OSINT (Open Source Intelligence) currently faces two problems. One is age verification laws and the other is verification of evidence/findings.
Before we continue, for the uninitiated, let’s talk about what OSINT is.
What is OSINT?
OSINT, or Open Source Intelligence, is the collection of information in the public domain, analyzing it, and using what’s learned.
A couple of the other sub-disciplines that fall under OSINT are social media intelligence (SOCMINT) and geospacial intelligence (GEOINT).
Some OSINT sources include:
- Search engines
- Websites
- Archival sites
- News
- Databases
- Maps
- Images/video
- Social media posts
With this very broad definition of OSINT, let’s talk about the two problems this discipline currently faces.
Problem 1: Age verification laws

This problem we currently don’t have solutions for. We feel it’s important to bring it up because of the potential impact on how researchers conduct their investigations.
In the United States, there are a multitude of states laws pertaining to age verification. These laws either target social media, and other websites that may contain adult content, and Operating Systems.
These laws are in various stages of legislation. Some have become law, some were just introduced into legislation, and some were introduced to legislation but failed to pass.
Here is the potential impact these laws have on OSINT:
- Sockpuppet accounts: Researchers may use accounts created specifically for work they do with social media. They provide some anonymity and they also keep the work they do separate from their personal/business social media accounts. Age verification laws might put researchers’ safety at risk if they’re required to provide identifying information about themselves to create a sockpuppet account.
- Operating System level age verification: The way these laws are supposed to work is that Operating System (OS) developers will have to find a way to collect age data on anyone who uses an OS. Then, when that person goes to an app store to download a program, their OS sends a signal to the developer. If the developer sees the age signal is of age, then the user can download and install the app. If the age signal shows the user isn’t of age, they won’t be able to download certain apps. This is causing some open source projects to exclude residents of certain U.S. states from being able to download their applications or operating systems.
How does this affect OSINT?Some popular tools are open source projects. OS age verification laws could cause these projects to restrict who can download them by geographic location.
We also don’t know how age verification laws would impact actual OSINT research. How would these laws affect journalists, researchers, CTI, or investigators? These are questions we need answers to.
If you’re an OSINT practitioner, we’d love to hear how age verification laws may impact what you do. You’ll find a contact form at the very bottom of the article to reach out with your thoughts and ideas.
Now let’s finally turn our attention to the second problem OSINT currently faces.
Problem 2: Verification of evidence/findings

Verification is a very important part of OSINT. It’s the difference between accurately identifying someone/something in your research and just guessing. Guessing has consequences.
In the beginning of the COVID era (2020 – 2022/23) certain threat actors launched disinformation campaigns. One tactic used was creating posts about events where they wanted two rival groups to attend in the hope that violence would break out. These social media posts had a look that felt off.
Contact info in these posts were fake as were the accounts that posted them.
People still fell for it and shared these posts on social media.
Also around this time we were monitoring threat actors weaponizing legitimate cybersecurity bulletins to push their plans to weaken trust in critical infrastructure.
Allies of these threat actors also started creating deepfake videos. Compared to deepfake videos as of this writing, these early attempts were crude looking.
This was the moment we knew things were about to change where disinformation was going to be a feature, not a bug, in the social media tapestry.
This is what prompted us to put together a program called Web Digital Literacy (which is now retired) to give people the foundational skills to spot disinformation.
It covered things like:
- Looking for old images/videos repurposed to look like current events.
- Picking apart websites to look for certain information and how to verify the findings.
In 2024 we published findings from research we had done that involved fake social media accounts.
This research discussed some of the limitations with OSINT/SOCMINT when trying to unmask fake accounts and attribute them to a real person/group that’s operating them.
Not having a process to review and verify social media profiles can put your investigation in a precarious place. If you get things wrong, your findings won’t stand up to scrutiny and you may be targeting the wrong person or group.
With AI blowing up with the launch of OpenAI’s ChatGPT, other AI tools to create audio and visuals improved.
This ushered in an unbearable amount of AI slop.
AI slop is low effort AI generated content.
We did a two part mini investigation on YouTube AI slop here(part 1) and here (part 2).
Part 1’s focus is on the disinformation side of AI slop content. Part 2 is more of a technical exploration into identifying if the audio is synthetic or real.
Artificial intelligence is going to trip us OSINTers up if we don’t build our verification skills.
And using AI to verify things doubles our work because we must check the bot’s output for accuracy.
Unchecked, inaccuracies from AI output can make it’s way into your reporting. This destroys the credibility of your deliverables.
Bad actors’ use of generative AI makes the OSINT community’s job more difficult too.
Is that PDF you found legit or synthetic? If it’s synthetic, what’s it’s purpose for existing? Why did the bad actor publish it?
And for those of you reading this that are collecting and preserving online evidence, using AI to “enhance” a photo can alter it. We shared a tip about it here and why doing this is dangerous to your work.
Conclusion
We don’t currently know how age verification laws will impact OSINT research, but it’s something we all need to start thinking about.
With verifying findings, there are always challenges to this. With platform changes, generative AI, and AI tools to help researchers, things become complicated with how we all research.
This is why age verification laws and verifying findings are two problems OSINT currently faces.
How Bsquared Intel Helps
Regarding OSINT, we provide various services for organizations and law firms.
Organizations: External Cyber Risk and Threat Assessments and research.
Law Firms: Website and Social Media Forensics
Schedule a free strategy call using the contact form below. Also use this form to chime in on your thoughts about this article.
And while you’re still here, sign up for our newsletters.
Contact Us | Bsquared Intel
Please fill out the form below, or call 203.828.0012, to learn how Bsquared Intel can assist you.


