Guide
How to Review AI-Generated Assets Before Publishing
Review AI-generated text, images, and code for truth, sources, rights, consent, privacy, security, accessibility, provenance, approval, and final-channel behavior.
In this article
How to Review AI-Generated Assets Before Publishing
An AI-generated asset is ready for publication only after a named human owner verifies its purpose, claims, sources, rights, consent, privacy, security, accessibility, provenance, brand fit, and behavior in the final channel. A polished preview, disclosure label, watermark, or generation record does not replace those reviews.
Text, images, and interactive artifacts share one release gate, but they fail in different ways.
Assign an owner before reviewing the asset
The owner is accountable for the release decision. They do not need to perform every specialist review, but they must know which reviews apply, who completed them, what evidence exists, and which unresolved risks remain.
Name the publisher, audience, purpose, channel, jurisdiction, intended lifespan, and consequence if the asset is wrong or misused. A private concept, public article, advertisement, product representation, news image, interactive calculator, and production application need different evidence.
The owner must be able to reject the asset. If speed, sunk cost, or executive enthusiasm makes rejection impossible, the review is ceremonial.
flowchart LR
A["Source and generation record"] --> B["Truth, rights, and consent"]
B --> C["Privacy, security, and accessibility"]
C --> D["Provenance and disclosure"]
D --> E["Final-channel review"]
E --> F["Named approval or rejection"]
F --> G["Monitor, correct, withdraw, and retain evidence"]
Preserve the source and generation trail
Retain the source material, prompt, system instruction, model or product surface, date, settings, input files, output files, edit history, human changes, failed runs, exports, and final asset.
Record where each input came from and the authority to use it. A public URL is not a license. Access to a client file is not permission to send it to a model. A person's consent to a photograph is not automatically consent to create new depictions.
The NIST Generative AI Profile recommends documenting tasks, assumptions, upstream data sources, content lineage, knowledge limits, human oversight, and test and evaluation. It also recommends comparing output to known ground truth using multiple methods. The profile is voluntary risk-management guidance, not a publication certificate.
Verify truth in the form the audience will receive
For text, check every factual claim, date, quotation, number, name, link, citation, and implication against the underlying source. Read the source. Do not validate a citation because its title looks relevant.
For images, determine whether the audience could reasonably read the asset as evidence of a real person, event, place, product, result, or endorsement. Verify labels, maps, charts, diagrams, and embedded text separately.
For code or an interactive artifact, test the displayed output, calculation, state transition, error, and claim. A correct-looking interface can conceal fabricated data or nonfunctional behavior.
| Modality | Frequent truth failure | Required evidence |
|---|---|---|
| Text | Invented claim, source mismatch, stale date, synthetic quotation | Primary source, claim record, current link, quotation verification |
| Image | Fabricated event, altered identity, wrong product, invented label | Source and edit record, subject or product review, contextual disclosure |
| Code or app | Incorrect calculation, fake data, hidden failure, misleading completion | Acceptance tests, code review, runtime evidence, final-surface test |
Grounding or retrieval can support a review. It does not transfer responsibility to the model.
Establish rights and consent
Create an input-and-output rights record. Identify text, photographs, likenesses, voices, logos, product designs, fonts, music, video, code, datasets, licenses, and contractual restrictions.
The United States Copyright Office AI initiative maintains current reports and notices on copyright and artificial intelligence. Copyright is only part of the review. Publicity, privacy, contract, trademark, consumer-protection, labor, biometric, confidentiality, platform, and sector rules can also apply.
Consent should match the actual generation and release. It should not be inferred from a person's public presence, employment, prior photograph, or agreement to a different project.
If ownership or authority is unclear, do not publish while hoping a disclaimer will cure it. Obtain qualified review, replace the asset, or narrow the use.
Remove private and secret material
Inspect prompts, files, outputs, metadata, screenshots, logs, console messages, URLs, document properties, EXIF data, code, environment files, comments, and analytics.
Remove personal data, confidential business information, credentials, tokens, internal hostnames, private locations, hidden layers, and identifiers that do not need to reach the audience. Confirm that the generation service, export destination, collaboration link, and final platform match the approved data boundary.
Google's Gemini Apps Privacy Hub is one example of why settings, retention, model improvement, and human review must be checked for the actual product and account. Do not generalize its terms to an API, Workspace agreement, another vendor, or a different plan.
Review security and abuse
For text and images, consider whether the asset materially enables fraud, impersonation, harassment, evasion, dangerous action, or deceptive use. Review whether publication exposes a target, procedure, vulnerability, or personal detail.
For code, inspect architecture, trust boundaries, dependencies, input validation, output encoding, authentication, authorization, secrets, storage, network behavior, error handling, logging, configuration, and business logic.
The OWASP Secure Code Review Cheat Sheet explains that manual review complements automated tools because business logic and context-specific vulnerabilities require human analysis. A passing preview or scanner does not establish secure production behavior.
Run the appropriate tests in the production-like environment. Do not put a public share link into service as a substitute for deployment review.
Test accessibility in the final channel
For text, review heading structure, link purpose, reading order, language, tables, captions, and clarity. For images, decide whether the image is informative, functional, decorative, or complex and provide the corresponding text alternative. Do not repeat decorative details as noise.
For interactive work, test semantic structure, keyboard operation, focus order and visibility, forms, errors, status messages, contrast, zoom, reflow, motion, timing, and assistive technology.
The W3C WCAG 2.2 Recommendation is the current technical standard cited by this framework. Conformance depends on the full page and applicable requirements, not a model's claim that its output is accessible.
Test the final channel because a content-management system, social crop, embed, script, or design export can change the result.
Use disclosure and provenance for their actual jobs
A visible disclosure can tell a reader that AI materially assisted the work. It should be understandable in context, not hidden in metadata that the audience never sees.
A generation record supports internal accountability. A watermark may support detection under a particular implementation. A Content Credential can provide signed assertions and asset-integrity evidence under a trust model.
The C2PA specification site maintains the current Content Credentials standards and related security, harms, implementation, and user-experience guidance. A valid credential does not prove that the depicted event is true, that inputs were licensed, that a person consented, or that the use is ethical. A missing credential does not prove that an asset is synthetic.
Validate provenance on the final file and delivery surface. Platforms may remove, transform, or fail to display the information.
Review the final rendered surface
Open the exact page, email, app, feed, video, document, or advertisement the audience will receive.
Confirm title, author, date, revision date, disclosure, captions, links, alt text, structured data, canonical URL, crop, responsive behavior, embedded media, share controls, data collection, consent flows, and correction route.
Read summaries and snippets that a content-management system or AI publishing agent generates. A safe boundary in the article can disappear from a social caption or search description while the risky instruction remains.
For a Canvas app, recheck the current sharing behavior. Google's Canvas help page says a public link can allow anyone with the link to view and edit data associated with the app. That fact alone makes final-surface testing and synthetic data essential.
Record the decision
PUBLICATION DECISION
Asset, version, owner, purpose, audience, and channel
Source and generation record
Truth and source review
Rights and consent review
Privacy and data review
Security and abuse review
Accessibility review
Provenance and disclosure review
Final-channel test
Approvers, conditions, unresolved risks, and decision
Monitoring, correction, withdrawal, and evidence-retention owner
Approval should identify the version. A later regeneration or edit creates a new asset and may reopen the relevant gates.
Plan for correction and withdrawal
Publication is not the end of ownership. Define how a reader reports an error, who evaluates it, how quickly a material problem is escalated, what correction history is visible, and when an asset is withdrawn.
Withdrawal cannot guarantee erasure from caches, downloads, screenshots, syndication, model training, or derivatives. State the boundary honestly.
Retain enough evidence to explain the release decision without retaining sensitive source material longer than authorized. Retention, deletion, and legal-hold obligations require the actual publisher's policy and counsel.
[[How to Evaluate AI Image Consistency]] owns the visual test set. [[How to Build a Prototype in Gemini Canvas]] owns the safe prototype and engineering handoff.
Editorial note
This is an editorial control framework, not legal advice, security certification, an accessibility conformance determination, or a safe harbor. Requirements vary by jurisdiction, sector, platform, asset, audience, and use. The draft was developed with AI assistance from the preserved episode and cited authoritative sources, then prepared for editorial, legal, rights, privacy, security, accessibility, provenance, and modality-specific human review. Publication has not been authorized.
Sources
Follow the evidence.
- policies.google.com: use policypolicies.google.com
- open.spotify.com: 4O0DCv9Na8StBZnoXJlZ1bopen.spotify.com
- workspaceupdates.googleblog.com: introducing canvas for the gemini appworkspaceupdates.googleblog.com
- Gemini Apps Privacy Hubsupport.google.com
- ai.google.dev: image generationai.google.dev
- blog.google: gemini collaboration featuresblog.google
- daltonanderson.ghost.io: googles new ai gemini canvas consistent image modelsdaltonanderson.ghost.io
- youtu.be: qoGIyz0azwwyoutu.be
- support.google.com: 16047321support.google.com
- ai.google.dev: modelsai.google.dev
- Gemini API changelogai.google.dev
- blog.google: google gemini ai update december 2024blog.google
- w3.org: WCAG22w3.org
- NIST Generative AI Profilenvlpubs.nist.gov
- spec.c2pa.org: aboutspec.c2pa.org
- daltonanderson.net: googles new ai gemini canvas consistent image modelsdaltonanderson.net
- copyright.gov: aicopyright.gov
- cheatsheetseries.owasp.org: Secure Code Review Cheat Sheetcheatsheetseries.owasp.org