Deepfake evidence: how courts test video and audio they can no longer trust
How forensic examiners authenticate video and audio evidence in an era of synthetic media: codec analysis, metadata review, frame-level examination, and what UK courts now expect.
For most of the last century, a recording was its own authentication. A video tape shown in court came from a camera, through a chain of custody, and if the opposing side doubted it they could examine the tape itself. That assumption is finished. Current generative models produce video and audio that passes casual inspection by trained observers, and the tools improve every quarter. The consequence for litigation is direct: the party tendering a recording now has to prove it is genuine, and the party attacking it has a real argument available that did not credibly exist five years ago.
This cuts both ways. Genuine footage of a real event can now be labelled a deepfake by a party who simply does not like what it shows. That is becoming the more common problem in practice: not fabricated evidence, but authentic evidence met with a synthetic denial. Courts need a way to resolve both directions of the dispute, and forensic practice has had to supply one.
This article describes how video and audio evidence is actually examined in professional forensic practice: what is tested, what the tests show, and what the courts in England and Wales currently expect when authenticity is challenged.
What has changed, precisely
Two things. First, generation quality. Voice cloning reached the point of convincing telephone-quality replication some years ago; video is now close behind at short durations, particularly for talking-head material, where a few seconds of a person speaking can be reanimated with different words. Second, and less discussed, awareness. The "sophisticated falsifier" argument used to require expert evidence to even articulate. Now a jury understands it from the news, which means judges must engage with it rather than treat the recording as self-proving.
What has not changed is physics and process. A real camera recording a real event carries the fingerprints of the device, the compression pipeline, and the editing history. A generated or altered recording carries different fingerprints. The examiner's job is to find them.
Container and stream analysis
Every video file is a container, typically MP4 or MOV, holding video and audio streams encoded with codecs such as H.264, H.265, or AV1. Before anyone examines a single frame, the examiner examines this structure, because it answers questions the frames cannot.
The checks include: whether the container structure is internally consistent; whether the codec profiles and parameters match what the alleged recording device produces; whether keyframe intervals and bitrate patterns match the claimed acquisition mode; and whether the duration and timestamps are coherent. A file that claims to be a continuous recording from a phone camera but has keyframe intervals no phone produces, or a variable bitrate pattern characteristic of a re-encode, has already told you something. Re-encoding is not proof of fabrication, people transcode video for innocent reasons constantly, but it is proof the file is not the original, and it shifts the burden of explanation.
Metadata, and its limits
Container metadata can record the capturing device, date, GPS coordinates, and editing software. It is the first thing examined and one of the least reliable. Metadata is trivially editable, and much of the sharing infrastructure strips or rewrites it: WhatsApp re-encodes video and discards original metadata, and platforms like TikTok and Instagram re-process every upload. The absence of metadata therefore proves little, and its presence proves little on its own. What metadata can do, when it survives, is provide testable claims: if the file says it was recorded on a specific iPhone model in a specific mode, that claim can be checked against what that device actually produces.
We cover the general problem of what metadata does and does not prove in our article on email header analysis in legal disputes; the same healthy scepticism applies to media containers.
Frame-level and signal-level examination
This is where the substantive work happens. The examiner looks inside the frames for things a generator struggles to produce and an editor struggles to hide.
For video: consistency of lighting and shadows across the scene; the persistence of fine detail, where generative models historically lose texture on things like hands, jewellery, teeth, and text; the behaviour of the scene at motion boundaries; sensor noise patterns, which are characteristic of the physical device and which synthetic video does not reproduce; and compression history, because every generation or edit leaves a re-compression signature layered over the previous ones.
For audio: the electrical network frequency, ENF, analysis where the recording environment supports it; background noise floor consistency; spectral characteristics of the voice against known samples; and the acoustic signature of the claimed recording environment. A cloned voice dropped into a different room's ambience can be detectable precisely because the room is wrong.
None of these tests is individually conclusive, and the examiner who reports a single artefact as proof of fabrication is not doing the job properly. The findings accumulate into an assessment, and the honest finding is often indeterminate: the examiner can say the file is consistent with an original recording, or shows signs of alteration, or cannot be resolved.
The reference sample problem
Most authentication work is comparative, and it needs known material to compare against. Device samples: other videos from the same phone. Voice exemplars: known recordings of the speaker. Environmental references: what the location sounds and looks like. In practice, the quality of the examination is limited less by the tools than by whether the instructing party can produce reference material. If a party tenders a recording but cannot or will not identify the recording device, the examiner can still analyse the file, but a whole class of comparison tests is unavailable, and the court is entitled to draw inferences from that.
How courts handle the issue
In England and Wales, the framework is the Civil Procedure Rules Part 35 and the criminal equivalents, with expert evidence governed by the duty to the court over the paying party. When authenticity of a recording is challenged, the normal course is disclosure of the original file, not a copy, examination by a qualified expert, and a report that states findings, limitations, and the alternative explanations considered.
Two practical points recur. First, the original file matters enormously: hash values, native container, unaltered. A party who tenders a screen recording of a video, or a file forwarded through three messaging apps, has degraded the evidence before the examiner ever sees it, and the resulting report will say so. Second, the challenge must be specific. A bare assertion that "this could be a deepfake" is not evidence; a report identifying the artefacts that support alteration, or conceding that none were found, is. Courts have shown little patience for synthetic denial unaccompanied by expert support.
Practical guidance for litigators
- Preserve originals immediately, with hash values recorded at collection, and keep the chain of custody documented from the start.
- Obtain reference material early: device exemplars, voice exemplars, and the recording environment details, while they are still available.
- Instruct an expert with genuine media forensics credentials, not a general IT expert, and instruct them early enough for findings to shape the case rather than decorate it.
- If your client's own evidence has been through messaging apps, establish that at the outset and be ready to explain the transmission history rather than have it surface under cross-examination.
- When challenging opposing evidence, be specific about what is alleged: generation, manipulation, misattribution of context, or selective editing are different claims requiring different examinations.
The deeper point is that evidence practice has caught up with the technology faster than most commentary suggests. Synthetic media has not made recordings useless; it has ended the era when a recording proved itself. What replaces self-authentication is exactly what forensic practice has always demanded: original files, documented handling, qualified examination, and findings stated with their limitations. The parties who lose these disputes are, overwhelmingly, the ones who treated the file casually at the moment it mattered, on day one.
Editorial policy: This article is written for instructing solicitors, in-house legal teams, and law-enforcement professionals. It describes how digital forensic examinations are conducted in professional practice. Nothing here constitutes instruction for unqualified individuals. All work is conducted under professional indemnity insurance and is governed by the laws of England and Wales, the Civil Procedure Rules Part 35, and the ACPO/NPCC Principles of Digital Evidence.
© 2026 SolveAssist. All rights reserved.