Deepfake evidence in court: how lawyers test, challenge and defend digital proof
For most of the past century, a photograph, a recording or a video came with a quiet assumption attached: producing one was hard enough that it usually meant something happened. That assumption has gone. The practical consequence for litigators is not that courts will be flooded with fabricated exhibits. It is that authenticity, which used to be conceded in a sentence, now has to be capable of being proved — and that the party who prepares for that question is the party who wins the point.
The short answer: European procedural law already contains the tools to handle synthetic evidence. What has changed is that lawyers must actually use them. Secure the original rather than a copy, fix its state with a hash and a qualified time stamp, document how it was obtained, and put authenticity in issue with specific grounds rather than a general allegation. Do not rely on AI Act labelling to tell you whether a file is genuine, and do not rely on a detector's percentage to prove that it is not.
Why this became a live litigation question in August 2026
Article 50 of the AI Act has applied since 2 August 2026. It requires providers of AI systems that generate synthetic audio, image, video or text to mark those outputs in a machine-readable format and make them detectable as artificially generated or manipulated. It also requires deployers of a system that produces a deepfake to disclose that the content has been artificially generated or manipulated (1). The Regulation defines a deep fake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
The Commission adopted its final guidelines on those transparency obligations on 20 July 2026 (2), and a voluntary Code of Practice on Transparency of AI-generated Content was published on 10 June 2026, with roughly 190 organisations signed up by the end of that July (3). The Digital Omnibus on AI, in force since 27 July 2026, left the transparency regime standing but allows certain generative systems already on the market until 2 December 2026 to meet the marking obligation (4).
Read from a litigator's chair rather than a compliance officer's, that framework has one dominant feature: it regulates the honest. A provider that follows Article 50 will mark its outputs. A deployer that follows Article 50 will disclose. The person who fabricates a recording in order to win a case will do neither, and will use whatever tool imposes the fewest constraints. Transparency obligations improve the information environment. They do not authenticate the exhibit in front of you.
Elsewhere, rule-makers are still deliberating. In the United States, proposals for a new Federal Rule of Evidence 707 on machine-generated evidence and a Rule 901(c) on deepfakes remained study items at the Advisory Committee's May 2026 meeting rather than being advanced for approval (11). There is, for now, no jurisdiction in which a lawyer can wait for a bespoke rule to solve this.
Two failures, not one
Authenticity disputes go wrong in two opposite directions, and a firm that prepares for only one of them is half prepared.
The first failure is the obvious one: a fabricated or altered file is accepted because nobody tested it. A voice note that never happened. A photograph of damage that was generated rather than taken. A screenshot of a conversation that was assembled rather than captured. The exhibit is plausible, the deadline is short, and the opposing party concentrates on what the recording appears to show rather than on where it came from.
The second failure is quieter and, on current evidence, more common: a genuine file is neutralised by an unsupported allegation that it is synthetic. Robert Chesney and Danielle Citron named this the liar's dividend in 2019 — as public awareness of deepfakes grows, denial becomes cheaper, because a party no longer has to fabricate anything to create doubt (10). A litigant who has nothing to say about a damaging recording can now say that recordings cannot be trusted, and shift the cost of proof onto the party that behaved properly.
Both failures have the same root cause and the same remedy. Provenance is either documented at the moment the material enters the matter, or it is reconstructed later at far greater cost and with far less certainty.
What the rules of evidence already give you
There is a widespread assumption that European evidence law has no answer to synthetic media. In fact the general principles are well suited to the problem; they simply place the work on the parties.
Free evaluation of evidence is the starting point in the civil-law systems where most European commercial disputes are heard. In the Netherlands, article 152 of the Code of Civil Procedure permits proof by any means unless the law provides otherwise, and leaves the assessment of the evidence to the court (13). In Germany, section 286 of the Zivilprozessordnung requires the court to decide according to its free conviction, taking into account the entire content of the proceedings, and to be bound by statutory rules of evidence only in the cases the statute designates (14). French law likewise admits proof of legal facts by any means. A synthetic file is therefore not excluded by a categorical rule, and a genuine file is not admitted by one either. Everything turns on persuasion.
The more useful provisions are the ones that allocate the burden once authenticity is properly disputed.
- Netherlands. Article 159(2) of the Code of Civil Procedure provides that a private deed whose signature is firmly denied by the party against whom it would furnish conclusive evidence produces no evidence at all until it is proved from whom the signature originates. The party invoking the document carries that proof.
- Germany. Section 440(1) of the Zivilprozessordnung states that the authenticity of a private document that has not been acknowledged must be proved. Section 371a extends the rules on the evidential value of private documents to electronic documents bearing a qualified electronic signature, and provides that the appearance of authenticity can only be displaced by facts giving rise to serious doubts about authorship (14).
- France. Article 287 of the Code de procédure civile directs that, where the denial concerns an electronic writing or signature, the court verifies whether the conditions of articles 1366 and 1367 of the Civil Code are satisfied — due identification of the author and integrity guaranteed by the conditions of creation and preservation. Article 1379 of the Civil Code treats a reliable copy as having the same probative force as the original, and grants a rebuttable presumption of reliability to a copy whose integrity over time is guaranteed by a process meeting the requirements set by decree (15).
Two cross-border instruments deserve to be better known in this context. Under the eIDAS Regulation, a qualified electronic time stamp enjoys a presumption of the accuracy of the date and time it indicates and of the integrity of the data to which they are bound, and is recognised in every Member State (5). That is a rare, inexpensive and portable evidential advantage, and it is available to any firm willing to build one step into its intake routine. Separately, the guarantee of adversarial proceedings under Article 6 of the European Convention means that a party must be able to know and to comment effectively on the evidence relied on, including expert material. A court that resolves an authenticity dispute on an expert report the parties could not test is exposed on appeal.
The authenticity workstream: seven steps
The following sequence works for a client's own material and for material received from an opponent, a regulator or a third party. It is deliberately ordered: each step is cheaper and more effective when the previous one has been done.
1. Obtain the original, not a copy of a copy
Ask for the file as it exists on the device or in the account that produced or received it, together with the surrounding items in the same directory or thread. What arrives in practice is usually something else: a WhatsApp forward, an image pasted into a slide deck, a screen recording of a screen, a PDF export of a chat. Every one of those steps re-encodes the file, strips or rewrites metadata, and destroys the very traces an examiner would rely on. The distinction to record is between a copy that is faithful in content and a copy that is faithful as an object. Only the second is useful in an authenticity dispute.
2. Freeze the state: hash, time stamp, acquisition note
Calculate a cryptographic hash of the file as received and record it. Apply a qualified electronic time stamp so that the state of the material at a defined moment carries the eIDAS presumption. Then write a short acquisition note while it is still fresh: who provided the item, on what date, through which channel, from which device or account, what the person said about its origin, and what was done to it afterwards. Three sentences written on the day of receipt are worth more than an affidavit written eighteen months later.
3. Reconstruct the chain of custody
The chain runs from the moment of creation to the moment of production in the proceedings, and every unexplained gap is an opening for the other side. Record where the file was stored, who had access, whether it was edited, converted or compressed, and which copy is being tendered. In a firm this also means resisting the ordinary reflex to circulate a client's video by email, which produces a second-generation copy that then becomes the working version by accident.
4. Read the container before you read the picture
Container-level analysis examines the file rather than the scene: creation and modification timestamps, device and software identifiers, encoder signatures, colour profile, compression structure, GPS data where present, and internal inconsistencies such as a file produced by one application but bearing the structural fingerprint of another. Metadata is informative and easily manipulated at the same time, which is why it can support a conclusion but rarely delivers one. Its most valuable use is comparative: the questioned file against known-good files from the same device, produced in the same period, under the same settings.
5. Check provenance signals, and know what they cannot say
Content Credentials, the provenance format developed by the C2PA and being standardised as ISO 22144, attach a cryptographically signed manifest describing how a file was captured or edited and by which tools (8). Where such a manifest is present and intact, it is genuinely probative. Three limits must be stated in the same breath. A signed manifest testifies to the recorded history, not to the truth of what is depicted. Provenance data is routinely stripped by ordinary sharing, so its absence is uninformative. And a manifest can attest that a file was generated by an AI system just as well as it can attest to a camera capture. The same logic applies to AI Act marks: their presence is evidence of an honest producer, their absence is evidence of nothing.
6. Move to forensic examination, and instruct properly
Content-level examination is expert territory: sensor and noise patterns, compression history, lighting and geometry consistency, physiological plausibility in faces and voices, lip-audio alignment, and generator artefacts. The European reference points here are the ENFSI best practice manuals, in particular the manual for digital image authentication (6) and the manual for digital audio authenticity analysis (7). They repay reading by the instructing lawyer, because they describe what a competent examination can and cannot conclude, and they set the vocabulary in which conclusions should be expressed.
Instruct with questions the expert can actually answer. Not "is this a deepfake?", but: is the file internally consistent with capture by the identified device; are there indications of re-encoding or local editing; can the questioned file be compared with reference material from the same source; what alternative explanations remain open; and how strong is the support for each hypothesis. Methods are still developing — the Netherlands Forensic Institute, for example, has been researching detection of the subtle facial colour changes caused by blood flow, and has been explicit that the technique is not yet available for casework (16). An expert who reports a certainty the field does not have is a liability in cross-examination.
7. Corroborate outside the file
The strongest authenticity arguments are usually not made inside the file at all. A recording that matches a calendar entry, a badge log, a train ticket, a bank record, a weather report and two witnesses who describe the same conversation is hard to attack, whatever the metadata show. Conversely, an exhibit that exists in a vacuum — no sender, no device, no second copy, no contemporaneous mention — deserves scrutiny even when it looks perfect. Reconstructing that surrounding record across large document sets is ordinary litigation work, and it is usually where document-heavy matters are won or lost; our note on fact reconstruction in document-heavy cases covers the method in more depth.
Challenging an opponent's digital exhibit
A challenge succeeds or fails on specificity. Courts are, rightly, unsympathetic to a party that alleges fabrication in the abstract and then asks for an adjournment and an expert at the other side's expense.
- Ask for the original and the acquisition history first. A request for the native file, its container metadata, the source device or account, and the route by which it reached the file is cheap, proportionate and revealing. Refusal or inability to produce it is itself an argument on weight.
- State grounds, not suspicions. Identify what is wrong: an inconsistency between the recording and an undisputed document, a shadow or reflection that does not match the stated time, an encoder signature inconsistent with the claimed device, a chat export with a message order that the platform does not produce, a voice sample with no breath or room tone.
- Anchor the challenge in the applicable provision. Deny authenticity in the form the national code requires, so that the burden consequences described above are actually triggered rather than left as rhetoric.
- Propose a proportionate examination. Frame the questions, propose the material to be made available, and address who bears the cost. A narrow, well-framed instruction is far more likely to be granted than an open-ended request for a forensic report.
- Preserve the position on weight. Even where authenticity cannot be disproved, an unexplained gap in provenance goes to the weight the court gives the exhibit. Plead in the alternative.
Defending your own exhibit
If your client's material is likely to matter, treat it as contested from the first day, not from the day it is attacked.
- Collect the original from the source device, and keep that device or account available rather than wiping or replacing it.
- Hash and time-stamp at intake, and record the hash in the matter file.
- Take a short signed statement of origin from the person who created or received the material, describing the circumstances of capture in their own words.
- Never work from a messenger forward when the original exists; where a forward is all that exists, say so openly rather than presenting it as the original.
- Preserve the surrounding context — the whole thread, the adjacent files, the device backup — because selective preservation is itself attacked.
- Where the material is decisive and the opponent is well resourced, consider a proactive expert examination before service, so that the answer to a fabrication allegation already exists.
Confidentiality discipline applies throughout. Client media should be handled in the environments the firm has approved for that category of data, and a file whose authenticity may be tested should not be passed through consumer tools that re-encode it. The practical framework for those decisions is set out in our guidance on secure AI use for lawyers and on document analysis in law firms.
Why a detector score is not evidence
The market now offers many tools that will report a probability that an image, video or voice sample is synthetic. They are useful for triage. They are not, on their own, a basis for a submission to a court.
The core problem is generalisation. A detector learns the artefacts of the generators and datasets it was trained on, and performance degrades when it meets a generator, a compression pipeline or a capture condition outside that distribution. A 2026 study evaluating detection across fourteen benchmark datasets found that models trained on the most recent data performed well on their own test set while generalising poorly to earlier benchmarks, and that architecture choice materially affected cross-dataset decline (9). Aggregate accuracy on a benchmark is not the error rate on the file in dispute, and the file in dispute is the only one the court cares about.
There are three further objections a competent opponent will raise. A closed tool that cannot explain its reasoning cannot be tested in adversarial proceedings, which is precisely what Article 6 requires. A tool that reports a single percentage invites the court to treat a probability as a finding. And detection is not the same task as authentication: showing that a file bears traces consistent with generation is a different exercise from showing that this file came from that device at that moment. Use detectors to decide whether to instruct an expert. Do not use them as the expert.
The CCBE's technical guide for lawyers makes the general point in professional terms: competence in using AI tools includes understanding their limits and retaining responsibility for the conclusion drawn from them (12).
A one-page intake protocol for client media
Most of the value in this area comes from a routine that takes ten minutes at intake. The following is short enough to be used.
- What exactly is the item, and what is it said to show?
- Who created it, on what device or in which account, and on what date?
- Is this the original, or a copy? If a copy, how many generations away, and does the original still exist?
- Where has it been stored, and who has had access?
- Has it been edited, converted, trimmed, enhanced or compressed — including by the person providing it?
- Hash recorded? Qualified time stamp applied? Both noted in the matter file?
- Is the source device or account preserved and available for examination?
- What independent material would corroborate or contradict it?
- If the other side alleged fabrication tomorrow, what would we produce in response?
The last question is the one that changes behaviour. A file that cannot survive it should be flagged to the client before it is served, not after.
What to do in the next 30 days
Firms do not need a synthetic-media programme. They need a small number of habits embedded in matters that are already running.
- Add provenance fields to the intake form used when clients supply photographs, video, audio or screenshots, and make hashing and time-stamping the default rather than an exception.
- Write a two-page internal note covering the questions above, the national provision your litigators should cite when denying authenticity, and the point at which an expert is instructed.
- Identify your experts before you need them. Know which laboratories in your jurisdiction perform image, video and audio authenticity examinations, their lead times and their indicative costs.
- Review live matters for exposure. Which pending cases turn on a photograph, a recording or a screenshot whose provenance nobody has documented?
- Brief the litigation team on the liar's dividend so that an unsupported fabrication allegation is answered with provenance and a demand for specific grounds, rather than with a costly and unnecessary expert report.
How this fits the way LexVera supports legal work
Authenticity disputes are, at bottom, disputes about traceability: can this assertion be followed back to the material it rests on, and can someone else check the same route? That is the same discipline that should govern any use of AI in legal work.
LexVera is built around it. Analysis stays attached to the material it came from, so a lawyer can move from a statement in a summary back to the passage, document or authority that supports it instead of accepting a fluent paragraph on trust. Adversarial analysis is treated as part of the work rather than an optional extra, because the useful question in a contested matter is what would defeat the position, not what confirms it. Matter material stays within the context the firm has approved for it. And the platform is designed so that a qualified lawyer decides what becomes advice, correspondence or a filing — the judgement, and the responsibility, remain where professional rules put them. The same distinction between sourced fact, professional interpretation and product context underpins our editorial policy.
Frequently asked questions
Is a deepfake admissible as evidence in a European court?
Admissibility and weight are matters for national procedural law, and most European civil systems permit proof by any means while leaving assessment to the court. The practical question is not whether synthetic material is barred in principle, but whether the party relying on a file can show where it came from and that it has not been altered.
Does the EU AI Act mean unlabelled content can be treated as genuine?
No. Article 50 obliges providers to mark synthetic outputs and deployers to disclose deepfakes, and it has applied since 2 August 2026. It binds compliant market actors rather than someone who intends to deceive, and a transition runs to 2 December 2026 for certain systems already on the market. The absence of a label proves nothing about authenticity.
Who has to prove that a video or recording is authentic?
It depends on the instrument and the jurisdiction. Free evaluation of evidence is the general rule, but several provisions shift the practical burden once authenticity is properly disputed — article 159(2) of the Dutch Code of Civil Procedure, section 440 of the German Zivilprozessordnung, and the verification procedure in articles 287 and 288-1 of the French Code de procédure civile.
Can an AI detector prove that a video is a deepfake?
A detector output is an indication, not proof. Published evaluations show accuracy falling when a model meets generators or compression conditions it was not trained on, and a tool's percentage says nothing about the error rate on the specific file in dispute. Courts expect a method an expert can explain and an opponent can test.
How should we preserve client media so it survives a challenge?
Take the original from the device that produced it, record a cryptographic hash, apply a qualified electronic time stamp, write down who supplied it and how, and keep the source device or account available. Messaging apps re-encode media and strip metadata, so a forwarded copy destroys much of what an examiner would look at.
What if the other side claims our genuine recording is AI-generated?
Answer with provenance rather than indignation: the original container, the acquisition record, an independent time anchor, corroborating documents and, where the challenge is properly substantiated, an expert examination. Ask the challenging party to state specific grounds; a bare allegation should not shift the cost of proof.
Do we need a court-appointed expert, or can we instruct our own?
Both routes exist across European systems and they serve different purposes. A privately instructed examination is faster and useful for deciding whether a challenge is worth making. A court-appointed expert usually carries more weight in the judgment, and the parties' ability to participate in and comment on that examination is part of the fair-trial guarantee. Decide early, because the timetable rarely allows both.
Sources and methodology
This guide reflects legislation, Commission materials, forensic best practice and published research available on 15 August 2026. It distinguishes binding text from non-binding guidance and from technical literature. National procedural law is summarised at the level of principle to show where the burden of proof shifts; it is general professional information rather than advice on a specific dispute, and the applicable code, case law and local practice must be checked in context.
- Regulation (EU) 2024/1689 (AI Act), Article 3(60) and Article 50
- European Commission, final guidelines on Article 50 transparency obligations, 20 July 2026
- European Commission, Code of Practice on Transparency of AI-generated Content, 10 June 2026
- Regulation (EU) 2026/1744, Digital Omnibus on AI
- Regulation (EU) 910/2014 (eIDAS), Article 41 on qualified electronic time stamps
- ENFSI, Best Practice Manual for Digital Image Authentication (ENFSI-BPM-DI-03)
- ENFSI, Best practice manuals, including digital audio authenticity analysis
- C2PA, Content Credentials technical specification (under ISO standardisation as ISO 22144)
- Yermakov and others, Deepfake Detection that Generalizes Across Benchmarks, WACV 2026
- Chesney and Citron, Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security, 107 California Law Review 1753 (2019)
- Advisory Committee on Evidence Rules, agenda book, May 2026, on proposed Rules 707 and 901(c)
- CCBE, Technical guide on the use of AI tools and models by lawyers, 27 March 2026
- Wetboek van Burgerlijke Rechtsvordering, articles 152 and 159
- Zivilprozessordnung, section 371a, with sections 286 and 440
- Code civil, article 1379, with articles 1366 and 1367 and articles 287 and 288-1 of the Code de procédure civile
- Netherlands Forensic Institute, research on detecting deepfakes through facial blood-flow signals