Tactic · AI-generated content
Synthetic media
AI-generated images, audio and video, now past the point where visual inspection is dependable. Detection tools produce false positives. Provenance still works.
Who published this first, and do they stand behind it?
What it looks like
The advice you have heard — count the fingers, check the teeth, look for warped text in the background — described a real weakness of image generators around 2022. It is no longer a reliable test, and the measurements say so.
What has not changed is that a piece of media has a history: somebody made it, somebody published it first, and somebody either will or will not put their name to it. That history is outside the file, which is why it survives when everything inside the file becomes unreliable.
Why it works
A meta-analysis of 56 studies covering 86,155 participants puts overall human detection of synthetic media at 55.5 percent — not significantly above chance. By type: audio 62 percent, video 57 percent, images 53 percent, text 52 percent.1 For voice specifically, a 2025 study of 604 people found listeners judged an AI clone to be the same person as its real source about 80 percent of the time.2
The obvious response — run it through a detector — is worse than it sounds. When state-of-the-art open-source detectors were tested against deepfakes collected in the wild rather than from academic benchmarks, they lost roughly half their accuracy.3 An independent test of eight public detectors found that cropping and rescaling flipped verdicts, and that a compressed audio file scored "highly likely real" while its own uncompressed original scored 74 percent likely fake.4
And detectors are not neutral about who they accuse. Seven AI-text detectors run over essays by non-native English writers produced a false-positive rate averaging 61 percent, against about 5 percent for native writers.5 That is a tool that would systematically accuse the wrong people.
Provenance signing is the part that works, with one limitation that has to be stated in the same breath. Signed Content Credentials are meaningful when present. Their absence proves nothing, because metadata can be stripped deliberately or accidentally — a point the initiative behind the standard makes itself.6
overall human accuracy at detecting synthetic media — not significantly above chance. Audio 62%, video 57%, images 53%, text 52%.Diel et al., Computers in Human Behavior Reports, Dec 2024, meta-analysis of 56 papers, 86,155 participants
of their accuracy lost by state-of-the-art open-source detectors when tested on deepfakes collected in the wild rather than on academic benchmarks.Chandra et al., Deepfake-Eval-2024, arXiv:2503.02857, Mar 2025
false-positive rate when seven AI-text detectors were run over essays by non-native English writers, against about 5 percent for native writers.Liang et al., Patterns, July 2023, 91 and 88 essays
in adjusted losses across 22,364 complaints referencing AI, out of 1,008,597 total complaints.FBI Internet Crime Complaint Center, 2025 Annual Report, published 6 Apr 2026
Documented cases
A video call in which everyone but one person was fake, 2024
A finance employee at the engineering firm Arup joined a video call with people who appeared to be colleagues, including the chief financial officer, and transferred the equivalent of about 25.6 million US dollars across fifteen transactions. Arup later confirmed that "fake voices and images were used."7
The employee did the thing everyone recommends: they were suspicious of the initial message, so they checked by seeing and hearing the people involved. That check no longer works, which is the point.
A cloned voice selling cookware, 2024
A cloned celebrity voice fronted a fake giveaway for a cookware brand, run through a social media page with an unrelated name. The brand stated publicly that it was not involved in any such promotion with that person.8
This is the ordinary case, far more common than any political deepfake: a recognisable voice, a plausible offer, and a brand that has to spend its own time denying something it had no part in.
What to do about it
- Stop trying to spot artifacts. Pooled human accuracy is about 55 percent. You are not the exception, and neither are we.
- Do not paste it into a detector and act on the score. Compression, cropping or a screenshot can flip the verdict, and the false positives fall hardest on people writing in a second language.
- Ask who published it first and whether they stand behind it. This is the check that still works, and it works because it is not about the file.
- Check for Content Credentials. Valid ones are real evidence. Missing ones are not evidence of anything — platforms strip metadata routinely.
- For any voice or face asking for money or access: hang up and call back on a number you already had. Agree a code word with family and with your finance team in advance. Seeing and hearing someone is no longer authentication.
Sources
Every figure on this page comes from one of these. Each entry names the publisher, the date and the sample size, so you can check it rather than take our word for it.
- Diel, A. et al. — "Human performance in detecting deepfakes: a systematic review and meta-analysis"Computers in Human Behavior Reports 16:100538 · December 2024 · 56 papers, 86,155 participantshttps://doi.org/10.1016/j.chbr.2024.100538
- Barrington, S., Cooper, E. & Farid, H. — "People are poorly equipped to detect AI-powered voice clones"Scientific Reports · 31 March 2025 · n=604https://www.nature.com/articles/s41598-025-94170-3
- Chandra, N. et al. — "Deepfake-Eval-2024: A multi-modal in-the-wild benchmark of deepfakes"arXiv:2503.02857 · March 2025 · 45h video, 56.5h audio, 1,975 images from 88 websites in 52 languageshttps://arxiv.org/abs/2503.02857
- Anlen, S. & Vázquez Llorente, R. — "Spotting the deepfakes in this year of elections: how AI detection tools work and where they fail"Reuters Institute · 15 April 2024 · 8 public detectors testedhttps://reutersinstitute.politics.ox.ac.uk/news/spotting-deepfakes-year-elections-how-ai-detection-tools-work-and-where-they-fail
- Liang, W. et al. — "GPT detectors are biased against non-native English writers"Patterns 4:100779 · July 2023 · 7 detectors over 91 and 88 essayshttps://arxiv.org/abs/2304.02819
- Parsons, A. — "Durable Content Credentials"Content Authenticity Initiative · 8 April 2024https://contentauthenticity.org/blog/durable-content-credentials
- Fortune — "Arup deepfake fraud: British engineering firm confirms it lost $25 million"Fortune · 17 May 2024https://fortune.com/europe/2024/05/17/arup-deepfake-fraud-scam-victim-hong-kong-25-million-cfo
- NBC News — "That Taylor Swift AI-generated Le Creuset ad is not real"NBC News · January 2024https://www.nbcnews.com/tech/taylor-swift-ai-generated-le-creuset-ad-not-real-rcna133285
- FBI Internet Crime Complaint Center — 2025 Internet Crime ReportFederal Bureau of Investigation · published 6 April 2026 · 1,008,597 complaintshttps://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
What this page is not sure about
Every page here carries this section. A site that tells you to check its sources should be the first to say where its own evidence is thin.
- A widely quoted 2021 study found ordinary people roughly matched the best detection models at spotting deepfake video. That study used generators from 2019 and 2020 and its conclusion does not transfer to today. We cite the 2024 meta-analysis instead, and we mention the older one here so you know we did not simply miss it.
- Numbers in this area go stale faster than anywhere else on this site. Every figure above is dated. If you are reading this well after those dates, assume detection has got harder, not easier.
- The most commonly cited evidence that platforms strip image metadata is a set of tests from 2015 and 2016. The behaviour is still widely reported, but we could not find a current systematic measurement, so treat "platforms strip metadata" as well-established practice rather than as a freshly measured fact.