Skip to content

Digital marketing

Deepfake and AI – how to recognise fake content?

Read the articleQuestions and answers

Article cover: Deepfake and AI – how to recognise fake content?
You will usually recognise a deepfake not by one “magic test”, but by a set of small inconsistencies in the image and sound that together create red flags. Such synthetic or manipulated video can convincingly imitate a specific person, but it usually “breaks” in the details: the mouth, the eyes, the edges of the face and the interactions with the surroundings. The problem is getting worse because short, heavily compressed clips watched on a phone can hide artefacts and encourage hasty sharing. In this section, you’ll find practical warning signs that can be checked in a few dozen seconds. If, after that analysis, you still have doubts, treat the material as requiring further verification of the source and context.

how to recognise a deepfake using video warning signs

The easiest way to spot a deepfake in video is through inconsistencies in lip movement, eye movement, lighting and the edges of the face that do not match the rest of the frame. To begin with, pause the clip at a few moments where the face and background are clearly visible, because a single frame can reveal detail “swimming” after manipulation. Remember that short material (e.g. 10–20 s) and heavy compression in social media can increase the apparent credibility of the fake, because artefacts are harder to notice. If something looks “too smooth” or seems “pasted in”, treat it as a sign that you should check more carefully.

Four phone screens showing video thumbnails in search results, on the Images tab, on the Video tab and in Discover
Diagram Videos appear in the main results, on the Video tab and in Discover; the thumbnail and duration come from VideoObject data. Source: Google Search Central, CC BY 4.0

Lip-sync and facial expression often give away a deepfake first, because plosive consonants (p/b/m) and dental consonants (t/d) should clearly match the movement of the lips and tongue. In practice, look out for a “rubbery mouth” effect, a slight delay (around 1–3 frames) and suspiciously smooth transitions without micro-movements. The second area is the eyes: rather than “odd blinking”, you now more often see a lack of micro-movements and a “dead stare”, when the gaze stays in one point for too long. If the eyes and mouth are not “alive” in the same way as the rest of the face, it is worth going frame by frame.

Lighting, shadows and object edges help distinguish manipulation from simply poor recording quality, because a deepfake is often selective and deforms mainly the area around the face. Check whether the shadows on the nose and cheeks are consistent and whether the reflections in the eyes match the light source visible in the frame. Also examine the edges: the hairline, ears, glasses and jewellery — typical signs are blurring, frames “melting” into the skin, disappearing earrings and jagged contours during head movement. Pixelation alone does not prove a deepfake, because compression (e.g. on platforms) usually degrades the whole image in a similar way, whereas manipulation more often causes local detail “swimming” and errors when the face is obscured by a hand or object (e.g. a mug).

Deepfake & video How to recognise a deepfake using video warning signs
  1. 01Inconsistent lip-sync“Rubbery mouth” effect, delays
  2. 02Unnatural eye movementArtificial blinking, dead stare
  3. 03Mismatched edges and lightingThe face does not fit with the background
  4. 04Check frame by framePause, look for detail “swimming”

Key elements give away fake video, especially when the quality is deliberately reduced.

warning signs in voice cloning and audio manipulation

Voice cloning is most often betrayed by unnatural prosody, that is, the rhythm and intonation, which do not fit the content or the situation. “Too even” pacing and a predictable sentence melody can be concerning, especially when an important message sounds as if it were being read by a narrator. It is worth picking up on unnatural pauses and odd emphasis on proper nouns, because voice models can get stuck on them. If the intonation and emotions do not form a coherent whole, treat the recording as requiring additional verification.

Manipulation can also be indicated by artefacts on consonants and by breaths being “delivered” in an illogical way. In synthetic audio, the sound of “s”, “sh”, “f” often comes across as unusual, and there may be a metallic echo on “k” and “t”, while breaths may be omitted, overly even or “pasted in” at the wrong moments. Also check the background noise: in real conversations it remains continuous and consistent, whereas in fakes it can sound flat, as if looped, or change abruptly. This inconsistency is especially noticeable when the voice sounds as if it were in a studio, even though the speaker claims to be on the street or in a noisy place.

The most practical warning sign is a time-pressure scenario combined with sensitive data, such as BLIK codes, account numbers or an “urgent” change of payment account details. Models more often confuse numbers, abbreviations and company names, and in financial scams this is sometimes used to force a quick reaction without checking. If the caller will not let you hang up, demands secrecy or threatens consequences, that is a red alert. The safest option is to end the call and ring back on a known number from your contacts, because even a convincingly sounding voice may be cloned.

Strategy for verifying the source and context of content

Effective verification of the source and context involves establishing who published the material first and whether there is a checkable original. Assess whether the publication comes from the official account of an institution or person, or rather from an anonymous profile with no history, because this is often the first risk filter. When content circulates as a “screen” or a “re-uploaded video”, ask for a link to the original publication so you can verify the description, date and context. The lack of a verifiable source is a classic pattern of disinformation, not proof in itself — but it is sufficient reason not to take content “at face value”.

The simplest way to catch recycling and context swapping is reverse image search of frames and analysing the clip with OSINT tools. Use Google Images, Bing Visual Search or TinEye, uploading a frame from the video to check whether the image has appeared elsewhere before, at another time. In practice, it is also worth searching by the background (building, logo, landscape), because the face may have been replaced on an older recording. For quick analysis of viral content, the InVID-WeVerify plugin (Chrome/Firefox) is useful, as it breaks video into frames, supports reverse image search and lets you view basic metadata.

The context of place, time and the full statement usually determines whether the material is authentic, manipulated or merely misdescribed. Compare location details with Google Maps/Street View (signs, window layout, style of signs, advertising language), and confront the declared “today” with weather data (e.g. Meteostat, IMGW archives or services with weather history). If you only see a few seconds of a controversial statement, look for the full recording, because a misleading edit can reverse the meaning. It is also worth checking whether there are other angles and witnesses, and whether reach is being artificially boosted by accounts with random names, no history and repetitive hashtags.

  • Establish the original source of publication and ask for a link to the original rather than a “re-uploaded” clip.
  • Carry out reverse image search of frames and a distinctive background fragment (Google Images, Bing Visual Search, TinEye).
  • Break the video into frames and check them in InVID-WeVerify when the material is circulating as a viral on social media.
  • Verify the location and time: geolocation (Maps/Street View) and consistency of weather and season (Meteostat, IMGW archives).
  • Assess the description and the “pressure to share”: phrases like “Share before they delete it.” without checkable details increase the risk of manipulation.
Content verification Strategy for verifying the source and context of content
  1. 01Find the original sourceWho published it first?
  2. 02Assess credibilityOfficial account or anonymous?
  3. 03Verify the contextAsk for a link to the original.
  4. 04Detect recyclingUse reverse search.

The lack of a verifiable source is the first risk filter — do not trust it at face value.

AI detection tools and practical methods for checking deepfake

AI detection tools help identify deepfake, but in practice they work best as support for a fast workflow, rather than as a “verdict”. The best results come from combining frame analysis, metadata and context verification, because material that has been re-encoded, trimmed, noised or blurred can “fool” automatic detectors. Treat the detector’s output as a probabilistic clue, not a certain answer. If all you have is a clip from social media, start with steps that do not require specialist software and provide the fastest return of information.

  • Freeze the material on several frames with the face and background to catch areas prone to model errors.
  • Check those frames with reverse image search to detect recording recycling or context swapping.
  • Look for the original source and full context (e.g. the full video or an institution’s statement) before considering the clip trustworthy.

For a more detailed analysis of a recording, it helps to play it frame by frame and watch for places where a deepfake can “break” during movement. In VLC you can move between frames with the E shortcut, and similar control can also be done in video editors (e.g. DaVinci Resolve), paying particular attention to the edges of the face, the mouth and glasses. If you are working with a file, check the metadata and technical parameters in ExifTool (desktop) or MediaInfo, because traces of export from editing apps or transcoding history can be an important clue, although they do not in themselves prove forgery. In audio, a spectrogram in Audacity or ocenaudio can be useful, and in professional applications iZotope RX (noise and artefact analysis) can also help.

Content credentials can sometimes make it easier to assess whether material is authentic, provided the file has retained information about its origin and subsequent edits. The C2PA standard and so-called Content Credentials can show who created the material and when, and what modifications were made, but their availability depends on whether the platform has removed the data and whether the content comes from tools that support such markings (e.g. some Adobe products and some editorial teams). For generated images, look out for typical mistakes in hands, jewellery, text and small patterns, as these are common places where generation “slips up”. If the image of a public figure appears in a short, polished advert or “sponsored interview”, check whether the collaboration is confirmed on official channels and whether the same quote is circulating in other adverts with a different face.

how to protect yourself from financial scams using deepfake

The best protection against financial fraud using deepfake is the rule not to make transfers or pass on BLIK codes solely on the basis of a phone call or video call, even when the voice and face look “perfect”. Usually what is at work here is time pressure and an attempt to block verification (“don’t hang up”, “this is secret”, “you have 30 minutes”), in order to prompt action without confirmation via another channel. If the caller insists on urgency, secrecy or threatens consequences, end the contact and verify the identity with a callback to a known number from your contacts list. This habit usually works, because it sidesteps the question of deepfake quality and gets to the point, namely confirming identity via an independent channel.

In companies, the basis is a procedure that does not rely critical decisions on an ad hoc conversation and limits the risk of “CEO fraud” with a fake voice of a superior. In practice, dual authorisation of payments works well (e.g. 2 people + confirmation in the ERP system) and a list of approved channels for urgent instructions (e.g. only the company messenger). In scenarios where someone “changes the bank account number on an invoice” or dictates transfer details, treat it as a high-risk signal and demand additional confirmation. It is also worth training employees and practising scenarios such as a fake CFO asking for an urgent transfer or a fake client requesting a change to the account number.

In family conversations, especially with seniors, the simplest form of protection is to hang up, call back and ask a verification question. This approach makes sense because voice cloning can sound convincing, and the attacker usually relies on an automatic reaction under time pressure. In video calls, when you suspect a live deepfake, ask the other person to do something unusual (e.g. show their hand in front of their face, turn their head and say a specific phrase), because scammers often end the call when the risk of exposure increases. If you want to raise the security level, introduce a control word or a rule requiring mandatory confirmation in the company messenger before you make any “urgent” financial move.

Digital security How to protect yourself from deepfake scams
  1. 01On the conversation sideDo not make transfers based only on a phone call.
  2. 02Red flagsPressure, urgency, blocking verification.
  3. 03Stop and verifyUse a callback to a KNOWN number.
  4. 04Company procedureCritical decisions via an independent channel.

Bypass deepfake scams by confirming identity via an independent communication channel.

law, ethics and responsibility for deepfake content in Poland

In Poland, deepfake can give rise to legal liability when it infringes an image and personal rights or misleads viewers into thinking that the material shows a real person and a real event. Distributing someone’s image without consent can infringe personal rights (Civil Code), especially when the content harms reputation or privacy. If the material is presented as real and harms someone’s good name, the risk of infringement increases regardless of whether it was created “for a joke”. In practice, the boundary can be blurry in the case of parody, because context, caption, scale of harm and the risk of misleading people all matter.

A deepfake suggesting that someone committed a reprehensible act or said certain things may meet the criteria for defamation (Art. 212 of the Penal Code) or other infringements. In such cases, what is crucial is whether the content could humiliate the person in public opinion or expose them to a loss of trust, and whether it was distributed as credible information. Using deepfake to extort money (e.g. a transfer, BLIK, changing the account number) falls under classic fraud, and digital evidence such as logs, recordings and account numbers plays an important role. Prompt reporting of the incident increases the chances of securing funds and establishing the source of the attack.

Publishing a deepfake may also infringe copyright and licences to source materials, especially when it uses fragments of other people’s audio or video recordings. In workplace relations, impersonating a colleague in communications (email, video, voice) may lead to disciplinary and criminal liability, and the company may seek damages. If you create synthetic materials in advertising or communications, the ethical minimum is to clearly and visibly mark that it is content generated or modified with the involvement of AI. In reports and disputes, the collected data helps: URL, dates, profile names, post IDs, file copies and archiving, because a screenshot alone is often insufficient once the content disappears.

education and digital hygiene as protection against deepfake

Education and digital hygiene help protect against deepfake, because they reduce the amount of material vulnerable to abuse and build the habit of verifying before you react emotionally or share anything. The more clean, long and high-quality recordings of your face and voice are publicly available, the easier it is to misuse them. The most practical approach is to limit public, longer-form statements, keep an eye on privacy settings and not upload unfiltered voice recordings to open groups. In platform settings, check, among other things, the ability to download video, duets/remixes (TikTok), use in Reels (Instagram), and whether the account is indexed by search engines.

When you come across a deepfake featuring your own image, the key is to secure evidence quickly and report the infringement on the platform. Save links, take screenshots and keep a copy of the page (e.g. via web.archive.org or a local HTML save), because the content may be removed or moved. Then report the material as impersonation or privacy infringement, and effectiveness usually increases when you point to specific fragments and attach proof of identity. If the content is sexual, extortionate or defamatory, removal speed and identifying the source matter, so consider reporting it to the police and seeking legal advice.

Responsible sharing is also a form of protection, because even a comment like “this is probably fake” can boost the reach of harmful material. A better practice is to point to the debunking analysis, blur the victim’s image in screenshots and move the discussion to primary sources rather than the viral clip. For companies, a minimum viable playbook helps: identity verification, a list of red flags and a duty to report incidents to IT/security, supported by regular training and impersonation scenario simulations. It is worth remembering the limitations of automated filters: content is often designed to trigger emotions (fear, outrage, urgency), so it is the verification procedure and user habits that often determine security.

Building awareness and procedures in companies against deepfake

Building awareness and procedures against deepfake in a company means ensuring that critical decisions (especially financial ones) are not based on a “credible-sounding” voice or video, but on verifiable identity and a documented process. In practice, attacks often combine cloned voice, elements of “legitimisation” (e.g. a company footer, a fake phone number) and pressure such as “payment in 30 minutes”. Effectiveness increases when employees understand that AI detectors operate probabilistically and can fail after compression or re-encoding. The best defence is an identity verification procedure via an independent channel, not trying to “guess” whether the material is perfectly authentic.

The simplest set of procedures is clear rules for authorising instructions and communication, which reduce the risk of someone impersonating a colleague in an email, phone call or video call. “Urgent” instructions should pass only through approved channels and required confirmations, and financial decisions must go into a log in company systems rather than being handled ad hoc during a conversation. If a live deepfake is suspected, a simple verification test can help, namely asking the person to perform an unusual action (e.g. show a hand in front of their face, turn their head and say a specific phrase), because this increases the chance of detecting manipulation. If there is a ban on hanging up, pressure to keep the matter secret or threats of consequences, treat it as a signal to end the contact immediately and verify via another channel.

Effective implementation in a company also requires the habit of documenting and readiness to report incidents, because without a “trail” it is difficult later to prove manipulation or reconstruct the sequence of events. When verifying materials, it is worth maintaining a chain of custody, i.e. recording file versions, links, download dates and screenshots so that the entire checking process can be reconstructed. At the same time, training and simulations of impersonation scenarios are needed (e.g. a fake CFO requests an urgent transfer or a “client” demands a change of account number), combined with a duty to report suspicious situations to IT/security. This package works because it strikes at the weakest link in the attack, namely haste and lack of verification, rather than only the “technique” of deepfake.

FAQ

Frequently asked questions

How do you spot a deepfake in video by the movement of the mouth and facial expressions?

Pay attention to inconsistencies between mouth movements and the spoken sounds, especially with consonants such as p, b, m, t and d. Suspicious signs also include “rubbery lips”, slight delay and a lack of micro-movements in facial expressions.

Can the eyes give away fake AI video?

Yes, because instead of natural micro-movements you often see a “dead stare” and an unnaturally long fixed gaze on one point. It is worth checking whether the eyes behave as “lively” as the rest of the face.

Why do facial edges and lighting help detect deepfake?

Manipulation often distorts the hairline, ears, glasses, jewellery and facial contours, making the elements look blurred or pasted in. Suspicious signs also include shadows and reflections that do not match the light source in the frame.

How do you spot deepfake voice from audio?

It is most often betrayed by unnatural prosody, meaning an overly even pace, predictable intonation and odd pauses. Alarm bells also go off for artificially sounding consonants, breaths in the wrong places and a constant background hiss.

What should you do if you suspect financial fraud using deepfake?

Do not make a transfer or give out a BLIK code based only on a phone call or video call. Break off contact and call back on a known number from your contacts to confirm the identity through an independent channel.

How can you check whether a viral video has been taken out of context?

Establish the original source and look for the original publication rather than relying on a “copied” clip. Reverse image search, background analysis and checking the location and time of the recording also help.

Contents