friday, september 18, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

Putting AI output on top of data people trust

How to add AI-generated content to the records, sheets and reports people rely on without losing track of which parts were verified and which were generated.

Published 2026-09-04 · Updated 2026-09-04 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-04 · Rami
on this page · 0 / 0 checked

You have a small number of places where your work is read as fact. The invoice ledger. The client status report. The price sheet you send out. The wiki page a subcontractor follows. The before-and-after photos on the job. Nobody re-derives those from scratch, which is the entire point of keeping them. AI now writes into all of them, and it writes in the same font as everything else.

That is the problem this guide is about, and it is not a prompting problem. A better prompt gives you a better draft; it does not tell the next person which figure in the spreadsheet you checked against a bank statement and which one a model produced from a sentence of context. If your AI use is private drafting that never leaves your own screen, none of this applies to you and you can skip it. This is for the moment your output lands somewhere a client, a colleague or a future version of you will treat as settled.

A trust surface is anything nobody re-checks

The useful definition is behavioural, not technical. A trust surface is any place where the people who read it have already decided not to verify it, because verifying it is the job the record was supposed to do for them. Satellite imagery is one. So is a bank reconciliation, a compliance register, a materials list, a photo of finished work attached to an invoice.

The public version of this failure is worth your time because it happened to a company with an entire safety apparatus, on a product whose whole value is being trusted. At the end of July 2026 Google added Nano Banana image generation to Google Earth, letting people type a description and generate custom imagery built on Earth’s satellite, aerial and 3D imagery. It rolled the feature back about a day later. The note Google appended to its own announcement names the asset first: “We know that people uniquely trust Google Earth for a reliable view of the world” [7]. Then it names the mechanism: “we’ve also seen people sharing screenshots of generated imagery that appear to violate our policies” [7]. The generation worked. The screenshots were the problem.

What makes it instructive rather than merely embarrassing is the sentence Google put at the end. “It’s important to note that generated images didn’t appear in the main Google Earth experience for others to see and were watermarked as AI generated” [7]. Read that as a post-mortem and it is remarkable. Both controls held. The images were fenced off from the shared map, and they carried a marker saying what they were. Neither fact travelled with the screenshot, because a label is only a control over people who go looking for it, and nobody looks at a picture in a feed.

Watermarks prove origin, not truth, and they do not travel

Google’s SynthID embeds watermarks directly into AI-generated images, audio, text and video, imperceptible to humans but detectable by SynthID’s own technology [1]. Google says they are “designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression” [1]. That is a real engineering claim and it is mostly about survival inside the file. Checking one is a separate act, and it is the act that is missing. SynthID Detector, the portal where you upload an image, video or audio file to test it, is still gated: Google is “currently collaborating with journalists and media professionals to test the portal”, and everyone else joins an early tester waitlist [1]. Detection is not something your client has.

The open standard is blunter about its own limits. The C2PA explainer, which defines Content Credentials, states plainly that “Provenance information alone cannot tell you whether the digital content is true, accurate or factual”, and describes itself as “not a cure-all for misinformation” [2]. On whether the credential can be removed, the document asks and answers its own question: “Can the provenance metadata be removed? Yes it can” [2]. It also notes the ordinary way provenance goes stale rather than being attacked: “It may happen that an asset is modified in a way that the provenance data is not updated” [2], which is what a crop in a non-participating editor does.

OpenAI documents the same thing for ChatGPT images. Content Credentials “can sometimes be removed by platforms, editing tools, or file conversions” [3]. And when its own checker finds nothing, OpenAI says “the content could still have been generated or exported by OpenAI” for a list of ordinary reasons, among them that “Metadata was stripped during upload, download, editing, conversion, or sharing” [3]. Read that from the other direction and it is the sentence that matters for your business: the absence of a marker tells a reader nothing at all, so the marker cannot be the thing you rely on.

Your spreadsheet already lost the audit trail

The version of this that affects a two-person business is smaller and quieter. Google Sheets has an AI function, written as AI("prompt", [optional range]), that generates text, summarises, categorises and analyses sentiment straight into a cell [4]. Google’s own documentation contains the detail that should stop you: “When you click ‘Generate and Insert’ or ‘Refresh and Insert,’ generated content is inserted and the cell edit is attributed to you in version history” [4].

Sit with that. The provenance layer you would actually consult, the edit history of your own file, records a human author for a value the human did not produce. Google adds that “You can’t undo or redo your function. You can regenerate your output instead” [4], that “The AI function doesn’t have access to your entire spreadsheet or other files in your Google Drive” [4], and, in its general caution, that “Gemini features may suggest inaccurate or inappropriate information” and should not be relied on “as medical, legal, financial or other professional advice” [4].

None of that is a scandal. It is a normal product decision, and the same shape shows up wherever an automation writes on your behalf: a Notion property that autofills, a Zapier or Make step that fills a CRM field, an n8n run that appends rows overnight. In every case a generated value lands in the same column as a measured one, styled identically, timestamped as yours. Six months later, the column is the record and there is no way back.

Separation is the control that survives a screenshot

The fix is layout, not labelling. Give generated content its own field, its own page or its own file, and never let it overwrite a verified one. A draft_summary column beside a reviewed summary. A status property that a person has to flip from Draft to Confirmed. An automation that writes into a review queue rather than into the live table. This is unglamorous and it is the only control in this guide that keeps working after the content is exported, pasted or photographed.

Apply a durability test to whatever separation you pick. Italics do not survive a CSV export. A footnote at the bottom of a PDF does not survive a crop. A “generated by AI” line in a chat summary does not survive being pasted into an email. A separate column does survive, because it is structure rather than styling, and structure is what export formats carry.

Where the value comes from a document you already hold, you can do better than a flag and record the actual provenance. Anthropic’s Citations feature returns “the exact passages that support each claim, so you can verify answers and surface sources to your users”, and all active Claude models support it [8]. A quoted span from an invoice is a categorically different object from a number a model wrote down, and storing the span next to the value is what lets someone later tell them apart in one glance. That is the bridge into reading invoices and forms properly, which is the next guide.

Since 2 August 2026 the transparency obligations in Article 50 of the EU AI Act have been generally applicable and enforceable by national competent authorities across the EU, and the AI Omnibus, Regulation (EU) 2026/1744, which pushed the Annex III standalone high-risk requirements out to 2 December 2027, left the transparency obligations on their existing timetable [6]. Providers of AI systems generating synthetic audio, image, video or text must ensure that “outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated”, using technical solutions that are “effective, interoperable, robust and reliable as far as this is technically feasible” [5]. Deployers who produce deepfake content “shall disclose that the content has been artificially generated or manipulated” [5]. Non-compliance can draw “administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher” [6].

For a solo operator or a small team the practical reading is that you are almost always the deployer, not the provider. The machine-readable marking is your vendor’s job. Yours is disclosure: on deepfake-style content, and on text “published with the purpose of informing the public on matters of public interest”, where the obligation falls away only “where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication” [5].

Treat that as a floor and nothing more. Article 50 compliance would not have saved the Google Earth feature, because the images were already watermarked as AI generated and the screenshots spread anyway [7]. Meeting the marking requirement and keeping your own records honest are two different jobs, and only one of them has a regulator attached.

An hour to find what is already mixed in

Start by listing every path along which a model can write to something you keep, including the ones you set up and forgot: a Zapier step filling a CRM field, an n8n or Make run appending rows, a Notion property that autofills, a Sheets formula, and your own habit of pasting a Claude or ChatGPT answer into a document. For each destination, ask whether there is any field that records where the value came from. Usually there is not.

Then sample. Take 20 records from your most consequential table and try, using only what is in the file, to say which values a person verified. Whatever you cannot determine is the size of your problem, and re-verification is the only way to clear it. That is a real cost and it is worth sizing before you decide how much structure to add.

checklist
Before AI writes into a record
0 of 7 · saved in this browser only
calculator
Cost of a record set you can no longer sort
h of re-checking

records × minutes ÷ 60. Computed in the page; nothing is sent anywhere.

What still goes wrong

Separation only works if the person merging drafts into the record is doing a real check. A review column that gets approved in bulk every Friday is a label with extra steps, and it is worse than no column because it produces a paper trail suggesting someone looked. If you cannot afford to check, reduce what the model is allowed to write rather than adding a stage that launders it.

Some outputs have nowhere to put the flag. A summary pasted into an email body, a caption under a photo, a figure read aloud on a call. Structure is a property of files and databases, and once content leaves those it degrades to whatever a reader remembers. What you control at that point is what you assert, which is why disclosure is a separate discipline from marking rather than a consequence of it.

The detection side is not a safety net. SynthID’s portal is still gated behind an early tester waitlist [1], C2PA’s own explainer warns against creating “a two-tier media ecosystem where assets without Content Credentials are universally less trusted than assets with it” [2], and OpenAI is explicit that a missing signal does not mean a human made it [3]. If your plan for a disputed document is to run it through a detector, you do not have a plan. Keep the record clean at the point of writing, because that is the only moment you have complete information about where the value came from.

sources
  1. 01Google DeepMind — SynthIDdeepmind.google
  2. 02C2PA — Content Credentials Explainer 2.4spec.c2pa.org
  3. 03OpenAI Help — C2PA in ChatGPT imageshelp.openai.com
  4. 04Google Docs Editors Help — Use the AI function in Google Sheetssupport.google.com
  5. 05EU AI Act — Article 50, Transparency obligationsartificialintelligenceact.eu
  6. 06Goodwin — Not Delayed, Not Deferred: EU AI Act Transparency Obligations Are Now in Forcegoodwinlaw.com
  7. 07Google — Transform any place with Nano Banana in Google Earthblog.google
  8. 08Anthropic — Citationsplatform.claude.com
next guide
Letting AI read your invoices and forms
9 min · verified 2026-09-05
related guides