Can deepfake detection prove a video is real?

Can deepfake detection prove a video is real?

No. A positive deepfake-detector result cannot prove that a video is real, that the person shown made it, or that the financial claim in the video is true. It is one technical signal, usually expressed as a probability or risk assessment. It is not a certificate of identity, intent, ownership or payment.

That matters when a video asks you to send money or crypto. A clip can be genuine and still be misleading. It can show a real person saying something that has been edited out of context, or a real recording can be used by someone who is not the person shown. A detector may also miss a synthetic or altered video. Do not pay, transfer crypto, connect a wallet or share account secrets because a detector says “real”.

The safer question is not “did a tool approve this file?” It is “what independent evidence supports the claim, and what would happen if the video were wrong?”

Why a detector result creates false confidence

Automated detection tools look for signals associated with generated or manipulated media. The ICO describes examples such as mismatches between mouth movements and speech, or boundaries where original and inserted material meet. Systems may combine several tests into an overall risk score.

That score has limits. A low-risk or “likely authentic” result does not prove that no manipulation occurred. It may mean that the tool found no signal above its threshold, on that file, under those conditions. Compression, cropping, re-encoding, a new generation of synthetic media or a detector trained on different examples can affect the result.

The direction of the error matters too. A false negative can make altered media look safe. A false positive can cast doubt on a genuine recording. Neither result answers the separate questions that matter in a payment dispute:

  • Who sent or published the video?
  • Was the person shown actually involved?
  • Is the request consistent with a previously verified contact or agreement?
  • Does the claimed transaction exist on the relevant network or provider system?
  • Who controls the receiving account or crypto address?

The NCSC says tools designed to detect synthetic or inauthentic data can be ineffective and unreliable. It recommends layered defences rather than relying on one technical test. The FCA has also warned that synthetic media is becoming harder to distinguish from real content and can expose consumers and firms to new forms of fraud and deception.

Provenance is useful, but it is not a truth machine

Provenance records information about where a file came from and what happened to it. Depending on the system, that may include a creator, device, timestamp, editing history or cryptographic signature. Content Credentials and C2PA-style manifests are examples of technology intended to preserve that lineage.

This is different from proving that the content is truthful. A provenance record may show that a particular camera or account created a file. It may show that the file has passed through named editing steps. It does not necessarily show that the person or organisation behind that identity is trustworthy, that the scene was accurately described, or that the request attached to the video is legitimate.

The opposite is also important: missing provenance is not proof of fraud. A file may lose metadata when it is downloaded, edited, sent through a messaging service or converted into another format. The ICO notes that watermarking can be vulnerable to tampering and that malicious creators may not follow marking schemes. The NCSC describes Content Credentials as an emerging, still-maturing technology that can help users make informed decisions but cannot solve the problem by itself.

Treat provenance as evidence about the file’s history. Check who supplied it and whether that chain is independent of the person asking for money.

Independent verification beats visual inspection

A video is evidence of what a file presents. It is not, by itself, independent confirmation of the claim made around it. Verification should move outside the video and outside the conversation that delivered it.

For a claimed crypto payment, that could mean checking the network record yourself using the correct network and a trusted route. A transaction hash may help establish that a transaction exists, its status, the addresses involved and the amount recorded by the network. It does not prove who controls an address, why the transaction was made or that the address belongs to the person shown in a video.

For a person or organisation, use a contact route you already trust. Find the official website or a known number yourself rather than using contact details in the message. Ask the person or organisation to confirm the request through that separate channel. Do not treat a second video from the same account, or a “live” call arranged by the same stranger, as independent verification.

Urgency is relevant evidence too. A request to act immediately, keep the matter secret, pay a release fee or move funds to a new address is a reason to pause. It is not a reason to run more detector scans until one returns the answer you want.

A layered-verification checklist

Use more than one layer before acting on a video-linked financial request. No single item below proves the whole story.

  • [ ] Pause the request. Do not send crypto, pay a fee, connect a wallet or share a recovery phrase while you check the claim.
  • [ ] Keep the original file and message. Save the unedited video, the surrounding text, the sender details and the time received. A forwarded copy may have different metadata.
  • [ ] Check the source. Ask how the video reached you and whether the account, domain or profile is independently known. Do not rely on a display name or profile image.
  • [ ] Use provenance where available. Inspect Content Credentials, signatures, timestamps and edit history, but treat them as information about lineage, not a guarantee of truth.
  • [ ] Use detection as a supporting signal. Record the tool, version, file submitted and result. Read its limitations. A “real” or “low risk” result is not permission to pay.
  • [ ] Verify the person separately. Contact the person or organisation through a previously known, independently sourced channel. Do not use a link, number or address supplied in the same request.
  • [ ] Verify the financial claim separately. Check the relevant account, invoice or blockchain record yourself. Confirm the network, transaction status, amount, recipient and timing. A matching record still does not prove the identity behind an address.
  • [ ] Check the request, not just the video. Ask whether the payment purpose, destination and urgency fit the relationship or agreement. Treat secrecy and pressure as warning signs.
  • [ ] Get a second human view for a material decision. Ask someone not involved in the conversation to review the evidence. For a suspected fraud or significant loss, preserve records and use an appropriate reporting or professional-advice route.

Why a positive result is not permission to transfer crypto

Crypto transfers are usually difficult to reverse, and a video cannot give you the protections that an independently verified payment route may provide. A detector result does not confirm the recipient’s identity, recoverability of funds, legal status of an offer or control of a wallet address.

The FCA specifically warns that AI-generated videos and deepfakes can impersonate trusted figures and encourage people to invest. A convincing endorsement is still an unverified marketing claim. The fact that a detector did not flag the clip changes none of the unanswered questions about the offer or destination address.

Never share a seed phrase, private key, wallet password or one-time code to “prove” that you are checking a transaction. Those secrets can authorise access or transactions; they are not evidence that a video is genuine.

If you have already sent funds, preserve the original messages, video, addresses, transaction hashes and timestamps. Do not pay a person who promises to recover the funds in exchange for an upfront crypto payment. Use the relevant exchange or wallet provider’s official support route and report suspected fraud through the appropriate UK channels.

What deepfake detection can and cannot tell you

A detector may help prioritise a file for closer review. It can sometimes identify patterns associated with synthesis or editing. That is useful, especially when combined with provenance and human review.

It cannot establish all of the following on its own:

  • that the video is unedited;
  • that the person shown recorded or approved it;
  • that the words were spoken in the stated context;
  • that the sender controls the account or crypto address mentioned;
  • that a payment or investment opportunity is legitimate; or
  • that sending crypto is safe or reversible.

The ICO and NCSC both point towards layered approaches because authenticity is a chain of evidence, not a single green tick. When money is involved, verify the identity, request, destination and underlying record separately.

Related reading

Sources

  1. Information Commissioner’s Office, “Synthetic media and its identification and detection” — why synthetic media is becoming harder to distinguish, and the limits of provenance, watermarking and automated detection.
  2. Financial Conduct Authority, “Emerging Technology Horizon Scan 2026” — how synthetic media and deepfakes may make financial fraud and deception harder to spot.
  3. National Cyber Security Centre, “Preserving integrity in the age of generative AI” — limitations of detection tools and the case for layered defences and content provenance.

Educational information, not legal, financial, forensic or cybersecurity advice. Guidance and technology change; check the linked sources before relying on them in a live dispute.

Leave a comment