Deepfakes Are No Longer Just a ‘Spot the Fake’ Problem

Why deepfake safety is no longer just about spotting visual clues — and why verification, prevention, reporting and resilience matter more.

Community Smart Hub · AI & You Series
Published 27 September 2026 · 6 min read · No tech background needed

Deepfakes Are No Longer Just a “Spot the Fake” Problem

From 30 September, online platforms in the UK face stronger expectations to prevent illegal intimate images — including explicit AI-generated deepfakes — from spreading. Here is what that means for ordinary people, and why knowing how to respond matters just as much as knowing how to recognise AI.

Imagine opening a messaging app and discovering that somebody has created a realistic-looking intimate image of you.

The image is fake.

But the embarrassment, fear and damage it can cause are very real.

This is one of the reasons the UK’s online-safety regulator, Ofcom, is increasing pressure on online services to stop this material spreading in the first place.

On 9 September 2026, Ofcom opened a new enforcement programme focused on non-consensual intimate imagery, often shortened to NCII. From 30 September 2026, affected platforms are expected to have stronger measures in place, including automated technology known as hash matching, or to demonstrate that they have other equally effective systems for reducing the spread of this illegal content.

The rules explicitly include AI-generated intimate deepfakes. Ofcom says services that fail to meet their legal duties can ultimately face significant penalties, including fines of up to 10% of global annual revenue.

Read Ofcom’s announcement.

So what is hash matching?

Despite the name, it is easier to understand than it sounds.

Think of a hash as a digital fingerprint for an image.

A harmful image can be converted into a unique digital value. Participating platforms can then compare material being uploaded with fingerprints of images that have already been identified.

If a match is found, the platform can take action to prevent the material being uploaded or shared again.

One service already using this approach is StopNCII.org, operated by the Revenge Porn Helpline, which is part of SWGfL.

Importantly, when an eligible adult uses StopNCII, the image itself does not have to be uploaded to StopNCII. The digital fingerprint is created on the person’s device, and the fingerprint — rather than the intimate image — is shared with participating companies.

That privacy-preserving design is important.

But it also teaches us something bigger about AI safety.

Hash matching is not a magic “deepfake detector”

People are often told to look for strange fingers, unnatural blinking, mismatched lighting or distorted faces to decide whether something was produced by AI.

Those clues can sometimes help.

But modern synthetic media is becoming increasingly convincing, and relying only on visual clues is not a reliable long-term strategy.

Hash matching solves a different problem.

It does not necessarily ask:

“Was this picture generated by AI?”

Instead, it can ask:

“Is this an image we already know should not be distributed?”

That difference matters.

A completely new deepfake may not already exist in a database. A previously reported image may be easier for participating systems to recognise.

This is why protecting ourselves from synthetic media requires several layers: technical detection, provenance, source verification, platform safeguards and human judgement.

What should you do if you encounter a harmful deepfake?

  1. Do not automatically believe or forward the content. Check where it came from, who posted it and whether you can confirm the information from the person or organisation involved.
  2. Report harmful material to the platform quickly. Keep useful information such as the account name, URL, time and your reporting reference where possible.
  3. If you are an adult affected by non-consensual intimate imagery, services such as the Revenge Porn Helpline and StopNCII.org may be able to help prevent images from being shared across participating platforms.
  4. If the person affected is under 18, the UK’s Report Remove service, operated by the Internet Watch Foundation and Childline, can help young people confidentially report nude or sexual imagery of themselves, including imagery they believe has been manipulated or generated using AI.
  5. Do not assume that “fake” means harmless. Synthetic intimate imagery can still be used for humiliation, harassment, blackmail and coercion. The harm comes from what the image is used to do, not simply from whether a camera originally captured it.

Why this matters now

The technology is advancing quickly.

In August, the Internet Watch Foundation reported that 420 reports from British under-18s involving suspected faked or manipulated sexual imagery were received in just the first six months of 2026. That had already exceeded the 397 such reports received during the whole of 2025.

Read the Internet Watch Foundation update.

At the same time, highly realistic AI images and video are becoming easier for ordinary users to create.

This means digital literacy has to evolve.

Teaching somebody to recognise one generation of deepfake artefacts is not enough.

Communities increasingly need to understand:

Where did this content come from?
Can the source be verified?
Is there provenance information?
Has the account posting it been authenticated?
What should I do before sharing it?
Where can I report it?
What technical protections exist — and what are their limitations?

Those are AI trust skills, not simply computer skills.

What we are building at Community Smart Hub

This is exactly the kind of problem we want the Community Smart Hub AI Trust Lab to make easier to understand.

Rather than simply showing people a presentation about deepfakes, the aim is to let people learn by doing.

A future lab exercise could present several pieces of media and allow users to investigate them.

Instead of asking only “Is this real or fake?”, users would work through a broader verification process: examining the source, checking context, looking for provenance, considering technical signals and deciding what action they should take.

Users could then see what tools such as detection systems, content credentials and image hashing can — and cannot — tell them.

That distinction is important.

The safest internet will not be created by expecting every member of the public to become a forensic deepfake expert.

It will come from a combination of better technology, responsible platforms, effective regulation and communities that know how to verify information and respond when something goes wrong.

And that is why AI literacy increasingly needs to become AI resilience.


Community Smart Hub
Helping communities understand AI, verify what they see and use technology with confidence.

Sources

Dr Jireh Jam
Dr Jireh Jam

Dr Jireh Jam is a computer vision and AI technologist specialising in deepfake detection, synthetic media, content provenance, watermarking, age assurance, AI evaluation and online safety. He holds a PhD in Computer Vision and has led applied AI research, evaluation and public-interest technology projects, translating complex technical risks into practical guidance for communities, organisations and policymakers.

Articles: 19

Leave a Reply

Your email address will not be published. Required fields are marked *