Security & safety

Deepfake

Audio, video or an image, generated or altered with AI, that shows a real person saying or doing something they never said or did, convincingly enough to be taken as genuine.

Public recordingsvoice and face samplesGenerationvoice clone, live videoFake meeting12 transfers · €4.2 millionCall-backthe number on fileTHREE LAYERS OF DEFENCEDetectionweaker with each new generatorProvenanceC2PA signature, invisible watermarkProcesscall-back, dual approval, code phraseA face you see and a voice you hear are no longer proof on their own; urgency calls for more checking.

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/deepfake

In plain terms

For a century a recording was proof: if you heard the voice or saw the face, the person had been there. That link is gone. From a short sample of someone's voice and a few photographs, software can now produce that person saying anything, in a phone call or on live video. A deepfake is a forged signature for the face and the voice, and the forgery tools are available to anyone.

Why it matters

For companies the first risk is fraud. Staff are used to trusting a familiar voice, and a cloned one asking for an urgent transfer exploits exactly that habit. Reputation and markets come second: a fabricated statement by an executive can circulate for hours before it is disproved. Detection tools exist and lag behind the generators, so they cannot be the main defence. What works is process: sensitive requests are verified through a second channel, whoever appears to be asking. That slows urgent payments down, which is the intention.

Example

A finance manager at a manufacturer joins a video call with the chief financial officer and two colleagues, who ask for 12 transfers totalling 4.2 million euros for a confidential acquisition. Every face and every voice on the call was generated from public conference recordings. The manager follows the rule introduced the year before and calls the CFO back on the number in the company directory. The CFO knows nothing about it.

Most often confused with

Deepfake vs. Cheapfake

DeepfakeGenerated or altered with AI; the event never happened
CheapfakeReal footage distorted by simple means: cut, slowed, mislabelled

A cheapfake needs no AI: a genuine video is slowed down to make a speaker seem drunk, cropped to hide the context, or shared with a false caption and date. A deepfake fabricates the material itself. The distinction matters for defence. Detectors that look for traces of generation miss cheapfakes entirely, and much of the misleading media in circulation is of the simple kind. Checking the source and the context works against both.

Origin: The word appeared in 2017 as the username of a Reddit user who posted face-swapped videos; it joins “deep learning” and “fake”.

Under the hood

Main forms: face swap, lip-sync to new audio, full synthesis of a speaking person from a text prompt, and voice cloning, which needs only a short sample and can run in real time. The generators are diffusion models and their relatives; earlier systems used autoencoders and GANs. Defences fall into three groups. Detection: classifiers that look for artefacts, and liveness checks in identity verification; accuracy drops with each new generator and after compression. Provenance: C2PA Content Credentials, which sign a file's origin and edit history, and invisible watermarks such as Google's SynthID, embedded at generation; both show where marked content came from and say nothing about unmarked content. Process: call-back on a known number, dual approval, agreed code phrases, and a rule that urgency triggers more checking. In regulation, the EU AI Act has required since August 2026 that deepfakes be disclosed as artificially generated or manipulated, and several countries have made non-consensual intimate deepfakes a criminal offence.

Written by Mehmet Erkek · Last updated: