Deepfake detection is usually framed as a technology problem — "run the video through a detector, get an answer." The uncomfortable truth: detection-after-the-fact is an arms race the detectors are not reliably winning, and every serious review of the field says so. Here's how the three real approaches work, where each fails, and the strategy that doesn't depend on out-guessing a generator. (Not legal advice; the takedown paths at the end vary by jurisdiction.)
Approach 1: Artifact detectors (the arms race)
Classifier models trained to spot generation artifacts — inconsistent lighting, blending seams, temporal flicker, physiologically odd details. They work best on yesterday's generators: each new model generation removes the artifacts the detectors learned, accuracy drops sharply on novel generators and on compressed re-uploads, and both false positives and false negatives carry real costs. Useful as a screening signal; dangerous as a verdict.
Approach 2: Provenance marks (better, but one-sided)
Generators increasingly mark their output — Sora with a visible overlay + C2PA metadata, Google with invisible SynthID (how each works and gets stripped), with the EU AI Act mandating machine-readable marks from August 2026. The structural weakness: marks prove presence, not absence. A stripped mark looks identical to no mark, so provenance labeling catches honest actors' content and misses exactly the malicious cases you care about.
Approach 3: Authenticate the real (the one you control)
Flip the problem: instead of proving a fake is fake, make the authentic provable. If your published photos and videos carry an invisible watermark, then when a manipulated version of you or your content circulates, you can demonstrate what the original was and that the circulating copy either derives from it (recovered signature) or can't be traced to anything you published. This approach doesn't degrade as generators improve — it's the only one of the three where time is on your side. It's the strategy HALLMARK.AI implements: invisible watermarking for your originals plus monitoring that flags where your content — including AI-modified derivatives — resurfaces.
If there's a deepfake of you right now
- Document it — URLs, screen recordings, dates, the account posting it. Before reporting, not after.
- Use platform synthetic-media policies — every major platform now has a dedicated reporting path for manipulated media impersonating real people, separate from copyright.
- Intimate-image deepfakes — in the US, federal law now requires platforms to remove non-consensual intimate imagery (including AI-generated) within 48 hours of a valid request; report to the platform first and cite it.
- If your original content was used as the source — copyright applies too: the DMCA route with template.