This morning I read a piece on SRF about a team at ETH Zürich that has spent nearly a decade building a chip to fight deepfakes. The chip sits directly on a camera sensor and generates a cryptographic signature the moment an image is captured. Anyone who alters the image after the fact invalidates the signature. Felix Franke, the professor leading the project, says he saw the problem coming ten years ago and decided to work on it rather than wait for someone else. The chip is still a prototype. The problem it addresses is not.
That piece landed differently than most I have read on the subject. Not because the technology surprised me. I have watched deepfakes improve steadily for years, and the trajectory is not subtle. What struck me was the framing: authenticity now needs to be verifiable at the hardware level, because human eyes passed their useful detection threshold some time ago.
My spam folder has been telling me the same story. What used to arrive as obviously fraudulent, misspelled names, impossible offers, transparent pretexts, has gradually become more careful. Some messages now use language calibrated to sound like a colleague, a trusted institution, or a service I actually use. The writing has gotten better. The targeting has improved. The cost of producing a convincing fake has dropped, and the volume has gone up. That combination is not an accident. It is the signature of a business model that found a technology it could use.
The question that tends to get avoided
Whenever deepfakes come up in public discussion, the conversation lands quickly on the technology: how realistic it is, how fast it is improving, whether detection can keep pace, and what regulators might eventually do. Those are reasonable questions. But there is a prior one that gets less attention.
Who owns a person’s face, voice, image, and identity? And who gave anyone else the right to use them for advertising, content, entertainment, fraud, or profit?
The law is genuinely unclear in some places. Enforcement is weak in others. Platforms move slowly, and by the time a policy is updated, the next version of the tool has already changed shape. But the basic question is not that complicated. It is about consent and about who carries the cost when something goes wrong. Creating fake celebrity investment pitches is not a gray area. Cloning someone’s voice to run a financial scam is not a gray area. Generating non-consensual images of real people is not a gray area. The law may be slow. The moral position on those cases was never unclear.
Neutral at the level of physics. Not at the level of the market.
We reach for “technology is neutral” because it feels true and because it lets us avoid harder questions. A camera does not decide whether it documents a family trip or records someone who never agreed to be filmed. A microphone does not decide whether it captures a podcast or a private conversation. An AI model does not decide whether it helps a student understand a concept or helps a fraudster replicate a trusted voice.
At the level of physics, yes. Neutral.
But once someone builds a business model around a technology, the neutrality ends. A business model decides who is served, who pays, who benefits, and who has no say in the matter. It translates capability into incentives. And incentives decide what gets built next, what gets repeated, what gets funded, and what gets scaled. The technology is the capability layer. The business model is the behavior layer. That distinction is what makes the deepfake conversation actually useful.
The productive version of this pattern
We know this mechanism from disruption, and its constructive form is not hard to describe. A new technology lowers the cost of something. A business model forms around that lower cost. The initial offer is simpler, less polished, and less profitable than what established players sell, so they ignore it. The margins are thin. The customers look marginal. The use case seems narrow. The new entrant serves those customers anyway, learns faster than anyone expected, and gradually improves until it reaches a market incumbents actually care about.
Christensen’s work on disruption describes exactly this: a simpler, cheaper, more accessible offer that reaches people who were overserved, underserved, or excluded entirely. The technology alone does not disrupt. The model around it does.
At its best, this serves society in a straightforward way. Lower cost enables a different offer. The different offer reaches people who were previously locked out by price, geography, or the complexity of the incumbent product. They do not need the full package. They need the job done well enough at a cost they can actually afford. That is not a compromise. That is progress.
The same engine, pointed differently
The mechanism does not care about intent. The same economic logic that powers useful disruption can power harmful extraction, and the structure looks nearly identical from the outside. A new technology lowers the cost of something. A business model forms around the reduced cost. The first version is rough but good enough for the target market. In this case, the target market is not underserved customers with a legitimate need. It is people who can be deceived, pressured, or defrauded before anyone notices.
Deepfakes fit the pattern precisely. The positive business model is real: better dubbing, accessible education, synthetic video for people who cannot appear on camera, language translation at scale, creative production at lower cost. These create genuine value for actual users. The harmful business model uses the same underlying capability to produce fake celebrity investment pitches, voice clones for financial fraud, synthetic identities for automated ID checks, and non-consensual images of real people. One side creates value with consent. The other extracts value from victims. The technology in both cases can be similar. The business model is not.
What makes harmful models economically durable is that they do not require repeat trust. A legitimate company needs customers to return. A fraud network needs one successful transfer, one click, one moment where a tired or distracted person fails to notice something is off. That asymmetry changes the economics entirely. The product does not need to be good. It needs to work once, on enough people, to generate a return. That is a far lower bar than building something people actually want.
Platforms are not passive pipes
This gets sharper when platforms enter the picture. A platform that profits from attention will optimize for what holds attention. A platform that profits from trust will protect trust. A platform that profits from frictionless distribution may find friction inconvenient, even when friction is what protects people from the content that travels fastest.
Shoshana Zuboff’s work on surveillance capitalism names the underlying incentive structure: a logic built around data extraction, behavioral prediction, and continuous experimentation. You do not need to accept every part of that argument to see the core point. If the system earns more when behavior becomes more targetable, the system is not neutral in practice. It favors what can be captured, measured, and monetized. In the best case, that produces convenience and relevance. In the worst case, it rewards manipulation at scale, because manipulation at scale is efficient.
The same question shows up in recruiting
AI in hiring shows the same split clearly enough to name. AI can help candidates write sharper applications, help teams handle large volumes, reduce repetitive administration, and surface patterns that manual review misses. That is the legitimate version.
The other version is an automated rejection machine with a professional interface. Hilke Schellmann spent years investigating exactly this in her book The Algorithm, documenting how AI hiring tools screen people out without explanation, hide weak assumptions behind a score, and make bias look technical. The research backing her findings is substantial: studies have repeatedly shown that algorithmic screening rewards candidates who know how to write for machines rather than candidates who can do the work, and that the systems encode the biases of whatever historical data they were trained on. Hiring gets faster. Accountability gets weaker. The EU AI Act classifies AI hiring tools as high-risk systems and requires human oversight, transparency, and a meaningful right to review for exactly this reason. Whether companies are meeting that bar in practice is a separate question, and a more interesting one.
Regulation arrives after the business model has already learned
Technology moves through experimentation. Business models move through incentives. Regulation moves through language, negotiation, enforcement, and courts. By the time a rule defines one harmful pattern clearly, the next version has already changed shape. That does not make regulation useless. It is necessary. But a label does not undo a business model built on manipulation. A watermark does not help much when the model depends on speed, scale, and low accountability. A consent checkbox does not make power symmetrical.
Regulation sets limits. The first decision still sits with the people building, funding, deploying, and monetizing the system.
Who actually decides
AI does not decide to scam pensioners with fake investment videos. AI does not decide to clone a voice for fraud or generate non-consensual images of a real person. People decide. Teams decide. Founders decide. Investors decide. Platforms decide what they tolerate. Boards decide what risks they accept.
The owner of the business model makes the real choice. And the business model reveals the real judgment, more clearly and more honestly than any mission statement, ethics policy, or press release.
So before adopting or funding any AI capability, the question is not whether you can use it. The question is what behavior becomes cheaper when you do, who benefits from that behavior, and who absorbs the cost when it goes wrong. That is what the ETH chip is really trying to answer at the hardware level: can we build a system where accountability is structurally unavoidable, rather than optional?
The invention opens the door. The business model decides what walks through it, and whether you can explain that decision in public three years from now.




