Published2026·08·27
AuthorGonçalo Sá

Life isn't real anymore.

Thesis

The human face and voice were an unwritten security control. Synthetic media made them cheap to reproduce. The answer is not detection, but verifiable personhood, delegation, and trust that can accumulate.

Nobody clicks the link anymore

The last year I spent building Creed, I noticed something I couldn't unsee.

People stopped clicking links. Not security people, who have always been paranoid for a living. Normal people. Clients. Friends. I'd send a calendar invite and get a “is this you?” on Signal. I'd share a doc and it would sit there, unopened, until I said the same thing out loud on a call. And then, slowly, the calls too: folks hesitating before joining a Zoom room because they weren't sure who set it up, or whether the room itself was the attack.

That's a weird thing to watch happen in real time. It's not a vulnerability. Nothing was exploited. It's an erosion. The substrate of every digital interaction we've built for thirty years is “you can identify the other side well enough to act,” and people had quietly stopped believing it. They were right to stop. I just don't think they knew how right they were about to be.

This post is my list of assumptions about where that goes, and why I decided to build Rebellion instead of anything else.

1925: the money was real

Let me start a century back, because we've done this before.

In 1925 a 28-year-old Portuguese man named Artur Virgílio Alves dos Reis pulled off what is still, per escudo, one of the largest frauds in history. Portugal was mid-collapse: hyperinflation, assassinations, governments with the shelf life of milk. Reis forged a contract in which the Banco de Portugal authorized a secret syndicate to issue currency to develop Angola. He traced the signatures he needed off existing banknotes with a homemade contraption, and he handed the thing to a notary who couldn't be bothered to read a long document.

Here is the part that matters. Reis did not print fake money. He took his forged authorization to Waterlow & Sons, the London firm that actually printed Portugal's banknotes, and had them run over 100 million escudos of 500-escudo notes on the real presses, with the real plates, the real paper, the real everything. The notes were genuine. They were indistinguishable from legitimate currency because they were legitimate currency. The only tell, discovered on 5 December 1925 when an inspector went to Oporto to look at some suspiciously large deposits, was duplicate serial numbers.

The fallout: Waterlow was found grossly negligent by the House of Lords and never recovered, the First Republic was mortally wounded, and the road to Salazar got a lot shorter. Trust collapse is not a technical event. It's a political one.

I bring up Reis because his era had a very specific security model and it was breaking at exactly that moment. Identity was a signature. Authorization was a signature. The whole apparatus of banking, contracts and property rested on a squiggle that any patient person with a light box could reproduce. Forgery was rampant enough that in 1910 Albert S. Osborn published Questioned Documents and effectively invented a profession out of thin air, and it still took until 1942 to get a professional body chartered for it. That's a 30+ year gap between “our authentication factor is broken” and “we have institutions that can adjudicate it.”

We are in year one or two of the same gap. Here's what I think fills it.

Assumption 1: the line between real and synthetic is going away, and it is not coming back

Deepfakes get better and cheaper. Cheaper means more frequent. More frequent means the base rate of your day flips: right now a synthetic video is remarkable, soon it's the default and the camera feed is the anomaly.

The important part is the second half: there is no legal off-ramp, because most of this use is either good or beloved. Higgsfield raised $400M at a $5.4B valuation this month on roughly half a billion in annualized revenue. That is not a fraud business, that is the next Netflix being born, and humanity likes entertainment more than it likes safety. There's a whole griefbot industry letting people talk to their dead, which is either beautiful or ghoulish depending on the day and which I am not going to be the one to legislate away. And there's a genuinely strange endgame where synthetic presentation becomes an equalizer, everyone shows up online as an avatar and nobody's face is a liability anymore. Dystopian, sure. Also kind of egalitarian. Also coming.

Yes, the EU is trying. Article 50 of the AI Act came into force on 2 August 2026: label your synthetic content or pay up to €15M or 3% of turnover. I'm not against it. I just want to be honest about what a label does. Labels bind honest producers. Provenance signatures (C2PA and friends) prove “this came from a pipeline that signs things.” Neither of those tells you the person on your screen asking you to move money is the person you think it is. That's not what they're for.

And at that point, “deepfake” is the wrong word. Nothing is being faked. It's a life-like avatar rendered by a legitimate tool for a spectrum of reasons that mostly aren't crime. Same as 1925: the notes were real. Only the authorization was forged.

Assumption 2: Thomas's creed is dead

“Unless I see the nail marks in his hands and put my finger where the nails were, I will not believe.” John 20:25

Doubting Thomas always demanded empirical verification and so do we, most of the time. “I'll believe it when I see it” is not a figure of speech, it's the root of trust for the entire human social stack.

It doesn't work anymore, and we have the receipts:

  • iProov tested 2,000 UK and US consumers and 0.1% got every item right. High-quality synthetic video was correctly identified 24.5% of the time. Worse than a coin flip, while primed to look for fakes.
  • A meta-analysis of 56 papers found human detection performance is not significantly above chance for any modality. Not video, not audio, not images, not text.
  • At Arup, a finance employee got a suspicious email from the “CFO,” was appropriately skeptical, and then joined a video call where every other participant, including several colleagues he knew, was synthetic. Fifteen transfers, $25M, five accounts, never recovered. Arup's CIO was very clear: no systems were compromised, no data touched. The video call was the exploit.
  • Injecting a real-time face swap into a call or a KYC flow now runs under 50ms on consumer hardware through a virtual camera, and it's sold as a service for less than $50 a month. Group-IB counted 8,065 injection attempts against a single financial institution's onboarding flow in eight months of 2025.

Until roughly now, faking personhood at that fidelity was Mission Impossible stuff: state budgets, a team, a latex mask, Tom Cruise. The compute requirement was the security control, and nobody wrote it down as one. It's a subscription now. That control is gone, and it was load-bearing for basically everything.

Assumption 3: people still need trust, and digital twins need a new threat model

Nothing above reduces the human need for trust. It just removes the mechanism. So we need a new one, and it has to survive a world where the impersonation is authorized.

This is the part I think most people are getting wrong. The interesting threat isn't “is this video fake.” Soon everything is synthetic and the question is meaningless. My agent legitimately acts as me. My avatar legitimately renders my face. Both are impersonation by design. So the only useful question becomes:

Which principal is this, who delegated to it, for what, and how far can it go?

That's a completely different question than “is this real,” and no amount of pixel forensics answers it.

Asimov got here first, obviously. In Evidence (1946), a politician is accused of being a robot and every attempt to prove or disprove his humanity fails, because each possible test is consistent with both hypotheses. He wins the election by punching a man in the face, which is the kind of proof-of-humanity that only works once, and Susan Calvin's closing suspicion is that the man he punched was also a robot. That story is a spec, not a warning.

Assumption 4: authentication goes continuous and bio-bound

Today's model is just-in-time. You prove yourself once at the door and receive a bearer token, and for the rest of the session the system believes anything that holds the token. That was fine when the expensive part was getting through the door. Now the expensive part is staying who you said you were, because the session is where the synthetic participant shows up. Nobody at Arup failed a login.

So: continuous, passive, bound to a body. Not “type your password again,” which users hate and which proves nothing about who is currently in the chair. Signals that are cheap to emit constantly and expensive to fake: how you hold the device, how you move, how you are shaped. This is where zero trust has been pointing for years without being able to close the loop, because it kept trying to do it with network telemetry instead of with the person.

One caveat I've had to eat the hard way: behavioral and biometric signals cannot bootstrap trust. There's nothing to compare against before the first interaction, and if you make the soft signal the root you've built a system whose security ceiling is your matcher's error rate. So the architecture has to be layered: a hard cryptographic root that is device-bound and unphishable (a passkey), with the bio-bound continuous signal riding on top as evidence about the human, not as the credential. Root and signal. Getting that boundary wrong is how you end up with a beautiful demo and a lockout.

Assumption 5: OAuth dies with the agents

In June 2026, Cloudflare's data showed bots passed humans at 57.4% of web requests, 68.6% in North America. That's the actual population of the internet now, and third-party authentication was designed for the minority.

OAuth encodes assumptions that agents violate by construction: a human present to consent, synchronously, in a browser, for a single hop, in a bounded session. An agent acts asynchronously, hours or weeks after any human was in the loop, and chains across five services to finish one task. You can patch it, and people are: token exchange, actor claims, scoped delegation, the pile of IETF drafts that materialized in the last year. And then you get novel failure modes like delegation chain splicing, where the attacker inserts himself between two legitimate hops, which is Alves dos Reis's forged authorization with extra steps.

“Log in with Google” is a human ritual. It does not survive contact with a population that is majority non-human and permanently delegated. What replaces it is delegation you can verify end to end, cryptographically, without a human being awake.

We solved the trust part in 1991 and then lost the receipts

Here's the uncomfortable bit. Decentralized trust in identity was solved. PGP's Web of Trust is correct. I sign your key, you sign hers, trust composes, no authority required. It's elegant and it lost, badly, and if you're building here you owe it to yourself to do the autopsy instead of the eulogy.

Why it failed, roughly in order of how much it mattered:

  • The UX was hostile. Whitten and Tygar's “Why Johnny Can't Encrypt” is from 1999 and the conclusions never got fixed. Key-signing parties. Fingerprint comparison over the phone. Nobody was ever going to do this.
  • Nobody actually built the graph. Public keyservers are overwhelmingly full of keys nobody ever signed (one analysis put the share of keys carrying any signature at all at around 0.3%), which is why “the web of trust never happened” is now the consensus reading. The whole design rests on edges, and the edges were never there. Trust composition at that density is a rounding error with a manifesto attached.
  • It leaked everything. The social graph was public by construction. Who you know, when you met, who vouched for you. In 2026 that's not a footnote, that's the product being unshippable.
  • Long-term keys were the wrong primitive. Filippo Valsorda and Moxie both made the same point from different angles: a key you use for a decade is a key that eventually leaks, and you'd usually rather have forward secrecy and ephemerality than ironclad eternal identity.

So here's the retrofit. The first one is a primitives problem. The rest are unglamorous and barely cryptography at all:

  1. Stop assuming the primitive is a key. This is the one I keep circling back to. A perennial key is a bearer token for your entire self: copy it once and you are copied forever, which is exactly why Valsorda and Moxie walked away from long-term keys rather than trying to fix the graph on top of them. So maybe identity shouldn't be anchored to a long-lived secret. Maybe it shouldn't be anchored to a secret at all. The primitive I actually believe in is a continuous authentication signal tied to some feature of yourself that is genuinely hard to copy, whether that's biological, biomechanical or mental: how you are shaped, how you move, how you remember. Those aren't secrets you hold, they're properties you exhibit, and you re-exhibit them every few seconds at zero cost to you. A key proves possession once and then trusts a token for the rest of the session. A body proves presence continuously, which is precisely the failure mode that got Arup. Keys don't disappear in this world, they get demoted: device-bound, replaceable, plumbing instead of identity. And the edges of the graph get signed by presence rather than by a squiggle that any patient person with a light box can trace, which is where this post started.
  2. Centralize a little. Yes, I hear it. I'm the guy who wrote “Decentralization Is Not Broken” in the middle of the DAO hack. I still believe it. But there's a difference between decentralizing authority and decentralizing operations, and PGP conflated them. Somebody has to run discovery, revocation, availability and recovery, and pretending otherwise is how you get a 0.3% signature density. Centralize the boring parts, keep the authority distributed, keep the operator blind.
  3. Make it private. The graph must not be publicly readable, and the operator holding it must not be able to read the sensitive parts either. That's a ZK and blinding problem, and unlike 1991 we actually have the tools.
  4. Make the UX infinitely better. Not “better.” Infinitely. The user's job is to be present. Everything else is our problem. If a user ever sees the word “fingerprint,” we failed.

The absurdly simple answer is a graph

Every interaction you have is an edge. Who vouched for whom, who transacted, who showed up, who got burned. Grade the edges, propagate, and you get something PGP promised and never delivered: a trust score that is local and personalized rather than global and absolute.

This is not novel and that's exactly why I like it. EigenTrust is from 2003 and it's PageRank pointed at people: your reputation is defined recursively by the reputation of those who trust you, computed as the principal eigenvector of the normalized local trust matrix. It's distributable, it degrades gracefully, and it holds up in the original paper even with 70% of the network colluding.

The honest caveat, which anyone selling you a trust graph will skip: symmetric global reputation is provably not sybilproof. If edges are free, I'll manufacture a million friends who love me. Which is precisely why the graph needs the layers above it: edges rooted in attested, device-bound, bio-bound personhood, so that creating a node has a cost you cannot pay with GPU time, and trust queries evaluated from your vantage point rather than from a global scoreboard.

Graph without proof of personhood is spam. Proof of personhood without a graph is a passport with nowhere to travel. You need both, and I don't think anyone has shipped both.

Why Rebellion

Because the gap between “our authentication factor just broke” and “we have institutions that handle it” was thirty years last time, and this time the factor that broke is the human face and voice, which is the one every other system quietly depends on.

I don't think this gets solved by detection. Detection is a losing arms race against a generator that improves monthly and against humans who perform at chance level. It doesn't get solved by legislation, because most synthetic media is legal, wanted and profitable. And it doesn't get solved by another federated login button, because the majority of the internet is no longer people.

It gets solved by making personhood provable, continuously, privately, without a central authority owning your identity, and by giving trust somewhere to accumulate. That's the whole thesis. Root of trust in the device, evidence of the human on top, zero knowledge so nobody has to hand over their body to a database, and a graph so that all those interactions add up to something instead of evaporating.

I want my friends to click the damn link again.

TL;DR

  • Synthetic media wins, because the good uses are worth more than the bad ones and you can't legislate away entertainment or grief. Stop calling them deepfakes.
  • “I'll believe it when I see it” is over. Humans detect synthetic video at chance. Real-time injection costs $50 a month.
  • The compute cost of faking personhood was an unwritten security control for all of human history. It's gone.
  • The question stops being “is this real” and becomes “which principal, delegated by whom, for what.”
  • Authentication goes continuous, passive and bio-bound, on top of a hard cryptographic root. Never make the soft signal the root.
  • OAuth was built for humans consenting synchronously in a browser. Bots are 57% of traffic. Do the math.
  • PGP was right and lost on UX, privacy, an empty graph, and betting identity on a perennial key. Keep the shape, replace the primitive: the anchor isn't a secret you hold, it's a hard-to-copy feature of you (biological, biomechanical or mental) that you keep exhibiting.
  • A graph is the stupidly simple answer to grading interactions, and it only works if creating a node costs something a machine can't pay.

I've always been for optionality, less human interaction in the loop, and less human dependence in our systems. Turns out the way to get there is to make the humans provable.

Gonçalo Sá
About the author

Gonçalo Sá

Gonçalo is co-founder of Rebellion Systems. He has spent his career breaking and rebuilding the systems people depend on.

More from Gonçalo