The Evidence Problem in the Age of Deepfakes
Introduction
Digital evidence has become part of almost every modern investigation. A photograph can place a person at a location, an audio recording can capture a conversation, and a video can appear to show an event as it happened. For years, the main forensic concern was whether such material had been altered. The rapid growth of generative artificial intelligence has added a harder question: even when a file is preserved exactly as received, can investigators still trust what it appears to show?
Deepfakes have made this question practical rather than theoretical. Synthetic or manipulated audio, video and images can imitate real people and real events with increasing realism. CERT-In describes deepfakes as a high-risk threat because they can support disinformation, fraud, social engineering and reputational harm.[1] NIST research likewise treats AI-generated media as a digital-forensics challenge that requires systematic evaluation of detection technologies.[2]

The result is an evidence problem. The answer is not to stop trusting digital evidence, but to become more disciplined about establishing its origin, integrity, context and authenticity.
The evidence problem begins before the laboratory
When a suspicious video reaches an investigator through WhatsApp, Telegram, email or social media, the file may already have passed through several transformations. It may have been compressed, re-encoded, cropped, renamed or stripped of metadata. A screenshot may preserve what is visible but lose the original file structure. A forwarded audio clip may contain no reliable information about where it was first recorded.
For that reason, forensic examination should begin with acquisition and provenance, not with a quick “deepfake detector” result. Investigators should ask: Who supplied the file? Where was it obtained? Is there an original version? What device or account produced it? What happened to the file before it reached the investigator?
Cryptographic hashing remains important because it can demonstrate that an acquired working copy has not changed during examination. But a valid hash does not prove that the underlying event was genuine. A perfectly preserved fake is still a fake.
What a professional examination should look for
A reliable assessment combines several forms of evidence rather than relying on one technical indicator.
Source and acquisition. The original artefact should be preserved whenever possible. Investigators should record the acquisition method, date and time, source account or device, and any known transformations before collection. A documented chain of custody is essential when material may later support a legal, disciplinary or regulatory decision.
Metadata and file structure. Metadata may provide useful clues about creation, encoding, editing software and timestamps. File structure, compression behaviour and related technical characteristics can also reveal inconsistencies. However, these indicators are supporting evidence, not proof on their own, because metadata can be removed or rewritten during normal processing.
Content-level examination. Forensic analysis can include frame-by-frame video review, audio waveform and spectral examination, and inspection for inconsistencies in lighting, reflections, facial movement, lip synchronisation or background elements. Such signs may help guide an investigation, but they are not a permanent checklist. Generative systems continue to improve.
Independent corroboration. This is often the strongest step. If a recording allegedly shows that a person was in a particular place at a particular time, investigators can compare it with CCTV, access-control records, device artefacts, communications, location information, eyewitness accounts or other independent records. The goal is to determine whether the wider evidence supports the event represented by the media.
A real-world lesson: the Pikesville case
The 2024 Pikesville High School incident in Maryland provides a practical example of why authenticity cannot be assumed from appearance alone. An audio recording circulated online that was presented as the principal making racist and antisemitic comments. On January 17, 2024, Baltimore County Public Schools said it could not yet confirm the recording’s veracity and opened an investigation.[3]
Several months later, the school district reported that investigators, with assistance from the FBI and other experts, had verified that the audio had been created using artificial intelligence.[4] Police subsequently arrested the school’s former athletic director in connection with the fabricated recording.[5]

The forensic lesson is larger than the incident itself. The recording had social consequences before its authenticity was established. In a fast-moving online environment, the first version of an event can travel much further than the later correction. Deepfake investigations therefore have to consider not only whether media is authentic, but also how quickly unverified material can influence decisions.
From deepfake detection to content provenance
Detection tools will remain useful, but they should be treated as part of an examination rather than an automatic verdict. NIST’s Guardians of Forensic Evidence work reflects the need to evaluate how analytic systems perform against changing forms of AI-generated media and how well they generalise beyond controlled conditions.[2]
Another important direction is content provenance. The Coalition for Content Provenance and Authenticity (C2PA) has developed a technical framework for recording verifiable information about how digital content was created and changed. Content Credentials can bind provenance information to an asset using cryptographic techniques, allowing later users to inspect a recorded content history when that information is available.[6]

Provenance does not mean that every claim associated with a file is automatically true. It adds context: who created it, what actions were taken and how the asset changed. In a deepfake environment, that context can be as important as the content itself.
Why this matters in India
The issue is especially relevant to India’s fast-growing digital environment. CERT-In’s 2024 advisory identifies misinformation, fraud and reputational damage among the risks associated with synthetic media.[1] In August 2026, the Government of India stated that the regulatory framework addresses AI-generated deepfakes and noted amendments to the IT Rules in February 2026 concerning harms arising from synthetically generated information, including requirements related to labelling and traceable metadata for permissible AI-generated content.[7]
For organisations, deepfake response should therefore not be treated only as a media or public-relations issue. It can become an incident-response and forensic issue. A suspicious executive voice note, a manipulated employee video or a fabricated screen recording may require preservation, technical examination and independent corroboration before any action is taken.
Conclusion
Deepfakes do not make digital evidence useless. Deepfakes make handling of evidence more dangerous. The professional response is not to believe everything or to doubt everything. The professional response is to build a process around evidence: preserve the original where possible document how evidence was acquired, calculate and record hashes, examine metadata and technical characteristics use detection tools while understanding their limitations compare media with independent evidence and examine provenance information where it is available.
Importantly investigators and decision-makers should separate three questions: Is the file intact? Is the content authentic? Does the content actually prove the event being alleged? Deepfakes can pass the test while failing the other two.
In the age of AI evidence will increasingly be judged not only by how convincing it looks but, by how well its origin, integrity, context and history can be demonstrated. That is the standard that can help preserve trust when seeing and hearing're no longer enough.
References
1. CERT-In, “Deepfakes - Threats and Countermeasures,” Advisory CIAD-2024-0060, 27 November 2024. View source
2. NIST, “Guardians of Forensic Evidence: Evaluating Analytic Systems Against AI-Generated Deepfakes,” 27 January 2025. View source
3. Baltimore County Public Schools, “January 17, 2024, Community Update: Message from Superintendent Dr. Myriam Rogers Regarding Pikesville High School.” View source
4. Baltimore County Public Schools, “April 24, 2024 Staff and Community Update: Message from Superintendent Dr. Myriam Rogers Regarding Pikesville High School Investigation.” View source
5. The Baltimore Banner / WYPR, “Ex-athletic director framed principal with AI-generated voice, police say,” 25 April 2024. View source
6. Coalition for Content Provenance and Authenticity (C2PA), “Content Credentials: C2PA Technical Specification,” Version 2.1. View source
7. Government of India, Ministry of Electronics & Information Technology, “Government Strengthens Regulatory Framework to Address AI-Generated Deepfakes,” 6 August 2026. View source










