T5 – Escalation when first-line triage is inconclusive or tools disagree¶
TL;DR
Use this tree when first-line triage cannot reach a defensible result, when harm is high enough that the toolkit's two-non-detector-signals threshold has not yet been cleared, or when two detectors disagree. The workflow routes by content type into professional verification and ends at one of six narrow conclusions, including the explicit option of "insufficient evidence" carried forward as a published method note.
When to use this tree¶
Three triggers move a case out of the first-line trees and into T5. The first is impact: elections, violence, communal tension, public health, financial fraud, public officials, journalists or activists, minors, alleged crimes, or state-linked actors. The second is signal incompleteness – only one evidence class supports a synthetic label after T1 to T4 are run.
The third is the one this toolkit treats as load-bearing under Foundational Decision 3: detector disagreement. When Hive AI, Sensity, Reality Defender, Deepware, or TrueMedia / Georgetown return conflicting verdicts on the same artefact, the right response is not to average their scores or pick the loudest one. Step out of the detector layer entirely and reaffirm Architectural Anchor 2: at least two non-detector signal classes are required before any strong public claim. Sensity and Hive's multimodal stacks already count as one class under Anchor 3, not several. Adding a third detector to "break the tie" does not generate new evidence; it generates a louder version of the same evidence class.
The tree¶
high-impact OR detector conflict"]:::decision C["T5.3 / 5.4 Evidence prep
preserve + upload safety"]:::action D["T5.5 / 5.10 Professional verification
image · video · audio · text · mixed"]:::action E["T5.11 / 5.14 Convergence
2 classes · conflict · OSINT · subject"]:::decision F["T5.15 / 5.16 Method note + defensible conclusion"]:::terminal G["T5.17 / 5.18 External expert + regional partner"]:::action A --> C C --> D D --> E E --> F F --> G G -.->|accepts / conclusion| F click A "#t5-1" "T5.1 in Node detail" click C "#t5-3" "T5.3 / 5.4 in Node detail" click D "#t5-5" "T5.5 / 5.10 in Node detail" click E "#t5-11" "T5.11 / 5.14 in Node detail" click F "#t5-15" "T5.15 / 5.16 in Node detail" click G "#t5-17" "T5.17 / 5.18 in Node detail" classDef decision fill:#fff4cc,stroke-width:0,color:#000; classDef action fill:#e6f0ff,stroke-width:0,color:#000; classDef terminal fill:#c8f0c8,stroke-width:0,color:#000;
The diagram is a macro view of the main escalation chain. Click any block to jump to its row in the Node detail table below — that is the operational layer a fact-checker reads to find tools, time budgets, and exact wording for each step. A dedicated sub-diagram for the Anchor-3 reset / detector conflict path lives in the Conflict resolution behaviour section further down.
Side exits off the main chain — kept out of the diagram for clarity, documented here:
- Low-impact case at T5.1 → T5.2 Low-harm monitor (skip the chain; log and watch via tipline).
- Safety risk at T5.1 or T5.4 → T6 source-protection (apply S1 / S2 / S3 / S4 / S5 before any tool upload or third-party contact).
- Coordination dominates at T5.5 or T5.11 → coordinated-operation analysis (see the 1C Institutional Analysis section).
- Unsafe upload at T5.4 → T5.17 External expert directly, bypassing the in-house verification chain.
- High harm at convergence (T5.11 / T5.12) → T5.17 External expert, then back to T5.15 method note before publication.
- Close the case at T5.11 → T5.15 method note, then T5.16 narrowest defensible finding, when two independent non-detector classes have converged or further escalation will not move the finding. Insufficient evidence is itself a defensible close; a low-harm case can instead drop to the T5.2 monitor exit.
- Public response at T5.16 → T7 tipline routing for the per-country response surface.
How to read this tree¶
T5 has two doors. Most cases enter through T5.1 from T1 to T4, after the first-line workflow could not close the case at the required confidence. A separate door – the "tools disagree, Anchor 3 reset" branch – exists for the specific failure mode where two detectors disagree on the same artefact and the operator is tempted to settle the disagreement with a third detector. That branch routes directly to T5.13 contextual OSINT and locks in a method-note requirement at T5.15. The published output names the disagreement, names that detector evidence on its own does not satisfy Anchor 2, and reasons forward only on non-detector classes – provenance, source-history, behaviour.
The six classes of professional conclusion, written narrowly:
- false context (authentic media, false caption);
- manipulated or synthetic likely (forensic-grade evidence, not a label);
- AI-generated confirmed by provenance, expert, or source admission;
- authentic media but misleading claim;
- claim false, media origin unresolved (the liar's-dividend safe option);
- insufficient evidence (a defensible result, not a failure).
A "confirmed AI" or "confirmed deepfake" label without provenance, expert, or source confirmation routes to T5.17 before publication. The toolkit's editorial position is that this constraint is not optional.
Node detail¶
| Node | Question or action | Time | Tools |
|---|---|---|---|
| T5.1 | Escalation gate. Elections, violence, communal tension, public health, financial fraud, public officials, journalists, activists, minors, sexual content, alleged crimes, state-linked actors. | 1 to 3 min | – |
| T5.2 | Low-harm, low-spread, not legally sensitive: log, preserve minimal evidence, monitor through tipline / social listening. | 3 to 5 min | – |
| T5.3 | Build the evidence bundle: original file, URL, screenshots, timestamps, platform, uploader, captions, comments, tool outputs, hash, chain of custody. | 10 to 30 min | Auto Archiver, InVID-WeVerify WACZ |
| T5.4 | Safe to upload to third-party tools? Source identification, child safety, whistleblower, location, legally sensitive actor. | 2 to 5 min | – |
| T5.5 | Classify content type (image / video / audio / text / mixed / coordination) and signal strength (weak / conflicting / two independent / strong contextual contradiction). | 2 to 4 min | – |
| T5.6 | Image professional: pixel forensics, provenance, metadata, ensemble detector, localisation heatmap. | 30 to 90 min | InVID-WeVerify, FotoForensics, Sherloq, TruFor, Sensity, Hive AI |
| T5.7 | Video professional: keyframes, reverse search, deepfake panel, physics and context checks. | 45 to 120 min | InVID-WeVerify, Deepware Scanner, Sensity, Reality Defender, TrueMedia / Georgetown |
| T5.8 | Audio professional: verified transcript, comparison with known recordings, audio detector with codec and language note. | 45 to 120 min | OpenAI Whisper, Hiya Loccus, Reality Defender, Hive AI |
| T5.9 | Text professional: claim extraction and matching, source tracing, behaviour analysis. AI-text detection only as a style flag. | 30 to 120 min | Meedan Check, Meedan Alegre, ClaimBuster, Yudistira, X-CLAIM, Google Pinpoint |
| T5.10 | Mixed-media: split case across modalities, return per-modality confidence note, recombine with caveats. | 60 to 180 min | per modality |
| T5.11 | Two independent evidence classes converging? Provenance, reverse / source trace, metadata, visual or audio anomaly, detector, contextual contradiction, subject confirmation, distribution pattern. Multi-detector counts as one class under Anchor 3. | 5 to 10 min | – |
| T5.12 | Conflict resolution. Re-test on original and compressed versions; compare tool explanations; check whether file quality, compression, language, or cropping explains the conflict. Reframe from "AI verdict" to "what can be verified?" | 20 to 60 min | – |
| T5.13 | Contextual OSINT: geolocation, weather, shadows, architectural cross-reference, official schedules, archival footage, local witness or source check. | 30 to 180 min | GeoSpy for leads, Google Pinpoint for documents, InVID-WeVerify |
| T5.14 | Subject, uploader, venue, or authority contact through verified channels. Narrow questions; preserve replies. | 30 min to 24 h | – |
| T5.15 | Method note: tool name, date, file version, compression, language and accent, upload safety, output, why the tool was or was not used in the conclusion. | 5 to 10 min | – |
| T5.16 | Choose the narrowest supported finding from the six-class list above. | 10 to 20 min | – |
| T5.17 | External forensic or expert escalation: WITNESS Deepfakes Rapid Response Force, Bellingcat, vera.ai network, institutional labs. Send minimised evidence bundle. | intake 20 to 60 min; response per partner | WITNESS DRRF is the framework reference |
| T5.18 | Regional partner routing: Indonesia (Mafindo / CekFakta / Tempo), Philippines (Rappler / VERA / #FactsFirstPH), Thailand (Cofact), Malaysia (Sebenarnya AIFA plus independent verification), Sri Lanka (Fact Crescendo / AFP Sinhala-Tamil / Hashtag Generation), Laos (regional or diaspora partner). | 5 to 30 min | per country |
Conflict resolution behaviour – Anchor 3 reset¶
When two or more detectors disagree on the same artefact:
- Stop. Do not run a third detector to break the tie. Multi-detector consensus is one signal class under Architectural Anchor 3.
- Move the case into T5.13 (contextual OSINT) and T5.14 (subject contact) before any further detector work.
- Apply Architectural Anchor 2: at least two non-detector signal classes (provenance, source-history, behaviour, contextual OSINT, subject confirmation) before any strong public claim.
- Record the disagreement in the T5.15 method note. The published output names the conflict, names that detector evidence on its own is insufficient, and reasons forward only on non-detector classes.
This is the toolkit's standing answer to detector-stack-as-truth-machine, and it is the explicit output of Foundational Decision 3.
Cross-references¶
- T1 / T2 / T3 / T4 – feed cases into T5 when first-line triage is inconclusive.
- T6 – source-protection – S1, S2, S3, S4, S5 as gates at T5.1, T5.4, T5.14; S9 cross-border vendor retention before any T5.6 to T5.9 detector run.
- T7 – tipline routing – when the T5.16 conclusion routes to a public response or a tipline answer.
Anchor tool cards: Sensity, Reality Defender, Hive AI for the multimodal detector layer; TRIED Benchmark as the institutional reference framework for evaluating any detector before adoption; InVID-WeVerify for the cross-modality professional bundle.
Sources¶
- WITNESS Media Lab and Reuters Institute. Thinking About Deepfakes: A Verification Framework for Journalists. WITNESS, April 2024. witness.org. (Escalation criteria and inter-tool conflict resolution methodology.)
- Lyu, S. et al. Deepfake-Eval-2024: A Real-World Benchmark for Deepfake Detection. 2025. (Multi-detector category ceilings: best commercial video detector 0.78 accuracy / 0.79 AUC; basis for the Anchor 3 single-signal-class treatment when multiple commercial detectors are deployed.)
- Ha, B. et al. Organic or Diffused: Can We Distinguish Human Art from AI-generated Images? ACM CCS 2024. (Image detector robustness under adversarial edits and newer generators — basis for escalation gates at T5.3–T5.4.)
- WITNESS. TRIED Benchmark: Synthetic Media Detection Benchmarking. WITNESS, 2025. witness.org/tried. (Institutional-tier evaluation framework invoked at T5.15–T5.18.)
- Architectural Anchors — Anchors 1, 2, and 3; inter-tool conflict resolution operationalised at Anchor 3.