EICTA, IIT Kanpur

AI Deepfake: How AI Creates Synthetic Media and What the Risks Are (2026)

EICTA Content Team26 August 2026

A deepfake is AI-generated synthetic media that convincingly replicates a real person's voice, face, or both in ways designed to be indistinguishable from authentic recordings. The technology uses deep learning models trained on real media to generate new content that preserves the original person's appearance, voice, and mannerisms while making them appear to say or do things they never said or did.

The word deepfake combines deep learning with “fake.” The term originated in 2017 on online forums where users began using AI to superimpose faces in videos. By 2026, the technology has evolved from a research curiosity to an accessible tool that anyone can use without technical skills: a convincing voice clone can be created from as little as three seconds of audio, and deepfake video can be produced in under an hour using freely available tools that cost a few dollars per campaign.

Industry experts are calling 2026 the year of impersonation attacks. Accessible AI tools have given threat actors significant new capabilities to create and scale synthetic media for fraud, manipulation, and misinformation at a pace that has outrun most detection and regulatory frameworks.

Best CTO Online Course in India: Enroll Now!

What This Guide Covers

  • How AI creates deepfakes, the specific technologies involved
  • The difference between video, audio, and image deepfakes
  • Real-world risks: fraud, disinformation, and reputational attacks
  • Legitimate and creative uses of synthetic media
  • How to detect deepfakes with current tools
  • Laws and regulations governing deepfakes in 2026
  • How to protect yourself and your organisation

How AI Creates Deepfakes: The Technology Explained

Deepfakes are produced by training AI models on large quantities of real media featuring a specific person, then using those models to generate new synthetic content that faithfully replicates that person's appearance and voice. The two primary technologies are Generative Adversarial Networks (GANs) and diffusion models.

Generative Adversarial Networks (GANs)

The original deepfake technology uses two neural networks competing against each other. The generator creates synthetic images or video frames attempting to replicate the target person. The discriminator evaluates whether each output looks real or fake. The generator learns from the discriminator's feedback and continuously improves until its output is convincing enough to fool both the discriminator and human viewers.

This adversarial training process is why early deepfakes improved so rapidly: the generator was effectively learning to deceive, with the discriminator providing constant feedback on how to do it better.

Diffusion Models

The more recent and more capable technology behind most 2026 deepfakes is diffusion-based generation. Diffusion models learn to generate images by starting with random noise and progressively refining it toward a realistic output. They are harder to detect than GAN-generated content because they do not share the specific visual artefacts that GAN outputs often leave, and they produce higher-quality, more photorealistic results.

Models including Stable Diffusion, DALL-E, and Midjourney are diffusion-based image generators. Video generation models including Sora and Kling use similar architectures applied to video sequences.

The Deepfake Creation Process

Regardless of the specific technology, the deepfake creation process follows a consistent sequence.

Data collection: The AI model requires training data: photographs, video recordings, and audio samples of the target person. Public figures, politicians, executives, and celebrities are at elevated risk because vast quantities of their media are publicly available online. For voice cloning specifically, as little as three seconds of clear audio provides enough data for current AI models.

Model training: The AI learns the target person's facial geometry, micro-expressions, voice patterns, speech rhythms, and mannerisms from the collected data. Advanced systems model head movement, eye blink patterns, and emotional expression in addition to basic facial features.

Content generation: Using the trained model, the system generates new synthetic content. For video, this means placing the target's face and voice onto a different body or making them appear to say words they never spoke. For audio, it means generating entirely new speech in the target's voice. For images, it means creating photographs of situations that never occurred.

Post-processing: Generated content is refined to remove obvious artefacts, improve lip synchronisation, match lighting conditions, and improve audio quality. Professional deepfake production includes colour grading, motion blur adjustment, and compression optimisation to make the final output as difficult to detect as possible.

Types of Deepfakes: Video, Audio, and Image

Video Deepfakes

The most widely recognised form. Video deepfakes replace one person's face with another's in existing footage, or generate entirely new video of a person. Face-swapping deepfakes are used to put a public figure's face onto someone else's body. Lip-sync deepfakes make a real person appear to say words they never spoke by generating new mouth movements matched to fabricated audio.

The most dangerous video deepfakes in 2026 are real-time: technology now exists to generate live deepfake video in a video call, making the impersonation impossible to detect through normal call security instincts.

Voice Cloning and Audio Deepfakes

Voice cloning replicates a specific person's voice and uses it to generate arbitrary speech. Three seconds of audio is sufficient for current models to generate convincing voice replications. The cloned voice maintains the target's accent, speech patterns, emotional tone, and characteristic vocabulary.

Voice deepfakes are the most commonly used form in financial fraud. Attackers clone a CEO's voice and call a finance employee to request an urgent wire transfer. The employee hears what sounds convincingly like their boss, and the psychological pressure of an urgent request from leadership bypasses their scepticism. These “vishing” (voice phishing) attacks using AI-cloned voices have caused documented losses in the tens of millions of dollars at multiple large organisations.

Image Deepfakes

AI-generated images of people in situations that never occurred. This includes face-swapping in photographs, AI-generated photographs of real people, and synthetic images of events that did not happen. Non-consensual intimate images, placing a real person's face onto explicit content, represent one of the most harmful applications and are now subject to specific legislation in multiple jurisdictions.

The Real-World Risks of Deepfakes in 2026

Financial Fraud and Business Email Compromise

Deepfake technology has become a primary tool in sophisticated financial fraud . In 2024, a finance employee at a multinational company in Hong Kong was deceived into transferring $25 million after attending a video call where every other participant, including the company's CFO, was a deepfake. The employee saw and heard who he believed to be real colleagues authorising a transaction. The entire call was synthetic.

This attack pattern is now documented across multiple industries. Attackers study a target organisation, identify who has authority to approve transactions, gather public media of those individuals, generate convincing deepfakes, and conduct fraudulent video or voice interactions that authorise financial transfers.

Executive Impersonation and Reputational Attacks

A deepfake video of a CEO making controversial statements, announcing false information, or appearing to engage in inappropriate behaviour can cause significant stock price movement, customer damage, and regulatory scrutiny before the fraud is identified and the video debunked. By the time a correction reaches the people who saw the original, the reputational and financial damage is often already done.

Political Disinformation

Deepfake videos of political figures making statements they never made have been used in electoral contexts across multiple countries. The goal is not necessarily permanent deception: a deepfake released close to an election may be shared widely enough to influence voters before fact-checkers confirm it is fake. The asymmetry between how quickly false information spreads and how slowly corrections reach the same audiences is what makes deepfakes effective as disinformation tools.

Non-Consensual Intimate Images

AI makes it possible to generate intimate images of specific real individuals without their consent, using only publicly available photographs. The harm to victims is severe and documented: the content spreads rapidly and is extremely difficult to remove from the internet. This application of deepfake technology is the most frequently legislated against and has been the primary driver of specific deepfake laws in multiple countries.

Identity Fraud and KYC Bypass

Synthetic media is being used to bypass Know Your Customer identity verification processes. AI-generated faces that match a stolen identity document, or real-time deepfake video that defeats liveness detection checks in video-based KYC, allow fraudsters to open financial accounts, access services, and conduct transactions using synthetic identities.

Legitimate and Creative Uses of Synthetic Media

Deepfake technology is not inherently malicious. The same techniques that enable fraud and disinformation have significant legitimate applications.

Entertainment and film production: Visual effects studios use synthetic media to de-age actors, digitally recreate deceased performers for completion of existing projects with estate consent, dub films into other languages with lip synchronisation, and reduce the cost of certain types of production work. These applications are disclosed, consented to, and serve creative rather than deceptive purposes.

Education and training: Synthetic media creates historical educational content where original footage does not exist, enables personalised learning experiences with synthetic instructors, and produces training simulations for medical, military, and emergency response education.

Accessibility: Voice synthesis powered by the same technology as voice cloning provides accessible text-to-speech for people with visual impairments or reading difficulties, and enables people who have lost their voices to communicate using a synthetic version of their original voice.

Localisation and translation: Video dubbing using AI-generated lip synchronisation makes content more accessible across languages without requiring reshooting or the visual mismatch of standard dubbing.

Marketing and virtual influencers: Brands use AI-generated synthetic personas for marketing campaigns. These applications are legally and ethically distinct from using a real person's likeness without consent, but require clear disclosure when synthetic media is used in commercial contexts.

The key ethical and legal distinction across all applications is consent and disclosure. Synthetic media of a real person created and used with their knowledge and consent for disclosed purposes is fundamentally different from synthetic media used to deceive, defraud, or harm.

Also read: Addressing Ethical Concerns in AI-Driven Decision Making

How to Detect Deepfakes

Detection technology has improved significantly in 2026 but remains imperfect. The challenge is that detection tools and generation tools are in a continuous arms race: each improvement in detection prompts corresponding improvements in generation quality to evade the new detectors.

Visual and Behavioural Indicators

Human detection of deepfake video is unreliable but awareness of specific artefacts helps. Unnatural blinking patterns, too frequent, too infrequent, or poorly timed, are a common GAN deepfake indicator. Other signs include facial boundary inconsistencies where the synthetic face meets the original neck or hairline, inconsistent lighting between the face and background, unnatural skin texture that appears too smooth or inconsistently detailed, and subtle but detectable mismatch between facial expressions and emotional context.

Audio deepfakes sometimes produce unnatural breathing patterns, slight metallic or robotic qualities in long speech sequences, and vocabulary or speech rhythm inconsistencies when the source audio was limited.

These visual indicators are becoming less reliable as generation technology improves. Many professional deepfakes in 2026 are visually indistinguishable from authentic media to the human eye under normal viewing conditions.

Also read: Top Challenges in Artificial Intelligence in 2026

AI-Powered Detection Tools

Dedicated deepfake detection platforms use AI to analyse media for the statistical signatures left by generative models. Tools including Sensity AI, Reality Defender, and Microsoft's Video Authenticator analyse frame-by-frame inconsistencies, compression artefact patterns, and generative model fingerprints.

These tools are most effective when analysing original quality files rather than compressed versions that have been shared across social platforms, because compression removes the subtle artefacts that detectors look for.

Provenance and Authentication

Content provenance standards including C2PA (Coalition for Content Provenance and Authenticity) embed cryptographic metadata into media files at creation, allowing subsequent verification of where, when, and how content was created. Media created by participating cameras, software, and platforms carries a verifiable provenance record. Media with no provenance record, or a broken provenance chain, cannot be automatically authenticated.

This approach does not detect whether specific media is authentic. It certifies whether specific media was created through an authenticated process.

Deepfake Laws and Regulations in 2026

European Union: EU AI Act Article 50

The EU AI Act's Article 50 became enforceable on August 2, 2026, requiring mandatory labelling of AI-generated content. Organisations that deploy AI systems generating synthetic media must clearly disclose that the content is AI-generated. Non-compliance carries fines of up to €35 million or 7 percent of global annual turnover, whichever is higher. This is the most comprehensive deepfake-specific regulation currently in force globally.

Also read: AI Governance Platforms for Ethical and Transparent AI Implementation

United States: TAKE IT DOWN Act

The TAKE IT DOWN Act, effective May 19, 2026, criminalises the knowing publication and certain threats to publish intimate visual depictions and digital forgeries of identifiable individuals. This is the first US federal law dealing specifically with synthetic media. It focuses primarily on non-consensual intimate imagery rather than business fraud applications. 47 US states have additional deepfake-specific laws creating a complex patchwork of state-level compliance requirements.

Pending federal legislation including the NO FAKES Act aims to address unauthorised digital replicas of a person's name, image, likeness, and voice more broadly, with a private right of action for individuals whose likeness is used without consent.

India: IT Rules and Legal Gaps

India does not yet have a specific deepfake law. Existing legal provisions including Section 66E of the IT Act (privacy violation), Section 499 of the Indian Penal Code (defamation), and Section 66D (identity fraud) apply to harmful deepfake applications but were not written with synthetic AI media in mind.

The Rashmika Mandanna deepfake incident in late 2023, where a deepfake video of the Indian actress circulated widely, prompted the Ministry of Electronics and Information Technology to issue an advisory directing social media platforms to remove deepfake content and underscored the need for specific legislation. The IT Rules 2021 have been subsequently amended to include provisions on synthetic media disclosure and removal, though comprehensive deepfake-specific legislation remains pending.

India's DPDP Act 2023 has implications for deepfake creation: generating synthetic media using another person's images or voice data without consent may constitute unauthorised processing of personal data under the Act.

How to Protect Yourself and Your Organisation

Personal Protection

Limit the public availability of your voice and face. This does not mean avoiding all online presence, but being intentional about what media you share publicly and where. High-quality audio recordings shared publicly provide training data for voice cloning.

Establish verbal verification protocols with close contacts for unusual financial requests or urgent instructions. If you receive a call, voice message, or video call requesting something atypical, verify through a separate, established channel before acting.

The most important protection principle from Adaptive Security's 2026 deepfake guide: the authenticity of content is secondary to the legitimacy of the process through which a request is made. An urgent financial request from your CEO's genuine voice is still suspicious if the request process bypasses normal approval channels. Focus on process legitimacy, not content authenticity.

Organisational Protection

Establish an AI media policy covering the creation, procurement, disclosure, and internal use of synthetic media and digital replicas. Define what is permitted, what requires approval, and what is prohibited.

Implement out-of-band verification for high-value decisions. Any request to transfer funds, share credentials, or take consequential action should require verification through a pre-established secondary channel, regardless of how convincingly the requestor is identified through the primary channel.

Train employees to recognise deepfake attack patterns, not just deepfake visual artefacts. The most effective protection against deepfake-enabled fraud is an organisational culture where unusual requests trigger process verification rather than immediate compliance, regardless of who appears to be making the request.

Deploy AI-powered deepfake detection at media ingest points: email gateways, video call platforms, and content management systems can flag synthetic media before it reaches employees.

Establish media authentication requirements for high-stakes contexts: board meetings, executive communications, and investor interactions should use platforms with verified participant identity.

Deepfakes in India: Specific Context and Risks

India's deepfake threat landscape has several specific dimensions.

Political deepfakes: India's 2024 general election saw documented use of AI-generated videos and audio featuring political leaders. The Election Commission of India issued guidelines on synthetic media in political advertising, requiring disclosure when AI-generated content is used in campaign materials.

Entertainment industry targeting: Several Indian celebrities including Rashmika Mandanna, Priyanka Chopra, and Sachin Tendulkar have been targets of non-consensual deepfake content. The high public profile of Bollywood celebrities and cricketers, combined with extensive publicly available media, makes them prime targets for synthetic media creation.

Financial fraud via voice cloning: Indian financial institutions and businesses are experiencing vishing attacks using AI-cloned voices of executives and clients. The combination of widely available voice samples from corporate earnings calls, media interviews, and social media, with the ease of current voice cloning tools, has made executive voice impersonation practical for financially motivated attackers.

KYC bypass: India's digital financial services sector relies heavily on video-based KYC for account opening and financial onboarding. Deepfake-enabled KYC bypass is a documented and growing threat to banks, NBFCs, and payment platforms operating under RBI's digital KYC guidelines.

Related AI Articles

Frequently Asked Questions

What is a deepfake and how is it created?

A deepfake is AI-generated synthetic media that replicates a real person's face, voice, or both convincingly enough to appear authentic. It is created by training deep learning models on real media of the target person, then using those models to generate new content showing the person saying or doing things they never said or did. The primary technologies are Generative Adversarial Networks (GANs), where two competing neural networks refine output until it is convincing, and diffusion models, which generate realistic content by progressively refining random noise. A convincing voice clone now requires as little as three seconds of source audio.

What are the biggest risks of deepfakes in 2026?

The four primary risk categories are financial fraud, using AI-cloned executive voices and video to authorise fraudulent transactions, with documented individual incidents causing losses in the tens of millions of dollars; political disinformation, using synthetic videos of public figures making false statements to influence elections and public opinion; non-consensual intimate imagery, using real people's images without consent and causing severe personal harm; and identity fraud, using synthetic media to bypass KYC and biometric identity verification to open accounts and conduct fraudulent transactions.

How can you tell if a video or audio is a deepfake?

Visual indicators in video include unnatural blinking, inconsistencies at the boundary between a synthetic face and the original body, lighting mismatches, and skin texture anomalies. Audio deepfakes sometimes produce subtle mechanical quality in extended speech. However, many professional deepfakes in 2026 are indistinguishable from authentic media under normal viewing conditions. AI-powered detection tools from platforms including Sensity AI and Reality Defender provide more reliable detection than human visual inspection, particularly when analysing original rather than compressed files. Content provenance standards including C2PA provide cryptographic verification of media origin for content created on participating platforms.

What laws regulate deepfakes in 2026?

The EU AI Act Article 50, enforceable from August 2, 2026, requires mandatory labelling of AI-generated content with fines up to €35 million. The US TAKE IT DOWN Act, effective May 2026, criminalises non-consensual intimate deepfakes at the federal level, with 47 US states having additional deepfake-specific laws. India does not yet have specific deepfake legislation but existing IT Act provisions on privacy, defamation, and identity fraud apply to harmful deepfake use cases. The DPDP Act 2023 may apply to deepfake creation using personal data without consent. India's Ministry of Electronics and IT has issued advisories requiring social media platforms to remove deepfake content.

How can organisations protect themselves from deepfake fraud?

The most effective organisational protection is process-based rather than content-detection-based. Establish out-of-band verification protocols for all high-value financial requests: any request to transfer funds, share credentials, or take consequential action should require verification through a pre-established secondary channel regardless of how convincingly the requestor is identified. Train employees that process legitimacy matters more than content authenticity: a request that bypasses normal approval procedures is suspicious even when the voice or face appears genuine. Implement AI-powered deepfake detection at media ingest points, establish an AI media policy defining acceptable synthetic media use, and require verified identity channels for board-level and executive communications.

Customer Support

Subscribe for expert insights and updates on the latest in emerging tech, directly from the thought leaders at EICTA consortium.