Policy-as-Code↗
A compliance layer that translates the world's fragmented rules on synthetic media into automated, border-style checks – a digital passport for AI content.
In 2023, an image of Pope Francis in a white designer puffer jacket spread across the internet in a matter of hours. Millions of people believed it was real. It was generated by AI. And it did something that turns out to be at the heart of a much larger problem: it crossed every border on the internet instantly, while the laws meant to govern it stayed exactly where they were.
The problem is not the lack of regulation
It is tempting to describe AI-generated content as a lawless frontier. The opposite is true. Today, 75 legal instruments across 49 jurisdictions already regulate synthetic media across labelling obligations, disclosure duties, provenance requirements, liability regimes.
The problem is that they are contradicting each other.
The same synthetic image can be perfectly lawful in one jurisdiction, a labelling violation in the next, and a prosecutable deepfake in a third. For anyone whose content moves across borders – platforms, newsrooms, agencies, individual creators, there is no reliable way to know which rules apply where, or how they interact. Compliance becomes guesswork at exactly the moment the content is already everywhere. That reframing is the core of our thesis: AI-content governance is not an absence of rules. It is a conflict between regimes.
The solution: a digital passport check for content
Policy-as-Code turns that tangle of overlapping law into something a machine can actually read and act on. The metaphor we built it around is a passport check at a border.
Provenance standards like C2PA already answer the first question: what is this piece of content, and where did it come from? Policy-as-Code sits one layer above and answers the next one: given what this is, what does the law require, here? It is the legal-enforcement and orchestration layer on top of provenance – the part that translates "this is synthetic" into "and therefore, in this jurisdiction, these obligations apply."
Underneath the metaphor is a structured, machine-readable database of the governing instruments and an interactive world map that makes the fragmentation visible: the same content, checked against every regime at once, lighting up green, amber, and red across the map.
Where it went
We developed Policy-as-Code as part of the UN AI for Good initiative, within the ITU / ISO / IEC standards process, and presented it at the AI for Good Summit in Geneva in July 2026.
We are now producing a policy brief that makes the case directly: the failure in AI-content governance is fragmentation and the solution is interoperability between regimes. A machine-readable compliance layer is what makes that interoperability possible in practice rather than in principle.
Policy-as-Code sits on Synika's founding line – law and code working together on the technologies reshaping public life. If you're working on synthetic-media governance, provenance, or cross-border digital compliance, we'd like to hear from you.