Audio and video evidence sits at the heart of serious cases — custody fights, harassment claims, commercial fraud — where lives and livelihoods turn on what a recording appears to show. Generative AI has crossed a line the courts must now reckon with: to a layperson, AI-generated images, video, and audio are often indistinguishable from authentic recordings, and even experts may not be able to tell whether a given file was fabricated. For a profession that has long treated the camera as a truth-teller, that is a structural problem, not a curiosity.

The problem runs in both directions at once. Anyone with a computer and an internet connection can produce a convincing fabrication quickly and at little or no cost, while the tools built to detect synthetic media are not always reliable. And the mere possibility of fabrication has a value of its own: a party confronted with genuine evidence can now claim, with superficial plausibility, that it is fake.

§ 01 · Why casual inspection fails

The mechanism matters, because it explains why looking harder does not help. Modern deepfakes are built on generative adversarial networks: two machine-learning models locked in a loop, one generating imitations of real-world data, the other trying to distinguish the imitations from authentic samples. Every cycle, the generator gets better at fooling the discriminator, and the discriminator gets better at catching it. After countless iterations, the generator’s output is not merely realistic — it has been optimized, by design, to evade detection. The inspection a fact-finder performs in the courtroom is a weaker version of a test the machine has already learned to beat.

Two consequences follow. First, unlike conventional tampering, which distorts a real event, a deepfake can fabricate an event entirely. Second, the “liar’s dividend” described by law professors Bobby Chesney and Danielle Citron (Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security, 107 Calif. L. Rev. 1753 (2019)): the more the public learns to distrust recordings, the easier it becomes for a party to disclaim authentic ones. Both directions corrode the evidentiary record.

A deepfake does not merely distort the record of an event. It can fabricate the event entirely — and its very existence lets a party disclaim evidence that is real.

§ 02 · What Rule 901 actually requires

Federal Rule of Evidence 901(a) requires the proponent of an item to “produce evidence sufficient to support a finding that the item is what the proponent claims it is.” It is a deliberately low bar — at its core a question of conditional relevance, designed to err on the side of admission and leave the ultimate authenticity determination to the trier of fact. Rule 901(b) supplies illustrations: a witness with knowledge, comparison with an authenticated specimen, distinctive characteristics, evidence about a process or system shown to produce an accurate result. Because deepfakes are difficult to detect, many will clear that bar.

That gap has produced serious amendment proposals. Paul Grimm and Maura Grossman have proposed requiring a showing of “valid and reliable” results for AI-generated items under Rule 901(b)(9), plus a new Rule 901(c): a challenger who shows the evidence is more likely than not fabricated or altered shifts to the proponent the burden of showing that probative value outweighs prejudice. Rebecca Delfino, in Deepfakes on Trial 2.0, would go further — requiring an additional showing of reliability and moving the authenticity decision from the jury to the judge under Rule 104(a). The Advisory Committee on Evidence Rules has, for now, declined to amend the rule, a deliberate wait-and-see that echoes its 2014 decision not to write special authentication rules for texts and social media. That earlier restraint aged well: courts handled blanket “my account was hacked” objections by demanding substantiation, holding that “the mere allegation of fabrication does not and cannot be the basis for excluding ESI as unauthenticated as a matter of course.”

§ 03 · What the early cases teach

Huang v. Tesla, the California suit arising from a fatal Autopilot crash, tested the liar’s dividend directly. The plaintiffs cited a 2016 video of Elon Musk saying a Model S and Model X “can drive autonomously with greater safety than a person. Right now.” Tesla’s lawyers suggested the video might be a deepfake because public figures are frequent deepfake targets. The court refused, warning that on that theory public figures could “hide behind the potential for their recorded statements being a deep fake” to disown what they actually said, and ordered Musk to testify. The lesson: a bare deepfake claim, without substantiation, buys nothing.

Mendones v. Cushman & Wakefield, Inc., No. 23CV028772 (Cal. Super. Ct., Alameda Cnty. Sept. 9, 2025), shows the other half. The court noticed that video exhibits offered on summary judgment carried the tells of synthetic media — absent facial expressions, a looping feed — and ordered the plaintiffs to produce full provenance: file formats, creation and modification dates, capture device, lens, shutter speed, and the identity of the camera operator. The metadata did not hold up; the court concluded material metadata had been added after the fact, found the exhibits AI-generated, and dismissed the case with prejudice. The lesson: provenance interrogation works when the court asks the right questions.

And in Hohsfield v. Staffieri, a plaintiff who claimed an incriminating still image was “photo shopped” or made with a “deep fake app” lost on the totality of the circumstances: the contemporaneous witness report and the officers’ own observations defeated the bare allegation. So far, courts are treating deepfake evidence and deepfake objections with the same healthy skepticism.

§ 04 · An authentication protocol

The cases point toward a methodology counsel and courts can adopt now, without waiting for a rule change. (1) Interrogate provenance, not appearance. Demand the metadata record — creation and modification dates, capture device, editing history — and the identity of whoever operated the camera, as the Mendones court did. (2) Compare and corroborate. Test the recording against authenticated specimens, distinctive characteristics, and the surrounding circumstances; a genuine recording rarely exists in a vacuum. (3) Require substantiation for challenges. A party crying deepfake should bear the burden of producing evidence supporting the claim, exactly as courts required for hacking claims. (4) Budget for forensic expertise early. Proving a file authentic or synthetic takes specialized digital forensics; qualified experts are scarce and the analysis can cost tens of thousands of dollars, in a system where discovery of electronic evidence already accounts for 20 to 50 percent of litigation costs. (5) Consider a technical neutral or special master. Where authentication issues loom large, a neutral experienced with generative AI needs less briefing to get up to speed, relieves the court of sorting dueling experts, and tends to produce fairer, more accurate results at lower cost. (6) Train the bench and the bar. Judges and lawyers need not become forensic examiners, but they need enough baseline AI literacy to ask the right questions — a continuing-education requirement on AI, along the lines of New York’s cybersecurity CLE requirement, is overdue.

The legal system has absorbed the doctored photograph, the forged letter, and the hacked account without abandoning its rules of evidence, and the early returns suggest it can absorb the deepfake too — but only if the people running it change how they look at a recording. Interrogate the file, not the image. Authenticate the source, not the impression.

Draws on Daniel's writing on authenticating AI evidence under Rule of Evidence 901 and on deepfakes in family courts, the latter co-authored with Karen Silverman.