Deepfakes: analysis, real impact and major challenges

Last update: January 4, 2026
  • Deepfakes are AI-generated audiovisual content that threatens privacy, reputation, and public trust.
  • Its impact ranges from harassment and non-consensual pornography to corporate fraud and political manipulation.
  • The Spanish and European legal framework already offers tools to prosecute harmful uses, although technology is advancing very rapidly.
  • Defense requires combining technical detection, organizational protocols, and training in critical thinking and cybersecurity.

deepfakes: analysis, impact, and challenges

Deepfakes have gone from being an internet curiosity to one of the most serious challenges of the digital age. Videos, audio, and images manipulated using artificial intelligence can make us see someone say or do something that never happened, with a realism that, in many cases, fools even expert eyes. And this doesn't just affect celebrities or politicians: anyone with a social media presence can become a target.

This phenomenon combines three very dangerous ingredients: powerful technology, ease of use, and enormous reach . The result is a perfect recipe for disinformation, financial fraud, harassment, and a widespread erosion of trust in what we see and hear. Let's break down, calmly and in detail, exactly what deepfakes are, how they are created, what risks they pose to individuals, companies, and institutions, what the law says, and what real steps we can take to defend ourselves.

what is generative artificial intelligence
Related articles:
All about Generative Artificial Intelligence: how it works, uses, and risks

What are deepfakes and why do they matter?

The term deepfake comes from the combination of deep learning and fake . It refers to any audiovisual content—video, image, or audio—generated or manipulated by generative artificial intelligence algorithms to appear authentic. We're not talking about mere filters or retouching, but complete reconstructions of faces, gestures, or voices that very accurately imitate a real person.

With readily available, even free, tools, it's possible to superimpose someone's face onto another person's body, clone their voice, or recreate scenes that never happened . Advances in neural networks and GANs (generative adversarial networks) have dramatically increased the level of realism, making it much harder to distinguish between genuine and manipulated content.

Deepfakes are now considered an evolution of fake news : while previously text or photos were manipulated, now a fake video or credible audio recording is generated that has a much greater emotional and cognitive impact. Our brains tend to trust what they "see and hear" more than a simple headline, which multiplies their persuasive power.

Although this technology has existed since the late 90s, it rose to prominence in 2017 when a Reddit user began posting fake pornographic content featuring the faces of well-known actresses. Since then, its use has spread enormously, both in entertainment and in clearly malicious contexts.

How deepfakes are created: the technical side without technical jargon

Behind a deepfake are machine learning systems that analyze thousands of images, frames, or audio snippets . The typical process with faces follows two main steps: encoding and decoding. First, an encoding algorithm studies the similarities between two faces and extracts a set of common features. Then, a decoder reconstructs the target image using the other person's expressions.

In practice, two separate decoders are trained, one for each face. When data from one person is fed into the decoder of the other , we obtain a video in which subject A appears to perform the gestures and movements of subject B. If done correctly, the result looks like an original recording.

Another common technique is the use of generative adversarial networks (GANs) . This involves two networks: a generator, which creates fake images or video clips, and a discriminator, which attempts to distinguish the fake from the real. They compete against each other thousands of times, continuously improving until the discriminator can no longer easily detect the deception and the result closely approximates reality.

Most video deepfakes are created by feeding the algorithm large sets of images of the person being imitated . The more angles, gestures, and lighting conditions the model has, the more convincing the final result will be. Traditionally, therefore, the victims tended to be people with high media exposure, although today a single photo or a few seconds of voice recordings are enough to generate a decent clone.

In the case of voice, cloning systems allow, from just a few seconds of recording, the reproduction of timbre, accent, and speech rhythm . By combining speech synthesis with AI-generated scripts, it is possible to produce audio in which the victim "says" anything the attacker wants to put in their mouth.

Types of deepfakes: image, video, and voice

Within the umbrella of deepfakes, we can distinguish several types, depending on the kind of content manipulated and the technique used. Two categories have become especially popular: deepfaces and deepvoices.

Deepfaces are videos where a person's face is generated or completely replaced . Using multiple photographs, the system creates static faces so realistic they appear to be real portraits, and then links them together in sequence to create a smooth video. The goal is that, upon viewing, no one would suspect they are looking at an artificial composite.

Meanwhile, deepvoices focus on voice impersonation . The algorithm learns a person's vocal characteristics (frequency, intonation, pauses, filler words, etc.) and can then read any text, passing it off as that person. This type of deepfake is especially dangerous in the corporate and financial sectors.

A prime example occurred in 2019: cybercriminals cloned a CEO's voice to call a senior executive at his company and order an urgent transfer of over $250.000. The executive complied because the voice sounded exactly like his superior's, and the sense of urgency was believable.

  Machine Learning: Most common myths

Beyond these two categories, there are also hybrid deepfakes that combine AI-generated video, audio, and text , so that all the content—what you see and what you hear—is synthetic but coherent. As the technology matures, the lines between these types are blurring.

Legitimate uses and positive applications

Although we often associate deepfakes with scams and cyberbullying, the same technology has entirely legitimate and valuable applications when used transparently and with consent. In the film industry, for example, it's used to de-age actors, recreate deceased characters, or dub dialogue without losing lip-sync.

In the educational field, generative models allow audiovisual content to be adapted to multiple languages ​​while preserving the speaker's original gestures. This improves comprehension, avoids the feeling of "low-budget dubbing," and facilitates global accessibility for courses and conferences.

Accessibility applications are also being explored, such as creating avatars that interpret sign language in a personalized way, or custom-made synthetic voices for people who cannot speak. With the right ethical approach, the same technology that worries us today can open important doors for digital inclusion.

The biggest challenge isn't so much the tool itself, but rather the context, purpose, and transparency with which it's used. That's why recent European regulations emphasize the obligation to clearly label AI-generated content so the public can distinguish between different types.

Risks and threats of deepfakes to society

The negative impact of deepfakes ranges from an individual's private life to political, economic, and social stability . One of the most obvious dangers is disinformation: fake videos showing political leaders making inflammatory statements or admitting to crimes that never happened.

Even if they are later refuted, the damage is already done, because the emotional impact of the first viewing often outweighs any subsequent correction . This contributes to polarizing public opinion, fueling conspiracy theories, and weakening trust in the media and democratic institutions.

Another extremely serious risk is the use of deepfakes for harassment, defamation, and privacy violations . The creation of fake pornography using the faces of women—especially politicians, activists, and journalists—has become a form of digital violence with devastating consequences for their reputation, personal lives, and mental health.

Recent studies indicate that around 2,2% of people surveyed in certain academic works identify themselves as victims of intimate deepfakes, while 1,8% admit to having created or distributed this type of content. Although these figures may seem low, they reflect a worrying and growing trend.

Furthermore, deepfakes contribute to a “crisis of truth” : if any audiovisual evidence can be fabricated, society risks assuming that nothing is entirely credible. This is perhaps the most dangerous long-term impact, because it erodes the basic trust necessary for digital coexistence and informed public debate.

Impact on fraud and corporate cybersecurity

In the business world, deepfakes are becoming a highly effective attack tool for cybercriminals. This isn't science fiction: there are already numerous cases of executives being impersonated using video or audio to order transfers, request sensitive data, or give false strategic instructions.

One of the most common scenarios involves [ unclear - possibly "email address" or "phone number"]. In addition to the classic fraudulent email, the attacker includes a deepfake video or audio recording of the CEO or CFO, reinforcing the urgency of the request. Upon seeing or hearing their "boss," the victim lowers their guard and carries out the order.

Deepfakes are also used in advanced social engineering . For example, a seemingly routine video is sent to a law firm in which a partner demands the urgent signing of contracts or access to certain documents. The context is plausible, the image and voice match, and the verification system relies solely on facial recognition.

In increasingly common remote work environments, attackers infiltrate video calls by impersonating team members . Using AI-generated avatars, they participate in meetings, request access to internal systems, or pressure for confidential information. The impersonation can go unnoticed if the behavior doesn't seem too unusual.

All of this poses a direct challenge to security systems based on facial or voice recognition. Recent studies indicate that small adjustments to shadows, intelligent blurring, or adversary noise can drastically reduce the effectiveness of biometric detectors, allowing a fake face to bypass access control.

Detection challenges: why antivirus software alone is not enough

Detecting deepfakes isn't as simple as installing software and forgetting about it. Current detection models face a key problem: their generalizability is limited . They are typically trained using specific manipulation techniques and styles, and when a new generation algorithm emerges, they lose effectiveness.

Furthermore, attackers can introduce adversarial disturbances specifically designed to deceive detectors . That is, they add noise imperceptible to the human eye, but which confuses forensic systems and allows the manipulated content to pass through filters as if it were authentic.

Added to this is the challenge of scalability. Platforms and social networks receive enormous amounts of video and audio every day , making in-depth analysis of each piece virtually impossible. Many are forced to resort to sampling, superficial analysis, or automated systems that sometimes fail.

Therefore, there is currently no "silver bullet" against deepfakes. Defense requires a combination of techniques : metadata analysis, examination of visual or audio artifacts, neural networks trained to detect subtle patterns, and, very importantly, user training and critical thinking.

  How to use Artificial Intelligence without an account or registration

The very advancement of AI necessitates the continuous updating of detection models . Each new generation of generative tools requires the review and retraining of defensive systems, creating a perpetual cat-and-mouse game between attackers and defenders.

Legal framework: how Spain and the European Union are responding

From a legal standpoint, deepfakes are not always considered a specific crime, but their harmful use falls under several existing criminal offenses and regulations . In Spain, the Penal Code offers various forms of protection against impersonation and privacy violations.

Article 197 et seq. protect the right to privacy and one's own image, penalizing the obtaining, use, or dissemination of intimate images or recordings without consent , even if they have been digitally manipulated. A sexual deepfake disseminated without permission can be considered a crime against privacy.

Article 401 criminalizes identity theft , which can be applied when a deepfake is used to impersonate another person, for example, to deceive third parties or commit fraud. Articles 208-210 regulate defamation and slander, applicable if the false content seriously damages the honor or reputation of the victim.

Articles 248 and 249, relating to fraud, cover cases in which altered voices or faces are used to obtain an illicit financial gain . In these cases, deepfake technology is the means employed to commit the crime, although it is not classified as a separate offense.

In parallel, Organic Law 3/2018 (LOPDGDD) and the General Data Protection Regulation (GDPR) protect personal data, including biometric data such as face and voice. Using someone's image or voice in a deepfake without their consent can constitute a serious data protection infringement, with administrative penalties and potential civil or criminal liability.

Organic Law 1/1982, on the right to honor, privacy and one's own image, allows the victim to file a civil lawsuit against whoever disseminates a deepfake that violates their dignity or reputation , requesting removal of the content, compensation for damages and urgent precautionary measures to stop its dissemination.

At the European level, the AI ​​Act (EU Artificial Intelligence Regulation) will require that AI-generated content, including deepfakes, be clearly identified as such. Meanwhile, the Digital Services Act (DSA) obliges digital platforms and services to react quickly to content that is false, defamatory, or violates fundamental rights.

Furthermore, some governments—including Spain's—have begun to more specifically define crimes related to sexual deepfakes and grooming, strengthening criminal protection against non-consensual pornography generated with AI and the abuse of minors through audiovisual manipulation.

Specific risks for children, women and vulnerable groups

Deepfakes do not affect everyone equally. Data suggests that women, minors, and certain public groups bear a disproportionate share of the impact, especially regarding intimate content shared without consent.

Recent reports indicate that a significant portion of the deepfakes identified online are pornographic and target women, many of them public figures. This translates into campaigns of harassment, blackmail, and defamation, with a strong component of digital gender-based violence.

Some studies and reports estimate that one in five young people in Spain report having had some kind of experience related to deepfakes during childhood or adolescence, whether as a direct victim, bystander, or participant. This early exposure increases the risk of normalizing harassment and sextortion practices.

For criminology and the judicial system, deepfakes pose an additional headache: they could be presented as "evidence" in legal proceedings , making it difficult for judges, prosecutors, and experts to determine the authenticity of the materials.

The situation also raises serious problems in the area of ​​personal security and public cybersecurity, since face or voice-based access control biometrics could become increasingly unreliable if robust mechanisms for detecting synthetic content are not developed in parallel.

Crisis of confidence and large-scale social consequences

Beyond the individual harm, the proliferation of deepfakes contributes to a climate of widespread distrust in digital information . If any video or audio can be fake, the idea takes hold that "nothing is safe," and ultimately, many people stop trying to distinguish between what is real and what is manipulated.

This information fatigue is especially dangerous because it paves the way for disinformation campaigns and mass manipulation . Disinformation attacks that combine fake news with audiovisual deepfakes can influence elections, referendums, investment decisions, and international relations.

Social media acts as an accelerator of this process. False but impactful content can go viral in a matter of minutes , while verification and corrections arrive much later and with less reach. This lag clearly works in favor of those who use generative AI for malicious purposes.

Major platforms—Facebook, X (formerly Twitter), Google, etc.—have announced measures to limit the spread of harmful deepfakes , ranging from explicit bans to labeling and rapid removal systems. However, the scale of the problem and the speed at which technology evolves mean that the response is always partial.

The most profound risk is that these phenomena contribute to eroding critical thinking among citizens . If “everything can be a lie,” it becomes easier to sow doubt, spread extreme theories, and undermine trust in the media, institutions, and even the democratic system itself.

Technological and organizational strategies for defense

Faced with such a complex problem, the response must be equally multidimensional. On a technical level, AI-based detection algorithms are being developed that look for subtle inconsistencies in videos: lip-sync errors, unnatural blinking, compression artifacts, excessively smooth skin, or blurred edges in the facial area.

  The best Linux distributions to protect your security and privacy

Another approach involves protecting content "at the source" by inserting invisible watermarks or verifiable metadata that confirm the authenticity of a video or photo. These marks can then help distinguish original materials from manipulated copies, provided there is an accepted standard and tools to validate them.

In corporate environments, enhanced multi-factor authentication is gaining increasing traction . This means not relying solely on a person's image or voice, but combining it with other factors: geolocation, typical usage patterns, confirmations via alternative channels (SMS, secure applications), or one-time codes.

It is also recommended to implement clear protocols for sensitive transactions , such as bank transfers or changes of credentials. For example, establish that no important financial order is executed solely by email or video call, but always requires additional verification through a different channel.

Finally, ongoing training is key. Organizations that conduct phishing and deepfake drills —teaching their staff to detect subtle signs such as audio sync issues, unnatural gestures, or unusual behavior—develop a much more resilient security culture.

How to detect a deepfake: practical signs for everyday life

From a user's perspective, there are several clues that can help identify fake content, although they aren't always conclusive. A first recommendation is to look for obvious visual flaws : blurred edges around the face, inconsistent lighting compared to the background, jerky movements, or "strange" facial expressions.

Blinking is another useful indicator. Many deepfakes still exhibit unnatural blinking patterns : eyes that remain too open for extended periods or blinks with an odd rhythm. While newer models are improving in this area, it remains a weak point in many cases.

It's also important to look at the person's body, neck, and shoulders. Most manipulations focus on the face , so the rest of the body can betray the forgery if the proportions, posture, or gestures don't match what's expected for that person.

The video's length can be another clue. Generating a long deepfake requires more resources and increases the likelihood of errors, so much manipulated content is relatively short and focuses on a single, impactful phrase or scene. A very brief clip with an explosive message should raise a red flag.

Finally, it's crucial to analyze the context and origin of the recording . Who shared it first? Does it appear in reputable media outlets or only on anonymous accounts? Are there other independent sources that confirm what you see? Slowing down playback or watching the video frame by frame can help detect sudden changes in the background, facial alignment, or the inside of the mouth (tongue, teeth)—areas where many algorithms still fail.

Media literacy and verification culture

No detection technology will be sufficient without a citizenry that possesses critical thinking skills and basic verification abilities . Organizations such as INCIBE and the Internet User Security Office emphasize the need to be vigilant about the information we receive, analyze content in detail, and always verify it with reliable sources.

Developing the habit of not impulsively sharing anything , especially if it appeals to strong emotions (fear, anger, outrage), is one of the best defenses against the spread of deepfakes and fake news. Taking a few seconds to ask yourself, "Who benefits from me believing this?" can make a big difference.

Cybersecurity training, online research, and cyber intelligence aren't just for specialists. Understanding how phishing, social engineering, and disinformation attacks operate helps anyone significantly reduce their vulnerability, both in their personal and professional lives.

For children and teenagers, it's especially important to integrate these topics into digital and emotional education , explaining the risks of cyberbullying, sextortion, and the sharing of intimate images. Knowing that a video might be fake, but that its consequences can be very real, makes a huge difference.

For businesses and institutions, investing in awareness programs that go beyond generic cybersecurity advice is now a strategic necessity. Those who don't understand deepfakes, their impact, and how to react to them will be at a clear disadvantage in the new digital landscape.

All indications suggest that deepfakes will continue to multiply in volume and sophistication , affecting the security, economy, politics, and private lives of millions. Accepting that they are part of the digital landscape, demanding clear legal frameworks, investing in robust detection technologies, and, above all, cultivating a culture of verification and shared responsibility are the best ways to prevent this powerful tool from becoming a weapon that completely undermines trust in our online lives.