
Privacy & Surveillance · 11 min read
The Deepfake Problem Is an Institutional Failure Before It Is a Detection Problem
Synthetic media is often described as a problem of gullible audiences and ever-more-convincing fakes. That framing is incomplete. It places the burden on people to identify manipulation while overlooking the institutions
Synthetic media is often described as a problem of gullible audiences and ever-more-convincing fakes. That framing is incomplete. It places the burden on people to identify manipulation while overlooking the institutions that make manipulation cheap, rewarding, and difficult to remedy.
Generative AI changes more than the appearance of online content. It changes the economics of producing, distributing, and denying deceptive material. A persuasive fake no longer requires a specialist studio, a large budget, or even a coherent campaign organisation. It can be generated quickly, adapted to specific communities, and distributed through systems designed to reward attention. The resulting harm is not limited to someone believing one false video. It can also produce uncertainty, cynicism, reputational damage, withdrawal from public life, and a growing sense that evidence itself is negotiable.[S1] [S4]
That means practical protection cannot rest on a single promise: better detection. Detection matters, but it arrives after a system has already made harmful content profitable or viral. The more durable response is institutional: change what platforms amplify, what developers must disclose, what organisations verify before acting, and what support exists for people targeted by synthetic abuse.
The Core Risk Is Cheap, Scalable Plausibility
Generative systems can create text, images, audio, and video that resemble material made by people. They do not need an intent to deceive in order to be used for deception; the relevant intent can belong to the person deploying them. The European Parliamentary Research Service notes that generative AI can make it easier and cheaper for threat actors to automate activities including content creation, while vulnerabilities may arise across a system’s lifecycle, from biased or polluted training data to manipulated prompts and harmful outputs.[S7]
This matters because a lower production cost changes the range of actors able to participate. Manipulation no longer depends solely on well-funded political operations, governments, or professional fraud networks. A person can create material tailored to a local dispute, a workplace, a school community, or an individual target. A coordinated network can produce endless variations of the same narrative: posts, fake news sites, impersonated audio, comment replies, and visual “evidence.”
The institutional consequence is a mismatch. The creator of deceptive material may need minutes. A victim, journalist, school, employer, or platform may need days to establish what happened, preserve evidence, file a report, obtain a correction, and limit further distribution. The system effectively gives the fastest actor an advantage.
The problem is not simply that content looks realistic. It is that plausibility can be produced at industrial speed while verification remains labour-intensive. A recent scoping review of 24 empirical studies found that large language models can generate convincing misinformation, sometimes exploiting audiences’ cognitive biases and ideological leanings. The review also found that exposure to AI-generated misinformation can reduce trust and affect decision-making.[S1]
An institution that treats every suspicious item as an isolated fact-checking task will lose this race. It needs procedures that reduce the value of rapid manipulation before it spreads: authentication channels, escalation paths, preservation rules, and decisions that do not depend on instant public certainty.
Uncertainty Can Be More Damaging Than Deception
The common mental model is that a deepfake succeeds only if it convinces its audience. Research suggests a more troubling possibility: it may succeed by making people unsure whether anything can be trusted.
In an experiment with a representative UK sample, researchers found that people exposed to synthetic political video were more likely to feel uncertain than directly deceived. That uncertainty reduced trust in news on social media. The authors warned that deepfakes can contribute to generalized indeterminacy and cynicism in democratic public discourse.[S4]
This is the institutional version of the problem. A fabricated clip may fail to change anyone’s mind about a particular claim but still weaken confidence in the evidence needed to hold public figures, organisations, or abusive individuals accountable. Once synthetic media is widely plausible, a genuine recording can be dismissed as fabricated. The result is not merely misinformation; it is a contest over whether verification is possible at all.
That is why “be skeptical” is not sufficient advice. Excessive skepticism can turn into blanket disbelief. If every document, voice note, photograph, or recording is treated as potentially worthless, people lose a shared basis for making decisions. The aim should be calibrated trust: neither automatic belief nor automatic dismissal, but reliable ways to establish provenance and context when the stakes are high.
Institutions should therefore avoid designing safeguards around a binary question—“Is this fake?”—as though a single answer resolves every case. A better set of questions is: Where did this content originate? Who is accountable for the channel distributing it? Is there a reliable original? Has it been independently corroborated? What decision is being requested, and can it wait for verification?
These questions are less dramatic than a forensic verdict, but they are often more useful. A forged voice message requesting a money transfer does not need to be perfectly classified before an organisation applies its payment-verification procedure. A questionable video of a public official does not need to be conclusively disproved before a newsroom declines to frame it as established fact.
Attention Markets Create the Wrong Incentives
Synthetic media does not circulate in a vacuum. It travels through systems that reward novelty, emotional intensity, speed, and engagement. Social platforms make rapid sharing, algorithmic reach, and popularity metrics central features of their environments; these affordances can give fringe ideas and false material unusually large visibility.[S3]
Generative AI fits these incentives exceptionally well. It can create large volumes of tailored material without the time and cost constraints of conventional production. The European Parliament briefing describes generative AI as a tool that can facilitate deceptive influence campaigns that are more persuasive and harder to detect than earlier forms of manipulation.[S7]
The same pressures affect legitimate institutions. Newsrooms compete for attention and speed. Schools and employers want a quick answer when a clip causes panic. Platforms may be judged by growth and engagement more visibly than by the quality of their response to a victim. Developers may be rewarded for making systems more capable and frictionless, while the downstream cost of impersonation or abuse is borne by users and public institutions.
This does not require a conspiracy to create harm. Incentives can produce harmful results even when each participant pursues an ordinary objective: growth, efficiency, audience reach, or reduced moderation expense. The practical question is whether the cost of foreseeable harm sits with the party able to reduce it.
A platform that benefits from rapid distribution should bear meaningful responsibility for rapid reporting, clear status updates, preservation of evidence, and a fair appeal path. A developer making powerful generation tools available should not treat transparency as an optional decorative label. An organisation that can be impersonated should establish an official channel for urgent verification before a crisis occurs.
The goal is not to make every participant responsible for every fake. It is to prevent an ecosystem in which the creator’s cost is low, the distributor’s risk is limited, and the target’s burden is overwhelming.
Provenance Is More Useful Than a Universal “AI Detector”
There is understandable demand for a tool that can identify every synthetic image, video, audio clip, or text. But the available evidence points away from treating detection as a complete solution. Generative AI and deceptive tactics evolve together; standards and technical methods can help, but they operate within changing platforms, files, formats, and adversarial behaviour.
The more promising institutional goal is provenance: preserving and communicating information about where material came from, how it was created, and whether it was altered. The European Parliament briefing notes the role of labeling, watermarking, and provenance signals in commitments by pan-European political parties to identify AI-generated content and avoid deceptive material during elections.[S7] The AI Act’s transparency approach also reflects the importance of informing people when they are interacting with AI or encountering certain AI-generated or manipulated content.[S6]
Provenance is not magic. Metadata can be removed, labels can be absent, and bad actors will not reliably cooperate. Yet a provenance system need not prove that every unmarked item is false. Its value is positive rather than universal: it gives trustworthy publishers, institutions, and creators a way to show readers what they can stand behind.
That distinction matters. A detector makes a negative claim: this file appears manipulated. Provenance supports a positive claim: this material came from an identified source, passed through a documented process, and has an accountable publisher. In high-stakes settings, that positive chain can be more actionable.
News organisations can preserve original files and document editorial handling. Public bodies can publish important announcements through stable, verifiable channels rather than relying on screenshots or reposted clips. Companies can establish authenticated communication methods for payment requests and executive instructions. Schools can publish clear procedures for assessing alleged student-created synthetic material, including an opportunity for the accused person to respond.
The point is not to demand perfect proof from ordinary people. It is to create stronger defaults where the consequences of error are serious.
Institutions Need Response Systems, Not Just Policies
A written policy that says “we take misinformation seriously” is not a safeguard. A useful system specifies who acts, how quickly, with what evidence, and what happens while facts remain uncertain.
For platforms, a practical response system should include a distinct route for impersonation, non-consensual intimate imagery, fraud, election-related deception, and threats to physical safety. These reports should not disappear into the same generic queue as ordinary content complaints. The person reporting needs an acknowledgement, an explanation of the next step, a way to supply supporting material, and an accessible appeal process if the first decision is wrong.
For employers, schools, publishers, and community organisations, the most important safeguard may be procedural restraint. Do not discipline, dismiss, publicly accuse, pay money, or make a major operational decision because of a clip alone. Preserve the original material where lawful, record when and where it was received, identify the claimed source, seek direct confirmation through a known channel, and allow affected people to respond before drawing conclusions.
This approach recognises an uncomfortable reality: institutions can amplify harm even when they are not the original source. A school that circulates an alleged fake image widely while investigating it may expose the target to further humiliation. An employer that announces an allegation before verification can make later correction ineffective. A newsroom that shares a clip merely to debunk it may still extend its reach.
Synthetic abuse also has a human dimension that institutional procedures often ignore. Accounts of deepfake harm describe anxiety, loss of control, reputational damage, and withdrawal from online spaces; the available material particularly emphasizes the risks to people targeted by non-consensual and identity-based manipulation.[S5] These accounts should not be treated as a reason for panic, but they are a reason to design response systems around dignity.
Victim-centred safeguards include limiting unnecessary re-sharing, offering a single case contact, explaining available options in plain language, preserving evidence without demanding repeated retelling, and separating the target’s credibility from the technical certainty available at the start of an investigation.
Regulation Should Create Accountability, Not a False Sense of Closure
The EU AI Act is an important institutional development because it makes transparency and responsibility part of the governance conversation rather than leaving them entirely to voluntary practice. The Act entered into force in August 2024, and its framework distinguishes different levels of risk while establishing obligations relevant to providers and professional deployers.[S6]
But regulation is not self-executing. Rules matter only if the institutions covered by them understand their duties, build operational capacity, and face meaningful consequences when they do not comply. The European Parliament briefing places the AI Act alongside the Digital Services Act, the European Media Freedom Act, and measures addressing violence against women, reflecting the fact that information integrity is not one isolated technical problem.[S7]
This broader approach is necessary. The harms associated with synthetic media cut across consumer protection, privacy, platform governance, gender-based abuse, election integrity, media independence, and cybersecurity. No single regulator, company team, or technical standard can address all of them.
The risk is that legal compliance becomes a substitute for genuine responsibility. A tiny disclosure buried in a caption may technically label AI-generated material while doing little to prevent deception. A platform may adopt a policy without adequately staffing enforcement. A developer may publish safety principles without providing meaningful mechanisms for targets of impersonation or abuse.
Good governance asks more demanding questions. Can a user understand the label at the moment it matters? Can a victim obtain a timely response? Are professional users trained to challenge suspicious material? Is there an audit trail for serious decisions? Are public claims about detection or moderation independently testable?
Transparency is a necessary condition for accountability. It is not accountability itself.
What Individuals Can Do Without Becoming Full-Time Investigators
The institutional perspective does not absolve individuals of all responsibility. It does, however, reject the idea that every person must become a forensic analyst.
A practical personal rule is to verify before amplifying, especially when content demands an immediate emotional response or asks for money, outrage, fear, or punishment. Look for the original source rather than relying on a repost. Check whether a credible institution has published the information through its own established channels. Treat unexpected voice messages, video calls, and urgent requests as prompts to use an independent verification method.
For creators and public-facing professionals, it is sensible to establish official channels in advance: a verified website, a known public account, a consistent method for announcements, and a clear warning that sensitive requests will be confirmed through a second channel. These practices cannot eliminate impersonation, but they reduce ambiguity when an incident occurs.
For parents, educators, and community leaders, media literacy should mean more than teaching people to spot visual glitches. The evidence suggests that uncertainty and declining trust are central risks.[S4] The healthier lesson is not “nothing is real online.” It is “important claims deserve a process.” People should learn how to pause, corroborate, ask who benefits, and distinguish a striking item of content from evidence that has been independently verified.
This is slower than sharing. That is precisely why it is protective.
Conclusion
Synthetic media is not only a test of whether people can identify a fake. It is a test of whether institutions can build systems that make deception less rewarding and verification easier.
The available evidence shows that generative AI can lower the cost of persuasive misinformation, enable manipulation at scale, affect trust, and deepen uncertainty even when people are not directly deceived.[S1] [S4] [S7] The answer cannot be a permanent state of suspicion, nor an unrealistic faith in universal detection.
The more practical path is to distribute responsibility toward the institutions with the power to reduce harm: developers that create the tools, platforms that distribute material, organisations that act on contested evidence, regulators that set enforceable standards, and publishers that can model accountable provenance.
Detection should improve. Labels should be clearer. Laws should be enforced. But the deeper safeguard is institutional discipline: verify before acting, preserve provenance, protect targets from repeated exposure, and refuse to let speed determine what counts as truth.
Sources and Further Reading
- Springer — S00146 025 02620 3
- Journals Sagepub — 2056305120903408
- Europarl Europa — EPRS BRI(2025)779259 EN
- Stimson — Ai In The Age Of Fake Imagined Content
- Cjel Law Columbia — Deepfake Deep Trouble The European Ai Act And The Fight Against Ai Generated Misinformation
- Duckduckgoose — Psychological Impacts Of Deepfakes