
A private investigator in Baton Rouge submitted a social media screenshot as evidence last month. The judge asked one question, 'Did you verify this wasn't generated by A.I.?' She hadn't. That question is now the standard in Louisiana, and it's spreading. India's parliament just proposed mandatory identity verification for every social media and dating platform, plus fast-track courts built specifically to prosecute deepfake fraud.
According to ComplianceHub.Wiki, forty-seven U.S. states now have deepfake legislation on the books. Over eighty percent of those laws passed in just the last two years.
The new professional standard isn't 'assume it's real.' It's 'prove you checked.' And if you can't show documentation, you're not thorough, you're negligent.
But proving you checked only matters if the rules let you keep the evidence at all.
A defense attorney in Alameda County stood up last year and said two words about a photograph, 'prove it's real.' The court threw out the testimony connected to that image. That's not a hypothetical. That happened. A proposed federal rule, Rule 901(c), would formalize that exact move. If someone challenges your photo or video as a deepfake, you'd have to affirmatively demonstrate authenticity or lose the exhibit entirely.
The University of Baltimore Law Review put it plainly, generative A.I. 'undermines trust in litigation by rendering all evidence potentially suspect.'
By next year, 'I'm confident this image is real' won't be a legally defensible answer. Documentation will be. The investigators who have it will win. The ones who don't will watch their cases collapse.
And if courts can't trust photos anymore, what about the thing we trust even more, a familiar voice?
A finance worker at the engineering firm Arup joined a video call with his CFO and four colleagues. He recognized every face. He knew every voice. He wired twenty-five million dollars. Every person on that call was fake, generated in real time from public recordings. The video got the headlines. But the voice is what closed the deal. Modern cloning tools need just three seconds of audio, a voicemail, a LinkedIn clip, a podcast intro.
According to SQ Magazine, voice phishing attacks surged four hundred and forty-two percent last year. Among people who received a cloned-voice message, seventy-seven percent lost money.
A matching voice isn't identity confirmation anymore. It's the attack itself. If your verification ends at 'I heard them,' you're not catching fraud, you just haven't been targeted yet.
Three stories. One thread. Courts don't trust photos. Investigators can't trust voices. Platforms can't guarantee the identities behind their own accounts. Every channel we used to rely on for 'that's really them' is now compromised, which means the only verification that holds is one the attacker never got to touch.
Links to every story and today's podcast deep-dives are in the description. See you next time.