A Deepfake Claim Is a Question, Not a Finding
“Deepfake” is often used for several different problems: fully synthetic media, altered media, authentic media placed in a false context, a clipped recording, or a real person using an impersonator. Those possibilities require different tests. A strange blink, distorted hand, mismatched lip movement, or robotic voice may raise a question, but compression, poor lighting, network delay, editing, accessibility tools, and ordinary camera processing can create similar artifacts.
The investigation should first define the disputed proposition. Is the named person actually speaking? Did the depicted event occur at the claimed place and time? Was a real recording materially altered? Who published or transmitted it, and what action did they request? Fraud also requires more than synthetic content; harmless parody, disclosed creative work, and benign editing exist. The deceptive representation, intent, reliance, loss, or threatened harm must be evaluated under the law applicable to the incident.
The FBI's generative-AI fraud warning describes criminals using synthetic text, identification, audio, images, and video in impersonation and financial schemes. It does not mean every suspicious file is AI-generated.
Preserve the Earliest Available File
Do not repeatedly download, edit, enhance, screen-record, or forward the only copy before preserving it. Keep the earliest available file in its native format when possible. Record how it arrived, the sender or account, platform, URL, date and time, message thread, and device used to receive it. Save related emails with full headers and preserve payment requests, usernames, phone numbers, wallet addresses, and transaction identifiers.
A screenshot can preserve what appeared on screen, but it is not a substitute for the underlying file or platform data. Social platforms may resize media and strip metadata; messaging apps may recompress it; a copied file may acquire new timestamps. Those changes do not automatically prove deception, but they can reduce what a qualified examiner can determine.
Work from a verified copy and retain the preserved source. When the matter involves litigation, employment action, extortion, intimate imagery, or a significant loss, coordinate collection with counsel and a properly qualified digital-forensics professional. A private-investigator license alone does not establish expertise in media authentication.
Test Provenance Before Visual Artifacts
Provenance asks where media came from and what happened during its lifecycle. NIST's digital and multimedia evidence program covers research into digital evidence, forensic tools, and deepfake detection. Its broader synthetic-content report reviews provenance tracking, watermarking, labeling, and detection while recognizing limits and research gaps.
An examiner may inspect container and codec information, metadata, edit history, waveform or frame anomalies, source-device consistency, known reference media, and available provenance credentials. No single detector score should decide the issue. Tools may produce false positives or false negatives, especially after cropping, recompression, translation between platforms, noise, or adversarial modification.
The report should identify the tool and version, input file, method, result, confidence, known limitations, and whether another examiner could reproduce the work. “An AI detector said 92% fake” is not a complete forensic conclusion.
Corroborate the Person, Event, and Context
Media analysis is only one evidence stream. Verify the claimed speaker through a known contact channel, not the phone number or account embedded in the suspicious message. Compare the event with calendars, travel, weather, public appearances, transaction logs, camera sources, witnesses, or original recordings where lawfully available. Search for earlier uploads and alternate versions that may reveal cropping or a false caption.
For a corporate request, verify payment or instruction changes using a second person and a previously established number. For an emergency-family message, the Federal Trade Commission recommends independent verification even when the voice sounds familiar. Contextual corroboration can resolve a case without claiming to identify the exact generation model.
Investigators must not hack accounts, impersonate account holders to obtain protected data, or promise access to platform or phone records. Those records may require consent, provider process, a subpoena, or law enforcement.
Report Findings With Confidence and Limits
A useful report separates provenance facts, technical observations, source statements, contextual corroboration, and unresolved questions. Conclusions should use calibrated language such as “consistent with,” “inconclusive,” or “not supported by the available source file,” rather than claiming certainty the method cannot supply. Contrary evidence and missing data belong in the report.
Preservation and expert analysis do not guarantee admissibility. Florida Statute 90.901 addresses authentication, and other rules may govern relevance, expert testimony, disclosure, privacy, and hearsay. Counsel decides how the evidence should be used.
Verify an investigative agency through the FDACS license search and separately verify any examiner's technical qualifications. Emerging Investigations can preserve open-source context, identify sources and accounts, build a corroborated chronology, and coordinate specialized examination for a defined AI-related investigation. We do not claim that visual inspection alone can authenticate media.
Related Services
