Reliable decisions come from a documented evidence chain, not a single detection score. Provenance, context and independent confirmation usually carry more weight than visible artefacts.
Why the deepfake question can mislead
Manipulation does not need to be fully synthetic. Authentic video can be falsely captioned, cropped, revoiced or reused from another event. Conversely, edited material can still depict the core event accurately.
The operational question is therefore not only how a file was produced, but which claim is being made with it and whether that claim is supported by reliable evidence.
The first ten minutes: slow distribution and preserve the original
Avoid unnecessary redistribution before analysis. Recompression and editing may change technical traces, while posts, profiles and stories can disappear quickly.
- Secure the original or best available file, not only a screenshot.
- Record the URL, account, timestamp, accompanying text and discovery context.
- Limit internal circulation to those who need access.
- Write the exact claim to be tested in one sentence.
- Assign communication and escalation responsibility before responding publicly.
A five-stage verification process
The order matters. Looking for visual flaws too early narrows the analysis to the media file and can hide stronger contextual evidence.
- 01Source
Who published the material first, and is that channel authentic, current and competent to make the claim?
- 02Provenance
Is there an original file, metadata, content credential or traceable edit history?
- 03Context
Do location, weather, clothing, language and known timelines fit the claimed situation?
- 04Content
Which visual, audio or motion anomalies exist, and could compression, perspective or editing explain them?
- 05Corroboration
Do independent recordings, witnesses, official sources or primary evidence support the core claim?
Why a detector score is not a verdict
Automated detection can provide a useful signal, but performance depends on training data, manipulation type, compression and unknown generation methods. A percentage looks precise while saying little without model version, test conditions and error rates.
Use detectors as indicators: ideally several methods, controlled inputs and documented versions. A positive signal needs corroboration; a negative one does not prove authenticity.
Content Credentials support provenance, not truth
C2PA can carry cryptographically bound information about origin and editing. This helps determine whether a signed provenance record belongs to a file and whether documented changes occurred.
It is a strong trust signal, not a universal truth label. Authentic signed media can be miscaptioned, and genuine files can lose provenance data through platform processing.
The conclusion must reflect remaining uncertainty
A professional result may not be simply real or fake. It may say: origin unconfirmed, context partly verified, no decisive manipulation indicators, core claim corroborated by two independent sources.
That language prevents both an impulsive reaction to manipulated content and the dismissal of authentic evidence as an alleged deepfake.
Decision check
Questions before you act
- 01
Is the exact claim clearly defined?
- 02
Do you have the best available original and its discovery context?
- 03
Were source, provenance, context and content assessed separately?
- 04
Is there confirmation outside the same source chain?
- 05
Does the conclusion communicate uncertainty clearly?
Sources
Primary and authoritative references
Deepfake keynote
Make verification understandable through realistic examples, explicit limits and practical transfer.