Solution · At the point images are released
Appliances sit inline at the emission boundary, beyond the operator's reach. Each detected face is resolved against a public reverse-image corpus; a match to a real person withholds the token and blocks release. Cleared assets carry the token embedded inside them, so anyone downstream can verify it later.
The governance app
Screen Console · governance read-only · illustrative data
How this is an embodiment of the Semantic Enforcement Suite
The Aggregate Drift suite answers "has the set of an optimiser's instructions drifted out of the declared appetite?" This suite answers a sibling question at a different choke point: "Did this generated image or video depict a real, identifiable person, and can an outside party verify that the check ran before the asset left the building?"
The same inversion the whole family sells. We do not ask the image model to promise it will not produce real-person likenesses; instead a cluster of Semantic Enforcement Appliances sits inline at the emission boundary, outside the model operator's software reach.
The Engine's verdict logic is re-pointed: instead of allow/redact/deflect/block on a chat output, the Engine screens each asset, faces detected, each face resolved against a public reverse-image corpus, any face resolving to a real person is a gate event: the compliance token is withheld and the asset cannot be released.
The Appliance is the same deployed unit: default state blocking; no token, no release; the check declared in advance, run deterministically before actuation, recorded verifiably, the same three guarantees the meaning check makes everywhere else.
Same constituent apps, re-skinned: Likeness Report (↔ Oversight/Aggregate Drift Report), LK Concepts (↔ Semantic Library), Screen Console (↔ the governed-application seat), Attestation / Token Record / Interlock / Hardware / Provenance Ledger / Triage (unchanged mechanics), plus two new surfaces the oracle lane demands: Oracle and Consent Registry, and a public Verify page.
Why this deployment, why now
Guardrails lower the rate of real-person likeness generation; they cannot reduce it to zero or say which outputs were the exceptions.
US TAKE IT DOWN Act, state NCII and digital-replica statutes, EU AI Act Art. 50, AU Criminal Code deepfake amendments all converge on one operational question: can the operator prove, per asset, that a real-person screen ran?
Logs are testimony from the accused; the appliance sits beneath the software, at the boundary where output becomes a released asset.
The rules it enforces, LK (Likeness)
| ID | Control | Tier |
|---|---|---|
| LK-001 | Resolved-likeness prohibition, no asset with a face resolving to a real person gets a token, absent a consent match. | Semantic + oracle lane |
| LK-002 | Consent-registry release, a resolved face releases only against a valid, unexpired, scope-matching consent artefact. | Rules |
| LK-003 | Minor-likeness absolute bar, any face classified minor is an unconditional gate event; no consent, no override, no appeal on the appliance. | Rules + semantic |
| LK-004 | Composite-reconstruction drift, a session whose passing outputs converge toward one real identity is a set-level gate event even though every asset passed. | Set-level (Aggregate Drift) |
| LK-005 | Attestation completeness, every released asset carries a verifiable embedded attestation; an unattested asset at the edge is a reconciliation event. | Rules |
| LK-006 | Oracle-health floor, tokens issue only while the oracle lane holds its certified operating point; degradation demotes the tier, never fails open. | Rules |
LK-002/-005/-006 are rules-tier (decidable); LK-001 is a detection lane with an external oracle (certified miss-rate, not a proof); LK-004 runs on the unmodified Aggregate Drift Service; LK-003 combines a rules gate with abstention discipline.
What's different about this one
An N+1 pool of SEA-2800-P cards (SEA-GRK-01…04) in a physically and logically separate cage, its own rack, management network, signing keys, measured boot, no operator credentials. The operator's stack sees only an API and a yes/no. Inline, single-pass, fail-closed: the only route from render farm to CDN traverses the enclosure.
Adapter → identity evidence → evidence normalisation → identity decision → governance decision. The split isolates the one probabilistic link (the identity decision, bounded by a calibration certificate) from the deterministic governance decision above and the untrusted oracle below.
The reverse-image corpus is reached only through an OracleAdapter contract: the adapter proposes, the card disposes. Swapping the corpus is a configuration-and-certification event. Each adapter loads only with its own non-transferable calibration certificate; adapter disagreement abstains to review, never averages into a pass.
τ_id is calibrated via distribution-free risk control over a labelled corpus, yielding a certified miss-rate α at confidence δ, with an honest effective sample size and a stated adversarial scope limit.
Nominal → reduced-oracle → hold-and-queue → rules-only refusal. Every rung attested; no rung lets a face pass unscreened. Outage degrades throughput, never assurance.
Hard binding: a C2PA-conformant manifest whose claim signature is the on-card HSM signature, the operator cannot mint it because it never holds the keys. Soft binding: an imperceptible watermark carrying the token_id, robust to a declared transform budget, so a stripped asset still resolves via the Attestation Lookup service.
A public endpoint + reference CLI/SDK: validate the C2PA chain to the Foundation root, recompute hashes, fall back to watermark lookup, check the ledger anchor, return the verdict card, "screened against <oracle_lineage> on <date> under LK envelope <versions>, calibration α/δ, chain ✓."
The unmodified Aggregate Drift Service runs over the identity-embedding stream per session: convergence toward a single external identity gates the session's token issuance even though every individual asset passed, the Sorites blind spot the platform exists to name.
See it running
The suite screens generated images and video for resolved real-person likeness at the emission boundary and records a verifiable disposition. It does not author, edit, or remediate content, and makes no claim that no real person is depicted, corpus coverage is bounded and stated on the token.
Live sampled stream, per-face verdicts, drift plane.
Concept cards, consent registry, oracle adapters.
Attestation ledger, tokens & hardware interlock.
The generation endpoint, the enforcement point.
Cross-endpoint roll-up & obligation map.
Public downstream check, drop an asset, royalty-free, no sign-in.
The Sorites payoff
Every asset passed the per-face screen. The set did not. Steps 1–2 pass and release; step 3 resolves to a real person and is withheld at the boundary; step 4's twenty individually-passing variations trip the set-level LK-004 control and the session token is HELD. The appliance never authored anything, a blocked asset is the operator's problem upstream.
The demonstration console uses an instrument palette by design, this is the operator/regulator seat, not marketing. The detection lane is a calibrated signal with a certified miss-rate, never a proof of correctness.
What the proof does and doesn't say
Claimed
The declared screen ran, in hardware, before release; its result gated the token; the named oracle/envelope/calibration/registry versions are exactly those; the asset bytes are exactly those hashed; the record is anchored in a tamper-evident ledger; no facility software could suppress or reorder it.
Not claimed
That no real person is depicted (every corpus is incomplete; a private individual with no indexed imagery cannot resolve); robustness against a white-box adversary beyond the stated budget; soft-binding survival beyond the declared transform budget; any judgement about content other than resolved likeness.
The deployment described, a generative-media provider's data centre referred to as "the Grok facility", is a hypothetical reference deployment for specification purposes. No affiliation with xAI, Google, or any real organisation is implied. Google Images is referenced as the canonical example of a public reverse-image corpus; the oracle interface is defined generically.