Hany Farid is a computer science professor, co-founder and chief science officer at GetReal Security, and one of the world’s foremost experts in digital forensics and image authentication. A pioneer in the science of detecting manipulated media, his work spans law enforcement, journalism, and the courts. Whether the question involves a doctored photograph, a fabricated video, or an AI-cloned voice, Farid and his team are often the ones called in to determine what is real. He joined us to talk about how synthetic media has moved from novelty to genuine threat, tools that exist to fight back, and why our legal system may not be keeping pace.
The following conversation has been edited for clarity and length.
Ten years ago, putting someone’s face on a dancing elf was entertaining. Today, far more sophisticated versions of that technology are being used in harmful ways, from non-consensual imagery targeting minors to fabricated images of conflict zones. How serious has this become?
Not only is the technology easy and prevalent; the resulting images, audio, and video are now nearly perceptually indistinguishable from reality. You couldn’t say that 10 years ago.
We are seeing horrific things happening in child safety, non-consensual intimate imagery, disinformation campaigns, small-scale frauds, large-scale frauds, and interference with democracies — and these aren’t hypothetical. This isn’t technologists standing back saying, “Well, this may happen, we should be careful.” This is happening every day. I am inundated daily with questions, requests, and analyses. Just before this call, I was helping a major news outlet deal with fake imagery coming out of the conflict in Iran; fairly consequential, I would say.
Here’s the thing: You can look back over the last 10 years and trace where the technology has been, but 10 years is a long time and we can extrapolate. When you keep going, things are getting super-weird. Ten years ago, it was fun and games, dance videos. Today, with a single image and 15 seconds of someone’s voice, I can clone their likeness and do just about anything I want with it. That is not going to end well. I don’t think the technology sector is thinking carefully enough about this. I don’t think our federal regulators are thinking enough about it. I don’t think the public is thinking enough about it. Our whole sense of reality is, at best, shaky.
All of this — generative AI and deepfakes — is on top of the mess that is already social media. Two things are colliding. There’s the ugliness, the lowest common denominator, the idiocy of what social media has been for many, many years, and now it’s being supercharged with generative AI, where anybody, not just sophisticated actors, can do real harm online.
Is there a path to a soft landing here? What combination of approaches could meaningfully address these harms?
“Soft landing” is a good way to put it. It is going to be a hard landing, but let’s see if we can soften it a little.
There is good news and bad news.
Outside the U.S. federal government, the EU, the UK, and Australia have started to think very seriously about the potential harms of generative AI. The EU AI Safety Act, for example, mandates the labeling of AI-generated content. That doesn’t mitigate all the harms, but at least we now know what we’re getting. Think of it like nutrition labels at the grocery store: I can buy barbecue potato chips, but the label tells me they’re bad for me, if I read it. We’re not telling people what to do or what’s good or bad, but we’re telling them what’s what. California has a similar law, and several other countries and U.S. states are moving in that direction. The U.S. federal government, sadly, is AWOL on this issue.
My fear with regulation is that it moves very, very slowly, and this technology does not, but at least there is an acknowledgment that this is dangerous and that we need to start thinking about it.
If you ask me where I’d put most of my efforts right now: I want smart, thoughtful, effective regulation, but I also think we need to address this through liability. We need to tell these AI companies: When you create a product that generates child abuse material, non-consensual intimate imagery, and fraud, we are going to sue you back to the Dark Ages. Because when you threaten liability and companies are staring down the barrel of hundreds of millions to billions of dollars in lawsuits, companies get smart very fast. They figure out how to put guardrails in.
I like smart, somewhat future-proof regulation. I like creating liability and putting these companies on notice. I like technological solutions, and I think we should be developing tools to help consumers, media outlets, courts, and organizations figure out what’s real and what’s fake. The last piece is public education. A lot of this will come from conversations exactly like this one. Some combination of all of that will soften the landing. The question is how fast can we move to keep pace with the technology, how much pushback will we get from Silicon Valley, and how bad is it going to get before we get there?
What detection technologies currently exist, and how effective are they?
There are two types of technologies for spotting fake content: active and reactive.
Active techniques work like this: if you go to Google’s Gemini today and generate an image or video, Google will insert an invisible digital watermark into that content, called SynthID. Adobe has their own, called TrustMark. Meta has their own as well. The idea is the same as watermarks on currency: to prevent counterfeiting. Downstream, when a news organization or law enforcement receives a piece of content, they can check for the watermark. That technology is great. It is not perfect — there are ways to attack it — but it’s really good. The problem is that bad actors aren’t using these tools, and open-source libraries can’t be compelled to comply, so it’s a partial solution, but still an effective one.
The reactive techniques are my bread and butter. Something is going on — a court case, a viral social media post, a media outlet trying to verify content — and the question is: What is this? That’s where we come in, with a battery of tests that look at geometry, physics, statistics, biometric information; a whole suite of tools we’ve developed to distinguish real from fake.
The good news is that if you give my team and me a little bit of time, we can almost always get to the bottom of it. The bad news is that we often don’t have that time. If you think about the scale of the internet, the billions of uploads, the speed at which things go viral, we’re essentially performing a postmortem. We can help the courts; there’s time in the courts. We can help a media outlet that’s willing to wait a few hours. However, I don’t know how we help the billions of people doomscrolling through social media faster than we can possibly respond.
It depends on how you think about the intervention. At scale, screening every single piece of content? That’s never going to happen. For the things that actually matter — geopolitics, politicians, evidence in courts of law, we’re pretty good at that now. A year or two from now, that’s the battle we are in.
Beyond fabricated evidence, are there other accountability concerns deepfakes raise for you?
I worry a great deal about that. In fact, I worry about something very close to that as well. It's not just that bad people can hurt people by creating a fake video or audio or image of them saying or doing something they never did. Maybe that doesn’t survive the court of law, but it absolutely will survive the court of public opinion, given the way the world works today.
Here’s the other thing I worry about: What happens when you have a real video of a president doing or saying something unbelievably inappropriate or illegal, and they get to deny it? “It’s fake, it's a deepfake.” How do we hold people accountable for the things they actually did? I will tell you, this is happening every single day. Every single day, I see this response: “It’s not me.”
Are courts and legal systems currently equipped to handle deepfake evidence?
I assume that’s a rhetorical question, because I think we both know the answer: They are not equipped for this.
Here’s one example. We recently did a study, a joint project with Sarah Barrington and Emily Cooper, where we had people listen to AI-generated voices. I would take 15 seconds of your voice and clone it. Then I’d have listeners hear the real you alongside the AI-generated version and ask: Is that the same person? Almost always, the AI version sounds exactly like you. People couldn’t tell the difference. They also could not tell that the voice was AI-generated at all. That means that not only can we generate voices that are indistinguishable in terms of identity, people don’t even know they’re listening to an AI.
Now go look at the Federal Rules of Evidence and see what’s required to introduce a voice recording into a court of law. All that’s required is for someone who knows that person to say, “I know them, and it sounds like them.” That’s insane. I recently had a conversation with folks from the Department of Justice about exactly this, and they were skeptical that the rules needed to change. I’m thinking, are you not paying attention? The rules established years ago simply cannot hold up today.
Here’s another problem: It’s not just that false evidence can be introduced. People can now also deny real evidence. We’re starting to see investigators using so-called AI enhancement to take a grainy photo of a person or a license plate and “enhance” it, the way you’d see on an old “CSI” episode. It produces a beautiful, crisp image — but it’s hallucinating details. That may not be the person’s face. You’re potentially implicating someone who was never there, because the AI is filling in details that don’t exist.
There’s a whole other dimension here. It’s not just fabricating evidence; it’s taking low-quality real evidence and trying to clean up a voice, identify a face, or read a license plate in ways that are very, very tricky and potentially very wrong. We’re studying this right now, and there are no quick answers about when AI enhancement is appropriate and when it isn’t. That’s another avenue I’m deeply concerned about.



