Under Siege, Ukraine's Public Broadcaster Built a Defense Against Deepfakes
The Suspilne site displays the Content Credentials icon in the bottom left corner of a photo of a tired rescuer sleeping in the village of Myla near the epicenter of the fire and detonation at military warehouses after a Russian drone attack. Kyiv region, August 29, 2026. Photograph by Ivan Antipenko/Suspilne. See the full story.
Early in the war in Ukraine, malicious actors circulated a deepfake video of Ukrainian President Volodymyr Zelenskyy telling Ukrainians to put down their weapons. Its poor quality made it easily identifiable as disinformation and social media platforms removed it. But it was a sign of things to come.
In May of 2024, a fake video appeared misusing the logo of Suspilne, Ukraine’s public broadcaster, to appear legitimate. Suspilne called it “an element of the Russians' hybrid war, when the enemy wants to discredit public broadcasting and undermine trust in the country's largest independent media outlet.”
As AI video generation services have become more capable, this kind of impersonation has become increasingly convincing. To counter such efforts, Suspilne and BBC Media Action have spent the past year working together to provide verifiable provenance information for the digital media that Suspilne publishes. Suspilne operates as an independent media company adhering to journalistic standards, even though it's primarily funded by the state budget.
As a community mentor for the Content Authenticity Initiative (CAI), I was connected to the BBC Media Action team by Santiago Lyon, then CAI’s Head of Advocacy and Education, to help develop an implementation strategy. After some initial planning meetings, we agreed that I would work directly on the project, providing engineering support for the CAI’s open-source tools.
Over the last year, I have witnessed the Suspilne team’s persistent work on this project despite the war and through multiple bombings, once with sirens activated during our call. During the winter months, they had limited electricity, often no heat, and warmed their hands with candles so they could type. Their dedication made clear just how important and practical this work is. I want to share some background on the project, both to document it and to encourage other news organizations to implement Content Credentials in their own workflows.
The Suspilne site displays Content Credentials over a photo of the aftermath of a fire at military warehouses followed by a detonation in the Kyiv region, August 29, 2026. 37 people died in the village of Myla, Buchansky district. The fire started after a Russian jet drone hit. Photograph by Ivan Antipenko/Suspilne. See the full story.
How the implementation works
Suspilne uses two complementary standards to establish trust: C2PA Content Credentials to prove how content was created and edited and CAWG creator assertions to prove who published it. BBC Media Action provided Suspilne with two C2PA-enabled Sony cameras to sign photos at capture.
From there, the Suspilne engineering team and I implemented both C2PA and CAWG signing into their newsroom content management system (CMS) using the open-source CAI Rust library. When signed photos originating from the Sony camera are uploaded to the CMS, it validates the existing credential and carries it forward, adding a new credential each time the image is resized or cropped. It also adds signed CAWG identity assertions to the Content Credentials to prove that Suspilne officially published the content. The result is a complete, verifiable chain of provenance that readers can see on Suspilne’s site.
To measure the impact of this work, each display of Content Credentials on the Suspilne website contains a user poll to help assess whether this information increases the viewer’s trust in the content. Response data is limited, but the early results suggest that this does improve public trust in the published content.
Getting to production
After completing the implementation, the last step was to obtain trusted C2PA and CAWG signing certificates for Suspilne’s production environment. To get a trusted C2PA signing certificate, the implementation had to first pass C2PA conformance. This program provides assurance that software or hardware products follow the C2PA specification and adhere to their security requirements and guidelines. For the Suspilne implementation, this process took a little over a month to complete.
Once approved, C2PA added Suspilne Media to the C2PA conforming products list and they were able to get a trusted C2PA certificate. Finally, to get a trusted CAWG identity certificate, Suspilne had to complete an organizational identity vetting process. Suspilne used SSL.com for both their C2PA and CAWG certificates. We are very appreciative of their support of this collaboration by providing the certificates at no cost.
The Suspilne team I worked with on the implementation. From left to right: Anton Novytskiy (Software Engineer, Cybersecurity Solutions), Kyrylo Iesin (Product Development Lead), and Kyryll Taran (Software Engineer, Core Implementation).
“In wartime, the threat is asymmetric. The risk is not unauthorized reproduction without credit, but the publication of fabricated images under our name,” said Kyrylo Iesin, Product Development Lead at Suspilne. “In this context, a cryptographic signature is the only defense that does not require the audience to rely solely on our claims.”
“This is why the verification layer must remain independent. The authority responsible for verifying wartime visual evidence must be trusted by all parties and must not be owned by any platform, vendor, or party to the conflict. Independence is not just a feature; it is essential for credibility.”
I’d like to thank the Suspline and BBC Media Action teams for all their hard work. In addition to funding the project through support from the UK Foreign, Commonwealth and Development Office, BBC Media Action provided Suspilne with two C2PA-enabled Sony cameras to sign photos at capture. You can read the press release from BBC Media Action here.
I hope this collaboration will serve as inspiration for other news organizations to get involved.
To learn more about the CAI’s open-source tools and get started with implementing, check out Content Credentials Foundations and join the CAI Discord for resources and support.