From fake photos to cyberattacks: Central Asian experts and journalists discussed new risks for the media

From fake images to cyberattacks: Central Asian experts and journalists discussed new threats to the media
Journalists and specialists from Central Asian countries discussed the risks that artificial intelligence and digital attacks pose to the media, as well as how to verify content using open sources. Special attention was paid to the situation in Uzbekistan, where basic AI regulation is already in place, while the issue of liability for neural network errors remains open.
The meeting took place on September 28–29 in Dushanbe as part of the regional workshop Dushanbe Dialogue. It was attended by journalists, fact-checkers, cybersecurity experts, lawyers, and media managers from Central Asian countries. The event was organized by the National Association of Independent Media of Tajikistan with the support of CFI.
A separate section was dedicated to the verification of photos and videos. Tajik journalist and fact-checker Yokub Khalimov analyzed cases where media outlets published images unrelated to the events described. In one example, a photo of a woman in national dress was used in articles about traditional marriage, although she was actually a participant in a crafts exhibition in Dushanbe.
To verify such materials, reverse image search, social networks, Google Maps, and other open sources were used. Participants were also shown how to determine the filming location from photos and videos, identify individuals, and cross-reference publications with archival materials.
Experts concluded that editorial offices need to regularly verify visual content and require journalists to provide links to primary sources. This is especially important when working with materials that spread quickly on social networks.
Another topic was the security of newsrooms that are increasingly adopting AI tools. Experts warned that when creating their own services and bots, editorial offices often pay insufficient attention to data and infrastructure protection. This can create additional vulnerabilities for hacker attacks, phishing, DDoS attacks, and other types of interference.
Participants were advised to prepare a so-called "red folder" in advance in case of a crisis. It should contain contacts of technical specialists and lawyers, templates for appeals, instructions on preserving digital evidence, and procedures to follow during an attack. This approach avoids having to develop a defense algorithm after the website or editorial accounts have already been attacked.
If a hack is suspected, specialists recommended first saving technical data and isolating the compromised device or server from the network, and then contacting cybersecurity experts. Lawyers and newsroom management were advised to document evidence — screenshots, technical data, and addresses of the attacking resources — and, if necessary, contact law enforcement agencies and regulators.
The formation of the legal framework for the use of AI in Uzbekistan and Kyrgyzstan was discussed separately. In Uzbekistan, basic legislative regulation of AI is already in place. In January 2026, provisions defining the concept of artificial intelligence and general rules for its application were introduced into the law "On Informatization." At the same time, there is no separate comprehensive law on artificial intelligence yet.
In Kyrgyzstan, AI regulation is also in its initial stages. Meanwhile, government agencies are already testing the technology: for example, the parliament uses a system to transcribe sessions in Kyrgyz and Russian, and the healthcare system uses AI services for preliminary diagnostics.
Ultimately, the discussion came down to a problem common to the countries of the region: AI is developing faster than the rules for its use can be formed, and newsrooms have to simultaneously deal with new technologies, digital attacks, and the insufficient preparedness of the audience. For the media, this means the need not only to implement AI tools but also to build procedures in advance for verifying information, protecting data, and responding to cyber incidents.

