A fake photo of a politician, a video of a celebrity endorsing a “guaranteed investment”, or the voice of a grandson who urgently needs money. All of this can be produced by anyone in minutes today, and the results keep getting more convincing. The good news: most fakes can still be exposed if you know what to look for, and above all if you adopt one habit that will keep working even on the fakes that arrive next year. Let us get to it.

What a deepfake is and why you will meet one

A deepfake is an image, video or audio created by artificial intelligence to pass as a real recording. It used to take a powerful computer and days of work; today a web service and a few seconds of source material are enough. The use has changed accordingly: from internet fun to a scammer’s tool. These are the most common scenarios:

  • Fake investment videos: a familiar face (news presenter, politician, entrepreneur) in a news-style cut recommends an investment platform. The goal is to extract a deposit.
  • A cloned voice in an emergency call: a “grandson” or “daughter” calls from an unknown number, had an accident and urgently needs money.
  • A fake video call at work: the “CEO” or “accountant” on video demands an urgent payment. Even large companies have fallen for this one.
  • Invented imagery in news and hoaxes: a shocking photo or video of an event that never happened. This builds on what we cover in how to recognise a hoax.

How to recognise an AI-generated photo

Image generators improve fast, yet they keep repeating typical mistakes. Inspect the photo up close (zoom in on a computer) and look for:

  • Hands and fingers: the wrong count, oddly bent joints, fingers merging with objects.
  • Teeth, ears and eyes: irregular teeth fused into one mass, each ear different, reflections in the eyes showing a different scene in each eye.
  • Jewellery, glasses and buttons: an earring on one side only, a glasses frame that “melts” in the middle, asymmetric fastening.
  • Text in the background: signs, T-shirts and packaging carry a blurred pseudo-alphabet.
  • Hair and edges: strands blending into the background, “bitten-off” outlines around the head.
  • Light and shadows: a shadow falling somewhere the light does not point, or missing entirely; skin unnaturally smooth like plastic.

An important caveat: none of these signs is proof, and their absence is no guarantee. The latest models no longer draw six fingers. That is why the habit in the next chapter is the key one: verify the origin, not the pixels.

Want to train your eye on real examples? Take our quiz can you spot the AI photo? · 10 photos, each answer followed by what gave it away.

The habit that survives every new AI version: verify the origin

Flaws in the image will disappear over time; the origin of content remains. With every shocking photo or video:

  1. Run a reverse image search: upload the picture (or a screenshot from the video) to images.google.com or tineye.com. You will learn where it first appeared and whether it is an old shot in a new context.
  2. Look for the original source. Who published it first? An anonymous account created last month, or a newsroom with a name and accountability?
  3. Check whether trustworthy media report it. A genuinely major event reaches serious media within hours. If they are silent, be on guard.
  4. Watch for content provenance labels. The C2PA standard (Content Credentials) is arriving; it stores a verifiable signature of how a file was created. Cameras, editors and AI generators are gradually adopting it.

Deepfake video: what to watch and the live-call test

In video, watch the mouth and the edges of the face: lips slightly out of sync with the audio, teeth changing between frames, the face’s edge rippling when the head turns, blurred transitions around hair and ears. News-style cut videos with a single static face and a monotone voice deserve suspicion too.

If someone is speaking to you live on video and asking for money or sensitive data, run a simple test:

  • ask them to turn sideways (models often fail on face profiles),
  • to pass a hand in front of their face (the hand “flows” through the mask),
  • to move closer to the camera or hold an object in front of the face.

Above all: verify identity through another channel. Hang up and call back on the number you have saved. A business should have a four-eyes rule for payments that even a convincing video of a superior cannot break. These attacks are a form of social engineering, which we cover in detail in social engineering and AI scams.

The cloned voice: the most dangerous, because the most personal

For a voice clone, an attacker needs seconds of recording: a social media video, a voice message, even a voicemail greeting. The result will then say anything. The typical attack aims at emotion and time pressure: a crying “relative”, an accident, the police, money needed right now.

The defence does not depend on how good the clone is:

  • Hang up and call back on the number you have saved. A real relative will understand.
  • Agree on a family verification question or code word that cannot be read off social media.
  • Never send money or codes based on a single call, however convincing it sounds.

The same rules apply to businesses: an urgent payment “ordered by the director” over the phone always gets verified through a second channel.

AI content detectors: helpful, but not decisive

Online detectors of AI photos and videos give only a probabilistic estimate; high-quality fakes slip past them and genuine footage sometimes gets flagged. Treat them as one signal alongside origin checks, not a final verdict. If suspicious content reached you by e-mail, you can assess the message itself with our phishing e-mail checker; it evaluates the signs of fraud in the message, not the authenticity of a video.

Want certainty before you send money?

If a suspicious video, voice message or an "urgent" request has reached you, contact us before you react. We will assess the content, set up company rules against voice and video fraud and teach your team to recognise them.

Get advice on suspicious content

Summary

You spot a deepfake by combining two approaches. In the short term, visual signs work: hands, teeth, background text, face edges, inconsistent shadows and lips out of sync; train them in our quiz can you spot the AI photo?. In the long term, only one thing works: verify the origin with a reverse image search, find the primary source and wait for confirmation by trustworthy media. In calls and video calls, let the call-back rule and a verification question decide, not the impression of a voice or a face. Whoever verifies origins will not be surprised even by next year’s generation of fakes.

This article is part of our Cybersecurity overview.