A missing stamp is not proof of authenticity. The blood detector in the pixel is not a lock.

For image and video, the signature of origin and laboratory artifact can be verified, not the truth of the scene. Czech law punishes certain handling of a fake likeness, not the set itself.

A missing stamp is not proof of authenticity. The blood detector in the pixel is not a lock.
Editorial illustration created with AI assistance.For image and video, the signature of origin and laboratory artifact can be verified, not the truth of the scene. Czech law punishes certain handling of a fake likeness, not the set itself.
Evidence record

Evidence passport

Sources and checks
22 sourcesSources checked:
Publication and updates
Published: Updated: Not stated
Correction history
0 corrections
Role of AI
Not stated
Reading time
27 min read
Listen
00:0000:00
Advanced controls
1.00 ×
Ready
Evidence record

Conclusion at a glance

What is established

For image and video, the signature of origin and laboratory artifact can be verified, not the truth of the scene. Czech law punishes certain handling of a fake likeness, not the set itself.

What remains uncertain

A demonstrated technical capability alone does not establish real-world adoption, error rates in another setting or effects on particular people.

What would change the conclusion

An independent audit of the deployed system, reproducible measurement in a matching setting or new real-world impact data would change the conclusion.

Article contents
  1. A journalist, a detective and a public prosecutor do not deal with the same photo
  2. One scene on the display has at least six layers
  3. C2PA tells who claimed the origin. It does not say that the scene occurred
  4. DFDC left the detection open. No one has reached seventy on the black-box
  5. Screenshot drops the manifest. Does not match the event
  6. There is still no public prosecution under the new sections

Section: Technology & AI | Justice & right Author: IN Reading Length: ~27 min Sources and further reading: 22 items Topics: deepfake, C2PA, Content Credentials, video detection, photos, AI Act, criminal code SEO / Working Title: Deepfake: How to spot a fake video or photo?

The question is: how to recognise a fake video or photo? It sounds simple until we notice that we are not comparing one thing. A missing Content Credentials stamp is not proof of authenticity. C2PA says who claimed the origin, not that the scene occurred in the world. The "blood in the pixel" detector is not a forensic conclusion on Instagram. Designation under the AI ​​Act is not a criminal prosecution of the offender. Only when these four things are separated can the signature, laboratory and amendment be readof the Criminal Code as of September 2026 really holds — and what the eye that hit by chance does not hold.

This text does not solve the voice. Phone call, synthetic voice and payment belong to another article. Nor does it address the broader question of whether a photograph alone is sufficient as evidence in a court of law; this is a separate text on photography as evidence. Here is a more practical question: what to do with a file that lies on the display and looks like an image of the world.

1. A journalist, a detective and a public prosecutor do not deal with the same photo

Let's imagine an editorial meeting on a day when a short political video goes viral. The editor wants to know if he has an obvious label under the AI ​​Act. The graphic designer is looking for Content Credentials. A forensics enthusiast launches a detector that promises to detect synthetic video based on subtle color changes in a face. The lawyer asks whether it is defamation, fraud, interference with the likeness or a new factual basis in the criminal code. The reader writes in the comments that it "at firstthe sight sees".

At first glance, it is a dispute whether the video is genuine. In reality, everyone is holding a different object. The editor deals with the obligation of labeling towards the audience. The graph resolves the cryptographic manifest in the file. The enthusiast solves the statistical signal in the image. The lawyer deals with the handling of the likeness, intention and consequence. The reader deals with impression.

Therefore, they can all be partly right and the common verdict still wrong. Video can be unmarked and still genuine. It can have a valid manifesto and yet not capture what the viewer infers from the headline. It can pass through a laboratory detector and still be only poorly compressed. It may be clearly synthetic and yet may not fulfill a specific crime.

Therefore, the first rule of practical detection is not: find the best detector. It reads: specify a layer. For the signature, we ask whether the file carries a verifiable manifest. At the detector, we ask what population it was tested on. At law, we ask what someone did with the image. With the human eye, we ask whether it even has a chance to distinguish what it claims.

A missing stamp is not proof of authenticity.

— Jiný Kontext

2. One scene on the display has at least six layers

One picture on the phone looks like one thing. She is not. It is the result of a chain in which sensor, container, modifications, distribution, labels, algorithmic interventions and legal consequences mix. When these layers are mixed, a false certainty is created: the metadata is missing, so it's a fake; the detector showed a high score, so it's done; there is no sign, so the law is broken; the image looks weird, so it's AI.

Six layers of one scene:

  1. Sensor and container. Camera, phone, social network, messenger, screenshot and compression. Each step can preserve, change, or discard metadata.
  2. Generator or modification. Face-swap, GAN face, image model, video model, manual retouch, cut or regular filter. Not every edit is a deepfake and not every deepfake is the same.
  3. Detection signal. Visual artifact, biological rhythm in the face, watermark, machine metadata, network trained on a specific set.
  4. Distribution. Editorial publication, advertisement, private message, campaign material, anonymous repost. The same file in a different channel means a different responsibility.
  5. Designation. Machine-readable provider marking and obvious deepfake marking to the audience under Article 50 of the AI ​​Act are two things [6][7].
  6. Right after the deed. Penal Code, Civil Code and Privacy consider conduct, consent, harm, intent and context, not just pixel structure [9][10][22].

This layering is no pun. Changes who to ask on failure. If the manifest is lost, the screenshot may have dropped it. If the detector screams, it may be seeing the wrong light. If the work is unmarked, we don't yet know who published it and in what mode. When it comes to false likeness, the law will not only ask about the technique of creation, but about the treatment of the person depicted.

Illustrative diagram: Signature, detector and right are three columns. There is no "it's fake" arrow leading between them. In each column there is a different question: is the manifest valid, what set was the signal verified on, what action happened.

3. A missing stamp is not proof of authenticity

Content Credentials are sometimes described as the digital birth certificate of an image. It's a useful shortcut if we know where it ends. A C2PA manifest can carry claims about origin, modifications, and signed content. But most common files don't need to have such a manifest at all. The phone didn't add it. The social network dropped him. Messenger recalculated the image. Someone took a screenshot.

The absence of a stamp is therefore not a suspicion in itself. It is often the default state. If a file from a regular phone doesn't carry C2PA, it doesn't mean it was generated by artificial intelligence. If an image has lost metadata along the way through the chat, it doesn't mean the original scene didn't happen. It just means that the particular file we're holding doesn't carry a verifiable manifest.

This is inconvenient for the editor, but more accurate. The public census of how many news visuals in the Czech Republic as of September 2026 carry valid Content Credentials does not have a dossier. Without such a measurement, it is not possible to make a rule about Czech media traffic from the absence of a signature. It can only be said that the signature helps where it is present and where the chain of trust sits.

So the practical question is not whether the image "has a stamp of authenticity." It reads whether there is a verifiable origin signature for a particular file and what exactly it is signing. Absence is a signal for caution. It's not a judgment.

4. C2PA tells who claimed the origin. It does not say that the scene occurred

C2PA is a technical specification for provenance. At its core, it works with manifest, claims, claim and signature. If the file carries a manifest and the chain of trust fits, the verification can tell who signed a certain assertion about the content and whether the signed part has changed since then [1][2][3].

That's a lot. It's not all. The May 2025 specification 2,2 does not explicitly grant a value judgment of "good" provenance [1]. It does not say: this scene happened. It doesn't say: the label is true. It doesn't say: the person shown has consented. Nor does it say: any later viewer understands the context. C2PA can improve the trace of provenance, but it does not turn an image into evidence without additional work.

Let's imagine a photo from a demonstration with a valid camera manifest. A manifest can confirm that a file originates from a particular device and has not been modified after signing in a way that survives the signature. However, it does not answer by itself whether the caption correctly named the place, whether the picture is not from another day, whether the cut-out does not obscure the surroundings and whether the person in the foreground was doing what the text attributes to them.

The opposite error is equally dangerous. If the manifest is missing, it is not automatically a sign of tampering. If a manifesto exists, it is not automatically a sign of truth. The correct reading is narrower: C2PA is a layer of trust in certain claims about the origin and integrity of a file. C2PA is not a deepfake detector.

5. SynthID is not a Content Credential

In addition to manifests, there are watermarks. Google DeepMind describes SynthID as a technology that embeds a digital watermark in the outputs of selected models [19]. OpenAI announced C2PA and SynthID layering for image content in May 2026 and added audio in the July 2026 update; this text sticks to the image and video [20].

The difference is substantial. Content Credentials carry a structured assertion and signature in a container. A watermark is a signal embedded in the content. It can survive some transformations better than metadata, but usually carries less context. It can tell that the output is probably coming from a certain system involved. He cannot describe the entire chain of editing, the source of the image, the consent of the person, or the veracity of the scene on his own.

OpenAI cites metadata loss by screenshotting, re-encoding or container cropping as a reason to layer watermarks with C2PA [20]. This does not mean that the watermark is a lock. It works for the generators involved and according to the properties of the specific implementation. Content from a different model, manual edit, older file, or regular photo without that technology may not be readable.

It's not a "metadata vs. watermark" dispute. They are two different layers. The manifesto gives context and signature where it survived. Watermark gives the signal where it was inserted and where the detector can read it. Neither alone answers the question of what happened in the world.

6. Eye at GAN face hit chance

The human eye is good at many things. Can read expression, mood, intent, social cues. That's why we often trust him more than he deserves when it comes to synthetic faces. A 2022 study by Nightingale and Farid in PNAS tested the discrimination between real and StyleGAN2 faces. In the first experiment, 315 participants judged 128 faces out of 800 items, where 400 were real and 400 were synthetic. The mean correctness was 48.2 percent, with a 95% confidence interval of 47.1 to 49.2percent [13].

This is close to coincidence. The number measures the binary role of "real vs. synthetic" for static faces in a particular experiment. It does not measure video, Czech feed, current diffusion models or the ability to evaluate the entire context of the image. This is precisely why it is useful: it does not say that people will never know anything. He says that the certainty of the gaze is a bad detector.

The authors also tried training with feedback. In the second experiment, 219 new participants scored 59.0 percent, with a 95% interval of 57.7 to 60.4 percent [13]. This isn't a tutorial on how to hunt synthetic faces at work either. Between the first and second halves of 64 faces, the accuracy did not increase: 59.3 against 58.8 percent. The test shows that even short training has a limited effect.

This does not mean that visual inspection has no value. It follows that the eye belongs at the beginning of the question, not at the end. When something seems weird, it's wise to stop sharing and look for another channel, source, original and context. It is not reasonable to point to a colleague's face and say: I recognised AI.

7. Ninety-six percent on FaceForensics is not an Instagram lock

Intel introduced FakeCatcher as a real-time deepfake detector in November 2022 and stated a 96% accuracy rate in the product line [15]. Academic work by Ciftci, Demir and Yin describes the detection of synthetic portrait videos using biological signals, particularly subtle changes related to facial blood flow. It reports 96 percent accuracy on the FaceForensics dataset, 94.65 percent on FaceForensics++, 91.50 percent on Celeb-DF, and 91.07 percent on the authors labeled "in the wild" Deep Fakes Dataset [14].

These are specific results on specific sets. It's not a locked door. Accuracy is not the same as false positive rate in traffic. FaceForensics is not Instagram 2026. A well-lit portrait video is not a dark concert clip. The signal in the frontal face is not a profile, makeup, low fps, heavy compression or a newer generator that learns to imitate or blur a similar rhythm.

Moreover, a marketing phrase without a slice of datasets and without an operational population easily slips into misuse. If someone says "the detector has 96 percent", the question is missing: on what, when, with what threshold, with what proportion of false alarms and at what damage? For editorial decisions, a false alarm is expensive. Labeling a genuine video as fake can be just as damaging as sharing a fake as genuine.

The rPPG detector is therefore not a forensic conclusion. Can be a hypothesis for a portrait video if we know the conditions and limits. It should not stand alone in the "true/false" column. Without independent evaluation on current generators, with a calibrated false positive rate and real channels of distribution, this is an auxiliary clue, not a verdict.

8. DFDC left the detection open. No one has reached seventy on the black-box

The Deepfake Detection Challenge was useful precisely because it showed the difference between a known set and a hidden test. According to Meta AI, the challenge had 2,114 participants and over 35,000 models. The dataset described by Dolhansky and colleagues contained more than 100,000 clips with 3,426 paid actors [16][17]. This is a large but still concrete construction.

On the public set, Meta puts the figure at 82.56 percent, while communication fluctuates between accuracy and average precision [16]. On the black-box set, the best participant, Selim Seferbekov, achieved 65.18 percent; none reached 70 percent [16]. The number measures a specific 2020 challenge, not today's internet. Its value is in the distinction: performance on known data does not imply generalization to unseen forgeries.

This is the heart of the detection problem. Generators change. Compression varies. Publishing channels are changing. The detector can learn a trace of the dataset instead of a general spoof signature. In the laboratory, it works precisely and in operation it meets another world.

NIST GenAI Image-D publishes a schedule and metrics such as AUC, EER, TPR at a given FPR and Brier score in bins; at the same time, it prohibits participants from making advertising claims about the ranking [18]. That is reasonable restraint. As of September 2026, there is not a single "NIST verified 96 percent in the wild" primary number in the dossier. If such a sentence is circulating somewhere, there is no support for it in this text.

9. Designation under the AI ​​Act is not a criminal prosecution

The AI ​​Act introduces transparency obligations, not a new one-size-fits-all police detector. Article 3 point 60 defines deepfake cumulatively: it must be content that resembles existing or plausibly existing persons, objects, places, entities or events and must falsely appear to be authentic or true [6]. Article 50 then differentiates the obligations of providers and introducing entities [6][7].

From 2 August 2026, Article 50 shall apply; for systems placed on the market before this date, machine marking according to paragraph 2 is postponed until 2 December 2026 [7]. The Commission also states in its FAQ of 24 July 2026 that content created before 2 August 2026 does not need to be retroactively tagged [7]. As of 31 July 2026, the CTU drew attention to the applicability of transparency rules and referred to the Code of Good Practice [8].

This data measures the usability of the duties, not the authenticity of the file. A deepfake mark to the audience under Article 50(4) is not the same as a machine-readable provider mark under paragraph 2. Furthermore, the Commission states that the misleading entity should not rely solely on the machine-readable mark of the provider [7]. When the editors publish a synthetic or edited visual, they fulfill their own duty to the reader. When an offender uses an image to defraud, it is difficult to expect him to fulfill his duty honestly.

FAQ The Commission sets a penalty ceiling of up to €15 million or 3 percent of global turnover, whichever is higher, with proportionality for SMEs for breaches of transparency obligations [7]. That's a cap, not a tariff for an untagged meme. And most importantly: the transparency sanction regime is not a criminal qualification of a specific harm.

10. The non-consensual pornography section is not a political video section

Czech Amendment No. 270/2025 Coll. is effective from 1 January 2026 and adds, among other things, § 181 paragraph 2 and new § 191a to the Criminal Code [9]. This is a substantial change, but also a frequent source of shortcuts. The new § 191a refers to the production and dissemination of a pornographic work exploiting a person without their consent. The basic facts indicate a rate of up to 2 years of imprisonment [9].

This number measures the statutory rate of the underlying offense as of 1 January 2026. It does not measure the number of convictions, does not account for every synthetic image, and does not apply to a non-pornographic political video simply because it was created or edited by artificial intelligence. The handling of the work, the nature of the content and the consent of the depicted person are important.

Section 181(2) aims at false likeness or expression with the intention of causing serious damage to the rights [9]. That's a different construction. Satire and art are not automatically criminal. Likewise, not every bad label is a crime. The law assesses specific circumstances.

It does not follow that the technology is a legally neutral toy. It follows that "deepfake" is not one paragraph. An image can be a tool for sexual abuse, defamation, fraud, invasion of privacy or a civil dispute over an image. One detection app won't make the difference.

11. Slander and fraud punish falsehood and consequence. Not a file

The Criminal Code recognises defamation in § 184, fraud in § 209 and unauthorized handling of personal data in § 180 [10]. The Civil Code protects likeness and privacy in Section 84 et seq [22]. Deepfake can be a means. It is not automatically factual.

This sounds legal, but in practice it is a simple brake. If someone shows a video and asks "is it criminal?", it's not enough to answer whether the image is synthetic. It is necessary to know who created it, who distributed it, what it claimed, who it caused harm to, whether it was a pornographic work, whether there was consent, whether there was an intention to cause serious harm, and whether there was a financial or other consequence.

The detector does not construct the actual substance from the pixel. It can give an incentive for caution, it can help the editors not to publish quickly, it can be one clue for professional assessment. It cannot replace a legal qualification. Just as a valid C2PA manifest is not a substitute for a person's consent to disclosure, a high detector score is not a substitute for proof of intent.

The practical recommendation is therefore less spectacular but more solid: if harm is suspected, stop distribution, preserve the available file and context, verify with a second channel, and leave the legal qualification to reporting and law enforcement. The article does not link a specific video to a specific paragraph. It shows why it can't be done from one score.

12. Screenshot drops the manifest. Does not match the event

The shortest Content Credentials test is intentionally banal. Take a file that you know has Content Credentials signed and verify it at Content Credentials Verify [5]. Enter the status: valid, invalid, missing. Then take a screenshot of it and verify the new file again. You will often see the manifest missing.

This is not fraud detection. It is a property of the path. The screenshot does not create cryptographic continuity with the original file. Re-encode, crop or change the container can also throw the manifest; OpenAI cites this as one of the reasons it layers SynthID on top of C2PA [20]. The loss of the manifest must therefore not be read as evidence that the original event did not occur.

Likewise, a valid manifest for the original does not say that a screenshot circulating two hours later carries the same value. The reader is holding a different file. It can have a different viewport, a different label, and a different context. Verification is always for a specific file, not a general image memory.

How to test Content Credentials before and after screenshot

The test has three steps. First, verify the original file and save the verification result. Then make a screenshot or regular copy via an application that changes the container. Finally, verify the new file. If the manifest disappears, you are writing the difference between the files, not the conclusion about the truth of the scene. If the manifest remains, you're still only reading the statements that are in it.

13. The best control is the one whose false alarm you carry

With a deepfake image, there is often talk about how to catch a forgery. Equally important is how not to damage genuine content with a false alarm. The editors, the company and the individual must know what mistakes they can afford. Suspending internal sharing is a cheap mistake. Publicly branding a person as the author of a forgery is a costly mistake. Sending money based on a video is a different shame than accidentally not publishing an illustrative image.

A kind of failure What does he look like? How to test What will limit the damage
Absence of C2PA as fake A phone without a stamp is marked as AI Verify file, screenshot and file path Absence is not an adjustment; the census of Czech visuals is missing
Accuracy as operation The lab number will decide the dispute on the network Ask for dataset, threshold, FPR, generator year Detector only as a hypothesis, not a verdict
An eye is enough "I see the face is not real" Recall the experiment of 48.2 percent with GAN faces The second channel and restraint
Labeled as an offender We expect the fraudster to flag deepfake Separate Article 50 from the Criminal Code Do not read the marking as a punishment
One paragraph for everything A political video is automatically § 191a Separate § 191a, § 181 paragraph 2, § 184, § 209 and OZ Qualification by negotiation

NÚKIB mentions deepfake in cyber hygiene teaching, not as a certified detector [11]. The national plan for research and development in cyber and information security until 2025 works with deepfake as a risk vector [12]. ÚOOÚ included deepfake videos in the overview of AI fraud channels and digital traces in April 2026 [21]. The common thread of these materials is not "install a magic app". It is literacy, validation and process.

So the best control isn't the tightest control. It is a check whose mistake you recognise in time and bear the cost. For low damage, delay and a second resource may be sufficient. A stricter procedure is needed for a public accusation. In the case of a suspected crime, the matter belongs in a different mode than the comment thread.

14. Signature, detector and second channel do not add up to one verdict

A practical test must not teach you to make a forgery. It is meant to show the reader where the signature ends, where the detector ends, and where verification of the out-of-file situation begins.

What needs to be tested before you believe your eyes

The first test is about the signature. Verify the file with Content Credentials, then screenshot it. The second test is about absence. Take a regular photo from your own phone without C2PA and don't attribute artificial origin to it just because the manifest is missing. The third test is about the eye. Compare a known synthetic face from a secure demo source to a regular photo and anticipate that human certainty is a weak tool. Nightingale and Farid give for the first experiment48.2 percent, not a license to hunt colleagues [13].

For news or corporate visuals, look for obvious marking where it is to be addressed by the misleading entity under Article 50(4) [6][7]. Don't expect it in an anonymous repost as proof of the offender's honesty. If you suspect damage, verify using a second channel: a known number, a known account, a personal contact or an institution whose communication has its own verification procedure. It's a process, not a detector.

The blood detector in the pixel is not a lock.

— Jiný Kontext

The test result does not sound "true" or "false" in one word. It reads: signature valid, invalid or missing; the detector is usable only for the given file type and within the given limits; the independent channel acknowledges or disacknowledges the event. Only these sentences together reduce the risk of one impression becoming a public conclusion.

15. Personal use is outside the AI ​​Act. It is not outside the criminal code

The Commission's FAQ states that personal non-professional use is outside the AI ​​Act [7]. This is an important boundary. However, it does not mean that personal actions cannot conflict with other rights. If someone creates or spreads a non-consensual pornographic work abusing a person without consent, § 191a does not ask whether it was a business deployment of an AI system [9]. If someone uses a false likeness or expression with the intention of causing serious damage to rights, a different question arises according to § 181 paragraph 2 [9].

Mixing these layers is convenient, but wrong. The AI ​​Act regulates certain market roles and transparency. The Criminal Code assesses certain actions. The Civil Code protects the likeness and privacy. Personal data protection asks about data processing. A single file can fall into multiple layers, or none of the ones mentioned in the comment.

The practical implication is simple. When we ask whether the content should have been flagged, we read the AI ​​Act. When we ask whether a likeness has been misused, we read Czech law and specific circumstances. When we ask if a file is technically signed, we read C2PA. When we ask whether it is safe to act on the content, we call the second channel.

16. There is still no public prosecution under the new sections

As of September 2026, the dossier does not contain public police statistics on the number of prosecutions under Section 181(2) and Section 191a for the year 2026. This is not proof that the acts are not happening. It's a gap in the public row. So a more accurate sentence is not "no one prosecutes deepfake". It reads: for the new paragraphs, we do not have a public annual overview as of the date of the search, which could be honestly quoted.

Likewise, we have no verified primary number that FakeCatcher or a similar rPPG detector holds operational accuracy on 2025 and 2026 generators in free social channels. We don't even have an official Czech census of valid C2PA manifests for news visuals. And we don't have one aggregated NIST number that allows us to say "the detectors are operationally resolved" [18].

This does not weaken the main thesis. Rather, it keeps her grounded. If C2PA became the default, non-removable layer of majority sharing, the absence of a stamp would change the meaning. If independent rPPG evaluation on current generators with calibrated FPR showed stable operational performance, the detector would have a stronger role. If a DFDC-like challenge held well above 70 percent on the hidden set and in service, caution would be recalculated. Until it is, there is no missing stampauthenticity and 96 percent is not a lock.

17. Hidden cargo is an eye that hit by chance

The most convenient answer would be: learn a few characters, install a detector and look for a stamp. It would be short. And she would be dangerously confident. Image and video today do not require one trick, but a change in the order of inspection.

First we ask what we have in hand. Original, screenshot, repost, compressed video, or just a preview? We then ask if there is a verifiable manifesto and what it claims. Then we ask if any detector makes sense for this type of file, this quality and this population. Only then do we ask what follows legally and practically. And when it comes to damage, money, reputation or intimate likeness, we return from the pixel to the person and the institution.

This slows down the control, but it slows down in the right place. Not with every picture. With every picture we are to act upon.

The question is not how to recognise a fake video or photo at a glance. It reads: what from the signature, from the detector, and from the law can you believe about this file — and what false alarm, missing stamp or minute intervention of the eye will you tolerate about this scene?

Evidence record

How this article was made

Method, the role of AI, corrections and source details in one place.

Sources and further reading22 sources
  1. Other sourcehttps://spec.c2pa.org/specifications/specifications/2,2/specs/C2PA_Specification.html
    Specifications: Coalition for Content Provenance and Authenticity. C2PA Technical Specification (Content Credentials), v2,2, May · 2025
  2. Other source-04-22. https://spec.c2pa.org/specifications/specifications/2,2/explainer/_attachments/Explainer.pdf
    Interpretation: C2PA. C2PA and Content Credentials Explainer 2,2 · 2025
  3. Institutional sourceGuidance: C2PA. C2PA Implementation Guidance (series 2,4). https://spec.c2pa.org/specifications/specifications/2,4/guidance/Guidance.html
  4. Other sourceConsortium: Content Authenticity Initiative. How it works. https://contentauthenticity.org/how-it-works
  5. Other sourceVerification: C2PA. Content Credentials Verify. https://contentcredentials.org/verify
  6. Other source/1689, consolidated version, Article 3 point 60, Article 50. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02024R1689-20260727
    EU law: Regulation (EU) · 2024
  7. Institutional sourcehttps://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
    Institution: European Commission. Transparency obligations under Article 50 of the AI ​​Act (FAQ, update 24. 7. · 2026
  8. Book31. 7. 2026. http://ctu.gov.cz/tiskova-zprava-2.-srpna-2026-jako-klicove-datum-pro-pravidla-transparency-podle-aktu-o-umele
    Institutions of the Czech Republic: ČTÚ, press release on the applicability of Article 50 from 2. 8. · 2026
  9. Other sourceColl. (amended TZ, effective 1. 1. 2026), § 181 paragraph 2, § 191a. https://www.zakonyprolidi.cz/cs/2025-270
    Law of the Czech Republic: Act No. 270/ · 2025
  10. Other sourceColl., Criminal Code, current version (defamation § 184, fraud § 209, unauthorized handling of personal data § 180). https://www.zakonyprolidi.cz/cs/2009-40
    Law of the Czech Republic: Act No. 40/ · 2009
  11. Other sourceInstitution: NÚKIB. Give cyber 26: The risks of using artificial intelligence (deepfake in teaching). https://osveta.nukib.gov.cz/mod/page/view.php?id=4725
  12. Other source(deepfake as a vector). https://nukib.gov.cz/download/publikace/vyzkum/Narodni_plan_VaV_do_2025.pdf
    Institution: NÚKIB. National R&D plan in cyber and information security until · 2025
  13. Other sourceAI-synthesized faces are indistinguishable from real faces and more trustworthy. PNAS. https://www.pnas.org/doi/10,1073/pnas.2120481119
    Studies: Nightingale, S.J., Farid, H. · 2022
  14. Peer-reviewed study3009287 · https://arxiv.org/abs/190102212
    Studies: Ciftci, U.A., Demir, I., Yin, L. FakeCatcher: Detection of Synthetic Portrait Videos using Biological Signals. IEEE TPAMI; arXiv:190102212. https://doi.org/10,1109/TPAMI · 2020
  15. Other sourceIntel Introduces Real-Time Deepfake Detector. https://newsroom.intel.com/artificial-intelligence/intel-introduces-real-time-deepfake-detector
    Institution: Intel Newsroom, 11/14/ · 2022
  16. Other sourceDeepfake Detection Challenge Results. https://ai.meta.com/blog/deepfake-detection-challenge-results-an-open-initiative-to-advance-ai/
    Institution: Meta AI · 2020
  17. Official statisticsThe DeepFake Detection Challenge Dataset. arXiv:200607397. https://arxiv.org/abs/200607397
    Data: Dolhansky, B. et al. · 2020
  18. Other sourceInstitution: NIST GenAI, image discriminators / T2I challenge. https://ai-challenges.nist.gov/genai · evaluation plan https://ai-challenges.nist.gov/pub/GenAI_Image_Discriminators_Evalplan.pdf
  19. Other sourceTechnology: Google DeepMind. SynthID. https://deepmind.google/models/synthid/
  20. Other source; update 7/31/2026. Advancing content provenance for a safer, more transparent AI ecosystem. https://openai.com/index/advancing-content-provenance/
    Institution: OpenAI, 19/05/ · 2026
  21. Other sourcehttps://uoou.gov.cz/media/novinky/ai-podvody-a-vase-digitalni-stopa-2026/ai-podvody-a-vase-digitalni-stopa-duben-2026.pdf
    Institutions of the Czech Republic: ÚOOÚ AI fraud and your digital footprint (April · 2026
  22. Other sourceColl., Civil Code, § 84 et seq. (likeness). https://www.zakonyprolidi.cz/cs/2012-89
    Law of the Czech Republic: Act No. 89/ · 2012