INTELLIGENCE REPORT SERIES SEPTEMBER 2026 OPEN ACCESS

SERIES: MEDIA INTELLIGENCE

The Liar’s Dividend — When Real Evidence Stops Counting

In 2026, 85% of surveyed adults said they can no longer tell AI-generated content from the real thing. The deeper damage is not deception but deniability.

Reading Time39 min
Word Count7,703
Published23 September 2026
Evidence Tier Key → ✓ Established Fact ◈ Strong Evidence ⚖ Contested ✕ Misinformation ? Unknown
Contents
39 MIN READ
EN FR ES PT DE RU AR ZH JP

In 2026, 85% of surveyed adults said they can no longer tell AI-generated content from the real thing. The deeper damage is not deception but deniability.

01

The Default That Broke
Why synthetic media is costing more in doubt than in deception

In 2026, 85% of surveyed adults across five Western countries said they could no longer reliably separate AI-generated content from the real thing, against 66% a year earlier ✓ Established Fact [5]. The number that matters is not how many people were fooled. It is how many stopped assuming.

The central finding of this report is that the dominant cost of synthetic media is not successful deception. It is the collapse of a default. For roughly a century and a half, a photograph, an audio recording or a piece of video functioned as a presumption in ordinary reasoning: the burden of proof sat with whoever claimed the record was false. Generative models have removed that presumption without supplying anything to replace it, and the removal is doing more work than the fakes themselves. Robert Chesney and Danielle Citron named the consequence in the California Law Review in December 2019, calling it the liar’s dividend ✓ Established Fact [1].

The measurable damage from outright fabrication is real and rising. Resemble AI verified 821 distinct deepfake attacks drawn from 1,760 news reports in the first half of 2026, documenting at least 15,736 victims and linking the cases to 3.46 million synthetic files [9]. Its full-year 2025 count was 1,567 verified unique incidents with more than 1.28 billion dollars in documented losses, and the same report notes that over 80% of incidents disclosed no financial damage at all, which makes every published loss total a floor rather than an estimate [10]. The United States Federal Bureau of Investigation logged 22,364 complaints tied to AI-related fraud in 2025, with reported losses of 893 million dollars [12]. Those are large numbers. They are not the largest effect.

85%
Adults who say they can no longer separate AI-generated content from real content
Help Net Security survey of 1,500 adults, 2026 · ✓ Established Fact
37%
Global trust in news, the lowest level recorded since measurement began in 2015
Reuters Institute Digital News Report, 2026 · ✓ Established Fact
821
Verified deepfake attacks documented in the first half of 2026
Resemble AI, 2026 · ✓ Established Fact
62%
Average concern about telling real from fake information online, up 4 points
Reuters Institute Digital News Report, 2026 · ✓ Established Fact

Set those fraud figures against the trust data and the asymmetry becomes visible. The Reuters Institute for the Study of Journalism recorded global trust in news at 37% in its 2026 Digital News Report, the lowest level in the series since it began in 2015, with significant declines in 29 of 48 markets surveyed ✓ Established Fact [4]. Average concern about distinguishing real from fake information online rose four percentage points to 62%, and in Nigeria, Kenya, South Africa, the United States, the United Kingdom and Australia more than 75% of respondents named deepfakes and AI-generated material as a specific worry [4]. Trust in news encountered on social platforms stands at 22%, and trust in news delivered by AI chatbots at 20% [4].

The gap between those two data sets is the subject of this report. Fraud losses are concentrated: a few hundred thousand victims, mostly through impersonation of executives, relatives and identity-verification systems. Doubt is universal. Every person who now hesitates before believing a video has absorbed a cost that appears in no incident ledger, and every person who can now plausibly deny a recording has received a benefit that no regulator counts. A Quinnipiac University poll in March 2026 found 58% of Americans confident they could tell an authentic recording from an AI-generated one, which means 42% were not confident, including 20% who described themselves as not confident at all [6].

The Asymmetry Nobody Budgets For

Detection spending, platform labelling and criminal statutes are all aimed at the fake that succeeds. Almost nothing is aimed at the true record that fails. A fabricated video that fools a bank produces a police report, an insurance claim and a line in an incident database. A genuine video dismissed as fabricated produces nothing at all, because the person who benefits from the dismissal has no reason to file anything and the person harmed has no forum in which to prove a negative.

Confidence is also poorly calibrated, which matters because the liar’s dividend is paid out of confidence rather than out of accuracy. A Micro Center survey in March 2026 found 57% of respondents confident they could identify an AI-generated image, while only 55% actually did so when tested [7]. Copyleaks reported in October 2025 that 82% of respondents admitted having taken an AI-generated image for a real one at least once ◈ Strong Evidence [8]. People who have been wrong once and know it become harder to move in either direction, and that stickiness is precisely what a bad-faith denial exploits.

The structure of this report follows the asymmetry. Sections two and three separate the deception ledger from the deniability ledger and put numbers on each. Sections four and five examine the two institutions that cannot function without a working evidentiary default, the courts and the newsroom, and show what each is doing while the default erodes. Section six assesses the provenance and labelling response now being written into law across the European Union, China, India, Denmark, the United Kingdom and thirty-one American states. Sections seven and eight set out the strongest case on each side of the dispute over how severe this actually is, and then state what the evidence will and will not support.

02

The Deception Ledger
What fabricated media actually takes, and from whom

Documented deepfake-enabled fraud is concentrated, industrialised and growing fast, with the financial-services sector absorbing an average loss of 603,000 dollars per incident against roughly 450,000 dollars across all sectors ✓ Established Fact [11]. The composition of the harm is not what the policy debate assumes.

The deception side of the ledger is easier to count than the deniability side, and counting it first is necessary to keep the argument honest. Resemble AI recorded 2,031 discrete incidents in the third quarter of 2025 alone, a 317% jump from the second quarter [10]. Deloitte projects that generative-AI-enabled fraud losses in the United States will reach 40 billion dollars by 2027, growing at a 32% compound annual rate from 12.3 billion dollars in 2023 [13]. Forecasts of this kind carry vendor incentives and should be treated as directional, but the direction is consistent across independent counts.

Identity verification is where the industrialisation is clearest. Entrust reported in its 2026 Identity Fraud Report that deepfakes are now linked to one in five biometric fraud attempts, that injection attacks rose 40% year on year, and that deepfaked selfies increased 58% during 2025 ✓ Established Fact [14]. iProov recorded a 1,151% surge in injection attacks against iOS devices in the second half of 2025, contributing to a 741% annual increase [15]. An injection attack does not hold a fake face in front of a camera. It feeds synthetic video directly into the verification pipeline, which is why the countermeasure has to live below the application layer.

✓ Established Fact Deepfake-enabled fraud is now a routine operational risk for large organisations rather than an exotic one

A Gartner study in September 2025 found that 37% of cybersecurity leaders had encountered a deepfake incident during a video call, and Ponemon Institute research puts the share of organisations that have experienced deepfake attacks targeting executives at 41% [16]. The reference case remains the Hong Kong office of the engineering firm Arup, where a finance employee authorised a transfer after joining a video call on which every other participant, including the chief financial officer, was synthetic [12]. The attack did not defeat a detection system. It defeated a social convention about what a face on a screen means.

The largest single category of synthetic media, however, has never been financial. Security Hero found in 2023 that 98% of deepfake videos then circulating online were non-consensual sexual material, that 99% of the people depicted were women, and that production volume had risen 464% between 2022 and 2023 [17]. That distribution has not meaningfully changed. What changed is the cost of production, which fell to zero when consumer image models acquired editing capability, and the age of the people doing it.

South Korea provides the clearest national case study, because the scandal there was documented by police rather than by vendors. Between November 2024 and October 2025, Korean police apprehended 3,557 individuals for cyber sexual violence, with deepfake offences the single largest category at 1,553 cases [18]. In one crackdown, teenagers accounted for 42.9% of those apprehended, 723 people, and together with those in their twenties made up roughly 80% of the total [18]. The 2024 phase of the scandal ran through Telegram channels organised by school and university, one of which reportedly had more than 220,000 subscribers, and both victims and perpetrators were frequently minors [19].

98%
Share of deepfake videos online that were non-consensual sexual material
Security Hero, 2023 · ◈ Strong Evidence
1,553
Deepfake sex-crime cases recorded by Korean police in twelve months to October 2025
Korean National Police via Korea JoongAng Daily, 2025 · ✓ Established Fact
1,151%
Rise in injection attacks against iOS devices in the second half of 2025
iProov Threat Intelligence Report, 2026 · ◈ Strong Evidence
48h
Maximum removal window for reported intimate images under United States federal law
Federal Trade Commission, 2026 · ✓ Established Fact

The pattern repeated in the United Kingdom at the start of 2026 with the image tool attached to the Grok assistant on the platform X. Material amounting to image-based abuse, including depictions of a fourteen-year-old actor, was generated and shared at scale [21]. On 12 January 2026 the communications regulator Ofcom opened a formal investigation into whether X had failed its duties under the Online Safety Act 2023, an inquiry that can end in a penalty of up to 18 million pounds or 10% of qualifying worldwide revenue, whichever is greater [20]. The platform restricted image generation to paying subscribers on 5 January and added editing guardrails on 9 January, a sequence the British government publicly described as insufficient [21].

Two things follow from the deception ledger. The first is that the harm is heavily concentrated on women and children, and only secondarily on corporate treasuries, despite the inverse weighting in most coverage and most security budgets. The second is that almost none of this harm depends on the target being deceived. A non-consensual image humiliates whether or not anyone believes it is genuine, and an injection attack succeeds against a machine that has no beliefs at all. The deception frame is already a poor fit for the majority of documented cases, which is the first sign that the framework needs replacing.

03

The Dividend, Measured
What five experiments on 15,000 people found about denial as a strategy

The liar’s dividend is usually asserted rather than measured. It has now been tested, and the result is narrower and more unsettling than the slogan: denial works, but not where most commentary expects it to work ◈ Strong Evidence [2].

Chesney and Citron set out the mechanism in 2019. As deepfakes become widely known, they argued, the mere possibility of fabrication supplies a defence to anyone caught on the record, and the better the public understands the technology the stronger that defence becomes [1]. The formulation is elegant and, for five years, entirely untested. It had the structure of a plausible mechanism rather than the status of a finding, and that distinction has been lost in most of the policy literature built on top of it.

The test arrived in the American Political Science Review. Kaylyn Jackson Schiff, Daniel Schiff and Natalia Bueno ran five pre-registered survey experiments on more than 15,000 American adults, using text and video drawn from four real political scandals in the United States ◈ Strong Evidence [2]. Respondents saw a scandal report and then a politician response: an apology, silence, or a claim that the evidence was misinformation. The design separated two distinct denial strategies, one invoking general informational uncertainty and one calling on supporters to rally against a hostile press [2].

Deep fakes make it easier for liars to avoid accountability for things that are in fact true.

— Robert Chesney and Danielle Citron, California Law Review, December 2019

Three findings matter. Claims of misinformation raised politician support across partisan subgroups, and lying outperformed both apologising and staying silent, which is a direct incentive finding rather than a speculative one [2]. The effect was strong against text-based reports of scandal and largely ineffective against video evidence [2]. And the strategies did not measurably reduce general trust in media, which cuts against the most common version of the alarm [2].

The video result is the one most often reported as reassurance, and it is the one that deserves the most caution. The experiments were fielded on scandals whose video evidence was in fact authentic and whose provenance was not seriously in dispute. They measure how much a denial moves an audience that has just watched a real clip. They do not measure what happens once a substantial share of circulating video is genuinely synthetic, because in 2022 and 2023 it was not. The finding is a baseline taken before the condition it describes had fully arrived.

◈ Strong Evidence The measured liar’s dividend is a text-and-audio phenomenon, not yet a video phenomenon

Across five experiments with more than 15,000 respondents, false claims of misinformation reliably boosted support when the underlying scandal was reported in text, and failed to do so when the scandal was shown on video [2]. Read carefully, that is not evidence that video is safe. It is evidence that in the period studied, audiences still treated video as a stronger class of proof than text, which is exactly the default this report argues is now eroding [3].

The Brennan Center for Justice, writing with Georgetown’s Center for Security and Emerging Technology in January 2024, drew the practical conclusion before the experimental data was widely read: the dividend shrinks when the public can check, so tagging and tracing mechanisms matter, and so does refusing to inflate the threat [3]. Their recommendation to media organisations is unusual in this literature because it cuts against the interests of the people making it. They advise newsrooms to prepare the public for uncertainty and to avoid AI threat inflation, on the reasoning that every exaggerated warning about undetectable fakes is itself a deposit into the liar’s account [3].

That reasoning has a sharp implication for how synthetic media is covered. Each cycle of coverage announcing that video can no longer be trusted raises the base rate of scepticism that a dishonest actor can draw on, whether or not any particular fake exists. The dividend is funded by awareness, not by incidence. It is the only informational harm in general circulation that grows when the public is better informed about it, which is why education campaigns aimed at scepticism alone are not a solution and may be part of the problem.

04

The Courtroom Test
Authentication rules written for the photograph meet the generator

In September 2025 a Californian judge dismissed a civil case after determining that video witness testimony submitted as authentic had been generated ✓ Established Fact [26]. In May 2026 the federal evidence rules committee decided that no new rule was needed yet [30]. Both decisions are defensible. Together they describe the gap.

Evidence law has handled forgery for as long as it has handled evidence. Federal Rule of Evidence 901 requires a proponent to produce evidence sufficient to support a finding that an item is what its proponent claims, and Rule 104 governs how the judge decides preliminary questions of that kind. Courts have applied those provisions to forged deeds, retouched photographs and spliced tape for decades, and that history is the strongest argument that nothing new is needed [31]. The argument holds as long as the marginal cost of producing a convincing forgery stays high enough to keep the base rate low.

Mendones v. Cushman and Wakefield tested the assumption directly. Judge Victoria Kolakowski of Alameda County Superior Court reviewed video testimony from a witness and found the recording wrong in ways that were legible to an attentive reader rather than to a laboratory: the face lacked expressiveness, the delivery was monotone, pauses fell in the wrong places, word choices were odd, the mouth movement did not match the audio, and part of the footage looped [27]. Metadata sealed it. One purportedly authentic video carried capture data indicating an iPhone 6, a device incapable of the recording the plaintiffs’ own account required [27]. The judge imposed terminating sanctions, dismissed the case on 9 September 2025 and denied reconsideration in November [26].

✓ Established Fact The first documented detection of deepfake evidence in a United States courtroom was made by a judge, not by a detection system

Judge Kolakowski identified the generated testimony in Mendones by reading the recording closely and then checking the file metadata against the plaintiffs’ own timeline [27]. No forensic tool was required and none was decisive. That is reassuring about this case and alarming about the general one, because it means the detection capability that worked was a specific judge’s attention, which does not scale, is not reviewable, and is not evenly distributed across a court system [28].

The rulemaking response has been deliberate to the point of stasis. Professor Rebecca Delfino proposed a new Rule 901(c) to shift how courts handle disputed audiovisual evidence, submitted to the advisory committee in April 2025 [29]. At its May 2026 meeting the committee concluded that an amendment was not necessary at that time, citing the courts’ existing methods and the limited number of deepfake instances actually seen in litigation, while proposing Rule 901(c) for future consideration should circumstances change [30]. In parallel, a proposed Rule 707, released for public comment until 16 February 2026, addresses machine-generated evidence [30].

Rule 707 has a structural limitation that critics identified immediately. It applies to evidence the proponent acknowledges was produced by artificial intelligence, and not to evidence whose authenticity is contested [31]. That is precisely the wrong side of the line for this problem. The party submitting a deepfake does not volunteer that it is one, and the party denying a genuine recording does not need the rule at all. A disclosure regime for acknowledged AI outputs leaves the contested case exactly where it was.

Who Pays to Prove a Recording Is Real

Certified forensic analysts bill at between 150 and 300 dollars an hour, senior examiners at 250 to 400 dollars, and a typical examination runs 10 to 20 hours, placing a single contested item somewhere between 1,500 and 8,000 dollars [33]. That cost falls on whoever must prove authenticity. In a criminal matter it lands on a defence with no budget, and in a civil matter on whichever side has less of one, which converts an evidentiary question into a resource question.

Capacity is the constraint behind the cost. A House of Lords committee in the United Kingdom raised concern about the digital forensics backlog facing police forces, where the traditional model of routing every device to a central laboratory has been failing under volume for years [34]. Adding synthetic-media analysis to that queue does not add a task. It adds a category, applied in principle to any audiovisual item any party disputes, in a system already unable to clear the devices it has.

Meanwhile the denial strategy has already been attempted at the highest level. In litigation brought by the family of a man killed while his Tesla was operating on its driver-assistance system, defence counsel sought to exclude recorded statements by Elon Musk about the safety of the technology on the basis that they might be deepfakes [28]. The attempt failed. It was made in 2023, by sophisticated counsel, against a public figure whose recorded statements are among the most widely archived of any living executive, and it establishes the move as available rather than exotic [35].

The gap the courts now sit in is therefore not doctrinal but practical. Rule 901 is adequate in principle and unaffordable in application, judicial detection works and does not scale, and the rule most likely to be adopted first covers the disclosed case rather than the disputed one. Estate and family litigation is where practitioners expect the first sustained wave, because those matters turn on recordings of private conversations with no institutional custody chain and no second copy [35]. The National Center for State Courts frames the exposure precisely: the risk is less that a court is deceived than that the public stops believing courts can tell [32].

05

The Newsroom Inversion
When verification budgets are spent proving that real things are real

During the 2026 Iran war, an authentic photograph of crowds in Tehran published by a major newspaper was widely accused online of being AI-generated, and a video of the Israeli prime minister joking about reports of his death was examined by forensic analysts who found no indication it was synthetic ✓ Established Fact [36]. Both were real. Both had to be defended.

A newsroom that cannot authenticate is a newsroom that cannot publish, and the tooling it was promised has not arrived. The Deepfake-Eval-2024 benchmark took open-source state-of-the-art detectors trained and scored on academic datasets and ran them against deepfakes actually circulating in 2024. Measured by area under the curve, video models lost 50% of their performance, audio models 48% and image models 45% against their published benchmark figures ◈ Strong Evidence [22]. Those are not marginal degradations. They are the difference between a usable signal and a coin toss.

Researchers at the Vector Institute gave the effect a name in 2026, calling it the generalisation illusion: benchmark scores stay high while real-world performance quietly declines, because a detector trained on one generation of generators does not transfer to the next [23]. Work at the University of California, Berkeley reached the same conclusion from a different direction, finding that laboratory benchmarks systematically overstate what detectors achieve in circulation [24]. Methods that generalise across fourteen benchmark datasets spanning 2019 to 2025 do exist, built on parameter-efficient adaptation of pre-trained vision encoders, but they are research results rather than deployed products, and the gap between the two is measured in generator releases [25].

Media outlets should prepare for scenarios of uncertainty, educate the public about the liar’s dividend, and avoid AI threat inflation.

— Brennan Center for Justice and the Center for Security and Emerging Technology, January 2024

The inversion is what makes this different from previous verification problems. In March 2026 an account on X asserted that a newspaper had published an AI-generated image of crowds gathered in Tehran after Iran named a new supreme leader. The image was authentic, taken by a photojournalist [36]. In the same period a video of Benjamin Netanyahu responding to claims of his own death was examined by the detection firm GetReal Security, which found no indication of generation, a conclusion corroborated by independent footage of the same event [36] [38]. Fact-checkers spent their scarcest resource proving that real material was real, while recycled footage from earlier phases of the conflict circulated as current with far less resistance [37].

Volume is the second constraint. The Deepfakes Rapid Response Force, run by the human-rights organisation WITNESS since March 2023, connects frontline journalists, fact-checkers and human-rights defenders with media-forensics specialists for case-by-case analysis [39]. Through 2025 the force reported not only the persistence of old detection problems but a sharp rise in suspected AI video, particularly after the release of two leading video models [40]. WITNESS has since published a benchmark framework arguing that detection tools should be evaluated on whether they help the people who actually need them rather than on laboratory accuracy [39]. The Columbia Journalism Review reached the practical version of the same conclusion: no available tool gives a newsroom a defensible yes or no, and the honest workflow remains provenance, corroboration and open-source investigation [41].

The Verification Tax Is Regressive

Large newsrooms can absorb a standing forensics budget, a provenance workflow and a relationship with a detection vendor. Local outlets, freelance reporters and human-rights documenters cannot. The result is that the cost of proving a record authentic falls hardest on exactly the people whose records are least likely to have an institutional custody chain, and whose material is most likely to be the only evidence of an event.

The supply side moved faster than any of this. OpenAI released Sora 2 as a free iOS application on 30 September 2025, and it recorded a million downloads in five days [65]. The application carries a visible watermark and a cameo system through which a person authorises use of their likeness and can revoke it [65]. NewsGuard tested the model against known false narratives and found it would generate convincing news-style video for a substantial share of them, which is the relevant measure for a newsroom rather than the average quality of the output [66]. A week of backlash over generated depictions of deceased public figures and of actors who had not consented then produced tighter guardrails, which is the pattern the whole sector now follows: ship, measure the outrage, restrict.

Trust data closes the loop. Global trust in news is at 37% and concern about telling true from false online is at 62% [4]. Weekly use of AI chatbots for news rose from 7% in 2025 to 10% in 2026, while trust in news delivered through those chatbots sits at 20% [4]. Audiences are migrating towards the channels they trust least, at the moment when the evidentiary standard of the underlying material is weakest. That combination, rather than any individual fake, is what makes the period structurally distinct from previous waves of media anxiety.

06

The Provenance Bet
If fakes cannot be detected, authenticate the originals instead

Five jurisdictions have now written synthetic-media rules into binding law, and every one of them has made the same wager: that marking and labelling can substitute for detection ◈ Strong Evidence [42] [45] [47]. The wager rests on an assumption about distribution that the evidence does not support.

The provenance strategy is a reasonable response to a detection failure. If no classifier can reliably say whether a file was generated, the alternative is to sign files at the point of capture or creation and treat the absence of a signature as informative. That is the design of the Coalition for Content Provenance and Authenticity, whose specification attaches a cryptographically signed manifest recording device, edits and creation history [60]. It is a genuine technical achievement and it is being deployed at scale.

Adoption in 2026 is broader than most critics expected. Seventeen camera models from Leica, Sony, Canon and Nikon sign photographs at capture, joined by at least one flagship smartphone, with the Leica SL3-S the first to ship in January 2025 and the Sony PXW-Z300 the first camcorder with native signing [62]. On the distribution side, TikTok has labelled more than 1.3 billion videos with provenance data, and YouTube, Meta and LinkedIn surface content credentials to users [63]. The signing publishers now include the BBC, Reuters, Agence France-Presse, the Associated Press, NHK and several European public broadcasters [63]. Version 2.3 of the specification, released in December 2025, extended provenance to live streaming through segment signing [64].

2019
The liar’s dividend is named — Robert Chesney and Danielle Citron publish Deep Fakes in the California Law Review, arguing that the spread of synthetic media hands a defence to anyone caught on an authentic record [1].
2021
A cloned voice enters a primary election — Two days before the New Hampshire primary, robocalls carrying a synthetic recording of President Biden urge voters to stay home. The Federal Communications Commission ultimately imposes a 6 million dollar penalty and criminal charges follow [56].
2024
The Korean school scandal breaks — Male students at hundreds of Korean schools and universities are found to be running channels distributing generated sexual images of classmates and teachers, with both victims and perpetrators frequently minors [19].
2024
The first camera signs at capture — Leica ships the SL3-S in January, the first production camera to attach a signed content credential at the moment of exposure, opening the hardware phase of the provenance strategy [62].
2025
United States federal law reaches synthetic intimate images — The TAKE IT DOWN Act is signed on 19 May, criminalising non-consensual publication of intimate images including digital forgeries and requiring covered platforms to build a notice-and-removal process [52].
2025
China turns on mandatory labelling — The labelling measures finalised in March take effect on 1 September alongside a mandatory national standard, requiring both visible and machine-readable markers on generated text, image, audio and video [45] [46].
2025
A court detects generated testimony — Judge Victoria Kolakowski dismisses Mendones v. Cushman and Wakefield on 9 September after finding that video witness testimony submitted as authentic had been produced by a generative model [27].
2025
Consumer-grade video synthesis arrives — Sora 2 is released as a free iOS application on 30 September and passes a million downloads within five days, putting news-grade video synthesis into general distribution [65].
2026
A regulator opens a platform investigation — On 12 January, Ofcom opens a formal investigation into whether X breached the Online Safety Act by operating an image tool capable of generating image-based abuse and child sexual abuse material [20].
2026
India sets a three-hour clock — The IT Amendment Rules take effect on 20 February, defining synthetically generated information, mandating prominent labels and provenance metadata, and compressing takedown windows to roughly three hours [47] [48].
2026
Removal duties become enforceable — From 19 May the Federal Trade Commission begins enforcing the platform obligations of the TAKE IT DOWN Act, with a 48-hour removal window for valid requests and known identical copies [51].
2026
European transparency obligations arrive — Article 50 of the AI Act requires providers to mark generated output in machine-readable form and deployers to disclose deepfakes, with the Commission publishing guidelines and a code of practice to operationalise it [42] [43].

Article 50 is the most consequential of the new rules because of the market it covers. Providers of systems that generate or manipulate synthetic audio, image, video or text must mark outputs in machine-readable form through metadata, watermarking or fingerprinting, and deployers must visibly disclose when content is a deepfake [43]. The European Commission has published guidelines on the transparency obligations and a code of practice on transparency of AI-generated content to give the requirement operational shape, with an interim labelling icon pending an EU-wide symbol [42] [44]. The obligations attach on 2 August 2026, although the Council has signalled a revised date of 2 December 2026 that had not been formally adopted at the time of writing [43].

China moved first and moved harder. The Cyberspace Administration finalised its labelling measures on 14 March 2025 and brought them into force on 1 September 2025 together with a mandatory national standard, imposing both explicit labels that a user can see and implicit labels carried in the file itself, on providers of generation services and on the platforms that distribute the output [45] [46]. India followed with IT Amendment Rules notified on 10 February 2026 and effective ten days later, defining synthetically generated information, requiring prominent visual labels and spoken disclosure on synthetic audio, and compressing the takedown window for court-ordered or government-notified unlawful content to roughly three hours, with two hours for non-consensual intimate imagery [47] [48].

◈ Strong Evidence Provenance metadata does not survive ordinary social distribution, which is where the content that most needs it travels

Major platforms strip metadata during upload processing as a matter of routine engineering, so the material most in need of verifiable provenance, content shared virally, is precisely the material most likely to arrive without it [60] [61]. The standards response is durable content credentials, pairing the manifest with an invisible watermark and a perceptual fingerprint so that a stripped file can still be matched back to its record [60]. That work is real and incomplete, and no watermark is secure against a determined adversary with access to the model [61].

Denmark took a different route entirely, and it is the most interesting of the national experiments. Rather than regulating the generator or the platform, it amended its Copyright Act to create a neighbouring right in a person’s voice and physical appearance, so that an individual can issue takedown notices and claim compensation without having to show reputational harm, with protection extending for fifty years after death [49]. The European Parliamentary Research Service has examined whether the approach could serve as a model for the Union as a whole [50]. It converts a speech problem into a property problem, which makes enforcement tractable and raises questions about satire, journalism and historical depiction that the statute does not fully answer.

The American response has been narrower in scope and broader in coverage. The TAKE IT DOWN Act, signed on 19 May 2025, criminalises non-consensual publication of intimate images including digital forgeries and gave covered platforms one year to build a notice-and-removal process; the Federal Trade Commission began enforcing that obligation on 19 May 2026, with a 48-hour removal window that extends to known identical copies [51] [52]. Thirty-one states had election deepfake statutes on the books by July 2026 [53]. The United Kingdom criminalised the creation of, or a request to create, non-consensual intimate images from 6 February 2026 under section 138 of the Data Act, recognising that the harm begins before distribution [67].

Where the American approach has been tested against the First Amendment it has not held. In Kohls v. Bonta, a federal judge struck down California’s election deepfake statute on 29 August 2025, finding that it discriminated on the basis of content, viewpoint and speaker, and that its disclaimer requirements for satire were so onerous as to obstruct the work itself [54]. The court was explicit that the remedy for deceptive content is counter-speech, rigorous fact-checking and the uninhibited flow of democratic discourse rather than the suppression of creation [55]. That ruling leaves labelling mandates and consent-based rights standing while narrowing the category of prohibited political speech, and it is the most likely shape of American law in this area for the foreseeable future.

07

Overblown or Underrated
The strongest version of each side, stated without hedging

The dispute over synthetic media is not between people who have read the evidence and people who have not. It is between two groups measuring different quantities, and it can be stated precisely enough to show where the disagreement actually sits ⚖ Contested [57] [59].

The sceptical case is stronger than it is usually given credit for. Felix Simon, Sacha Altay and Hugo Mercier argued in the Harvard Kennedy School Misinformation Review that fears about generative AI and misinformation are overblown, on the grounds that the binding constraint on misinformation has never been the cost of producing it [57]. Supply was already effectively unlimited; what limits reach is demand, attention and distribution, none of which generative models change. Analysis of the Slovak audio case, the example most often cited as proof that a deepfake decided an election, found the causal claim far weaker than the coverage suggested [58].

The counter-case does not dispute those findings so much as their scope. Writing in Lawfare, critics of the all-clear position argue that measuring persuasion at the level of the individual voter misses the institutional effects: what degrades is not the average citizen’s belief but the evidentiary standing of recorded material inside courts, newsrooms, human-rights investigations and employment disputes [59]. Those are the settings where a record has to carry weight against a motivated denial, and they are not measured by survey experiments on political support.

The case that the threat is overstated

The measured effect is bounded
Five pre-registered experiments on more than 15,000 adults found denial strategies ineffective against video evidence and no measurable reduction in general trust in media [2].
Supply was never the constraint
Misinformation has been cheap to produce for a generation. What limits its reach is demand and distribution, neither of which generative models alter [57].
The canonical election case does not hold
Close analysis of the Slovak audio incident finds the evidence for electoral effect much thinner than the volume of coverage implied [58].
Courts caught the first real attempt
The generated testimony in Mendones was detected without forensic tooling, and the federal evidence committee found too few instances in litigation to justify a new rule [27] [30].
Provenance is scaling faster than predicted
Seventeen camera models sign at capture, one platform has labelled 1.3 billion videos, and the specification now covers live streaming [62] [63] [64].

The case that the damage is already structural

The default has already gone
The share of surveyed adults who say they can no longer separate real from generated content moved from 66% to 85% in a single year [5].
Detection does not survive contact with reality
Against deepfakes actually in circulation, video detector performance falls by roughly half relative to the benchmarks used to validate the same models [22] [23].
Most of the harm is not mediated by belief
Non-consensual sexual imagery humiliates whether or not it is believed, and an injection attack defeats a verification system that holds no beliefs at all [17] [15].
The dividend grows with public awareness
Every warning that video can no longer be trusted raises the plausibility of the next denial, which is why education aimed at scepticism alone cannot close the gap [3].
Authentication costs fall on the least resourced
A single contested item can cost between 1,500 and 8,000 dollars to examine, in systems already carrying multi-year forensic backlogs [33] [34].

Both columns can be correct at once, and the reconciliation is straightforward. The sceptics are measuring persuasion: whether synthetic media changes what people believe about the world. The alarmists are measuring adjudication: whether a record can still settle a dispute. Persuasion is demand-limited and therefore robust, which is what the experimental literature keeps finding. Adjudication is supply-limited, because it takes only one plausible alternative explanation to stop a record from being decisive, and that is what the courtroom and newsroom evidence keeps showing.

The Two Sides Are Not Measuring the Same Thing

Survey experiments ask whether a denial moves aggregate support for a politician. Evidence law asks whether a specific recording can be relied upon by a specific decision-maker against a specific objection. A denial can fail badly at the first while succeeding completely at the second, because a judge, an editor or a human-resources panel needs only reasonable doubt about provenance to set the item aside. The literature showing small persuasion effects is not evidence that adjudication is safe.

The sharpest version of the sceptical position deserves a direct answer. If the dividend has not yet produced a documented case of a guilty party escaping through a false deepfake claim, why treat it as a present harm rather than a projected one. The answer is that the absence of documented cases is exactly what the mechanism predicts. A successful false denial leaves no artefact: the record is set aside, the matter does not proceed, and nothing enters a database. The Tesla attempt is visible only because it failed and was reported [28] [35].

What would falsify the structural case is specific and worth stating. If in-the-wild detector performance recovered to within ten points of benchmark levels and held there across two generator generations, if provenance metadata survived ordinary platform distribution at high rates, and if courts began routinely resolving authenticity disputes without specialist expenditure, the structural claim would be substantially weakened. None of those three conditions currently holds, and the second is the furthest from holding [22] [60] [61].

08

What the Evidence Actually Supports
A narrower and harder set of conclusions than either camp offers

The defensible reading is that synthetic media has not yet changed what most people believe, and has already changed what can be proved. Those are different claims with different remedies, and conflating them has produced a policy response aimed at the wrong target ◈ Strong Evidence [2] [22].

Begin with what is established. Deepfake-enabled fraud is real, industrialised and concentrated, with documented incidents rising across every independent count and the largest single category being non-consensual sexual imagery of women and girls rather than financial deception [9] [17]. Detection performance collapses when moved from academic benchmarks to circulating material, losing roughly half its measured accuracy on video [22]. The share of surveyed adults who report being unable to distinguish generated from authentic content rose from 66% to 85% between 2025 and 2026 [5]. Trust in news is at a recorded low of 37% [4]. None of these is seriously contested.

What is contested is the causal chain from those facts to political and institutional outcomes, and here the evidence supports a narrower claim than the public debate. The experimental record shows denial strategies raising politician support against text-based reporting and failing against video, with no measurable erosion of general media trust [2]. That is a real finding and it should discipline the rhetoric. It is also a finding about aggregate persuasion in 2022 and 2023, in a period when the video default was still largely intact, and it cannot be extended to adjudication or to the present distribution of synthetic video.

Structural riskSeverityAssessment
Detection fails to generalise to new generators
Critical
Detector performance against circulating deepfakes falls by roughly half relative to the benchmarks used to validate the same systems, and each new generator resets the problem [22] [23]. Procurement decisions are being made on benchmark figures that do not describe deployment [24].
Provenance is stripped in ordinary distribution
Critical
Platforms remove metadata on upload as routine processing, so the virally shared material that most needs provenance is least likely to carry it [60] [61]. Durable credentials pairing manifests with watermarks and fingerprints are the intended fix and are not yet general [60].
Authentication cost shifted to the least resourced party
High
A contested audiovisual item costs between 1,500 and 8,000 dollars to examine at prevailing rates, in jurisdictions already carrying multi-year digital forensic backlogs [33] [34]. The burden lands on criminal defendants, small outlets and individual complainants.
Evidence rules address the disclosed case, not the disputed one
High
The proposed federal rule covering machine-generated evidence applies where the proponent acknowledges AI involvement, which is never the situation in a contested authenticity dispute [31]. The rule aimed at that situation was deferred in May 2026 [30].
Regulatory fragmentation across major markets
Medium
China labels from September 2025, India from February 2026, the European Union from August 2026, Denmark through copyright, and the United States through a patchwork of thirty-one state statutes and one federal removal duty [45] [47] [43] [49] [53].

The policy implication of that distinction is uncomfortable for most current proposals. Labelling mandates, criminal penalties for creation and platform removal duties are all aimed at the fake that succeeds. They do very little for the authentic record that fails, because a label on generated content is not a signature on genuine content, and an absent label proves nothing about a file that was stripped of its metadata in transit [60]. Provenance infrastructure is the only part of the current response aimed at the right target, and it is the part whose central assumption about distribution is not yet satisfied [61].

Three measures follow directly from the evidence rather than from the rhetoric. Sign at capture, because the asymmetry between signing an original and proving a negative later is the whole argument, and the hardware base now exists [62]. Fund adjudicative capacity rather than only detection research, because the bottleneck in courts is examiner hours and judicial training, not classifier accuracy [34] [32]. And treat the burden of proof explicitly, because a regime in which any party can force an authentication proceeding by asserting doubt is a regime in which the better-resourced party wins by default [33].

There is also a narrower recommendation for the institutions that report on this subject, and it is the one the Brennan Center made before the experimental data existed. Threat inflation is not a neutral error [3]. Every confident statement that video can no longer be trusted is a transfer to whoever will next need that sentence, and the transfer is made whether or not the statement is accurate. The accurate statement in September 2026 is that most circulating video is authentic, that a growing minority is not, and that the tools to tell them apart work substantially worse in the field than in the papers describing them [22] [41].

The conclusion this report reaches is therefore narrower than either camp offers and harder than both. Synthetic media has not yet been shown to change what electorates believe, and the studies claiming otherwise are weaker than their coverage [57] [58]. It has already changed what institutions can establish, and the studies documenting that are stronger than their coverage [22] [27]. The damage runs through deniability rather than deception, it lands on adjudication rather than on opinion, and it is being addressed by a policy apparatus that has mostly not noticed the difference.

SRC

Primary Sources

All factual claims in this report are sourced to specific, verifiable publications. Projections are clearly distinguished from empirical findings.

Cite This Report

APA
OsakaWire Intelligence. (2026, September 23). The Liar’s Dividend — When Real Evidence Stops Counting. Retrieved from https://osakawire.com/en/deepfakes-and-the-liars-dividend/
CHICAGO
OsakaWire Intelligence. "The Liar’s Dividend — When Real Evidence Stops Counting." OsakaWire. September 23, 2026. https://osakawire.com/en/deepfakes-and-the-liars-dividend/
PLAIN
"The Liar’s Dividend — When Real Evidence Stops Counting" — OsakaWire Intelligence, 23 September 2026. osakawire.com/en/deepfakes-and-the-liars-dividend/

Embed This Report

<blockquote class="ow-embed" cite="https://osakawire.com/en/deepfakes-and-the-liars-dividend/" data-lang="en">
  <p>In 2026, 85% of surveyed adults said they can no longer tell AI-generated content from the real thing. The deeper damage is not deception but deniability.</p>
  <footer>— <cite><a href="https://osakawire.com/en/deepfakes-and-the-liars-dividend/">OsakaWire Intelligence · The Liar’s Dividend — When Real Evidence Stops Counting</a></cite></footer>
</blockquote>
<script async src="https://osakawire.com/embed.js"></script>