(5/10) Deepfakes: When Seeing Is No Longer Believing
Digital Safety Series: Ep. 5
Think about how fast things have changed over the last two years. AI tools went from a niche tech experiment to an overnight explosion. Today, anyone with a basic smartphone and an internet connection can generate a highly realistic video or clone a voice in less than thirty seconds. It has spread out so much, and so fast, that it leaves many of us feeling completely exposed.
In January 2024, a finance employee at the engineering firm Arup’s Hong Kong office joined a video call with people he believed were the company’s CFO and several colleagues. He’d already been suspicious of an earlier email requesting a confidential transfer, but seeing familiar faces and hearing familiar voices on the call put him at ease. He went on to make 15 separate transfers totaling HK$200 million, about $25.6 million. Every person on that call was an AI-generated deepfake, built from public footage of the real executives. The money was never recovered. It’s one of the largest AI-powered frauds on record, and it happened to a company with 18,500 employees and a security team. The uncomfortable reality is that our digital likenesses are under constant evaluation by scraping networks. But here is what no one tells you: you are not powerless. Today, we are breaking down the exact science of deepfakes, walking through simple, beginner-friendly tools, and uncovering the legal frameworks that back you up right now.
How Deepfakes Work: The Science Behind the Scams
To defeat a deepfake, you first have to understand how the technology builds them. Remember this core fact: AI cannot build a model of you without clean, high-quality reference data. Your public photos and videos are the raw fuel for their engine. If we corrupt or cut off that fuel, the engine stalls completely.
Deepfake relies on a specific type of artificial intelligence called deep learning. High-quality deepfakes are usually created using two main frameworks.
Autoencoders: The Digital Translators
The first framework utilizes Autoencoders. Think of this like a digital translator. The AI takes a video of Person A and runs it through an ‘Encoder,’ which translates their face into fundamental data points, like the precise distance between eyes, the curve of a jaw, or the motion of lips. Then, it uses a ‘Decoder’ programmed for Person B to reconstruct those exact movements using Person B’s features. The result is Person B’s face perfectly mapped onto Person A’s real body movements.
Generative Adversarial Networks (GANs): The AI Cat-and-Mouse Game
The second framework uses a GAN - Generative Adversarial Network. This is essentially a high-speed game of cat and mouse inside a computer. One AI model, the ‘Generator,’ creates a fake image. A second AI model, the ‘Discriminator,’ evaluates it to see if it can spot the forgery. They train against each other millions of times in a matter of hours. The Generator fails, learns, improves, and tries again until its fakes are so perfect that even the detective AI can’t tell them apart.
How to Spot a Deepfake: 3 Visual & Auditory Clues
Even though this technology is evolving at breakneck speed, human observation combined with healthy skepticism remains a powerful first line of defense. AI models still make subtle structural mistakes, which we call artifacts. When you are looking at a video that triggers a strong emotional reaction, look for three critical indicators:
The ‘Uncanny Blur’: Look closely at the jawline, the hairline, and the ears. When a person in a deepfake turns their head quickly, the AI digital mesh frequently struggles to keep pace, causing a brief, unnatural lag or soft blurring where the face meets the neck.
Mismatched Lighting in the Eyes: In a real video, light reflects symmetrically across both pupils because they are catching the same ambient light source. Deepfakes often generate left and right eyes independently, leading to mismatched reflections or strange, dull pupils that don’t match the environment’s lighting.
Lip-Sync Lag on Explosive Consonants: Pay close attention to hard, explosive consonants like P, B, and M. To pronounce these words, human lips must physically press together completely. In many voice-cloned deepfakes, the audio track and the actual physical positioning of the lips fall out of alignment by fractions of a second. If it feels off, it probably is.
Your Legal Protections and Global Safeguards
What happens if a deepfake gets made? Many people feel helpless because they think the internet is a lawless wild west. But that is no longer true. You are protected by growing global frameworks that tech giants are increasingly held to.
Global Safeguards: Digital Nutrition Labels
Under international accords like the G7 Hiroshima AI Process, the world’s leading technology developers are pushing to build safety mechanisms into their systems. Major entities, including Adobe, Microsoft, OpenAI, Google, and Meta, have backed a standard called C2PA Content Credentials.
Think of this like a cryptographic digital nutrition label embedded into synthetic media files at the point of creation. It’s a real and growing part of the defense but it isn’t an automatic shield. The credential can be stripped by something as simple as a screenshot or a social media re-upload, and it only exists at all if the tool that generated the content chose to embed it, which most AI generators in use today don’t. Microsoft’s own 2026 integrity report put it plainly: no single method- provenance, watermarking, or fingerprinting, can stop this on its own. Treat it as one signal among several, not a guarantee, and don’t assume it shields you regardless of where you are or what platform the content lands on.
Domestic Laws and Rapid Takedown Demands
Alongside global protections, domestic laws have evolved to give you immense local leverage. For example, in India, the legal landscape was updated to deal directly with synthetic fraud under the Bharatiya Nyaya Sanhita and the Information Technology Rules.
Under these IT mandates, social media networks operate under a ticking clock and it keeps getting shorter. The original 2021 rules gave platforms 36 hours to remove a reported deepfake. As of a February 2026 amendment, that window was cut to just 3 hours for most synthetic content flagged through a court order or government notice, and to 2 hours for the most severe category, like non-consensual intimate content. If a company ignores a valid order, they risk losing their ‘Safe Harbor’ legal immunity, making the platform directly liable. To enforce this, you don’t need a lawyer, simply document the link, take screenshots, and submit an immediate report through the government’s centralized portal at cybercrime.gov.in. The system handles the rest.
Take Action: Establish a Family Security Plan
Finally, establish a personal safety contract with your inner circle. Sit down with your family and choose a unique, memorable ‘safe word’ or passphrase known only to you. If you ever receive a chaotic, high-pressure phone call demanding immediate financial assistance, simply ask for the safe word. If they cannot give it to you, hang up immediately. No safe word means no action.
AI is spreading incredibly fast, but technology cannot take away your persona unless you let it.
References:
CNN, “Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee,” May 2024 https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
Ecorpit.com, “India’s IT Rules 2026: deepfake takedown and AI-labelling,” on the 3-hour and 2-hour takedown windows effective February 20, 2026 https://ecorpit.com/india-it-rules-2026-deepfake-takedown-ai-labelling/
Truescreen.io, “What Is C2PA? The Standard, Its Metadata and Real Limits,” on the limits of C2PA provenance and Microsoft’s February 2026 Media Integrity and Authentication report
https://truescreen.io/articles/c2pa-standard-history-limitations/
Deepidv.com, “C2PA & Content Provenance vs Deepfakes (2026),” on the C2PA coalition’s founding members and standard overview https://www.deepidv.com/media/articles/c2pa-content-provenance-digital-watermarks-fight-deepfakes
