Swear only to what you can read back: preserve the item, extract the fields, mark what the score cannot establish, and leave the notice to the named counsel who signs it.
An item is preserved, and the score it drew is written down beside it, never inside it.
02
A detector reading perfect on the benchmark reads worse than a coin toss on real audio.
Reason
03
Synthetic is not false, false is not unlawful, and only unlawful content can be notified.
04
A Content Credential is missing, and C2PA says in terms that its absence proves nothing.
05
The perjury clause at 512(c)(3)(A)(vi) covers the fields, so the extraction is what is sworn.
Decide
06
Good faith sits at clause (v), and under Lenz that belief is held by the signer or by nobody.
07
A counter-notice lands, and 512(g)(2)(C) opens the put-back window the record must survive.
Out
08
No instrument reaches the item, and that is recorded as the finding rather than as a gap.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
Preservation, extraction and drafting belong to the agent. The oath, and the name that goes under it, belong to the counsel who is cross-examined on it later.
Example workflow
One notice, item to filing
AgentHuman
1Item referred inA flagged upload, a customer report, a broadcast clip or a link handed over by the listening lane
2Item preserved and datedThe capture, the hash, the archive location, the uploader account and the hour it was taken
3Notice fields extractedThe work asserted, the locations, the account identifiers and detector confidence
4Controls appliedProvenance checks, own-content checks, instrument checks and extraction confidence
No human action required
Stages 1 to 4 run unaided, and nothing is filed at any of them — the agent is assembling, and the counsel lane opens at the signature gate.
5DecisionSplits at the signature gate
A work the company owns
Goes to named counsel to sign.
Anything wholly synthetic
Adds a brand-protection read first.
Counsel review
The packet is held with its capture, its score and the steps the agent could not take.
Sign · Amend packet · Send to brand-protection review
Filed — by named counsel▼
6Matter and takedown records updatedOnly where write access and records policy allow it
7Outcome evaluatedNotice outcomes, counter-notices received, counsel corrections and what the later review turned up
Corrections
Each correction counsel makes counts in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Signing a notice under penalty of perjury.
Judging an item unlawful, not merely synthetic.
Deciding to sue rather than watch it return.
Naming the copyrighted work said to be infringed.
Automation boundaryAgent acts unaided
✓Preserve the item, hash it and date the capture.
✓Extract each notice field and record which source produced it.
✓Mark which of the three translations it cannot make on this item.
✓Hold the packet for the named counsel who signs it.
Nothing is filed with a platform except by named counsel, inside the agreed boundaries.
Forming the good-faith belief clause (v) wants.
Telling a platform the packet is complete.
Choosing which remedy an item is filed under.
Changes to the holding rules or the signature gate.
Example output
One notice packet, annotated
A listening agent found the item and a crisis agent will answer for it; this one assembles what a signature would rest on. Below is one packet exactly as the agent leaves it.
Notice packet · single itemIllustrative example
Item
Recorded as
Classified
Evidence of record
Confidence
Held for
Executive video, one account
Synthetic on the audio track, unproven
Score only
Capture hash, 4 August 2026
Held unsigned
Named counsel, by name
As receivedDrawn from the capture, the hash and the account record, and it asserts nothing those three establish.
What the record holdsCapture and hashUploader accountCross-post graph
Why no filing hereSwearing to the notice is an act that named counsel performs alone.
ActionSignAmend packetSend to brand-protection review
What the score decidesBelow the configured threshold a packet gets a brand-protection read before counsel sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Each noticeFrom the item it names
03Notice
Where the notice is filed
Under Lenz the good-faith belief is subjective and must be held by the signer, and willful blindness can supply the knowing misrepresentation that 512(f) punishes.
01Approved path
Sworn to, not proven
The oath at clause (vi) runs to the fields a machine filled in; the claim that the item infringes sits at clause (v), on good faith alone.
02Human review
What was checked, and not found
No instrument consulted takes a detection score as grounds for removal. TAKE IT DOWN runs a forty-eight-hour clock on intimate imagery alone; both California deepfake statutes are permanently enjoined; NO FAKES is still a bill; and the FTC rule on impersonating an individual was never finalised.
04Build an evidence trail
The item, the score it was given and the person who swore to the notice stay together.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Detection and provenanceDetector APIs · manifest readers Model scores and credentials
Evidence preservationCapture · hashing · archives Timestamped copies of items
Notice and platform channelsPlatform notice forms · DSA portals Filed notices and the responses
Agent
Misinformation and deepfake notice
Reads the item Assembles the packet Holds the signature
Matter and counsel recordsMatter management · legal hold Signature trails and filed versions
A class-level packet-accuracy figure can read clean while unseen generators carry most of the counsel corrections. Nestack reports the correction rate by generator class, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Unseen generator families
9.5%
3.7×
Review
Cloned executive audio
6.7%
2.6×
Review
Re-encoded platform copies
4.2%
1.6×
Watch
Known generator families
2.2%
0.9×
Normal
Bar: correction-rate lift vs. known-generator baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What an unread score costs
A cycle shuts when the notice sworn on a score nobody opened is a standing case. That suite is what the next takedown filed is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on unseen generator families.
02Diagnose
The notice sworn out on a number nobody opened, against a clip the company had itself upscaled, is worked backwards until one cause is left standing.
03Improve
Notices ship numbered, and the items behind them travel attached.
04Verify
Each touched notice case is run again, and one red holds it back.
05Learn
The case is kept, and the review rules are amended in that same commit.
Learn → DetectThe return edge. The next item meets a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, packet assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Deepfake-notification and automation-boundary scope.
02Detection, capture and notice sources.
03Statutory-instrument and counsel-signature mapping.
04Item capture and intake.
05Field binding and packet logic.
06Confidence scoring and review routing.
07Counsel signature workflow.
08Matter-system integration.
09Review and notice cases.
10Guardrails and filing controls.
11Notice-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne generator class, one cycleProductionProduction notice workflowAdvancedMultiple platforms / jurisdictions
Introduced at Pilot
Assembly to your holding rules✓✓✓
Named counsel signature✓✓✓
Detector-baseline measurement✓✓✓
Introduced at Production
Reporting by generator class—✓✓
Brand-protection review workflow in your systems—✓✓
Approved matter write-back—✓✓
Detector-and-registry integration—✓✓
Introduced at Advanced
Multi-regime notice rules——✓
Cross-platform notice packs——✓
High item volume——✓
Multi-platform notice controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, item volume, signature controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your live item classes and the instrument each one points at→Holding-rule capture and detector versioningWeek 1
02Representative items, captures and past notices→Field binding, packet logic and the detector baselineWeek 2
03Your escalation path and the counsel it names→Holding-rule mapping, instrument binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Detection, capture and matter source assessment, then integration setupWeek 2
05Notices you would not want cross-examined→Review cases and the evaluation roundWeek 4
06What no score may be sworn to→Confidence scoring, review routing, guardrails and filing controlsWeek 3
07Named counsel who signs the notice→Handover to named counsel, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
A band here is as wide as the phase actually costs, so week five shows a pair rather than a tidier blank.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Holding-rule discovery, detector versioning and the automation boundaryW2Detection and capture integration and the packet baselineW3Field binding, packet logic and filing controlsW4Evaluation suite, review cases and failure-mode testingW5Matter-system integration, pilot items and targeted correctionsW6One detection cycle run under the brand-protection lead, then Agent Care handover
Reading the bandNo bar runs past the weeks its own work is named for, and week five is the one overlap.
At the end of W6Once the notice record validates, Agent Care adopts the agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Public relations AI agent
Build a deepfake detection agent around the notice your last incident nearly swore out.
Show us one item you wanted taken down and the notice you drafted for it. Not how fast the detector flagged it. Which work you named as infringed, what the score actually established, and whose name would have gone under the oath. A score nobody opened comes back as a case.