Proof-of-Work: The Credential AI Can't Fake Retroactively

The Signal · ENTRY 008 · 8 MIN · EVERY CLAIM TAGGED

Proof-of-Work: The Credential AI Can't Fake Retroactively

The headline overstates the case.

AI can help fabricate a document. A person can backdate a page. A coordinated actor can construct profiles, websites, references, and an employment story. The US Department of Justice has described alleged remote-worker schemes involving stolen or borrowed identities, false documentation, domains, and other infrastructure used to appear credible to employers. [R008-C01 · DUAL-VERIFIED]

Nothing about a public record makes deception impossible.

The defensible claim is narrower:

A dated, multi-source, internally consistent record of real work is harder to fabricate retroactively than a polished assertion created for today's opportunity.

The difficulty comes from history, not style.

R008-M01 · MECHANISM — A claim asks to be believed. Proof-of-work gives the evaluator artifacts, dates, provenance, and independent points of comparison.

The résumé is an assertion layer

A résumé is useful because it compresses.

It lists roles, dates, responsibilities, and selected results. Compression is also its weakness: the evaluator receives the conclusion without the path.

“Built a category strategy.”

“Led a cross-functional transformation.”

“Recognised authority in responsible AI.”

Each line may be accurate. Each can also be generated in seconds.

The answer is not to reject résumés or AI-assisted writing. It is to identify which claims require a richer evidence surface.

For a material professional claim, the surface might include:

  • a dated article that explains the underlying judgment;
  • a public talk or transcript;
  • a released product, filing, standard, or document;
  • a sequence of revisions that shows development rather than instant perfection;
  • independent references to the work;
  • corroboration by someone entitled to speak;
  • provenance showing what was created, changed, and approved.

No single artifact certifies the person. The pattern changes the cost of the claim.

Time is evidence, with limits

Suppose two candidates claim expertise in a field that became strategically important this year.

One has a newly polished biography and a set of current posts. The other has four years of dated work: early questions, later corrections, talks, diagrams, and a visible change in position as evidence evolved.

The second record does not prove superior expertise.

It does establish that the claim did not begin entirely in response to the current incentive.

That is why a longitudinal record matters. It preserves the order in which ideas, evidence, and opportunities appeared.

The chronology still needs authentication. Platform timestamps can be altered or misunderstood. Reposted material can look older than the author's involvement. A domain's registration date does not prove the content existed then. A screenshot is not a trustworthy clock by itself.

The evaluator should prefer dates supported by multiple systems and records, not one self-authored timestamp.

R008-M02 · MECHANISM — Chronology becomes useful when independent records constrain the story a person can tell about when the work existed.

Provenance is not truth

The C2PA specification defines Content Credentials as cryptographically bound provenance records that can include an asset's origin, edits, tools, hashes, and signatures. It also states an essential limit: valid provenance does not tell the viewer whether the depicted or asserted content is factually true. [R008-C02 · DUAL-VERIFIED]

This distinction is the centre of the problem.

Integrity asks whether the asset and its recorded history have been tampered with.

Identity asks who or what signed the record and whether that signer is trusted.

Provenance asks where the asset came from and what happened to it.

Factuality asks whether the claim corresponds to the world.

Authorship asks what contribution the named person actually made.

These questions support one another and do not collapse into one badge.

A perfectly signed false statement remains false. An unsigned but independently documented artifact may still be credible. An AI disclosure says something about method, not whether the conclusion is right.

NIST's synthetic-content report presents provenance tracking and synthetic-content detection as two computational categories and treats authentication as a process that can span provenance, detection, and labeling. [R008-C03 · DUAL-VERIFIED]

The practical lesson is to build a stack, not search for one detector.

Detection is the weakest retrospective credential

An AI detector produces a model judgment about text or media.

It does not know who formed the idea, who gathered the evidence, who edited the draft, or who accepted responsibility for the final version. Detection can be wrong. It can be evaded. Human writing can be classified as synthetic, and synthetic writing can be classified as human.

A public authority system should not base authorship on detection.

It should preserve positive evidence:

The source material existed.

The claim was extracted and classified.

The draft has a version and hash.

The person changed or approved exact bytes.

The evidence registry records the support and limits.

The released artifact can be traced back through those decisions.

This does not prove private mental authorship. It creates an auditable process for public accountability.

R008-M03 · MECHANISM — Provenance is stronger when it records affirmative creation and decision events, not merely a detector's guess after publication.

Proof-of-work is plural

One article can be ghostwritten. One repository can be fabricated. One reference can be coached.

A credible record combines different kinds of evidence with different failure modes.

Public analysis reveals reasoning.

Operational artifacts reveal execution.

Independent records reveal external contact with the work.

Version history reveals change.

Corroboration reveals whether another authorised observer recognises the account.

Conversation reveals whether the person can inspect and defend the judgment now.

The evaluator should not demand every category for every claim. That would reward people with privileged access to public work and penalise confidential or less visible roles.

The burden should match the consequence.

A casual statement needs less support than a claim of leading a major transformation. A board biography, expert-witness credential, regulated responsibility, or investor-facing claim may warrant deeper inspection.

Confidential work still leaves a legitimate trace

Proof-of-work does not require publishing client documents.

An executive can document the structure of a decision without identifying the organisation. They can explain a framework with synthetic or public examples, label the account as the author's experience, and omit sensitive results.

They can publish a methodology before an opportunity arises, then allow an authorised referee to corroborate that it was used.

They can point to public outcomes the organisation has already released while carefully stating their own role.

They can say, “I cannot evidence this publicly” rather than converting confidential access into a vague superlative.

The refusal is itself informative. It demonstrates that the person understands the boundary between authority and disclosure.

A credential has an expiry condition

Longitudinal evidence can become stale.

A technical standard changes. A regulatory interpretation is superseded. A person has not worked in the field for years. An article remains online after the author changes their view.

The record therefore needs maintenance.

Sources should have checked dates. Claims should identify the period and population. Corrections should create new versions without erasing the original. A current biography should not rely on an old credential without stating the date.

A durable record is not a museum of permanent correctness. It is a record of what the person could responsibly say at a given time and how that position evolved.

R008-M04 · MECHANISM — The ability to correct a record without rewriting its history is part of the credential.

What we mean by “AI can't fake”

We mean that generation alone cannot produce the past.

It can write a plausible 2022 article today. It cannot make that article have been cited in an independent 2022 document, discussed in a recorded 2023 event, revised after a 2024 result, and used by an authorised colleague whose own records support the sequence—unless the actor fabricates or compromises those independent records too.

The word “can't” is therefore rhetorical, not absolute. The security property is increasing cost and detectable inconsistency.

This is similar to other trust systems. No control makes fraud impossible. Good controls require an attacker to cross independent boundaries and leave more evidence while doing so.

For ordinary professional evaluation, that can be enough to distinguish a recently polished assertion from a developed body of work.

Build the record before the need

The worst time to begin proving a credential is after someone asks whether it is real.

Start with one problem you genuinely work on.

Record the sources that shape your view. Publish one bounded argument. State what would change your mind. Return when the evidence changes. Preserve the earlier version. Link related artifacts without pretending they are independent if they share the same source. Let authorised people corroborate what they can actually know.

Over time, the record becomes useful for more than validation.

It improves thinking. The person can see where they repeat claims without new evidence. They can identify which ideas remain assertions. They can show a sponsor or evaluator a sequence rather than a slogan.

The public benefit is discovery.

The deeper benefit is disciplined memory.

Honest limits

No public record is unfakeable. The DOJ source describes allegations in a specific criminal case and cannot be generalised to ordinary candidates or to AI-generated applications. Defendants are presumed innocent unless proven guilty.

C2PA provenance can establish recorded origin, integrity, and history under its trust model; the specification explicitly does not certify factual truth. NIST describes a set of technical approaches, not a guarantee.

Longitudinal public work may disadvantage people whose roles are confidential, less public, or constrained by safety and access. Evaluators should not treat public output volume as a proxy for ability. Independent references can be biased. A consistent false story can persist for years.

The title should therefore be read as a design direction:

Do not rely on prose that can be generated today to prove a history that supposedly existed yesterday.

Build a dated, bounded, multi-source record of real work before the credential is needed.

AI can imitate the sentence.

It cannot, by itself, supply the history around it.

RUN MY IMPACT ANALYSIS