Skip to content
recaplica

    One moment: security check

    Cloudflare wants to make sure you're not a robot. Tick the box below and your search will continue on its own.

    IT
    recaplica What Is a Deepfake? How It Works and How to Spot One
    © 2026 Recaplica · recaplica.com — All rights reserved
    Home › Civics

    What Is a Deepfake? How It Works and How to Spot One

    By Recaplica Newsroom · Updated on September 19, 2026

    What to print

    Page numbers appear when printing with default margins.

    Slides

    Choose a cut

    Flash10 slidesThe essential thread, to present in classFull14 slidesEvery chapter and the deeper detail

    Both come with speaker notes.

    Telegram channel
    recaplica Clear in 30 seconds, yours in 10 minutes.
    In 30 seconds Key points Figures Deep dive Slides Myths Mind map Quiz Flashcards FAQ

    In 30 seconds quick read

    A deepfake is audio or video content that artificial intelligence creates or alters to make fake images or words look real, sometimes depicting people who don't exist at all. The technique began with generative adversarial networks and has relied mainly on diffusion models since 2023, tools capable of producing convincing results within minutes. In January 2024, a Hong Kong company lost $25 million after a video call in which the colleagues present, including the chief financial officer, turned out to be synthetic reconstructions, a case that shows how usable the technology already is for real-world fraud. Spotting a deepfake is no longer a matter of watching for odd shadows or listening closely, and this Recap explains which signals still hold up and what European law requires.

    Key Points

    • A deepfake is an image, audio clip, or video that AI generates or manipulates to convincingly depict a real or plausible person, even though the scene never happened.
    • Diffusion models have largely replaced generative adversarial networks (GANs) as the dominant technique for producing deepfakes since 2023.
    • The World Economic Forum's Global Risks Report 2024 named disinformation, partly fuelled by deepfakes, as the most severe global risk over the following two years, according to experts and decision-makers surveyed worldwide.
    • A 2025 study cited by UNESCO found that people can no longer reliably distinguish an AI-cloned voice from a real one.
    • Since August 2, 2026, the EU AI Act has required anyone who distributes a deepfake to disclose it to viewers or listeners, except for content that is clearly artistic, satirical, or fictional.
    • In the Hong Kong finance scam of January 2024, the deepfake likely didn't need to respond live: pre-recorded clips played during the video call were enough.

    Key figures

    • $25 million Amount lost in January 2024 by a Hong Kong company, deceived by a video call in which the colleagues present, including the chief financial officer, were actually deepfakes. Source: Trend Micro / UNESCO, 2024
    • 53% Share of experts and decision-makers surveyed in 2024 who named AI-generated disinformation among the most severe global risks of the following two years, the second most-cited risk after extreme weather events. Source: World Economic Forum, Global Risks Report 2024
    • 46% Share of fraud experts who in 2024 reported having encountered synthetic identity fraud, according to a fraud-expert survey cited by UNESCO. Source: Fraud-expert survey cited by UNESCO, 2024

    Deep Dive

    What it actually is

    The EU AI Act, the regulation governing artificial intelligence across the European Union, defines a deepfake in Article 3(60) as AI-generated or manipulated image, audio, or video content that resembles existing (or plausible) persons, objects, places, entities, or events and gives a false impression of their authenticity. Three elements have to coexist: resemblance to a real or plausible subject, the existence of that subject, and the content’s ability to look authentic to whoever sees or hears it. UNESCO places it within a broader category, synthetic content: any material, audio, image, or video, produced by generative artificial intelligence, of which the deepfake is the most deceptive case because it convincingly mimics a real person’s voice or likeness.

    How it’s made, in brief

    Until around 2022, the leading technique was generative adversarial networks, or GANs: two neural networks pitted against each other, a generator that produces a fake image and a discriminator that judges its authenticity. The process repeats for hours or days, until the generator produces results the discriminator can no longer catch. Since 2023, this architecture has largely given way to diffusion models, the family that includes Stable Diffusion, Sora, and Runway Gen-3.

    TechniqueWhen it dominated
    GANs (generative adversarial networks)Until around 2022, the technology described in the Europol report
    Diffusion models (Stable Diffusion, Sora, Runway Gen-3)Since 2023

    In practice, a few seconds of real voice or a handful of images are enough to train a model that can generate a video within minutes: some commercial tools, such as HeyGen, make the process accessible to anyone with a starting video of the person being imitated. Within a few years, machine learning applied to this purpose went from a research lab to a widely available tool.

    A real case: the video call that cost $25 million

    Practical example: in January 2024, an employee at a Hong Kong engineering firm joined a video call with what looked like the chief financial officer and several other colleagues. They were all deepfakes. Convinced he was talking to real superiors, the employee authorized transfers totaling $25 million. Analysts at Trend Micro believe it’s unlikely the fraudsters used an AI that responded live; more probably, they played a set of pre-recorded clips in real time during the call.

    Misuses beyond disinformation

    The 2022 report from the Europol Innovation Lab lists a range of criminal uses for deepfake technology that goes well beyond false news: online harassment and humiliation, extortion and fraud like the case above, document forgery, digital identity theft, non-consensual explicit material, child sexual exploitation, manipulation of evidence in legal proceedings, and finally disinformation and political polarization. A Recap on spotting fake news covers a different problem: fake news is a false story in any form, while a deepfake is synthetic content built with AI to look real.

    Why eyes and ears aren’t enough anymore

    A study published in Nature Communications in 2024, led by Matt Groh and colleagues at the MIT Media Lab, tested how well people can recognize a political deepfake using a set of 32 short speeches by Presidents Joe Biden and Donald Trump. On the audio side the picture is even starker: a 2025 study cited by UNESCO found that people often perceive an AI-generated voice as identical to a real one, without being able to tell them apart reliably. UNESCO also points to a parallel limit on the technology side: automated detection tools consistently lag behind the techniques used to create deepfakes.

    How to spot a deepfake, in practice

    Some precautions remain useful precisely because they don’t depend on catching a visual or audio detail. UNESCO suggests that families agree on a code word to verify each other during a suspicious call, and proposes the “prove you’re live” technique: asking the other person to perform an unplanned physical action in real time, something live-generation systems struggle to reproduce naturally.

    The rules: what the EU AI Act requires

    Since August 2, 2026, the AI Act has required anyone who distributes a deepfake, the so-called “deployer” of the system, to disclose it clearly to whoever views or hears it, at the latest upon first contact with the content. Works that are evidently artistic, creative, satirical, or fictional are exempt from the strict version of the rule, needing only a disclosure that doesn’t get in the way of enjoying the content. Content generated before August 2, 2026, doesn’t need to be labeled retroactively, even though the European Commission recommends it. For systems already on the market, the technical marking obligations begin on December 2, 2026. Non-compliance carries penalties of up to €15 million or 3% of worldwide annual turnover. The rules are covered in more depth in the Recap on the EU AI Act.

    Slide deck

    Slides ready to download and make your own in PowerPoint or Google Slides, with speaker notes. Pick the Flash cut or the Full one.

    Slide 1 of the presentation on What Is a Deepfake? How It Works and How to Spot One: DeepfakeSlide 2 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Is that video real?Slide 3 of the presentation on What Is a Deepfake? How It Works and How to Spot One: In four stopsSlide 4 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Chapter 01: What it isSlide 5 of the presentation on What Is a Deepfake? How It Works and How to Spot One: The technique, in three stopsSlide 6 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Chapter 02: How it deceivesSlide 7 of the presentation on What Is a Deepfake? How It Works and How to Spot One: The deepfake tallySlide 8 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Ears aren't enough anymoreSlide 9 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Chapter 03: Other misusesSlide 10 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Not just false news: Fraud, Non-consensual, DisinformationSlide 11 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Chapter 04: How to spot itSlide 12 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Who's winning the race?Slide 13 of the presentation on What Is a Deepfake? How It Works and How to Spot One: Since when has the EU AI Act required labeling a deepfake?Slide 14 of the presentation on What Is a Deepfake? How It Works and How to Spot One: The Recap continues on the site
    Flash10 slidesThe essential thread, to present in classFull14 slidesEvery chapter and the deeper detail

    Common myths

    • ✗ Myth Listening closely is enough to spot an AI-cloned voice.

      ✓ Reality A 2025 study cited by UNESCO measured how well people can tell a synthetic voice from a real one, and found that most often they can't: the ear perceives the cloned voice as identical to the original, with no reliable cue to hold onto.

    • ✗ Myth Some tool can always unmask a deepfake.

      ✓ Reality UNESCO describes the relationship between deepfake creators and detectors as a race that detection tools tend to lose, because they stay one step behind the latest generation techniques: no software guarantees a definitive verdict.

    • ✗ Myth Deepfakes are mostly used to manipulate politics.

      ✓ Reality The 2022 Europol Innovation Lab report lists a much wider range of criminal uses: online harassment, extortion, document fraud, identity theft, non-consensual material, and manipulation of electronic evidence, alongside disinformation and political polarization. The Hong Kong finance scam of 2024 itself involved a $25 million corporate fraud, not an election campaign.

    Mind map

    Drag the background to move around and the nodes to reposition them; use − and + to collapse and expand branches.

    Customize
    Mind map: What Is a Deepfake? How It Works and How to Spot One
    • Deepfake
      • What it is
        • Legal definition three criteria in the AI Act, resemblance, existence, false authenticity
        • Synthetic content the broader category it belongs to, per UNESCO
      • How it's made
        • Generative adversarial networks generator and discriminator, competing for hours or days
        • Diffusion models the dominant technique since 2023
      • Why it deceives
        • Hong Kong case, 2024 $25 million lost in one video call
        • Pre-recorded clips no live-responding AI required
      • Improper uses
        • Fraud and identity theft
        • Non-consensual material
        • Disinformation and polarization
      • How to spot it
        • Limits of the ear cloned voices are no longer reliably distinguishable
        • Code word
        • Prove you're live
      • The rules
        • EU AI Act labeling obligation since August 2, 2026
        • Limits of automated detection tools stay behind the technique

    Quiz: test yourself

    Answer the questions to check what you have learned: you get instant feedback and a short explanation.

    Grade 0/10 0/5
    1 Under the EU AI Act's definition, what does a piece of content need to count as a deepfake?

    Article 3(60) of the AI Act lists three cumulative criteria: resemblance to a real or plausible subject, the existence of that subject, and a false appearance of authenticity capable of deceiving viewers or listeners.

    2 Which technique had largely replaced generative adversarial networks (GANs) in deepfake production by 2023?

    Since 2023, tools such as Stable Diffusion, Sora, and Runway Gen-3 have largely supplanted GANs as the dominant architecture for generating convincing deepfakes.

    3 What have the most recent studies shown about people's ability to recognize an AI-cloned voice?

    A 2025 study cited by UNESCO confirms that people often perceive an AI-generated voice as identical to a real one, without being able to tell them apart reliably.

    4 In the Hong Kong finance scam of January 2024, how were the deepfakes likely used during the video call?

    Trend Micro's analysts think the fraudsters most likely prepared the clips in advance and played them during the call, instead of using an AI system that could actually respond live.

    5 What does the EU AI Act require of anyone distributing a deepfake, as of August 2, 2026?

    Article 50 of the AI Act requires the deployer of the system to disclose the deepfake at the latest upon first exposure; content that is evidently artistic, satirical, or fictional only needs a disclosure that doesn't hinder its enjoyment.

    Answers: 1-A · 2-A · 3-B · 4-A · 5-A

    Flashcards

    Tap the card to flip it and check whether you remember the answer, then move to the next one.

    1 / 7

    Explain it in your own words

    The ultimate test: if you can explain it in simple words, you've truly understood it. Write your explanation, then compare it with the Recap.

    Your explanation is saved only on this device.

    A deepfake is audio or video content that artificial intelligence creates or alters to make fake images or words look real, sometimes depicting people who don't exist at all. The technique began with generative adversarial networks and has relied mainly on diffusion models since 2023, tools capable of producing convincing results within minutes. In January 2024, a Hong Kong company lost $25 million after a video call in which the colleagues present, including the chief financial officer, turned out to be synthetic reconstructions, a case that shows how usable the technology already is for real-world fraud. Spotting a deepfake is no longer a matter of watching for odd shadows or listening closely, and this Recap explains which signals still hold up and what European law requires.

    Frequently asked questions

    What is a deepfake?

    It's audio, an image, or a video that artificial intelligence creates or alters to look authentic: it can show a real person saying or doing something that never happened, or reconstruct a face that doesn't exist. The EU AI Act defines it in Article 3(60) as content that resembles a real or plausible subject and gives a false impression of authenticity.

    How is a deepfake made?

    Until around 2022, the leading technique was generative adversarial networks (GANs): two neural networks trained against each other for hours or days. Since 2023, production has relied mainly on diffusion models such as Stable Diffusion, Sora, or Runway Gen-3, now built into commercial tools that can generate a video in minutes from a handful of images or a few seconds of real voice.

    How do you spot a deepfake?

    Listening or watching closely is no longer enough: a 2025 study found that people can't reliably tell a cloned voice from a real one, and automated detection tools still lag behind the techniques used to create deepfakes. UNESCO suggests practical steps instead, such as agreeing on a family code word for suspicious calls, or asking the other person for an unplanned physical gesture that a real-time system struggles to reproduce.

    What does European law say about deepfakes?

    Since August 2, 2026, the AI Act has required anyone distributing a deepfake to clearly disclose it to viewers or listeners, with a lighter exception for works that are clearly artistic, satirical, or fictional. Content generated before that date doesn't need to be labeled retroactively. Penalties for non-compliance reach up to €15 million or 3% of worldwide annual turnover.

    What's the difference between a deepfake and fake news?

    Fake news is a false story in any form, even a simple text written to mislead. A deepfake is a synthetic audio or video piece built with AI to look real: it can spread disinformation, but it's also used for fraud, identity theft, or non-consensual material that has nothing to do with news at all.

    Sources

    • Europol Innovation Lab, deepfakes report (summary via eucrim.eu)
    • MIT Media Lab, How to Spot Political Deepfakes
    • UNESCO, Deepfakes and the crisis of knowing
    • Trend Micro (TrendAI Security), Deepfake video calls
    • Infosecurity Magazine, on the World Economic Forum's Global Risks Report 2024
    • European Commission, transparency obligations under Article 50 of the AI Act

    Every Recap goes through an independent review before publication.

    Every evening, the day's new Recaps on our Telegram channel. Join the channel →

    Keep learning

    • Civics Credible Sources for Research: the CRAAP Test, Step by Step Not every source that turns up in a search engine belongs in a research paper, a school assignment or a thesis. The CRAAP test breaks the question into five checks, currency, relevance, authority, accuracy and purpose, that a student can run on any source before citing it. It also helps separate a primary source, the original document, from a secondary one that comments on it, and clarifies that Google Scholar applies no peer-review filter to the results it returns. Curated databases such as Scopus and Web of Science, by contrast, flag peer review at the journal level. With these tools a student can judge a source on its merits instead of trusting whatever ranks first. Read the Recap →
    • Civics SPID Digital Signature: Italy's Advanced Electronic Signature, Explained Since 2020, Italian law has allowed a real 'signature with SPID': a button on a public body's or company's website that lets someone sign a document with the same legal weight as a handwritten signature, without needing a separate qualified digital signature. In practice, though, this free and direct service is offered almost only to public bodies and partner companies, not to a private citizen who wants to sign a contract on their own. What providers like InfoCert and Poste sell to the public as 'digital signature with SPID' is usually something else entirely: SPID used just to verify identity, then a separate qualified digital signature, often paid. Knowing the difference keeps people from paying for a product they assume is the free one the guidelines describe. Read the Recap →
    • Civics Media Literacy: What It Is and How to Judge a Source's Credibility Media literacy is the set of skills that lets people read, judge, and use articles, websites, and encyclopedia entries with a critical eye. The University of Chicago Library lists five practical criteria for judging a source: currency, relevance, authority, accuracy, and purpose. FactCheck.org published an eight-step method for spotting fabricated news in 2016, later translated and distributed worldwide by IFLA. Wikipedia works the same way, with reliability resting on the quality of the sources cited in its footnotes. Read the Recap →

    recaplica

    Clear in 30 seconds, yours in 10 minutes.

    Recaps Mind maps Request a Recap Telegram channel Mind map maker Our method About Privacy & cookies Legal notes & terms of use

    © 2026 Recaplica · A project by Curi S.r.l. — VAT IT05472000750

    Statistics, only if you say so

    To learn which Recaps help most we would use Google Analytics, with aggregate, anonymous data. It starts only with your OK, and you can change your mind anytime. Privacy policy