Skip to main content
0byte
All posts
0byte Team9 min read

Deepfake evidence reached court before the rules did

A federal rule written for deepfakes already exists in draft. Its comment period closed in February 2026, and the committee declined to advance it in May. So synthetic evidence is still governed by rules written before generative models — which work, but only for a party with a record of origin.

A colossal keyhole plate set into a plain wall, its keyway cut deep and standing empty, with no key anywhere in sight.
On this page

There is a draft federal rule of evidence written specifically for deepfakes. It has been drafted, published for public comment, and discussed at length by the committee that would advance it. The comment period closed on 16 February 2026. At its meeting on 7 May 2026, the Advisory Committee on Evidence Rules did not send it up for approval — it kept proposed Rule 901(c) as a study item, in part because relatively few federal judges reported actually encountering the problem.

The often-cited effective date of 1 December 2027 is no longer on track. Which means that for the foreseeable future, deepfake evidence in American courts is governed entirely by rules written before generative models existed.

That is less of a crisis than it sounds, and more of one. The existing rules handle synthetic evidence better than most commentary admits — but only for parties who can produce a record of origin. Everyone else gets a credibility contest.

What Rule 901(c) would have done

The draft does not attempt to define a deepfake or require a detection tool. It allocates a burden, in two steps.

First, a party objecting that an item is AI-fabricated has to do more than say so. They must present evidence sufficient to support a finding of fabrication — a real threshold, designed to stop a blanket "that's a deepfake" from being a free move.

Second, if the objector clears that bar, the burden shifts back to the party offering the evidence, who must then show authenticity by a standard higher than the prima facie showing Rule 901 normally demands.

The proposal has an intellectual history worth knowing, because it explains the design. Professor Rebecca Delfino of LMU Loyola Law School put the original version before the committee, arguing in Deepfakes on Trial and its 2025 revision that authenticity determinations for audiovisual evidence should be reallocated from the jury to the judge. Her reasoning is about cognition, not cryptography: deepfakes exploit the "seeing is believing" heuristic, and a jury instructed to weigh whether a video is genuine is being asked to do something the research says it cannot do well.

The numbers in her filing make the point. Reviewing 22 experimental studies on deepfake identification, Birrer and Just found human accuracy averaged 63.3%, varying with image resolution, familiarity with the person depicted, and demographic similarity between viewer and subject — and participants reliably overestimated their own ability. That is the competence level a juror brings to the "does this look real" question.

It is a sensible piece of drafting. Note what it does to the party holding genuine evidence, though: it creates a scenario in which a credible-enough challenge forces you to prove your recording is real. And "prove" means something specific in a courtroom. It does not mean the video looks fine.

The rules already in force do more than people think

Strip away the assumption that new technology requires new rules and look at what Article IX already offers.

Rule 901(a) sets a low bar — evidence sufficient to support a finding that the item is what its proponent claims. Rule 901(b)(9) allows authentication by "evidence describing a process or system and showing that it produces an accurate result," which is a general-purpose hook for machine-generated records.

The more interesting provisions were added in 2017, for reasons that had nothing to do with generative AI and everything to do with digital forensics. Rule 902(13) makes self-authenticating:

A record generated by an electronic process or system that produces an accurate result, as shown by a certification of a qualified person...

And Rule 902(14) covers:

Data copied from an electronic device, storage medium, or file, if authenticated by a process of digital identification, as shown by a certification of a qualified person...

The committee note to 902(14) explains what "a process of digital identification" was expected to mean in practice: hash comparison. Matching hash values between an original and a copy establish that the two are identical.

So the federal rules already contain a pathway for authenticating digital content by cryptographic means, with no courtroom testimony required beyond a certification. It was built for forensic images of hard drives. It describes, almost exactly, what a provenance record is for.

Why hashing alone does not finish the job

Rule 902(14) assumes a forensic chain of custody: an investigator images a device, hashes the image, and the hash proves the copy matches the original. That works because nothing in between is allowed to touch the bytes.

Evidence in ordinary litigation does not arrive that way. It arrives as a video texted between three people, uploaded to a cloud album, downloaded at a lower resolution, and emailed to counsel. Every one of those steps changes the bytes. A cryptographic hash of the file as received matches nothing, because a hash is a statement about bytes, and the bytes are new.

This is the precise gap a perceptual fingerprint fills. It is derived from what the content looks or sounds like rather than from its encoding, so it still matches after re-compression, resizing, and screenshotting — the mechanism we take apart in how a fingerprint survives what the file cannot. A record keyed that way survives the journey real evidence actually takes.

Add two more properties and you have something a court can work with. The record must be signed, so there is an identifiable party accountable for the claim about origin. And it must sit in an append-only public log with independently verifiable inclusion proofs, so its timestamp is not merely asserted by the party relying on it. That second point is doing the heavy lifting in a dispute: a record created before the litigation existed, in a log no participant can rewrite, is a fundamentally different object from an affidavit produced afterward. It is the same structure Certificate Transparency uses, and the reason we built on it is covered in a record you can't rewrite.

The deepfake defense is the bigger threat

Most anxiety about AI evidence points the wrong way. The dangerous move is not smuggling a fabricated video into court — that requires committing a felony and surviving discovery, expert examination, and the metadata that a forged file usually fails to carry.

The cheap move is the opposite: claiming that authentic evidence is fabricated. No forgery, no technical skill, no exposure. Just reasonable doubt, borrowed from the general public awareness that fakes exist.

Professor Rebecca Delfino, whose suggestion to the Advisory Committee helped put Rule 901 on the agenda, has written extensively on this dynamic. Researchers call the general version the liar's dividend: as synthetic media becomes plausible, denial becomes credible, and the cost of dismissing true evidence drops for everyone.

Courts are the place this hurts most, because the legal system's response to genuine uncertainty is to discount the evidence. A defendant caught on video gets to argue it was generated. A plaintiff with a recording of harassment gets told to prove it is not synthetic. And the party with the fewest resources to hire a forensic expert loses that exchange regardless of who is telling the truth.

The Advisory Committee's stated reason for deferring — that few judges have reported deepfake disputes — is worth taking seriously, but it measures the wrong thing. The deepfake defense does not show up in the docket as a deepfake dispute. It shows up as ordinary doubt about ordinary evidence.

Detection will not be the answer the court accepts

The instinct is to hand the question to a classifier. Run the video, report the percentage, let the judge weigh it.

That runs directly into Daubert. An expert opinion has to rest on a reliable methodology with a known error rate, and AI-detection tools fail on multiple prongs at once: error rates that shift with every new generator, opaque and often proprietary training data, no established standards, and performance that collapses on exactly the recompressed, re-uploaded material litigation produces. A tool that reports "78% likely AI" on a file it has never seen the original of is offering an impression dressed as a measurement.

There is also a separate proposed rule — Rule 707 — addressing machine-generated evidence offered without a human expert, and it too was held as a study item in May 2026. The committee is being appropriately slow about admitting model output as proof. We have made the underlying argument before in why provenance beats detection: a probability is not a fact, and a courtroom is the one venue where that distinction is enforced.

Provenance sidesteps the problem by changing what is offered. A verification result is not an opinion about the content. It is a retrieval: here is a signed record, made at this time, by this party, recorded in this public log, and here is the inclusion proof you can check yourself. That is documentary evidence about a process — the thing Rules 901(b)(9), 902(13) and 902(14) were written to accommodate.

The honest limits

None of this makes provenance a truth machine, and the failure modes matter more in court than anywhere else.

A signed record establishes that a specific party asserted a specific origin at a specific time. It does not establish that the assertion was true. A camera can sign a photograph of a staged scene; a model can be misdescribed by whoever configured the stamping. Cryptography moves the question from is this file authentic to do you trust the party who signed, and was their key sound — which is a better question, and a familiar one, but still a question. We wrote about how thin the word "valid" really is in valid is not trusted.

And an unstamped file is not a fake. Most evidence in most cases will carry no record at all for years, and a court that treated missing provenance as evidence of fabrication would have manufactured a far worse problem than the one it solved. Absence of a record is absence of a record. Nothing follows from it.

The rule is not coming. Build the record anyway.

Rule 901(c) may arrive in some form — the committee kept studying it rather than rejecting it. But the timeline has slipped past any date worth planning around, and the cases are being tried now.

The useful conclusion is that the rules were never really the blocker. Rule 902 has had a cryptographic authentication pathway on the books since 2017, waiting for content that could actually use it. What has been missing is content that arrives carrying a verifiable record of its own origin.

Courts do not need a new rule for deepfakes nearly as much as they need evidence that can answer for itself. You can check what a verification returns today, or stamp your own output so that the answer exists before anyone needs it.

A rule allocates the burden of proof. It cannot create the proof. That part has to be written down at the moment of creation, by somebody who cared before there was a dispute.


Further reading: Advisory Committee on Evidence Rules, May 2026 agenda book (U.S. Courts) · Prof. Rebecca Delfino's Rule 901 suggestion to the Advisory Committee · Federal Rules of Evidence, Rule 902 · Federal Rules of Evidence, Rule 901 · Adapting the rules of evidence for the age of AI (Quinn Emanuel)

Want proof of origin on your own AI content?

Stamp a C2PA manifest at generation time and let anyone verify it — free, no account needed.