AI Must Leave Fingerprints: Transparency Obligations, Deepfake Financial Fraud, and Responsible Engineering
Original Chinese title: 法條開始要求機器留下指紋:AI 透明義務、深偽金融詐騙與責任工程
Deepfake financial fraud is not just a criminal case; it exposes differences between mainstream legal and Indigenous normative understandings. Written law demands evidence, responsibility, and traceability; tribal norms and taboos prioritize relationships, consent, shame, restoration, and the prohibition of arbitrary replication of identity boundaries.
Sulangal
Sulangal is a senior Indigenous cultural and visual media practitioner from the Puyuma people, long concerned with image ethics, ethnic narratives, cultural data sovereignty, and how technology reshapes memory, identity, and public trust.

I. The Law Demands Fingerprints; Indigenous Norms Ask Where This Hand Came From
Many discussions of AI deepfake fraud still linger on the thriller image: “the voice sounds like,” “the face looks like,” “the video is terrifying.” That is indeed frightening, but what truly troubles financial institutions, platforms, and regulators is that deepfakes are now embedded in ordinary workflows. It is not a single isolated fake video; it is a sequence of seemingly reasonable actions: a corporate email, a voice confirmation call, a video conference, an instant transfer instruction, a customer service verification—a work scenario designed precisely so people do not pause to suspect.
Mainstream law’s first response to this risk is tracking: content must be labeled, models must disclose themselves, data must leave traces, transactions must be traceable. This is the requirement that machines must leave fingerprints. That direction is necessary; otherwise every fraud becomes a fog of responsibility—platforms say they are merely tools, banks say users verify on their own, victims say they were deceived, and fraud rings have already washed accounts into empty shells. Without fingerprints, law can only investigate against air.
But viewed through Indigenous legal consciousness and normative worlds, the picture is not just that. Tribal norms do not ask only “is this file labeled as AI-generated?” They also ask: from whose body was this voice taken? Is this face permitted to be replicated? Can names, images, voiceprints, ritual utterances, elder authority, kinship terms be broken into data and used for training? Were taboos crossed? Were relationships damaged? Mainstream Han state law often centers on written statutes, contracts, evidence, rights attribution, and individual responsibility; Indigenous norms and taboos tend to situate people within land, ancestors, kin, age order, ritual, and communal life. Neither is superior; they simply offer different entry points into the question of what constitutes responsibility.
II. Han Legal Intuition Often Asks “Is It Illegal”; Tribal Norms Ask “Is It Imbalanced”
In mainstream legal systems, illegality is usually understood as violation of clearly identifiable statutes, contracts, or administrative orders. Evidence enters the file; responsibility is assigned to individuals or corporations; remedies proceed through courts, mediation, administrative appeals, or compensation. This system has its strengths, especially in cross-regional, stranger transactions, financial risk, and platform governance—without written rules it would be hard to operate. The problem is that it also tends to compress social relations into “who has the right,” “who violated,” “who compensates.”
Indigenous norms do not necessarily exist as state statutes. They may appear as taboos, customs, forms of address, sharing rules, hunting regulations, gathering sequences, ritual boundaries, elder-younger order, family responsibilities, and shame. Taboo is not the mysterious superstition mainstream society imagines; it is a normative system that maintains communal life, land ethics, and relational balance. Certain words cannot be spoken at random—not because discussion is feared, but because speaking itself alters relationships. Certain images cannot be freely published—not because they are backward, but because viewing permissions and cultural positions differ. Certain elder voices cannot be synthesized—not because of anti-technology sentiment, but because voice is not ownerless material.
Thus, deepfake financial fraud in tribal contexts is not merely property loss. It may appropriate kinship trust, impersonate elder authority, disrupt communal shame and mutual aid, and even force victims to bear relational embarrassment outside the law. Mainstream anti-fraud advice that simply says “do not believe strange calls” often falls short in many close-knit societies. Fraud’s most cunning feature is precisely that it does not always impersonate strangers; it may impersonate the person you are least willing to doubt.
III. Transparency Labels Are Insufficient Because Taboos Cannot Be Solved by Watermarks
The EU AI Act and related discussions are pushing content transparency obligations into institutional cores. Requiring AI-generated or substantially altered content to be labeled in specific contexts, and retaining machine-readable information technically, is important for cross-platform tracking and public trust. But if transparency is understood as “a small line of text in the corner,” that is merely legal self-comfort. Fraudsters can screenshot, transcribe, compress, remaster, switch platforms, or have real people retell; a single label easily evaporates through propagation chains.
From an Indigenous normative perspective, transparency raises deeper issues: not everything that can be labeled may be used. Certain images, voices, stories, Indigenous language terms, ritual fragments—even if you label them “AI-generated”—do not automatically confer legitimacy. Mainstream law often imagines consent as individuals ticking boxes; tribal norms may require collective judgment by family, community, age cohort, ritual office, or specific knowledge holders. Transparency does not replace consent, nor does it resolve taboo boundaries.
This matters equally for FinTech. If banks or platforms wish to use voiceprints, facial recognition, AI customer service, and risk models serving Indigenous communities, they cannot merely translate interface text. They must understand that some identity data are not personal property but relational; certain verification methods may be affected by shared family devices, elder language habits, weak network environments, and tribal mutual-aid patterns; anomalies flagged as suspicious in urban models may be everyday life in remote areas. If the model does not know the place, it will misclassify cultural differences as risk—or worse, overlook genuine risks.
IV. Responsible Engineering: Designing Statutes, Data Chains, and Relationship Chains Together
One of the most important concepts emerging for future legal tech is responsible engineering. That means asking at system design stage: when deepfake fraud occurs, who has the capacity to know? Who has the obligation to know? Who can prevent it within reasonable cost? Who preserves evidence? Who notifies victims? Who cannot push all responsibility onto users? If service includes Indigenous and remote communities, further questions arise: who can represent the community in discussions about data use? Which data must not be collected? Which contexts require cultural advisors? Which risk prompts need Indigenous language, imagery, voice, or local worker assistance?
If these questions are left to courts, it is usually too late. Good responsible engineering should allow reconstruction of data flows, decision flows, consent flows, and notification flows. It must also avoid dumping all responsibility on front-line customer service, who often serves as the last flesh-and-blood firewall for inadequate institutional design. What truly needs scrutiny includes how companies set risk thresholds, train models, audit anomalies, handle outsourced customer service and third-party tools, and prevent agent-style AI from automatically executing high-risk operations.
For Indigenous peoples, this responsible engineering must also preserve cultural negotiation. Tribal norms are not merely decorative footnotes; they should be written into product design and governance documents: clauses prohibiting secondary training of image and voice data, restrictions on sensitive cultural content entering customer service templates, prohibitions on using elder voiceprints via family proxy signatures, community education that does not rely solely on urban financial language, and post-victim restoration that goes beyond monetary compensation. Financial fraud harms money; it also harms relationships. Repairing only the wound in clothing is insufficient.
V. Machines Must Leave Fingerprints; Law Must Also Leave Humility
In black humor, the most dangerous aspect of the AI era may not be machines becoming human-like, but companies behaving like machines when things go wrong: every department claims it is merely part of a process. Legal says compliance, product says following requirements, customer service follows SOPs, users say they were deceived, and finally only victims search for an exit in the maze. If legal tech is to have public character, such responsibility mazes must become traceable.
But tracking does not mean controlling everything. For Indigenous communities, legal tech must also learn humility: state law is not the sole norm; contracts are not the only form of consent; data usability does not imply cultural usability; individual clicks do not represent community authorization. When mainstream law begins to require machines to leave fingerprints, tribal norms add a further sentence: please first confirm whether this hand was permitted to extend inward.
AI transparency obligations ultimately cannot be merely a technical format exported from European regulations nor simply the anti-fraud cost for financial institutions. They should become an opportunity to re-understand trust. Trust is not authentication codes; it is relationships. Identity is not just accounts; it may also be names, voices, families, and land. Law is not only statutes; it includes norms and taboos recognized in communal life. Machines can leave fingerprints, but civilization must preserve memory: not everything that can be replicated may be used.
VI. Indigenous Legal Consciousness Is Not an Exception Clause; It Is Governance Knowledge
Placing Indigenous norms into AI governance does not require financial tech companies to become ethnographic institutes each time they develop products; it reminds institutional designers not to treat mainstream urban users as the human default. Users are not only credit card holders, phone numbers, facial features, and KYC fields; they may also be community members, elders, ritual participants, cross-language families, shared-device users, residents of weak-network areas. If a product is designed with a single legal intuition and a single lifestyle, it will classify others’ normal lives as anomalies or disguise genuine anomalies as normal.
Thus, legal tech needs more mature multi-normative design. Written law provides the minimum baseline; platform rules supply operational procedures; Indigenous norms and taboos remind that data, identity, and voice cannot be arbitrarily decomposed. These three do not replace each other but complement gaps. When AI begins to speak for people, verify them, transact on their behalf, true transparency is not merely making machines leave fingerprints—it also makes society see whose norms are ignored. If this point remains invisible, transparency becomes only a technical format; if it is seen, transparency can become the beginning of trust reconstruction.
Sources retained from the Chinese original
AI use and content-safety disclosure
This article was assisted by AI for data organization, structural drafting, and sentence polishing. Human editors set the viewpoint and fact-checking direction