AI can forge a certificate in ten seconds. The only defence is a record that is not the certificate
Image models now produce a flawless fake certificate for free: logo, seal, signature, foil, even the QR code. Every visual cue verifiers rely on is worthless. What is left is a record held somewhere the forger cannot write to. Here is what that means for anyone who checks certificates, and for anyone who issues them.

Two years ago a convincing fake certificate took some skill. You needed the right fonts, a clean copy of the seal, a steady hand for the signature, a printer that did not smudge, and the patience to get the paper texture right. Most people who wanted one bought it from someone who had those skills, and the price kept the volume down.
That barrier is gone. Type a sentence into an image model, attach a photo of a real certificate for style, and ten seconds later you have a new one with a different name, a plausible serial number, a seal that reads correctly under a magnifying glass and a signature that flows like ink. It costs nothing, it needs no skill, and it can be repeated a thousand times before lunch.
This article is about what that changes, and what does not change, for anyone who issues or trusts certificates.
Forgery used to be expensive. Now it is free
The important shift is not that fakes got better. Good fakes have always existed. The shift is in who can make one and how many.
When forgery required a skilled person and a few hours, only high-value targets were worth it: a medical licence, a degree from a famous university. A language institute's completion certificate was safe by being not worth the effort. That protection has evaporated. When a forgery costs nothing, everything is worth forging, including the certificate for a six-week course, because it moves a CV up a pile.
The second shift is on the verifier's side. Recruiters and admissions staff have spent years developing an instinct for what looks right: the crisp logo, the embossed seal, the consistent typography, the signature that does not look pasted in. Every one of those cues is now produced perfectly by default. The instinct still fires, and it is now wrong exactly when it matters.
Everything printed on the document is now worthless as proof
It is worth being blunt about this, because a lot of money is still spent on the opposite assumption.
- The logo and the layout are the easiest part. The model has seen thousands of certificates.
- The signature is a shape. A model reproduces a real signatory's signature from one example.
- The seal and the stamp are images. So is the foil effect, the guilloche border and the microtext that used to defeat photocopiers.
- The hologram stops a photocopy. It does not stop a PDF, which is how certificates travel now, and a printed forgery does not need one because nobody checks under a light.
- A "verified" or "blockchain secured" badge printed on the page is text. It proves that someone typed the word verified.
- The QR code is a pattern that encodes an address. It can be generated to point anywhere, including to a page the forger made, as we set out in a QR code on a certificate proves nothing.
None of these was ever a proof in the strict sense. They were friction, and friction only works while making the thing is harder than checking it. That is no longer true, and it will not be true again.
The one thing a model cannot generate
A model can generate any picture. It cannot generate a record on a server it does not control.
That is the whole defence, and it is the only one left. A credential is real when there is a record of it somewhere the forger cannot write to, and when the person checking can reach that record directly rather than through anything the holder handed them. Everything else follows from that:
- The record must be independent. Not the certificate file, not a page on the issuer's own editable website, but a record held by a platform whose job is to hold it, reachable by an address the issuer cannot fake and the holder cannot alter.
- The issuer's identity must be established by someone else. A record that says "issued by the Royal Academy" is only useful if a third party confirmed that the account that wrote it really belongs to that academy. Domain and business verification do this.
- The record must carry status. Valid, expired, revoked, with dates. A record that is silent about revocation is a record that lies by omission.
- The record must be machine-readable. A page a human reads can be imitated by a page a human reads. A signed, hosted assertion in an open format, which is what an Open Badge is, can be checked by software against the issuer's own hosted data without trusting the page it arrived on.
- The record must outlive the subscription. If the platform can switch it off, the certificate reverts to being a picture the day the invoice goes unpaid.
Certifada is built exactly on this: every credential resolves to a record on the platform, issuers are identity-verified before the mark appears, revocation and expiry are shown rather than hidden, every badge is a valid Open Badge with a hosted assertion, and verification is free forever so the record never goes dark.
What this means if you verify certificates
Stop judging documents. Start locating records.
- A PDF is not evidence. Treat it as a claim, the same as a line on a CV. It tells you what to check, not that it is true.
- Ask for the link, not the file. A real credential has a verification address. If the candidate cannot produce one, the institute did not issue a verifiable credential, and you are back to phoning them.
- Look at where the link goes. An independent verification platform, with the issuer's name and a verification mark, is a record. The institute's own website or a cloud drive is a copy.
- Read the status, not the design. Valid or revoked, issue date and expiry, are the only things on the page that matter.
- For anything that decides a hire, ask for the badge and drop it into a public Open Badges validator. Software does not have instincts about foil.
That is a two-minute process, and it is robust against every image model that will ever be built.
What this means if you issue certificates
Every certificate you have issued as a PDF only is now a template for its own forgery. Not because your design is weak, but because designs stopped being defences.
The response is not a better design. It is a record behind each certificate.
- Issue through a platform that holds the record, so the certificate points at something you did not make with a design tool.
- Complete issuer verification so the record carries your identity, confirmed by someone other than you.
- Put the QR code to the record on the printed copy too. The paper then points at the proof instead of pretending to be it.
- Enable Open Badges for programmes that lead to jobs, so employers' systems can check the claim without a phone call.
- Stop paying for holograms, foil and security paper. They reassure people who do not check, and the people who check no longer look at them.
- Re-issue what matters. Past cohorts can be issued as verifiable credentials from a spreadsheet in an afternoon. Alumni get a link that works; you get a back catalogue that cannot be cloned.
Beyond defence there is an upside. Once every certificate has a record, the verification page becomes a channel, and you finally see who is checking your credentials and from where.
The other side of the same coin
The same models that forge certificates are being used to read them. Recruiting tools already extract credentials from CVs automatically, and increasingly they try to verify them. A PDF gives such a tool a picture to guess at. A hosted, machine-readable record gives it an answer. Institutes whose certificates can be checked by software will find their graduates' claims accepted faster, and those whose certificates are pictures will find them quietly discounted.
The short version
The picture was never the proof. For a long time it was a good enough stand-in, because pictures were hard to make. Now they are free, and the stand-in has failed. What is left is what should have been there all along: a record that is not the certificate, held where the forger cannot reach, checkable by anyone in a minute. Issue that, ask for that, and the image models can generate whatever they like.



