How to spot a deepfake.

Weird hands are not a strategy. Checking where something came from is, and it takes about a minute.

An ornate Venetian carnival mask
Photo by Fer Troulik on Unsplashdithered by Cyborb

The most reliable way to spot a deepfake in 2026 is to check the context, not the pixels. Ask who posted it, where it first appeared, whether trusted sources confirm it, and whether it carries content credentials. For a call or video chat, the test is simpler still: hang up and call back on a number you already know.

Visual glitches still happen, but the best fakes no longer have them, and research shows people are poor judges. This guide shows how to spot a deepfake with a routine that works anyway, and what to do if someone makes one of you.

The short version
  • People are poor judges of good fakes: 48% accuracy on AI faces in one study, about a coin flip, and 73% on synthetic speech in another.
  • Check context instead of pixels: the source, the first appearance, a reverse image search and independent confirmation.
  • For calls and video chats, verify the person, not the picture. Call back on a known number, or use a family code word.
  • Content credentials can confirm where a file came from, but most real files have none.
  • If you are targeted, save evidence and report it. Hash tools such as StopNCII help with intimate images, and US platforms must now remove those within 48 hours of a valid request.

Why looking harder no longer works

For years the advice was to look for glitches: warped hands, odd teeth, strange lighting. Those tells still show up in cheap fakes. But controlled studies show that even careful people struggle with good ones.

48.2%
accuracy at telling real faces from AI faces, about the same as a coin flip
PNAS, 2022
59%
accuracy after training with feedback on every answer
PNAS, 2022
73%
how often listeners caught synthetic speech
PLOS ONE, 2023

Those studies were published in 2022 and 2023, and generators have improved since. In the speech study, 529 people listened in English and Mandarin, and showing them examples first helped only slightly.

So treat visual and audio clues as a bonus, not a test. The FBI still lists a few worth noticing: distorted hands or feet, and a familiar voice whose tone or word choice sounds off. In fake video job interviews, it has seen lips that do not match the audio, and coughs or sneezes out of sync with the picture. If you spot one of these, stop. If you do not, you have learned nothing.

How to spot a deepfake image or video in 60 seconds

  1. Pause before you share or react

    Deepfakes are built to trigger outrage, fear or excitement. That rush is your cue to slow down. Nothing true becomes false because you waited a minute.

  2. Find the original source

    Who posted it first? Check the account’s age, history and other posts. A dramatic clip from a days-old account with no history deserves suspicion, whatever it shows.

  3. Run a reverse image search

    Upload the image, or a screenshot of a key video frame, to Google Lens or TinEye. You may find the original, unedited version, or learn that a “breaking news” photo is years old.

  4. Look for independent confirmation

    A real major event gets covered by several credible outlets and official accounts. One viral post with no confirmation is a warning sign.

  5. Check for content credentials

    Upload the file to Verify, or ask the Gemini app whether an image is AI-generated. A valid credential tells you which camera or tool made the file. Our guide to content credentials explains how to read the result.

01Google LensReverse image search

Finds matching and similar images across the web. Works on screenshots of video frames too.

02TinEyeReverse image search

Shows where else an image appears online, which helps you trace the original.

03VerifyContent credentials

Reads C2PA content credentials in images, video, audio and PDFs, if the file still has them.

04Gemini appSynthID and credential check

Checks images, video and audio for Google’s SynthID watermark, and reads content credentials too. A “no” only means no signal was found.

Deepfake calls: verify the person, not the picture

Live fakes are the most dangerous, because you have to decide on the spot. In 2024, an employee of the engineering firm Arup in Hong Kong joined a video call with people who looked and sounded like senior colleagues, then sent HK$200 million to criminals. Our guide to AI scams covers how these frauds work.

The defenses are the same for families and companies:

  • Hang up and call back on a number you already have, not one the caller gives you.

  • Agree a code word with family, in person, and never post it. The FBI recommends a secret word or phrase.

  • Ask something only the real person knows, and that is not on social media.

  • Never move money or share a code because of a call, voice note or video alone.

What to do if someone makes a deepfake of you

Being faked is distressing, and it is not your fault. Act in this order.

  1. Save evidence. Take screenshots that show the content, the account name, the date and the web address. Do not engage with the poster.

  2. Report it on the platform. Use the impersonation or privacy report. YouTube, for example, accepts privacy complaints about AI-made content that looks or sounds like you.

  3. For intimate images, use a hash tool. StopNCII.org makes a digital fingerprint on your device and shares only that, so partner platforms can find and remove matching copies while the image stays with you. It covers AI-made images of you. If you were under 18 in the image, use NCMEC’s Take It Down.

  4. Remove it from Google Search. Google has a form for fake sexual content of you, and it tries to remove duplicates too.

  5. Report crimes. Extortion, threats and sharing intimate images without consent are crimes in many countries. In the US, report to local police and the FBI.

SituationWhere to go
An intimate image of you as an adult, real or fakeStopNCII.org
An intimate image from when you were under 18Take It Down, run by NCMEC
A fake of you on YouTubeYouTube privacy complaint
Fake sexual content in Google resultsGoogle removal request
A US platform ignores your removal requestTakeItDown.ftc.gov
Fraud or extortion using a deepfake, in the USic3.gov

The deepfake laws that apply in 2026

Several places now have laws aimed squarely at deepfakes. These are the main dates as of September 2026:

  1. February 6, 2026England and Wales: creating, or asking someone to create, a sexually explicit deepfake of an adult without consent becomes a crime. Sharing one was already an offence.
  2. May 19, 2026United States: under the TAKE IT DOWN Act, covered platforms must remove reported intimate images, including AI deepfakes, and known copies within 48 hours. The FTC enforces it.
  3. August 2, 2026European Union: the AI Act’s transparency rules apply, including clear labels on deepfakes.
  4. December 2, 2026European Union: a ban on AI apps that create non-consensual intimate images takes effect.

The US law also makes it a crime to publish intimate images without consent, and it covers AI-made “digital forgeries” as well as real photos. US states have their own laws too, and they vary, so check yours. For the EU rules, our EU AI Act guide explains who must label what. This is general information, not legal advice.

FAQ

Can an app tell me for sure whether something is a deepfake?

No. Watermark and credential checks can confirm some origins when the signal is present. Tools that judge the content itself make mistakes in both directions. Use them as one input, alongside the source and independent confirmation.

What are the signs of a deepfake video call?

Lips that do not match the audio, coughs out of sync, pressure to act fast, a request for secrecy, and resistance to switching to a channel you choose. The strongest test is to end the call and ring back on a number you already know.

Is it illegal to make a deepfake?

It depends on what it shows and where you are. Sexual deepfakes made without consent are now illegal to create in England and Wales, and illegal to publish or share there and in the US. Other fakes are judged under laws on fraud, harassment and defamation, which vary by country.

Should my family have a code word?

Yes. The FBI recommends a secret word or phrase to confirm who is calling. Pick something no one could guess from social media, agree it in person, and never write it in a message.

How do I protect myself from being deepfaked?

Keep social accounts private and limit public clips of your voice and face, as the FBI advises. Anyone with a public profile can still be faked, so the habits above matter more than hiding.

Next, see how AI scams use these fakes to take money, or read who owns AI-generated content for the copyright side.

Sources
  1. AI-synthesized faces are indistinguishable from real faces and more trustworthy, PNAS, February 2022
  2. Warning: Humans cannot reliably detect speech deepfakes, PLOS ONE, August 2023
  3. Criminals use generative artificial intelligence to facilitate financial fraud, FBI Internet Crime Complaint Center, December 2024
  4. Deepfakes and stolen PII utilized to apply for remote work positions, FBI Internet Crime Complaint Center, June 2022
  5. UK engineering firm Arup falls victim to £20m deepfake scam, The Guardian, May 2024
  6. Making it easier to understand how content was created and edited, Google, May 2026
  7. Privacy guidelines, YouTube Help
  8. Frequently asked questions, StopNCII.org
  9. Take It Down, National Center for Missing and Exploited Children
  10. Remove personal sexual content from Google Search, Google Search Help
  11. What will the FTC’s enforcement of the TAKE IT DOWN Act mean for you?, FTC, May 2026
  12. Public Law 119-12, the TAKE IT DOWN Act, U.S. Government Publishing Office, May 2025
  13. Complying with the Take It Down Act, FTC business guidance
  14. Data (Use and Access) Act 2025, section 138, legislation.gov.uk
  15. Government crackdown on explicit deepfakes, GOV.UK, January 2025
  16. AI Act: regulatory framework for AI, European Commission
  17. AI Act: deal on simplification measures and a ban on nudifier apps, European Parliament, May 2026
cyborb.ai

Stop reading about it. Build it.

Describe what you want in plain words. Cyborb plans the work, writes and runs the code, makes the assets, and puts the result online.

Download Cyborb

Free to start. No card required.