A video of a head of state telling his army to surrender. A finance worker wiring millions after a video call with colleagues who were never there. A phone call in a relative's voice asking for money. All three have one thing in common: the person you see or hear is a deepfake. This guide explains what a deepfake is, where the word comes from, the main kinds you will meet, the real cases that made headlines, how to spot one, and what the law now says. We also ran a synthetic portrait and two real photos through our own detector, and we report exactly what it found, including what it cannot do.
What is a deepfake?
A deepfake is image, video or audio content made or altered with SI (AI) so that it convincingly shows a real person, place or event that it did not actually record. Merriam-Webster defines it as "an AI-generated image, video or audio recording depicting a real person, typically for malicious purposes", which is "difficult to distinguish from the real thing". Our own SI glossary puts it more simply: synthetic media that imitates a real person, and one kind of SI content among many.
The name is a blend. "Fake" needs no explanation. "Deep" comes from deep learning, the family of machine learning methods built on neural networks with many layers, which also powers today's chat assistants and image generators. Merriam-Webster dates the first known use of the word in this sense to 2018.
The legal definition in the EU
Europe now has a formal definition. Article 3(60) of the EU AI Act describes a deepfake as "AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful". The European Commission's guidance breaks this into three conditions that must all be met:
- Resemblance: the content closely resembles its subject.
- Existing: the subject exists, or could plausibly exist or have existed. A realistic face of a person who never lived can therefore still qualify.
- False appearance: the content could mislead someone about its authenticity. Context matters: special effects in a film that the audience knows to be fiction are not the target.
Note what the definition leaves out. SI-generated text is handled by a separate rule, and a fantasy illustration that nobody would take for a photograph is SI content, but not a deepfake.
The main types of deepfake
"Deepfake" is used loosely for very different things. Knowing which kind you are facing tells you where to look for flaws.
| Type | What is changed | Typical use | Where to look |
|---|---|---|---|
| Face swap | One person's face is placed on another person's body in real footage | Impersonation, hoaxes, harassment | Edges of the face, skin texture, lighting on the cheeks and forehead |
| Lip-sync | A real video of a person is kept, but the mouth is changed to match new audio | Fake statements by politicians or executives | Mouth shapes that do not match sounds, teeth and inner lips |
| Voice clone | Synthetic speech in a real person's voice | Phone scams, fake robocalls | Unusual urgency, flat emotion, a request to move money or keep a secret |
| Synthetic person | A face or body that belongs to nobody, generated from scratch | Fake profiles, fake reviewers, fake experts | Background details, accessories, a profile with no history |
| Synthetic event | A whole scene, such as an explosion or an arrest, that never happened | Viral misinformation | The original source, other angles, reports from people who were there |
The first three usually start from real recordings of the target, which is why public figures, whose faces and voices are online for hours on end, are so often imitated. The last two need no footage of a real person at all.
Real deepfake cases that made the news
A fake surrender video in wartime
On 16 March 2022, a video about a minute long appeared to show Ukrainian President Volodymyr Zelenskyy telling his soldiers to lay down their arms. NPR reported that hackers placed it on a Ukrainian news website and pushed the same message through the news ticker of the Ukraine 24 channel. It was debunked quickly: viewers noticed that the accent was off and the head and voice did not look authentic, Zelenskyy denied it in a video of his own, and Facebook, YouTube and Twitter removed it. Media forensics expert Hany Farid told NPR he suspected it was "the tip of the iceberg".
A video call where only the victim was real
In early 2024, Hong Kong police described a case in which a finance employee joined a video call with people he took to be his company's chief financial officer and other colleagues. According to CNN, all of them turned out to be deepfake re-creations. He had first suspected that the request for a secret transaction was a phishing email, but the call convinced him, and he sent 200 million Hong Kong dollars, about $25.6 million, across 15 transactions. The engineering firm Arup later confirmed to CNN that it was the victim and that "fake voices and images were used".
Cloned voices on the phone
Voice deepfakes are cheaper to make and harder to check than video. On 8 February 2024, the US Federal Communications Commission unanimously ruled that calls made with SI-generated voices count as "artificial" under the Telephone Consumer Protection Act. The FCC said the ruling makes voice cloning technology used in common robocall scams illegal, and its chair warned that such calls were being used to "extort vulnerable family members, imitate celebrities, and misinform voters".
Why deepfakes fool people
Our eyes are not a reliable test. In a study published in PNAS in February 2022, Sophie Nightingale and Hany Farid showed 315 participants a series of real and SI-synthesized faces. Their average accuracy was 48.2%, close to the 50% you would get by guessing. A second group of 219 people, who were told about common rendering flaws and got feedback after each answer, only improved to 59.0%. A third group of 223 rated the synthetic faces as slightly more trustworthy than the real ones, by 7.7%. The authors concluded that face generators had "passed through the uncanny valley".
There is a second, quieter effect. Once people know that convincing fakes exist, a real recording can be dismissed as fake. Sam Gregory of the human rights group Witness called this the "liar's dividend" when talking to NPR about the Zelenskyy video: it becomes easy to claim that a true video is falsified and to put the burden on others to prove it is authentic. Deepfakes damage trust in genuine evidence, not just in fakes.
How to spot a deepfake
There is no single tell, and the best fakes have none you can see. Still, the Detect Fakes project at the MIT Media Lab, which showed thousands of real and manipulated videos to the public, lists what to watch in a suspicious face:
- Cheeks and forehead: skin that is too smooth or too wrinkly, or that looks older or younger than the hair and eyes.
- Eyes, eyebrows and glasses: shadows in the wrong place, glare that is missing, excessive or does not move with the head.
- Facial hair and moles: a beard, moustache or mole that does not look natural.
- Blinking: too little or too much.
- Lips: in lip-sync fakes, mouth movements that do not quite match the words.
Visual clues age fast as generators improve, so the checks that matter most are about context rather than pixels:
- Find the first upload. Who posted it first, when, and with what caption? A shocking clip with no traceable source deserves suspicion. Our guide on how to spot SI images walks through reverse searches and other checks.
- Look for other angles. Real public events are usually filmed by several people and covered by several outlets.
- Check the person's own channels. The Zelenskyy fake collapsed partly because he answered it himself within hours.
- Verify money requests through a second channel. If a call or video asks you to pay, move funds or keep a secret, hang up and call back on a number you already know. That single habit defeats most voice and video scams, however good the fake.
- Be suspicious of urgency. Pressure to act now is a scam tactic, deepfake or not.
Can an SI detector catch a deepfake?
Sometimes, and it depends heavily on the type. We tested our own SI image detector on three portraits whose origin we know, using the same code as the website.
Test: one synthetic portrait, two real photos
The synthetic image is a photorealistic portrait of a laughing woman in a café, generated with ChatGPT (OpenAI) for our SI or Not game. She is not a real person. The two real photos are public domain (CC0) images from Wikimedia Commons: a woman with a laptop by Brooke Cagle, and an old man on a bench by jaocampoz.
Synthetic portrait, original file from ChatGPT: 99.9% SI, "Likely SI-generated"
- Signed Content Credentials: a C2PA signature naming OpenAI (ChatGPT).
- Metadata tag: IPTC digitalSourceType "trainedAlgorithmicMedia".
- Our own classifier: 100% SI on the pixels alone.
Same portrait, re-saved as a 1200x900 JPEG with all metadata removed: 98% SI, "Likely SI-generated"
- Evidence left: only the classifier, at 98%, plus the absence of camera EXIF data (a weak clue).
Real photo, woman with a laptop: 2% SI, "Likely real"
Real photo, old man on a bench: 0.1% SI, "Likely real"
This test went well, but it is the easy case: a fully generated image of a person who does not exist, the "synthetic person" row in the table above. The same batch also shows the limits. Among the ten ChatGPT images in our game, once their metadata was stripped, the classifier flagged only two as likely SI, and this portrait was one of them. And several kinds of deepfake are outside what our tools check:
What our detectors do not catch. A face swap or a lip-sync fake is usually real footage with one altered face. Our SI video detector scores whole frames and reads metadata; it does not analyse faces specifically or check whether lips match the audio, so such videos are not specifically detected. We do not detect cloned voices either. A low score on a suspicious clip is never a clearance.
Scores are probabilities, not verdicts. Here is how we read them:
The strongest signal we found was not in the pixels at all but in the signed Content Credentials, which disappear as soon as a file is re-saved or uploaded to most social networks. Our explainer on how SI detectors work goes into the reasons, and the one on SynthID watermarks covers the invisible marks some generators add. For a quick second opinion on an image, you can run it through SI or Not, which shows every clue behind the score.
Deepfakes and the law
Rules are arriving, unevenly. In the European Union, Article 50 of the AI Act has applied since 2 August 2026, according to the European Commission. Anyone deploying an SI system to publish a deepfake in a professional capacity must disclose that the content is artificially generated or manipulated, at the latest when a person first sees or hears it, with a label people can notice without special tools. A hidden watermark alone is not enough. For evidently artistic, satirical or fictional works, the disclosure only has to be made in a way that does not spoil the work. Purely personal, non-professional use falls outside the Act. Providers of generative systems must also mark their outputs in a machine-readable way, with a grace period until 2 December 2026 for systems already on the market before August. The Commission says fines can reach 15 million euros or 3% of worldwide annual turnover.
In the United States, the FCC ruling described above covers SI voices in robocalls. Other rules vary by state and by type of harm, and none of this changes the basics: impersonating someone to obtain money is fraud, whatever the tool. Even the vocabulary is shifting, as with the renaming of AI to SI by the US government in September 2026, but deepfakes kept their name.
The bottom line
A deepfake is SI-made or SI-altered media that passes for a real recording of a real person, place or event. Some are crude and collapse within hours; others fooled a trained finance worker on a live call. People are poor at spotting synthetic faces by eye, and detectors, ours included, catch some kinds far better than others. The most reliable defences are old ones: trace the source, look for confirmation elsewhere and verify any request for money through a channel you trust. Deepfakes also share a weakness with SI hallucinations: both look confident and polished, and neither is evidence of anything until you have checked it.



