The phone rings. The voice sounds exactly like someone you know, claiming there has been an emergency and asking for money. Everything feels credible. Yet that person never called. In 2026, that scenario is no longer science fiction.
What is a deepfake?
A deepfake is AI-generated or AI-manipulated visual or audio content that can make a person, voice or event appear authentic even though it did not happen that way.
The EU AI Act focuses precisely on this ability of synthetic media to appear genuine and mislead.
Old visual clues are becoming less reliable
Strange hands, inconsistent teeth, distorted text or odd blinking can still expose poor generations, but they are no longer a dependable test. Models are improving quickly.
Germany’s BSI warns that AI-generated imitations are becoming increasingly difficult to recognise.
The future of verification depends less on finding a strange pixel and more on being able to prove where content came from.
Start with the source, not the face
If a dramatic image appears on social media, check who published it, whether independent sources confirm it, whether other images exist and whether the account, place and timing make sense.
A perfect synthetic image can be hard to diagnose. A fabricated event often lacks independent evidence.
Reverse image search still matters
Not all misinformation is AI-generated. A genuine old photograph can be reused with a false caption. Reverse image search can reveal whether the image circulated years earlier in another context.
Verification must cover both the file and the story attached to it.
Voice and video are especially difficult
Low-quality deepfakes may still show unstable edges, inconsistent lighting or poor lip-sync. High-quality ones may not. Voice cloning also exploits panic and urgency.
German police prevention services already warn about scams involving cloned voices and manipulated video calls.
For a suspicious call, verification beats detection
If a familiar voice suddenly asks for money, end the call and contact the person using a number you already know. In companies, unusual payment instructions should be confirmed through a separate trusted channel.
The more urgent the request feels, the more important it is to slow down.
Content Credentials shift the focus to provenance
Content Credentials, based on the C2PA standard, can attach cryptographically signed information about the origin and editing history of media.
C2PA released version 2.3 and new implementation guidance in 2026. The goal is to make the history of trustworthy content easier to verify.
Invisible watermarks add another signal
Google DeepMind’s SynthID embeds machine-readable signals in certain AI-generated media, and Google is expanding ways to check for them.
Not finding SynthID never proves authenticity; the content may simply have been created by another system.
Do not trust a single AI detector
Online detectors can provide clues, not mathematical proof. New generators, compression and editing change technical traces.
For important content, combine source checking, independent confirmation, forensic tools and provenance data.
The EU requires more transparency from August 2026
From 2 August 2026, certain Article 50 obligations under the EU AI Act apply to AI-generated or manipulated content. In relevant cases, machine-readable marking and disclosure duties apply.
Rules help, but criminals are unlikely to label fraud voluntarily.
The next deepfakes may look completely normal
We need to prepare for synthetic media with no obvious defect. Video, voice and real-time manipulation will continue to improve.
The better question becomes: who published this, what independent evidence exists, and can I verify its origin?
Can every deepfake be detected?
Sometimes. Always? No. Visual clues, forensics, watermarks and provenance complement one another, but no system detects everything.
Digital trust will require several layers of verification. “Does it look real?” is giving way to a stronger question: “Can I prove where it came from?”
