Knowledge · New threats: agents, MCP, prompt injection · 8 minutes

How to spot a deepfake: fake video, cloned voice and scam ads

How to spot a deepfake by image and voice, how AI voice scams posing as family or the CEO work, and what the law and Article 50 of the AI Act say.

Last updated: October 5, 2026

What is a deepfake?

A deepfake is AI-generated or AI-manipulated image, audio or video content that resembles existing people, places or events and that a viewer could wrongly take as genuine. That is the definition in Article 3(60) of the EU AI Act, which the Polish data protection authority (UODO) also relies on in a 2026 letter, because Polish law has no definition of its own.

In practice you meet three forms: fake video (a face and lip movement laid over someone's voice), a cloned voice (a short sample is enough to generate any statement) and a fake image. They are most often used for financial fraud, impersonation and harassment. UODO notes that the algorithms can produce realistic images and sound from a small sample, so a short clip from social media is enough.

How to spot a deepfake: mouth, voice, content, background

NASK, the Polish research institute that runs CERT Polska, in January 2025 published a video series by experts from its AI security research centre. They point to these signals:

1. Mouth. The face, and the mouth area in particular, is where image generation errors often show. 2. Voice. Wrong intonation and lack of fluency, because a generated voice ignores punctuation. 3. Content. Grammar errors, especially in how numbers are inflected (in Polish). 4. Logic. Body language that does not match the spoken words. 5. Masking. Effects and textures laid over the image to hide its imperfections.

A caveat: these are signals, not a test. No glitches does not prove a recording is real. Tools improve faster than guides do, and on a phone call you have only the voice and the stress. So the key rule is non-technical: do not judge authenticity, verify the request through another channel.

AI voice scams: fake grandchild and fake CEO calls

The AI version of the grandparent scam goes like this: someone calls in the voice of a loved one, talks about an accident or an arrest and asks for money urgently. In a 3 December 2024 public service announcement the FBI warned that criminals generate short audio clips of relatives' voices and impersonate bank customers to get into their accounts.

The business version is CEO fraud: a message, call or video meeting with a "board member" asking for a confidential, urgent transfer. It often comes together with a changed bank account number on an invoice.

What the FBI recommends: agree on a secret word or phrase with your family. When a relative or a bank calls asking for money, hang up and call back a number you know from another source. Limit public recordings of your voice and image and keep social media accounts private. At work: no transfer to a new account without confirmation by a second person on a known number.

Fake ads with celebrities and politicians

Ads in which a famous person "recommends" an investment platform are a very common fraud pattern in Poland, and that person's face and voice are sometimes faked. In April 2025 the Polish Ministry of Digital Affairs described the pattern: an ad disguised as a news article, a contact form, a call from an "adviser" and pressure to keep paying in.

The scale, according to the CERT Polska annual report for 2025: fake investments were the most common phishing target on its Warning List, with 98,663 domains in 2025 against 42,172 a year earlier. The report notes that fraudsters use public figures' likenesses as fake endorsements and show victims fabricated profit charts to get more deposits.

The rule is simple: a famous person urging you to invest with guaranteed returns is a fraud signal, whatever the quality of the recording. You can check the address the ad leads to for free: the result shows whether the domain is on the CERT Polska warning list, how old it is and whether it resembles a known brand.

Deepfake phishing at work: procedure beats intuition

Deepfake phishing is impersonating a manager, supplier or bank with a faked voice or image. Training people to look for blurry mouths does not stop it. A procedure that cannot be skipped "because the CEO asked" does:

1. Any change of bank account or urgent off-process transfer is confirmed on a number from your records, not from the message. 2. Large transfers are approved by two people. 3. A verification phrase for money conversations among executives and finance. 4. An employee who pauses a transfer to check never faces consequences for the delay.

If the request came by email, check the sender first. The step-by-step process is in how to check whether an email is genuine.

Are deepfakes legal?

The technology itself is not banned. What it is used for can be. In a letter to the police (ref. DPNT.413.21.2026) the head of the Polish data protection authority points out that a deepfake can meet the elements of several offences under the Polish Criminal Code: impersonation (Art. 190a(2)), coercion (Art. 191), distributing an image of a naked person without consent (Art. 191a), offences under Art. 202, defamation and insult (Arts. 212 and 216) and fraud (Art. 286). On top of that come infringement of personal rights and unlawful processing of personal data, because a face and a voice are personal data.

Article 50 of the AI Act applies from 2 August 2026. According to the European Commission's guidance of 24 July 2026, whoever publishes a deepfake must disclose it clearly and distinguishably at the latest at the viewer's first exposure. For evidently artistic, satirical or fictional works the duty is lighter. Providers of generation tools must mark content in a machine-readable way, and for systems placed on the market before 2 August 2026 that duty applies from 2 December 2026. Fines reach 15 million euros or 3% of worldwide turnover.

A fraudster will not label their recordings, so Article 50 does not replace your caution. It does help tell legitimate publishers from the rest. More on the dates in AI Act: what it is and who it applies to.

What to do if you have seen a deepfake or been scammed

If you transferred money: call your bank immediately and ask them to stop the transfer, then report it to the police. Time matters.

In Poland, report a fake ad or website to CERT Polska through the form at incydent.cert.pl or in the mObywatel app, and report the ad directly on the platform where you saw it. Keep screenshots, addresses and phone numbers. CERT Polska adds confirmed domains to its Warning List: 244,341 domains were added in 2025.

If someone used your face or voice, collect evidence and report it to the police. The UODO letter notes that people whose likeness was used can demand removal of the content and compensation.

In short

  • Image and voice signals help but do not prove authenticity. Verify the request through another channel.
  • Agree on a code word for money conversations with your family and at work.
  • A famous person recommending a sure-profit investment is a fraud signal. In 2025 CERT Polska added 98,663 such domains to its warning list.
  • A deepfake is not illegal in itself, but fraud, impersonation and defamation are crimes.
  • From 2 August 2026 legitimate publishers must label deepfakes under Article 50 of the AI Act.

Have a website, app or email address that looks suspicious?

Frequently asked questions

How can you tell if a video call is a deepfake?

Watch the mouth area, voice intonation, whether body language matches the words, and effects laid over the image. More reliable: end the call and call back a number you know from another source.

Are deepfakes legal in Poland and the EU?

The technology is not banned, but using it can be a crime, for example impersonation (Art. 190a(2) of the Polish Criminal Code) or fraud (Art. 286). From 2 August 2026 whoever publishes a deepfake must label it under Article 50 of the AI Act.

How do I know if a voice on the phone is real?

You cannot reliably tell by ear. Ask for a code word you agreed on earlier, or hang up and call the person back on a number you know.

Where do I report a deepfake scam ad?

In Poland, to CERT Polska at incydent.cert.pl or in the mObywatel app, and to the platform that showed the ad. If you lost money, report it to your bank and the police.

Are there tools that detect deepfakes?

There are, but none gives certainty and none replaces verification through another channel. Treat a detector's result as one piece of evidence, not a verdict.

Sources

  1. NASK: Mouth, voice, content, background. Can you spot a deepfake? (15 January 2025, in Polish)
  2. CERT Polska: Annual Report 2025 (in Polish)
  3. Polish Ministry of Digital Affairs: Ad with a famous person? It may be a scam (17 April 2025)
  4. FBI IC3: Criminals Use Generative AI to Facilitate Financial Fraud (3 December 2024)
  5. Personal Data Protection Office (UODO): letter on deepfakes, ref. DPNT.413.21.2026
  6. European Commission: Transparency obligations under Article 50 of the AI Act (24 July 2026)
  7. CERT Polska: domain report form

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also