What Is a Deepfake?
A deepfake is a video, photo or audio recording created or altered with AI to make it look or sound like a real person said or did something they did not. Deepfakes can swap one face for another, clone a voice or generate entirely new footage. Because the best ones are hard to spot by eye, your strongest protection is checking where content came from and verifying unusual requests through another channel.
How to protect yourself from deepfakes
Deepfakes are not only a problem for celebrities and politicians. They can be used to trick you directly: a cloned voice of a family member asking for money, or a video call with someone impersonating your manager. These steps help, whether or not you can tell the content is fake.
- Pause when a message is urgent, emotional or secret. Scams rely on pressure. A request to act immediately and tell no one is a warning sign on its own.
- Verify through a separate channel. Hang up and call the person back on a number you already know is theirs. The Federal Trade Commission's advice is simple: "Don't trust the voice."
- Agree on a family code word. The FBI recommends creating a secret word or phrase with your family to verify identity in an emergency.
- Be wary of unusual payment requests. The FTC notes that requests to wire money, send cryptocurrency or buy gift cards can be signs of a scam. The FBI advises never sending money or gift cards to people you have met only online or over the phone.
- Limit the raw material available. The FBI suggests limiting online content of your image or voice where possible, making social media accounts private and restricting followers to people you know.
- Build verification into work processes. Require a second confirmation, through a known channel, for payments and sensitive requests, even when they come by video call. In early 2024, an employee of the engineering firm Arup in Hong Kong transferred HK$200 million, about US$25.6 million, after a video call with deepfake versions of senior managers.
- Check before you share. Look for the original source and credible reporting before passing on shocking videos or images.
If you are targeted. Save evidence, report the content to the platform and report fraud to the authorities. In the U.S., fraud can be reported to the FTC at ReportFraud.ftc.gov and to the FBI's Internet Crime Complaint Center. For intimate images shared without consent, including AI-generated ones, U.S. law now requires covered platforms to remove them within 48 hours of a valid request, and the FTC runs TakeItDown.ftc.gov for complaints about platforms that fail to act.
How to tell if a photo, video or audio clip is a deepfake
Often, you cannot tell just by looking or listening. In a 2021 study published in iScience, participants could not reliably detect deepfake videos, tended to mistake deepfakes for real videos and overestimated their own ability to spot them. A 2022 study in PNAS found that AI-generated faces were indistinguishable from real faces, and were rated as more trustworthy. The U.S. Government Accountability Office reported in 2024 that current deepfake detection technologies have limited effectiveness in real-world conditions.
Checking still helps, as long as you combine several kinds of clues and treat none of them as proof.
Context clues: usually the most useful
- Where did it come from? Is the account new, anonymous or known for sensational content?
- Is anyone credible reporting it? Major events are rarely captured by a single unverified clip.
- Does it push you to act or react? Content designed to provoke anger, fear or urgency deserves extra scrutiny.
- Can you find the original? A reverse image search can reveal an older or unaltered version of a photo or video frame.
Visual clues
The FBI advises looking for "subtle imperfections" such as distorted hands or feet, unrealistic teeth or eyes, irregular faces, unrealistic accessories, inaccurate shadows, lag time and unrealistic movements. It also warns that AI-generated content "is often difficult to identify," so the absence of these flaws does not mean something is real.
Audio clues
With voice cloning, listen closely to tone and word choice, as the FBI recommends. Unnatural pacing, flat emotion, or phrasing the person would not normally use can be clues. A convincing voice is not proof of identity.
Provenance and watermark tools
- Content Credentials are tamper-evident labels, based on the C2PA standard, that record how some media was created and edited. The U.S. National Institute of Standards and Technology notes that metadata like this is often stripped when files are shared on social media. That means a missing label does not prove content is fake, and a label shows where content came from, not whether it is true.
- Watermark checks can identify content from specific AI tools. Since November 2025, people can upload an image to Google's Gemini app to check for Google's SynthID watermark. The check looks for Google's own watermark, so a negative result says nothing about content from other tools.
For text rather than images, video or audio, see How to Tell If Something Was Written by AI.
What a deepfake is
Merriam-Webster defines a deepfake as a digital image, video or voice "that has been convincingly generated or altered to misrepresent someone as doing or saying something that was not actually done or said." The word combines "deep," from deep learning, with "fake."
According to the U.S. Department of Homeland Security, the term traces to late 2017, when an anonymous Reddit user calling himself "deepfakes" claimed to have created a pornographic video with a celebrity's face swapped in.
Laws define the term more precisely. The European Union's AI Act defines a deep fake as AI-generated or manipulated image, audio or video content that resembles existing people, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
How deepfakes are made
Deepfakes are made with neural networks, AI models that learn patterns from large amounts of data. Several techniques are common:
- Face swapping with autoencoders. A neural network learns to compress and rebuild images of two people's faces, then rebuilds one person's expressions with the other person's face.
- Generative adversarial networks (GANs). Introduced by Ian Goodfellow and colleagues in 2014, a GAN pits two neural networks against each other: one creates fakes and the other tries to detect them, and both improve as they compete.
- Diffusion models. Many recent image and video generators are diffusion models. NIST explains that they start from random noise and refine it step by step into an output that matches a prompt.
- Voice cloning. Voice cloning tools learn to imitate a specific voice. The FTC warns that a scammer may need only a short audio clip of someone's voice, possibly taken from content posted online.
Making a convincing deepfake once required technical skill and time. Many consumer tools now produce realistic results quickly. Arup's chief information officer told the World Economic Forum that it is "freely available to someone with very little technical skill to copy a voice, image or even a video." For how these networks learn, see What Is a Neural Network?.
Deepfake vs AI-generated image
Every deepfake is AI-generated or AI-altered, but not every AI-generated image is a deepfake. The difference is deception about reality: a deepfake depicts real, identifiable people or events in a way designed to seem authentic.
| Traditional fake | Deepfake | AI-generated image | |
|---|---|---|---|
| How it is made | Manual editing, misleading captions or clips taken out of context | AI creates or alters media of a real person or event | AI creates an image from a prompt |
| Depicts real people or events? | Usually | Yes | Not necessarily |
| Designed to appear authentic? | Usually | Yes | Not necessarily |
| Example | A real photo with a false caption | A video of a politician saying words they never said | A fantasy landscape made with an image generator |
An AI image of an imaginary city is not a deepfake. An AI image showing a real public figure at an event they never attended, presented as real, is.
What deepfakes are used for
The technology behind deepfakes has both harmful and legitimate uses.
Harmful uses:
- Nonconsensual intimate imagery. A 2019 report by the detection company Deeptrace found that 96% of the deepfake videos it identified online were pornographic. That is an older snapshot, but sexual imagery has been a central concern since the term appeared.
- Fraud and impersonation. Criminals use cloned voices and faces to impersonate relatives, executives and officials. The FBI warned in 2025 of a campaign using AI-generated voice messages impersonating senior U.S. officials.
- Political disinformation. Fabricated videos or audio of candidates and leaders can mislead voters.
- Harassment and reputational harm. Deepfakes can be used to humiliate, intimidate or discredit people.
Legitimate uses: GAO notes the same techniques can let filmmakers include a performer who is unavailable, let shoppers virtually try on clothing, and make a speaker appear to talk naturally in another language. Satire and parody also use these tools, and EU law provides lighter disclosure duties for clearly artistic, creative or satirical works.
Is making a deepfake illegal?
It depends on where you are and what the deepfake is used for. In the U.S., the UK and the EU, deepfakes are not banned outright. Instead, laws target specific harms, especially sexual imagery made without consent, fraud, election deception and failure to disclose AI-generated content. This section is general information, not legal advice, and laws in this area change quickly.
United States (federal):
- The TAKE IT DOWN Act, signed on May 19, 2025, makes it a federal crime to knowingly publish nonconsensual intimate images online, including AI-generated "digital forgeries." Covered platforms must remove such images within 48 hours of a valid request. The FTC began enforcing those platform requirements on May 19, 2026.
- In February 2024, the Federal Communications Commission ruled that AI-generated voices, including voice clones, count as "artificial" voices under the Telephone Consumer Protection Act, so existing robocall rules apply to them.
- A proposed federal law on unauthorized digital replicas of people's voices and likenesses, the NO FAKES Act, had not been enacted as of September 2026.
United States (states): State laws vary widely. Ballotpedia reported in August 2026 that every state except Ohio and New Mexico has a law addressing sexually explicit deepfakes. Many states also regulate deepfakes in election messaging. Some protect a person's voice and likeness directly: Tennessee's ELVIS Act, effective July 1, 2024, added voice to the state's protections against unauthorized use of a person's likeness.
United Kingdom (England and Wales): Sharing intimate images of someone without consent, including images made or altered by computer, has been an offense since January 31, 2024. Since February 6, 2026, intentionally creating an intimate deepfake image of an adult without consent, or asking someone else to create one, is also an offense. Scotland and Northern Ireland have separate legal systems, and different rules apply there.
European Union: Under the AI Act, from August 2, 2026, deployers of AI systems that create or manipulate deepfakes must disclose that the content has been artificially generated or manipulated. Deployers are people and organizations using AI, except in the course of a personal, non-professional activity. A lighter duty applies to evidently artistic, creative, satirical or fictional works.
Beyond laws aimed at deepfakes, existing laws on fraud, defamation, harassment, copyright and the right to control commercial use of one's likeness may also apply.
Why deepfakes matter
Deepfakes weaken a basic assumption: that a recording of someone is evidence of what they said or did. That affects personal safety, business security, elections and trust in genuine footage.
Detection alone will not solve the problem. GAO has noted that identifying a deepfake is not by itself enough to prevent abuse, because disinformation can keep spreading after it has been exposed. Habits like verifying through a second channel and pausing before sharing matter as much as any detection tool.
Related AI terms
- Voice cloning: using AI to imitate a specific person's voice
- Generative AI: AI that creates new images, video, audio and text
- Neural network: the kind of AI model used to create deepfakes
- Diffusion model: a common type of model behind modern image and video generation
- Image generation: creating images from text descriptions or other inputs
Frequently Asked Questions
How do you tell if a picture is a deepfake?
Start with the source: find where the image first appeared, check whether credible outlets have reported it, and run a reverse image search for an original version. Then look for visual flaws such as distorted hands, irregular faces, odd accessories or inaccurate shadows. Many deepfakes have no visible flaws, so a clean-looking image is not proof it is real.
What is the difference between a fake and a deepfake?
A traditional fake is made by manually editing media or presenting real media misleadingly, such as a photo with a false caption. A deepfake uses AI to create or alter media so a real person appears to say or do something they did not. Deepfakes can be far more realistic and are faster to produce at scale.
What is the purpose of deepfakes?
Deepfakes are made for many purposes. Harmful uses include creating sexual images of people without consent, impersonating people for fraud, spreading political disinformation and harassment. The same technology also has legitimate uses in filmmaking, satire, virtual clothing try-ons and translating a speaker's video into other languages.
What does deepfake mean?
Deepfake means media, such as a video, image or voice recording, that has been convincingly created or altered with AI to show someone doing or saying something they never did or said. The word combines "deep learning," the AI technique used, and "fake."
Is deepfake illegal?
Deepfakes are not illegal everywhere or in every form. Legality depends on the jurisdiction and the use. Many laws prohibit specific harms, such as sharing sexual deepfakes without consent, using AI voices in unwanted robocalls, or deceiving voters, and the EU requires most non-personal uses of deepfakes to be disclosed. Laws vary by country and U.S. state and are changing quickly.
Sources
- FBI Internet Crime Complaint Center, "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud," December 3, 2024. https://www.ic3.gov/PSA/2024/PSA241203
- FBI Internet Crime Complaint Center, "Senior US Officials Impersonated in Malicious Messaging Campaign," May 15, 2025. https://www.ic3.gov/PSA/2025/PSA250515
- Federal Trade Commission, "Scammers use AI to enhance their family emergency schemes," March 20, 2023. https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes
- South China Morning Post, "UK multinational Arup confirmed as victim of HK$200 million deepfake scam that used digital version of CFO to dupe Hong Kong employee," May 17, 2024. https://www.scmp.com/news/hong-kong/law-and-crime/article/3263151/uk-multinational-arup-confirmed-victim-hk200-million-deepfake-scam-used-digital-version-cfo-dupe
- World Economic Forum, "Cybercrime: Lessons learned from a $25m deepfake attack," February 4, 2025. https://www.weforum.org/stories/2025/02/deepfake-ai-cybercrime-arup/
- Köbis, Doležalová and Soraperra, "Fooled twice: People cannot detect deepfakes but think they can," iScience, November 19, 2021 (University of Amsterdam repository). https://dare.uva.nl/personal/pure/en/publications/fooled-twice-people-cannot-detect-deepfakes-but-think-they-can(823426f2-0c93-44c6-b2a9-e9d63caed035).html
- Nightingale and Farid, "AI-synthesized faces are indistinguishable from real faces and more trustworthy," PNAS, February 22, 2022 (Lancaster University record). https://research.lancaster-university.uk/en/publications/ai-synthesized-faces-are-indistinguishable-from-real-faces-and-mo/
- U.S. Government Accountability Office, "Science & Tech Spotlight: Combating Deepfakes," GAO-24-107292, March 11, 2024. https://www.gao.gov/products/gao-24-107292
- NIST, "Reducing Risks Posed by Synthetic Content," NIST AI 100-4, November 2024. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-4.pdf
- C2PA, "FAQs." https://c2pa.org/faqs/
- Google, "How we're bringing AI image verification to the Gemini app," November 20, 2025. https://blog.google/innovation-and-ai/products/ai-image-verification-gemini-app/
- Merriam-Webster, "deepfake." https://www.merriam-webster.com/dictionary/deepfake
- U.S. Department of Homeland Security, "Increasing Threat of DeepFake Identities." https://www.dhs.gov/sites/default/files/publications/increasing_threats_of_deepfake_identities_0.pdf
- European Commission AI Act Service Desk, "Article 3: Definitions." https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3
- U.S. Government Accountability Office, "Science & Tech Spotlight: Deepfakes," GAO-20-379SP, February 20, 2020. https://www.gao.gov/assets/gao-20-379sp.pdf
- Goodfellow et al., "Generative Adversarial Nets," NIPS 2014. https://proceedings.neurips.cc/paper/5423-generative-adversarial-nets
- Deeptrace, "The State of Deepfakes: Landscape, Threats, and Impact," September 2019. https://regmedia.co.uk/2019/10/08/deepfake_report.pdf
- U.S. Government Publishing Office, Public Law 119-12 (TAKE IT DOWN Act). https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm
- Federal Trade Commission, "FTC Begins Enforcing the TAKE IT DOWN Act," May 19, 2026. https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-begins-enforcing-take-it-down-act
- Federal Communications Commission, Declaratory Ruling FCC 24-17, February 2024. https://docs.fcc.gov/public/attachments/FCC-24-17A1.txt
- U.S. Government Publishing Office, Bill Status, S. 4591 (NO FAKES Act of 2026). https://www.govinfo.gov/bulkdata/BILLSTATUS/119/s/BILLSTATUS-119s4591.xml
- Ballotpedia (via Newsfile), "Ballotpedia Reports Forty-eight States Now Have Laws Addressing Sexually Explicit Deepfakes," August 5, 2026. https://www.newsfilecorp.com/release/307866/Ballotpedia-Reports-Fortyeight-States-Now-Have-Laws-Addressing-Sexually-Explicit-Deepfakes
- Office of the Governor of Tennessee, "Gov. Lee Signs ELVIS Act Into Law," March 21, 2024. https://www.tn.gov/governor/news/2024/3/21/photos--gov--lee-signs-elvis-act-into-law.html
- Tennessee General Assembly, HB2091 (ELVIS Act). https://www.capitol.tn.gov/Bills/113/Bill/HB2091.pdf
- legislation.gov.uk, Online Safety Act 2023, section 188. https://www.legislation.gov.uk/ukpga/2023/50/section/188
- legislation.gov.uk, Data (Use and Access) Act 2025, section 138. https://www.legislation.gov.uk/ukpga/2025/18/section/138
- legislation.gov.uk, The Data (Use and Access) Act 2025 (Commencement No. 5) Regulations 2026. https://www.legislation.gov.uk/uksi/2026/31/made
- European Commission AI Act Service Desk, "Article 50." https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
- European Commission, "Quick Facts: Transparency rules for AI systems." https://digital-strategy.ec.europa.eu/en/factpages/quick-facts-transparency-rules-ai-systems