standards?
Content provenance work, principally the Coalition for Content Provenance and Authenticity, attaches a signed manifest to a media asset recording the capture device, the editing tools, and the chain of modifications. Adoption spans camera manufacturers, major editing software, and several large platforms. It is serious, well designed work and it is the right foundation for provenance.
It answers a different question than this post is about. As we set out in Content Credentials prove the camera, not the photographer, a manifest binds an asset to a device and a tool chain and an issuing entity. For most provenance purposes that is exactly right. For political approval it is insufficient in a specific way: knowing which software produced an advertisement tells you nothing about whether the candidate agreed to run it.
A campaign's genuine ad and a forger's ad might both be produced in the same editing suite. Content credentials would faithfully record that. The question a voter needs answered is not "what made this" but "who stands behind this," and provenance metadata does not carry that assertion.
The two compose well, which is the useful conclusion. Provenance describes the artefact's history. An approval receipt asserts a human decision about it. Neither substitutes for the other.
What would a verifiable approval actually look like?
Concretely: the campaign signs the specific file, and publishes the result where anyone can check it.
The important word is "specific." Not the campaign in general, not a class of messages, not a certificate that says this committee exists. A signature over the exact bytes of the exact asset that will be distributed, produced by an enrolled human on a device the campaign controls.
Here is the shape of the payload. The committee identifies itself, the asset is named by its cryptographic hash so no other file can be substituted, the approving human and their role are recorded, and the approval carries a scope and an expiry.
{
"type": "approved_message",
"committee": {
"name": "Friends of Jordan Ellis",
"registration_id": "C00000000"
},
"asset": {
"sha256": "9f2b4c7e1d8a3b06f5c2e9a7d41b8c30e6f2a95b7c18d4e0a3f6b2c8d5e719a4c",
"media_type": "audio/mpeg",
"duration_seconds": 31
},
"approval": {
"signer_role": "candidate",
"statement": "I approve this message",
"signed_at": "2026-10-01T14:22:09Z"
},
"distribution_scope": ["broadcast", "robocall", "paid_social"],
"notAfter": "2026-11-04T00:00:00Z"
}
A broadcaster, a platform, a carrier, or a newsroom that receives a file runs a check that requires no phone call, no portal login, and no request to the campaign:
digest = sha256(received_audio_bytes)
receipt = lookup_public_log(digest) # no callback to the campaign
if receipt is None:
return "unsigned: no committee has claimed this asset"
verify_signature(receipt, published_key_for(receipt.committee))
assert receipt.asset.sha256 == digest # exact file, not a similar one
assert now() < receipt.notAfter
assert channel in receipt.distribution_scope
return f"approved by {receipt.committee.name} at {receipt.approval.signed_at}"
The hash comparison is the load bearing line. It means an approval cannot be lifted from one asset and attached to another. Change a single sample of the audio and the digest changes and the receipt no longer matches. The signature covers the file, not a description of the file.
The verification runs offline against a published key. That property matters more than it first appears: a broadcaster checking an ad at two in the morning before a Tuesday buy does not want to depend on a campaign's web server being up, and a campaign should not learn every time someone checks its ads. This is the same offline verification model we describe in Can you verify a credential without phoning the issuer.
Who signs, and what happens when staff leave
Candidates are not going to personally sign every asset in the final week of a campaign, and a design that assumes they will is a design that will not be used. The realistic model is delegation: the candidate signs a scoped, time bound, revocable delegation to a communications director or a media buyer, and that officer signs individual assets under it. The chain verifies back to the candidate's own key, so the approval still traces to the person the law names.
Campaign staff turn over constantly, often abruptly, and a departing staffer's ability to approve messages must end when their employment does. That is a revocation problem, and revoking the delegation invalidates everything issued beneath it without needing to hunt down individual assets. We cover the general mechanics in delegation chains and revocation that propagates.
What would this establish for each kind of political content?
| Content type | What disclosure establishes today | What a signed approval would add |
|---|---|---|
| Broadcast candidate ad | A spoken claim of approval, forgeable with the same tools that made the ad | That this exact file was approved by this committee at this time |
| Robocall using a candidate voice | Nothing. The voice is the claim and the claim is the voice | That the audio hash matches an asset the committee approved for the robocall channel |
| Independent expenditure ad | A "paid for by" line naming the committee | Which committee approved it, when, and that the candidate's committee did not |
| Attack ad using an opponent's voice | Nothing about the opponent's participation | Absence of an approval receipt from the opponent, which is meaningful once signing is normal |
| Post from an official campaign account | Control of the account, which can be lost | That an enrolled officer approved the specific post |
| Anonymous synthetic content making no claim of approval | Nothing | Nothing. This is the honest limit, and it is a large one |
That last row deserves its own sentence. Most political disinformation does not claim to be an official campaign message. It is a video posted by an account nobody can identify, and no approval scheme touches it. What this addresses is the narrower category where a message asserts that a named, regulated, accountable entity stands behind it, which happens to be the category the law already regulates and the category where the New Hampshire calls sat.
Is requiring signatures constitutionally defensible?
This deserves a serious answer rather than a technologist's wave, because the constitutional constraints on regulating political speech in the United States are real, substantial, and not obstacles to be routed around. Political speech receives the strongest protection in American law. Anonymous political speech has been specifically protected. Courts have struck down disclosure requirements that burdened speech disproportionately to the interest served.
Several distinctions matter here.
First, this is a disclosure mechanism rather than a restriction on content. The regime being proposed does not prevent anyone from saying anything. It gives an entity that is already legally required to identify itself a way to do so that actually functions. Disclosure requirements have historically fared considerably better in court than content restrictions, though not universally.
Second, it does not require anyone to sign. It lets those who want to prove their authorship do so, and lets recipients draw their own conclusions about messages carrying no such proof. Voluntary attestation with voluntary verification raises different questions than a mandate.
Third, and this is the point I would want a court to focus on, it applies to entities rather than to individual speakers. A registered political committee is already a regulated, identified, reporting entity. Asking a committee to sign its own advertisements is a very different proposition from asking a citizen to identify themselves before speaking.
None of that makes it constitutionally free. A mandate that platforms downrank unsigned political content would face serious challenge, and should. Reasonable people will disagree about where the line falls, and a proposal that pretends otherwise is not worth taking seriously. What can be said with more confidence is that giving campaigns a working way to prove their own messages is a smaller intervention than most alternatives currently on the table, including the state statutes now in force.
The state of the rules
Several developments are worth knowing. The FCC issued a declaratory ruling in early 2024 confirming that AI generated voices in robocalls count as artificial voices under the Telephone Consumer Protection Act, which brought them within an existing prohibition rather than requiring new legislation. The Federal Election Commission considered whether its own rules needed an AI specific amendment and declined to write one, taking the position that its existing prohibition on fraudulent misrepresentation of campaign authority already reaches the conduct. Legislative trackers maintained by policy organisations have counted synthetic media election laws in more than twenty states, though counts vary considerably depending on what is included, and several have faced legal challenge.
The pattern across all of it is enforcement aimed at the forger. That is a reasonable instinct and it has an obvious weakness: forgers are frequently anonymous, sometimes outside the jurisdiction, and always faster than the process. Aiming at the message instead changes the default, because an unsigned message can be treated as unverified without anyone having to identify who made it.
Honest limits
This is a proposal with a working mechanism, not a deployed system, and several of the limits are severe.
It does nothing about content that claims no approval. The largest volume of political disinformation is anonymous and makes no assertion of official authorship. Signing addresses impersonation of accountable entities, which is a real and damaging category, and a minority of the problem.
A signature proves who, not whether it is true. A committee can sign a message full of falsehoods and the receipt will verify perfectly. This mechanism is about attribution and nothing else. Anyone who suggests it improves the honesty of political advertising is overselling it.
Verification nobody performs is theatre. If broadcasters, platforms and carriers do not check, the receipts might as well not exist. This is an adoption problem and it is the binding constraint, not the cryptography, which is straightforward.
Enrolment is the trust bottleneck. Someone has to establish that a given key belongs to a given committee. Get that wrong and a forger obtains a valid signing capability, which is worse than no scheme at all because it launders the forgery.
The absence of a signature is only informative once signing is common. In a world where two percent of campaigns sign, an unsigned message tells you nothing. The mechanism has a threshold effect and is close to useless below it.
What to do this week
For campaign and committee operations staff:
- Write down who is currently authorised to release paid media, by name and role. Most campaigns cannot produce this list quickly, which is itself the finding.
- Record what happens to that authority when someone leaves mid cycle. If the answer is a password change, note that as a gap.
- Hash your released assets and keep the digests with the media plan. This costs nothing and gives you a way to prove later that a circulating file is or is not yours.
- Decide in advance who speaks for the campaign when a fabricated message circulates, and what evidence they will point to.
For broadcasters, platforms, and newsroom verification desks:
- Ask the campaigns you deal with whether they can confirm a specific file, not a general claim. Their answer tells you what your current verification is worth.
- Log the hash of every political asset you accept. Retrospective disputes become tractable when you can say exactly which bytes you ran.
- Treat carrier attestation and content credentials as evidence about routing and production, not about approval, and record them separately.
If you want to see the underlying mechanism rather than read about it, the signing demo shows a payload being signed on an enrolled device and the resulting receipt being verified offline, and the developer documentation covers the delegation and revocation model that the campaign officer case needs.
Frequently asked questions
How can voters verify a political message was actually approved by the candidate? Today they cannot. The spoken disclaimer is a claim carried in the same audio as the message, so anyone who can fake one can fake the other. Verification requires the committee to sign the specific file and publish the receipt, so a recipient can compare the file's hash against a signature checkable offline.
What was the outcome of the AI Biden robocall case? The FCC pursued enforcement against the political consultant behind the January 2024 New Hampshire calls, with reporting describing a forfeiture order of six million dollars, and a separate court proceeding produced a judgment of twenty two thousand five hundred dollars that reporting indicates was not paid. Both came after the primary had been held.
Are AI generated political ads illegal? It depends on the jurisdiction and the conduct. The FCC has confirmed that AI voices in robocalls fall under existing telephone consumer protection rules. More than twenty states have enacted synthetic media election laws, with significant variation and some facing legal challenge. Impersonating a candidate to deceive voters can also reach existing fraud and election statutes.
Does STIR and SHAKEN stop deepfake robocalls? No. It authenticates the calling number and the originating carrier's confidence in its customer's right to use it. A caller who lawfully obtains numbers gets full attestation while carrying any content they like, including a cloned voice. It is answering a routing question, not an identity question about the speaker.
Would content credentials solve this? Not on their own. Content provenance records the capture device, tools and edit history of an asset, which is valuable and not the same as recording that a human authorised its release. The two compose: provenance describes the artefact, an approval receipt asserts a decision about it.
Would requiring signatures violate the First Amendment? A mandate would face serious challenge and this post does not claim otherwise. The proposal here is voluntary attestation by entities already legally required to identify themselves, with recipients free to draw their own conclusions. That is a narrower intervention than several statutes now in force, and it is not legal advice.
What stops a forger from signing their own fake as themselves? Nothing, and that is fine. The receipt proves who approved a message, not that the message is true. A forger signing as themselves has attributed the content to an identifiable party, which is the outcome the disclosure regime was aiming at in the first place.
Sources
- Federal Communications Commission, enforcement actions and declaratory rulings on AI generated voices in robocalls under the Telephone Consumer Protection Act: fcc.gov
- Federal Election Commission, disclaimer requirements for political communications, 11 CFR 110.11, and its consideration of artificial intelligence in campaign advertising: fec.gov
- Associated Press reporting on the court judgment against the political consultant responsible for the New Hampshire robocalls: apnews.com
- Bipartisan Campaign Reform Act of 2002, stand by your ad provisions, via the Federal Election Commission legal resources: fec.gov/legal-resources
- Coalition for Content Provenance and Authenticity, technical specification for content credentials: c2pa.org
- National Conference of State Legislatures, tracking of state legislation on artificial intelligence and elections: ncsl.org
- Alliance for Telecommunications Industry Solutions, STIR and SHAKEN caller ID authentication standards: atis.org
An unsigned political message is not a suspicious message. It is an unverified one, and after twenty four years of asking candidates to stand by their ads, we should be able to tell the difference.