What does it mean to “check the source” when the source can be copied?

Advice to “check the source” sits at the heart of media literacy — but what happens when the signals of a trusted source can be convincingly imitated? A reflection on de La Brosse & Holt, the “Holiday” bot network, and why verifiable communication is becoming trust infrastructure.

Matthew Davis · · 7 min read

I was reading a recent paper by Renaud de La Brosse and Kristoffer Holt (2024) on disinformation and the sustainability of democratic systems, and one part of their argument struck me as particularly relevant to the way the information environment is changing. Much of the paper deals with a familiar democratic problem: societies need ways of responding to deliberate manipulation, while being very careful that the mechanisms used to do so do not themselves undermine freedom of expression, political disagreement or media pluralism.

In general, they look at different approaches in France and Sweden, ranging from legislation and institutional responses to the broader emphasis placed on media literacy and the ability of citizens to critically assess information for themselves.

Towards the end however, they return to an apparently simple piece of advice: people need to cross-check information and establish the credibility of their sources. This is difficult to disagree with, and it sits at the heart of most contemporary guidance on how to deal with misleading information. The Swedish Psychological Defence Agency, for example, recently gave much the same recommendation after publishing its investigation into the “Holiday” bot network, a partly AI-driven network of around 1,200 accounts which produced more than 50,000 posts, comments and shares during 2025 and 2026. Among its suggestions to the public was to remain cautious around emotionally provocative material; ideally, one should “check the source” and try to confirm information before sharing it (Myndigheten för psykologiskt försvar, 2026). The problem is that this advice increasingly depends on our ability to establish where a piece of information actually came from in the first place.

A good illustration of this predicament came during the German federal election campaign in 2025, when Reuters documented a disinformation campaign which included a fabricated video made to look as though it had been produced by France 24, a well-known news network. The video reported that French security services were warning people to avoid public places in Germany because of an increased risk of terrorist attacks. Of course, no such warning had been issued, but anyone encountering the clip was forced to assess whether the terrorist threat itself was plausible, and more importantly, whether France 24, or the French security services, actually communicated any of this in the first place (Reuters, 2025).

Our point here is that, understandably, discussions of disinformation tend to focus on whether the claim itself is true, and so the authenticity of the communication through which that claim reaches us can easily be taken for granted. Generative AI adds another complication by making convincing imitations cheaper to produce, while the same information may subsequently be quoted, summarised and reproduced through dozens of other systems before somebody encounters it. If we are advising people to do their due diligence on claims they encounter in the wild, we also have to recognise that there is a practical limit to what media literacy alone can ask them to do. An informed citizen might sensibly recognise France 24 as an established broadcaster, and the French security services as an authoritative source, and yet still be misled because the signals they have been trained to look for have themselves been copied. The same problem applies to screenshots of government announcements, altered press releases, cloned websites, fake statements attributed to companies, or an AI assistant confidently explaining what an organisation allegedly announced last week.

For the work we are doing at Witnis, this issue helps clarify where ‘Verifiable Communication’ fits within the wider response to disinformation. Establishing that an organisation genuinely published a particular communication cannot tell us whether every claim contained within it is true, nor should it try to. What it can do however, is preserve a piece of evidence that increasingly disappears as information moves; who communicated something, what they communicated, when they did so, and whether the version now being presented still corresponds to that original record. Fact-checking, journalism, media literacy, platform governance and institutions such as Swedish Psychological Defence Agency (MPF) all address different parts of the information problem, but being able to establish what an authoritative source actually communicated gives those processes a more reliable place to begin.

And so I increasingly think about what we are building at Witnis as a form of trust infrastructure, with Verifiable Communication as one current use case for our technology. The aim is to preserve enough evidence for people, journalists, and increasingly AI systems, to establish where information came from and whether it still corresponds to the original, even after it has been copied, quoted, summarised or passed through other systems. In that sense, “check the source” remains very good advice, but as the source itself becomes easier to imitate, we may need to invest in the infrastructure that makes checking it possible.

Sources