In January 2026, a deepfake video of a sitting head of state announcing a military action circulated for 47 minutes before being authoritatively debunked. In that window, markets moved, diplomatic cables were sent, and millions of people believed something that never happened. This is the world we now live in — and the tools designed to prevent it are losing the race.

Why Detection Is Failing

The latest generation of video synthesis models — including Sora 3, Runway Gen-4, and several open-source alternatives — produce video that defeats every existing detection tool. The fundamental problem is that detection tools are trained on artefacts from previous-generation synthesis models. As synthesis improves, detection lags by 6–12 months. By the time a detection model is trained on the current generation's artefacts, the synthesis models have moved on.

A study published by the University of Washington's Security and Privacy Research Lab in April 2026 tested 14 commercial and open-source deepfake detection tools against videos generated by the five most capable current synthesis models. None of the detection tools achieved accuracy above 65% — and several performed worse than random chance on the most recent models. The researchers concluded that visual-artefact-based detection is "fundamentally insufficient" against current synthesis technology.

The Provenance Approach

The most promising solution isn't detection — it's provenance. The Content Authenticity Initiative, backed by Adobe, Microsoft, the BBC, and over 2,000 member organisations, has developed a cryptographic signing standard called C2PA that embeds tamper-evident metadata in media files at the point of capture. Cameras, phones, and recording software that implement C2PA create an unbroken chain of custody from capture to publication.

Sony, Nikon, and Leica have shipped C2PA-enabled cameras. Apple's iPhone 17 Pro implements C2PA for photos and videos captured in its native camera app. The New York Times, Reuters, and the BBC have updated their content management systems to display C2PA verification badges on authenticated content.

The Adoption Problem

C2PA is technically sound, but adoption is fragmented. Major news organisations have implemented it; social media platforms have not. Meta, TikTok, and X have all announced plans to support C2PA verification but have not yet deployed it at scale. Until the platforms where most people consume news require C2PA verification, the standard cannot fulfil its potential.

There is also a fundamental gap: C2PA can verify that a video was captured by a specific device at a specific time, but it cannot verify that the person in the video is who they appear to be. A genuine video of an actor performing a scripted scene would pass C2PA verification. The standard addresses fabrication, not impersonation.

Legislative Responses

Governments are responding with legislation, though the pace varies significantly. The EU's AI Act requires disclosure of AI-generated content in certain contexts. California's AB 602 and AB 730 require disclosure of AI-generated political advertising and synthetic media depicting real people in sexual contexts. Australia's Online Safety Act has been amended to cover non-consensual deepfake pornography. But enforcement is patchy, and the laws that exist are reactive rather than preventive.

What Individuals Can Do

In the absence of reliable technical solutions, media literacy is the most important defence. Treat any surprising video of a public figure with scepticism until it has been verified by multiple independent sources. Check the publication date and source. Look for C2PA verification badges where they exist. And remember: the most dangerous deepfakes are the ones that confirm what you already believe — our tendency to accept confirming information without scrutiny is the vulnerability that deepfakes exploit most effectively.

The Platform Responsibility

Ultimately, the deepfake crisis is a platform governance problem as much as a technical one. Social media platforms have the ability to require C2PA verification for political content, to label AI-generated media, and to remove synthetic content that impersonates real people. The EU's Digital Services Act requires large platforms to implement risk mitigation measures for systemic risks — including disinformation — and the European Commission has begun enforcement proceedings against platforms that have failed to comply. In Australia, the Online Safety Act gives the eSafety Commissioner powers to require platforms to remove harmful synthetic media. The tools exist; the question is whether the political will to use them is sufficient.

Sources & Further Reading