AI Policy Wiki
Dashboard

Inside My AI Law & Policy Class 14: When Anyone Can Fake Anything (Farahany, October 2025)

medium confidence · updated 2026-06-06

Deepfakes foundations class. Anchored on OpenAI's September 30 2025 Sora 2 launch (TikTok-like social app with cameo feature) and the 90-95% statistic — non-consensual pornography of women remains the dominant deepfake use since 2018. Distinguishes deepfakes from cheapfakes, walks through 4 modalities (image/video/audio/text), 3 generation techniques (face-swap/lip-sync/puppet master), and introduces the liar's dividend (Chesney-Citron). Establishes the 6-stage DHS mitigation lifecycle as scaffold for Class 15.

Author: Nita Farahany Source: https://nitafarahany.substack.com/p/when-anyone-can-fake-anything-inside Published: October 19, 2025

This Substack essay documents the fourteenth class (of 27) in Nita Farahany's introductory AI Law & Policy course, the foundations class on deepfakes. Published October 19, 2025, it opens with Farahany using OpenAI's Sora 2 to generate a fake video of herself in her own classroom minutes before live class, then surveys the technology, harms, and detection limits of synthetic media. It establishes a six-stage Department of Homeland Security (DHS) mitigation lifecycle as scaffolding for Class 15 (Inside My AI Law & Policy Class 15: Why Governing AI Synthetic Media is So Hard (Farahany, October 2025)).

Summary of argument

The class frames deepfakes through OpenAI's Sora 2, launched September 30, 2025 as a TikTok-like social application offering photorealistic video, synchronized dialogue and sound, and improved physical realism. Farahany describes its "cameo" feature, in which users upload themselves once and then appear in generated scenes; friends can revoke a cameo later, but Farahany notes that harm persists once content exists. She characterizes Sora 2 and cameos as an escalation in the harm vector.

Against the common assumption that the central deepfake risk is election interference or corporate fraud, Farahany emphasizes a different dominant use. Citing Sensity AI figures covering the period since 2018, she states that 90-95% of deepfake videos are non-consensual pornography of women, facilitated through Telegram ecosystems and including minors as targets.

Key claims

Deepfakes versus cheapfakes

Farahany distinguishes deepfakes, which are generated by AI or machine learning, from cheapfakes, which rely on basic editing such as the 2019 video of Nancy Pelosi slowed down to make her appear "drunk." She argues both cause real damage and that the definitional choice carries regulatory consequences: regulating only deepfakes misses cheapfakes, while regulating "synthetic media" broadly would criminalize much of the ordinary internet.

Four modalities

The class organizes synthetic media into four modalities. Images are described as the easiest to generate and the hardest to detect, illustrated by GAN-generated profile photos used in Belgium 5G discourse and in Lebanon influence operations. Video draws the most headlines, but Farahany cites reporting by Mark Scott (POLITICO) finding "little if any evidence" that video deepfakes skewed the 2024 elections in Pakistan or Indonesia despite widespread fears. Audio is presented as the most concerning fraud vector because people trust phone calls, with examples including the Biden New Hampshire robocalls and pre-election audio targeting Keir Starmer and Slovakia's Michal Šimečka. Text receives the least attention, even though AI-generated articles and social posts can be produced at effectively infinite volume.

Three generation techniques

Farahany walks through three generation techniques. Face-swapping traces to the origin of the term "deepfakes" on the 2017 Reddit community r/deepfakes and uses tools such as FaceShifter, FaceSwap, DeepFaceLab, and Reface; she notes it is the same underlying technology as Snapchat filters. Lip-syncing, exemplified by Wav2Lip, is "speaker-independent," meaning it can make anyone say anything without training on that specific person, with synced output preferred by humans over 90% of the time. Puppet-master techniques use GANs for full-body control, illustrated by the 2021 Tom Cruise TikToks, Channel 4's 2020 deepfake Queen Christmas message, and David Beckham's nine-language anti-malaria public service announcement.

Fraud scenario

To illustrate audio-driven fraud, Farahany sketches a voice-clone scenario: an attacker gathers personal details from LinkedIn and Facebook and a voice sample from earnings calls or podcasts, then places a call posing as the target's CEO requesting a $250,000 wire transfer. She poses whether a recipient would actually verify before wiring.

The liar's dividend

The class introduces the liar's dividend, a concept from Robert Chesney and Danielle Citron. In Farahany's example, a politician genuinely caught on video taking a bribe responds by calling the footage a deepfake, with the result that the public comes to believe nothing. The deeper effect is that truth becomes impossible to establish, not merely that falsehoods are believed. She also notes a DHS report variant in which a sophisticated actor recreates a real historical event with intentionally detectable "fake" signatures in order to cast doubt on the authentic record.

Why detection fails

Farahany argues detection keeps failing. Citing the Detect Fakes project at Northwestern's Kellogg School, she states that even with checklists and time, humans reach only about 50% accuracy. The GAN adversarial-training dynamic creates an arms race in which every detection improvement feeds a better generator. Detection is slow, taking hours, while AI generation takes seconds; attribution is technically difficult given VPNs and anonymous accounts; and scale overwhelms verification given the millions-to-one ratio of content to fact-checkers.

Six-stage DHS mitigation lifecycle

The class closes with a six-stage DHS mitigation lifecycle, presented as scaffolding for Class 15: intent (criminal and civil deterrence), research (organizational readiness), creating the model (developer responsibilities), dissemination (platform partnerships), viewer response (education and verification), and victim response (reporting channels).

Provenance

Single-source essay; the foundational class transcript and summary are the author's own (Source: https://nitafarahany.substack.com/p/when-anyone-can-fake-anything-inside). Empirical claims cited within carry their own attributions: the 90-95% figure to Sensity AI, the human-detection accuracy to the Detect Fakes project (Northwestern Kellogg), the 2024-election finding to Mark Scott of POLITICO, and the liar's dividend to Robert Chesney and Danielle Citron.

Relationships