HeadFlash

Topic · 15 stories

Deepfakes: AI fakes, scams and latest news

Updated · Edited by Marcin Rybak

In short

A deepfake is an image, video or audio clip generated or altered by AI to realistically imitate a real person. On 8 October 2026 Google opened its SynthID Detector to the public, but it only flags media carrying a SynthID watermark, and the same day the FBI and French authorities seized two sites selling deepfake child abuse material. Spotting fakes by eye is getting harder: 48 percent of test subjects took an AI avatar for a real person after a one-minute video call.

What is a deepfake

A deepfake is an image, video or audio clip generated or altered by artificial intelligence so that it realistically imitates a real person: their face, body or voice. The word joins “deep learning” and “fake”. It now covers a swapped face in a video, a cloned voice and a fully generated avatar that talks to you in real time. The technology itself is neutral; what matters is consent and purpose.

The same method produces jokes, film effects, fraud, harassment and sexual images made without consent. A deepfake attack is the use of such a fake to impersonate someone and deceive a victim, which links the topic to phishing. In 2026 the main stories are about detection and labeling, new laws, and how fast platforms react when a tool is abused.

How to spot a deepfake

Look at the mouth, listen to the voice and check the context, because that is where generators most often slip. Poland’s research institute NASK lists five groups of signs in its guide to recognizing deepfakes (a Polish-language page dated 15 January 2025, checked 10 October 2026): rendering errors in the face, especially around the mouth; unnatural intonation caused by ignoring punctuation; grammar errors; body language that does not match the words; and masking effects meant to hide flaws.

The Polish Ministry of Digital Affairs adds, in its disinformation guide (also Polish, checked 10 October 2026): in a video, check that lips match the words, that the person blinks at natural intervals and that hair does not shift position as the head moves. In photos, look for odd posture and extra hands, legs or fingers. Always check the source, author, date and publication context, and run a reverse image search.

Those checks have a limit that 2026 made visible. Tavus introduced an avatar called Griffin, and in its study 48 percent of participants took it for a real person after a one-minute video call, against a previous high of 2 percent. In an independent Nvidia test Griffin scored 3.83, humans 3.92 and the previous best AI model 2.80. Griffin-Lite is available to select testers. The practical conclusion: when a call asks for money, data or an urgent decision, confirm identity through a second channel.

Is there a tool that detects AI-generated images

Partly: there are watermark checkers and source tracers, but none catches everything. Google opened its SynthID Detector to the public. It checks JPG, PNG, MP4 and MP3 files for invisible watermarks from models including Gemini, Veo and Lyria. It is not a universal AI detector: it only flags content carrying a SynthID watermark, a limitation shared by other detectors, which usually verify only their own provider’s marks. OpenAI, Nvidia and Kakao also use SynthID for media, and Google says Apple is expected to join soon. Detection is built into Google Search, the Gemini app and Chrome, where Google reports one million verification requests a day, and it claims more than 180 billion watermarked images and videos. More in AI content watermarking.

A second approach is proving a photo is real at capture. Apple added an opt-in Apple Reference Image feature to the iPhone 18 Pro. The sensor signs pixel data before standard processing, and the Secure Enclave signs exposure, zoom and lens data. The developed file goes to Apple’s Private Cloud Compute, which verifies the signatures before outputting a JPEG carrying a composite RSA-3072 and ML-DSA-87 signature. It works only with the main camera.

A third approach is tracing origin. Researchers at the University of California, Riverside, with YouTube and Google DeepMind, built SAGA to trace fake videos to the AI system behind them. On public datasets with videos from 19 generators it told real from fake, text-to-video from image-to-video, model versions apart, and traced videos to the team that built the model. Doctoral student Rohit Kundu said the critical question has shifted from whether a video is fake to what its source is.

Is deepfake porn illegal

In the US, yes when it is published without consent. Deepfake porn means an intimate image or video of a real, identifiable person created or altered with AI. The TAKE IT DOWN Act, Public Law 119-12 of 19 May 2025 (text checked 10 October 2026), makes it unlawful to use an interactive computer service to knowingly publish such a “digital forgery” of an identifiable adult without consent, with up to 2 years in prison, and up to 3 years when the victim is a minor. Covered platforms must set up a reporting process within a year of enactment and remove reported images within 48 hours, and the FTC enforces that duty.

The FBI cited the law in its seizure of two deepfake child abuse sites: NudeLeaksTeens and NLTVIDS. The report says the sites violated the Act. Other places act differently. The UK has banned nudification apps. Illinois classes sharing unauthorized digital replicas or sexually explicit AI images as cyberbullying in schools, under HB3851, in force since 1 July 2026, with districts obliged to follow it from the 2026-2027 school year. A 2024 Illinois statute already allows prosecution of AI-generated images under child pornography laws, so one deepfake could trigger school discipline and a criminal investigation. China’s regulator published draft cyberbullying rules that reach AI-generated abuse on 29 July; critics note the same detection tools can identify speakers.

Who is responsible for sexual deepfakes and child abuse material

Offenders, distribution sites and, increasingly, platforms and the firms whose tools enable abuse. On 8 October the FBI and French authorities seized the two sites, and the Paris Prosecutor’s Office arrested a 25-year-old French resident suspected as primary administrator. A seizure warrant filed 2 October in the Eastern District of Virginia showed law enforcement learned of the sites in 2024. One collection, 189 GB covering 315 girls, sold for 64.90 dollars.

The scale shows in UK data. The National Crime Agency and the Internet Watch Foundation warned parents not to publicly share children’s images: the IWF identified more than 8,000 realistic AI-generated abuse images and videos in 2025, up 14 percent, and AI-generated videos rose from 13 in 2024 to 3,440. A September Sussex Police campaign showed how everyday back-to-school photos can be turned into harmful fakes, and that street signs, house numbers or names on uniforms reveal a family’s address.

Companies are being sued too. xAI is suing users accused of making abuse material with Grok while facing multiple class actions and individual suits over non-consensual nude images. Victims’ lawyers call the suits against users too little, too late; xAI says it builds in safeguards, and plaintiffs say it ignores industry standards. San Francisco City Attorney David Chiu sent cease-and-desist letters to Apple and Google over 13 nudify apps, 8 on the App Store and 5 on Google Play, accusing them of aiding and abetting by hosting the apps and taking a cut, with penalties of at least 25,000 dollars per violation. Google removed all five named apps and suspended hundreds more; Apple removed three and is terminating developer accounts. See also Grok, children’s online safety and AI lawsuits.

They withdraw features after a backlash, not before. Meta pulled a Muse Image feature that let anyone generate AI images of other people by @-mentioning their public Instagram accounts, enabled by default with an opt-out. Meta admitted “this feature missed the mark” and shut it down days after announcing it. Google removed its Nano Banana integration from Google Earth after two days when users made convincing fake satellite images, including a refugee column at the Mexican border and a bombed-out hospital in Gaza; it says the feature will not return until stronger safeguards are in place. Tinder suspended its Photo Enhance feature after users reported automatic edits to profile photos, and unwanted AI images also drew complaints on Reddit and Amazon.

People get a voluntary tool. On 23 June, RSL Media, co-founded by Cate Blanchett, launched the free Human Consent Registry for residents of the US and EU, where you set a red, yellow or green consent level for AI use of your name, face, voice and likeness. No enforcement mechanism exists and AI companies have no legal duty to honor the signals. Registering hands personal data to a third party, and the value is a timestamped record that could support future complaints.

What it means for you

  • If a call or video asks for money, data or a quick decision, confirm the person’s identity through another channel. A face and a voice are no longer proof.
  • Check source, author and date, and use a reverse image search. A SynthID check only recognizes files carrying Google’s and partners’ watermark.
  • Post children’s photos carefully: crop out street signs, house numbers, school logos and names, and review privacy settings first.
  • If someone published a manipulated intimate image of you, report it to the platform and to law enforcement. In the US, platforms covered by the TAKE IT DOWN Act must remove reported images within 48 hours.

Still open: whether Apple joins SynthID as Google says it will, how the courts treat the suits against xAI, whether Apple and Google fully comply with San Francisco’s demand over nudify apps, and whether China’s draft cyberbullying rules survive consultation.

Key facts

  • Google opened its SynthID Detector to the public for images, video and audio. It flags only SynthID-watermarked content, not all AI media. Google says over 180 billion files carry the watermark. (source)
  • The FBI and French authorities seized NudeLeaksTeens and NLTVIDS, which sold child abuse material including AI deepfakes. A 25-year-old French resident suspected as main administrator was arrested. (source)
  • In a Tavus study, 48 percent of participants believed its Griffin AI avatar was a real person after a one-minute video call, up from a previous high of 2 percent for earlier systems. (source)
  • Apple added an opt-in Apple Reference Image feature to the iPhone 18 Pro that cryptographically signs sensor data at capture, to prove a photo was not generated by AI. (source)
  • xAI sues users accused of making child abuse material with Grok while facing multiple class actions and individual suits over non-consensual nude images. (source)
  • San Francisco's City Attorney demanded Apple and Google remove 13 nudify apps, with penalties of at least 25,000 dollars per violation. Google removed all five named apps, Apple three. (source)
  • The IWF identified more than 8,000 realistic AI-generated child abuse images and videos in 2025, up 14 percent, with AI-generated videos rising from 13 in 2024 to 3,440 in 2025. (source)
  • Illinois now classes sharing unauthorized digital replicas or sexually explicit AI images as school cyberbullying (HB3851, effective 1 July 2026, enforced from the 2026-2027 school year). (source)

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. Google opens SynthID Detector to the public as watermarked media hits 180 billion AI
  2. FBI and France seize deepfake CSAM sites, arrest administrator Security
  3. Tavus Griffin Avatar Fooled 48 Percent of Test Subjects on One-Minute Call AI
  4. Apple’s iPhone 18 Pro signs photos at the sensor to prove they aren’t AI-generated AI
  5. UK police warn parents about risks of posting back-to-school photos Privacy
  6. xAI Sues Users Over Grok Deepfakes While Facing Mounting Victim Lawsuits AI
  7. Google pulls Nano Banana from Google Earth after two days over fake satellite imagery AI
  8. Unwanted AI Images Are Freaking Out Users Across Tinder, Reddit, and Amazon Privacy
  9. China Drafts Cyberbullying Rules Targeting AI-Generated Abuse Privacy
  10. Researchers Develop SAGA Tool to Trace AI-Generated Videos to Source Privacy
Show older (5 stories)
  1. San Francisco Demands Apple and Google Remove AI Nudify Apps Privacy
  2. Meta Pulls Muse Image Feature After Consent Backlash Privacy
  3. UK Agencies Warn Parents Not to Publicly Share Children’s Images Over AI Abuse Risks Privacy
  4. Illinois updates school code to combat AI deepfake bullying Privacy
  5. Cate Blanchett Launches Free Tool to Let Individuals Control AI Use of Their Likeness Privacy

FAQ

What is a deepfake?

A deepfake is an image, video or audio clip generated or altered by AI so that it realistically imitates a real person, for example their face or voice. The term covers face swaps in video, cloned voices and fully generated avatars, and uses range from jokes to fraud and sexual abuse.

How can I spot a deepfake?

Check the mouth, the voice and the context. Poland's research institute NASK points to rendering errors around the mouth, odd intonation and rhythm in speech, grammar slips and body language that does not match the words, and Poland's digital affairs ministry advises checking source, author and date and running a reverse image search. Newer generators make fewer of these errors, so none of these checks is proof.

Is there a tool that detects AI-generated images?

Partly. Since 8 October 2026 anyone can use Google's SynthID Detector on JPG, PNG, MP4 and MP3 files, but it only recognizes media carrying a SynthID watermark, not all AI content. Researchers also built SAGA, which traces a fake video to the generator that made it.

Is deepfake porn illegal?

In the US, yes when it is published without consent. The TAKE IT DOWN Act, signed 19 May 2025, makes it a federal crime to knowingly publish an AI-made intimate image of an identifiable person without their consent, and it requires platforms to remove reported images within 48 hours. The UK has banned nudification apps.

What is the penalty for publishing sexual deepfakes in the US?

Up to 2 years in prison when the victim is an adult and up to 3 years when the victim is a minor. That is what the TAKE IT DOWN Act (Public Law 119-12) provides; the FTC enforces the platform takedown duty (law text checked 10 October 2026).

What is a deepfake attack?

A deepfake attack is the use of a fake face, voice or video to impersonate a real person in order to deceive someone, for instance to extract money or data. The Tavus test, where 48 percent took an AI avatar for a real person after one minute, shows why a familiar face on a call is no longer proof of identity.