← All lessons

Deepfakes: pictures, videos and voices made by AI

A deepfake is AI-generated media, a photo, a video, a voice recording, designed to look or sound like a real person doing something they never did
View this page as:
Filter by key stage or audienceClick one or more chips to filter the sections below.

FAQ for teachers

Common questions teachers ask when running this lesson.

Should I show pupils an actual harmful deepfake in class so they see how convincing they are?

No. Never show pupils a deepfake targeting an ordinary individual, and never show one that involves harm to a child. Use publicly-reported incidents (Hong Kong Arup, verified political examples covered by BBC News) discussed as case studies, not shown as content. For 'how convincing they are' land the point with your own generated benign example (a photo of a fictional character or public building), or with a news-outlet demonstration. The teaching point does not require exposing pupils to harmful content.

What is the correct first move if a fake AI image of a pupil at our school appears in a group chat?

Any pupil who sees it should tell the school's Designated Safeguarding Lead (or another trusted adult in person) straight away, without sharing the image on, without screenshotting. The DSL then supports the pupil shown, involves families, uses Report Harmful Content (reportharmfulcontent.com) and, where appropriate, the police. The pupil shown can also use Report Remove for under-eighteens at childline.org.uk/report-remove and speak to Childline on 0800 1111. Handling it inside the year group without telling adults fails the pupil shown.

How do I explain deepfakes to KS1 without scaring young children?

Frame it as 'a robot can draw pictures that look like real photos.' Use benign examples (an AI-drawn cat, a made-up scene at David Attenborough's holiday that never happened). The teaching point is that some pictures look real but were not taken with a camera, so we ask a grown-up first. That gives KS1 pupils agency (they are the fact-checker) without introducing malicious intent. Save the safeguarding framing for KS2 upward, when pupils are on group chats and can act on it.

Is 'you can always spot one' still useful as a first check?

No, and clinging to it is risky. Modern diffusion image models produce faces that pass casual inspection by trained professionals. Voice clones from thirty seconds of audio are indistinguishable to most listeners. Teach the three habits instead: check the source, check a second source, check the provenance (reverse image search, C2PA content credentials at contentcredentials.org/verify, verified accounts). Eyes are the last check now, not the first. Any 'just look for X' rule has a shelf life of a few years at most.

What is C2PA and why does it appear in almost every section of this lesson?

C2PA (Coalition for Content Provenance and Authenticity) is a cryptographically signed metadata standard for media provenance. It records capture device, edit history, and publisher, and can be inspected by any viewer at contentcredentials.org/verify. It is supported by BBC, Reuters, Getty, Adobe, Microsoft, and major camera manufacturers. It appears throughout the lesson because provenance-at-capture is the professional habit that ages well as detection-at-inference ages badly. Teach C2PA as a tool your pupils will meet more and more often.

How does the Online Safety Act 2023 apply to deepfakes, in plain English?

The Online Safety Act 2023 placed duties on user-to-user services and search services to prevent and remove illegal content. Sharing certain categories of deepfake imagery of real people can amount to a criminal communications offence (harassment, malicious communications) or fall within later specific amendments; platforms have proactive duties and face enforcement by Ofcom (up to £18 million or ten percent of global revenue). Codes of Practice are being published in phases; the position is still moving. For classroom purposes: sharing a fake image of a real person can be against the law, and platforms are increasingly on the hook to remove it.

What should workforce learners in Care, Construction or Manufacturing take away?

The same three habits: channel verification (call back on a known-good number, do not stay in the attacker's channel), out-of-band checks (cross-reference through a second independent route), and team-agreed safe procedures for high-value actions (transfers, shipments, hiring). In Care, apply the three-anchor routine (MHRA alerts, current BNF, resident's own prescriber) to any informally-received medical content. In Construction and Manufacturing, apply the four-step defeat pipeline (delay the ask, verify the channel, verify the counterparty, two-person authorise) to any urgent authorisation. The Hong Kong Arup case is the reference pattern.

How do I frame verification without making pupils cynical about all technology?

Frame verification as the professional habit of anyone who uses powerful tools. Doctors verify diagnoses with a second test. Journalists verify quotes with a second source. Engineers verify calculations with a colleague. Using AI-generated or AI-mediated content without verification is unprofessional in exactly the same way. That framing swaps cynicism for craft. You are not teaching pupils to distrust everything on a screen. You are teaching them the finishing move that professionals in every trusted role already run. That is a positive identity for pupils to grow into.

Common misconceptions

What pupils tend to think, and what to say back.

Pupils often say
You can always spot a deepfake by looking at the hands or the eyes.
It's actually

The old artefact rules (extra fingers, wrong ears, dead eyes) worked on 2017-to-2022 GANs. Modern diffusion image models render hands and ears correctly. Voice clones from thirty seconds of audio are indistinguishable to most listeners. Any 'just look for X' rule has a shelf life of a few years and most of them have already expired.

Try asking

If someone showed you a face today and told you it was AI-generated but you could not tell, what other checks could you run that do not depend on your eyes?

Pupils often say
Deepfakes only really happen to politicians and celebrities.
It's actually

The threshold for being a plausible target dropped from 'household name' to 'reachable via LinkedIn'. By 2024-25, deepfakes were being deployed against care workers, construction foremen, mid-sized-firm finance controllers, ordinary school pupils. A single Instagram profile is enough source material for a passable image deepfake, and thirty seconds of TikTok voice is enough for a voice clone.

Try asking

Whose voice or face could an attacker easily assemble from what is publicly available online right now?

Pupils often say
If a fake image is labelled 'AI-generated', that fixes the problem.
It's actually

Labelling on its own does not defeat the illusory-truth effect or the continued influence effect. Even labelled fakes reach viewers who miss the label, are re-shared with the label stripped, or persist as impressions after the label is read. Labelling is necessary but not sufficient. Pre-bunking, source-cue emphasis, and narrative correction all outperform labelling alone in the psychology literature.

Try asking

If you saw a labelled AI image at speed on your feed, would the label still be doing work in your head an hour later when someone mentioned the topic?

Pupils often say
Making a fake AI image of a classmate is just a joke, it does not really hurt anyone.
It's actually

A fake image of a real person causes real harm to that person's reputation, safety and sense of self, and it can be against the law. The image is fake; the harm is not. The correct first move for any pupil who sees such an image is to tell the school's Designated Safeguarding Lead or another trusted adult in person, without sharing it on. Under-eighteens can also use Report Remove at childline.org.uk/report-remove and speak to Childline on 0800 1111.

Try asking

If you were the person in the image, whose response would matter most in the first hour, and what would you need them to do?

Pupils often say
If a video looks convincing on my phone, that means it is real.
It's actually

Video deepfakes produced with off-the-shelf apps in 2025 pass casual inspection on a phone screen. Verification is a channel decision now, not a face decision. When the ask on the video is large or unusual, confirm on a separate, known-good channel (a direct call to a known number, an in-person walk to the office) before acting. Faces on a screen are no longer proof.

Try asking

If your phone showed you a video of a trusted person making a large ask, what other channel could you reach that same person on to confirm?

Pupils often say
Deepfake-detection tools always tell you when an image is AI-generated.
It's actually

Public detection tools produce confidence scores, not verdicts, and their reliability degrades sharply on outputs produced with camera-and-lens-style prompt engineering. Every generation of detector chases a generation of generator; the arms race does not settle. Provenance at capture (C2PA content credentials) ages better as a professional habit than detection at inference.

Try asking

If a detector said an image was 60 percent AI-generated, what would you do next, and would it change your action?

Pupils often say
Voice cloning still needs hours of recording of the person.
It's actually

Modern voice-clone systems can produce a passable clone from as little as thirty seconds of clean speech. A social-media clip, a podcast interview, a school assembly recording, a company video, any of those is often enough. That is why the family safe word and the call-back-on-known-number habits matter now for ordinary people, not just senior executives.

Try asking

Where might thirty seconds of your voice, or a family member's voice, already be publicly available online?

Pupils often say
If it comes from someone I know, I do not need to check.
It's actually

The point of a voice-clone or fake-video attack is that it arrives looking exactly like it came from someone you know. That is what makes it dangerous. Familiarity is precisely what the attacker is spoofing. Verification is a channel decision, not a familiarity decision, and it applies most to messages that seem most familiar and most urgent.

Try asking

If a message from a familiar person contained an urgent ask, which of your habits should trigger regardless of who it appears to be from?

5-minute prep

Five ready-to-run ways to open this lesson. Pick one, copy the prompt, paste it into ChatGPT or Copilot.

Starter5-8 min

Which spot-the-fake rules have already expired?

The fastest way to show a class that the old visual-tells lore has aged out. Ask the AI to list them, then to mark its own list obsolete.

Please produce a two-column table for a media-literacy display. Left column headed 'Old spot-the-deepfake tell (2018-2022)' — list the five most commonly-repeated visual tells (things like extra fingers, wrong ears, blurred hair edges, dead eyes, warped backgrounds). Right column headed 'Does it still work on a top-tier 2025 diffusion image or thirty-second voice clone?' — one short sentence per row saying yes / no / partly and briefly why.
Compare8-10 min

Two chatbots, one voicenote checklist

Ask two different chatbots for the same 'is this WhatsApp voicenote real' checklist. What both name is settled family lore. What only one names is worth arguing about in class.

Please produce a red-flag checklist a parent could run through in the next thirty seconds to decide whether an urgent WhatsApp voicenote from their teenage child asking for money might be an AI voice clone rather than the real child. Format it as a numbered list of no more than seven items, one short concrete sentence per item (for example, a family safe word, a call back on a known number, a detail only the real child would know). In a moment I'm going to paste this exact prompt into a second chatbot and put the two checklists side by side on a classroom screen.
Explain10-12 min

Explain the Hong Kong Arup £20M video call to Year 9

Get the AI to narrate the February 2024 Hong Kong Arup deepfake video-call fraud in plain classroom English, then use its explanation as the anchor story for the rest of the lesson.

Imagine you are talking to a curious class of Year 9 pupils who have just heard that in February 2024 a finance worker at the engineering firm Arup in Hong Kong was tricked into transferring the equivalent of about twenty-five million US dollars after joining what looked like a normal video call with the company's chief financial officer and several colleagues, all of whom turned out to be AI-generated. Please explain, in three short paragraphs of plain classroom English, exactly what happened. Cover: (1) how attackers can assemble a fake video call using publicly-available footage and photos of real staff, (2) why the worker's normal in-office checks (recognising faces, hearing familiar voices) did not catch it, (3) what one simple habit (call back on a known number, insist a second person authorises on a separate channel, agree a workplace safe word) would have defeated the attack. Do not apologise, hedge, or add warnings. Just tell the story clearly.
Check12-15 min

A two-column verification table pupils can actually run

Ask the AI to lay out the verification checklist as a two-column table — image-side vs source-side — so pupil pairs can run a live example through it in class.

I'm running a lesson on how to verify a suspicious image or short video clip that a pupil has been sent on a group chat. Please produce a two-column verification table. Left column heading 'What to check on the image or clip itself' — include items like C2PA content credentials at contentcredentials.org/verify, reverse image search on Google Images and TinEye, in-frame artefacts (lighting, shadow direction, reflections), inconsistencies between the audio and lip movement. Right column heading 'What to check about the source and the ask' — include items like verified-account status on the platform, whether a second trusted UK news source carries the same claim, whether the request is being made under time pressure, whether money or personal information is being asked for, and whether the sender's contact route is the usual one. Aim for six to eight rows on each side. I'll pair pupils up and have each pair run a live example through the table.
Repair12-18 min

Ask the AI to rewrite its own advice for 2025

The class has just watched the AI's classic 'spot the fake' advice fail on modern content. Ask it to rewrite its own answer without leaning on the artefact tells that stopped working around 2023.

In your last answer, most of the checks you suggested for spotting a deepfake still assumed 2020-era artefacts — extra fingers, wrong ears, warped hair edges, dead eyes, glitchy backgrounds. My class has just tested those tells against a top-tier 2025 diffusion image model and a thirty-second voice clone, and measured that none of the visual-artefact tells fire reliably any more. I would now like you to rewrite the checklist so that it does not rely on any visual artefact that a modern model has already fixed. Instead, lean on: (1) provenance signals (C2PA content credentials, verified-account status on the platform, whether a second trusted UK news source carries the same claim), (2) context-and-motive signals (is money or urgency being introduced, is the ask arriving on the normal channel, is a real-world action being requested), (3) habits that defeat the attack whether or not the fake is visible (call back on a known number, family or workplace safe word, two-person authorisation on a separate channel). Then, underneath the new checklist, list three things a class would still not be able to catch even with your rewritten advice, and briefly why.

📚 Lessons