The Deepfake Watchlist is Resemble AI's weekly surveillance of synthetic media incidents, ongoing cases, and disputed content shaping the news cycle. Each week we track confirmed incidents, emerging attack vectors, and claims under investigation, alongside the provenance, detection, and policy threads running underneath them. New to the world of deepfakes? Read the Deepfake 101 Guide to learn more about how to protect yourself and your company from threats.
1. Spanish police catch deepfake identity fraud operator after software glitch
The Register's Deepfake hiccup unmasks suspected digital certificate fraudster reports that Spain's national police arrested a man in Murcia who used deepfake software and forged documents to impersonate 30 people across 38 attempts to fraudulently obtain digital certificates.
- Category: Fraud / Impersonation
- Type: Attack
- Modality: Video
- Policy / Regulatory: Digital certificates in Spain and across the EU carry legal weight for tax filings, contract signing, and official communications; the arrest was made under forgery of official documents statutes.
- Trend: Consumer-grade deepfake tools are being applied to government identity verification systems, moving the attack surface from corporate targets to state infrastructure.
- Attack vector: Real-time face-swapping software used during live video verification sessions, combined with forged ID cards and household spotlights with colored bulbs to simulate holographic security features on physical documents.
The arrest happened because the software lagged. For one frame during a live video verification session, the deepfake overlay dropped and the operator's real face was visible to the platform's staff, who flagged it. Investigators began cross-referencing the applications, and what they found was infrastructure: more than 320 phone lines across 24 devices, most registered under stolen identities, VPNs to obscure connection origins, and a custom lighting rig designed to make forged documents look authentic under the verification camera. The man had targeted a security company authorized to issue digital certificates, a process that is legally recognized across the EU.
The fact that a single operator could build this kind of operation against a live video verification system, using consumer-grade deepfake tools and an improvised desk lamp rig, says something about the gap between what KYC systems expect to catch and what is actually being attempted.
2. Paris prosecutor opens investigation after GRU-linked deepfake targets French presidential candidate
European Pravda's How Kremlin is trying to influence the French elections and how the government wants to prevent it and AFP reporting document that Storm-1516, a disinformation group identified by France's SGDSN as directly controlled by Russia's GRU military intelligence, deployed a fabricated video targeting presidential candidate Raphaël Glucksmann using an AI-cloned voice of journalist Edwy Plenel.
- Category: Political / Electoral
- Type: Attack
- Modality: Video, Audio
- Policy / Regulatory: The Paris prosecutor's cybercrime unit opened an investigation under articles covering AI-generated image/voice fabrication and providing false information to serve foreign intelligence interests; Blast filed a separate complaint for counterfeiting and identity theft.
- Trend: State-backed disinformation units are building increasingly sophisticated synthetic media operations targeting democratic elections, with production quality outpacing distribution reach.
- Attack vector: Fabricated media website replicating the French outlet Blast's design and editorial style, hosting a deepfake video with a cloned voice of journalist Edwy Plenel to falsely implicate the candidate's partner in a bribery scheme.
Storm-1516 built a replica of the French investigative outlet Blast, reproduced its visual style and web design, then used that fraudulent platform to host a fabricated video in which a synthetic version of Plenel appeared to detail a conspiracy involving Glucksmann's partner, journalist Léa Salamé, allegedly bribing media to promote his candidacy. Glucksmann disclosed the operation on August 4 after being briefed by France's national security secretariat. The cybercrime brigade is now investigating.
3. UK children's deepfake reports in six months surpass full-year 2025 total
The Internet Watch Foundation's press release, first reported by The Guardian, reveals that Report Remove received 420 reports from under-18s in the first half of 2026 from children who believed images of themselves had been manipulated or fabricated to appear explicit, already exceeding the 397 reports recorded during all of 2025.
- Category: CSAM / NCII
- Type: Attack
- Modality: Image
- Policy / Regulatory: The IWF added a specific flagging option for AI-generated material after seeing sufficient volume; the National Crime Agency is advising parents and schools to limit publicly identifiable photos of children online.
- Trend: AI-generated child exploitation imagery is accelerating faster than removal infrastructure can keep pace, with reports now doubling year-over-year.
- Attack vector: Consumer-grade AI nudification and image generation tools applied to ordinary social media and school photos of minors, requiring no technical skill and producing output that meets the criminal threshold for CSAM.
The IWF confirmed that the majority of manipulated-image reports it received in 2025 and 2026 were serious enough to cross its criminal threshold for child sexual abuse material. The National Crime Agency and IWF are now advising parents and guardians to limit publicly identifiable photos of children online, a recommendation that acknowledges something uncomfortable: prevention has moved upstream from platform moderation to whether a child's face is findable at all.
Dan Sexton, IWF's chief technology officer, warned that the figures show everyone is now a potential target. The tools that generate this material are consumer-grade and require no technical skill. The tools that remove it require filing a report, waiting for human review, and hoping the image hasn't already been copied elsewhere. That asymmetry, creation in seconds, removal in days or weeks, is the structural problem these numbers reflect.
4. Anthropic embeds invisible text watermarks as EU transparency rules take effect
Fortune's Anthropic to start embedding invisible watermarks in Claude's AI-generated text reports that Anthropic has begun embedding an imperceptible, machine-readable watermark in text generated by Claude models released from August 2 onward, aligning with the EU AI Act's Article 50 transparency requirements that became enforceable the same week.
- Category: Brand / Likeness
- Type: Response
- Modality: Image
- Policy / Regulatory: The implementation directly responds to the EU AI Act's Article 50 transparency rules, which require generative AI providers to make synthetic output machine-detectable; the rules became enforceable August 2, 2026.
- Trend: Provenance infrastructure is moving from images and audio into text, the hardest modality to watermark due to how aggressively text is transformed after generation.
Text has historically been the hardest modality to watermark because of how aggressively it gets transformed after generation: copied, paraphrased, translated, chopped up, folded into other writing. Anthropic acknowledges the watermark may not survive heavy editing or translation, and says the detection signal indicates the model "had a hand in something," not that it generated the entire output. The watermark applies across the chatbot, the API, and developer tools, and images processed by the model also receive a separate integrity watermark.
Last week's Watchlist covered the EU AI Act's Article 50 becoming enforceable. This is the first major AI provider to publicly ship a text-level implementation in response. It also lands alongside Substack's reader-triggered AI scanner and YouTube's clarified monetization policy against AI-generated content farms, a cluster of moves suggesting that provenance infrastructure is arriving from regulatory, commercial, and platform directions simultaneously. Whether any of these individually survives determined evasion matters less than the fact that the default expectation is shifting: synthetic content should be traceable.
5. 29 states have election deepfake laws, but voters face a patchwork
Axios' Voters face uneven AI deepfake protections maps the state-by-state regulatory landscape ahead of the 2026 midterm elections, finding that 29 states have AI election deepfake laws in effect while two have had their laws permanently enjoined.
- Category: Political / Electoral
- Type: Response
- Modality: Video, Image, Audio
- Policy / Regulatory: 29 states have laws in effect; California and Hawaii had theirs struck down on First Amendment grounds and are pursuing alternative approaches; no federal election-specific AI deepfake standard exists.
- Trend: State legislatures are outpacing Congress on election deepfake regulation, but the resulting patchwork creates dramatically different voter protections depending on geography.
The laws vary significantly in both approach and scope. Minnesota and Texas prohibit political deepfakes for a set number of days before an election. Maryland's ban is year-round. Colorado and Utah require detailed disclosures including the deepfake's creator, when it was created, and how it was edited. California and Hawaii both had their laws struck down on First Amendment grounds and are pursuing alternative approaches: California's AI Transparency Act, which took partial effect August 3, requires disclosures of AI-generated images, and Hawaii passed a law in July prohibiting deepfakes in ads without the subject's consent.
At the federal level, Congress has produced no election-specific AI deepfake standard. The TAKE IT DOWN Act, which took effect in May, addressed nonconsensual intimate imagery but not political content. House Democrats have signaled they will push election deepfake legislation if they regain power next year. In the meantime, AI-generated attack ads and campaign content are already widespread in the midterm cycle, and a voter in Maryland has fundamentally different protections than a voter in Florida. The Glucksmann story in this issue shows what state-actor election deepfakes look like at their most sophisticated; the question for American voters is whether any structural defense exists at all.
Honorable mentions
Third civil lawsuit filed against xAI over alleged AI-generated CSAM. Potts Law Firm's press release announced a third civil suit against xAI on August 7, this time on behalf of a family whose 6-year-old child was allegedly depicted in AI-generated CSAM created using authentic photographs. The lawsuits stem from the criminal case against Bentonville photographer Russell Bloodworth, who pleaded not guilty to more than 200 charges. Potts said the firm expects additional families to come forward.
Hong Kong man loses HK$10 million to AI voice clone on WhatsApp. Scammers cloned a man's father's voice and contacted him through WhatsApp requesting urgent financial transfers. The single-victim loss of roughly US$1.3 million marks another instance of family-impersonation vishing, a vector that exploits the emotional urgency of a parent or relative in apparent distress.
Brian May condemns Meta AI for generating inaccurate Freddie Mercury image. Queen guitarist Brian May publicly criticized Meta after its AI image generator produced a fabricated image of Freddie Mercury alongside the band's 1980 album artwork. May called the output disrespectful to Mercury's legacy, highlighting how generative AI tools handle the likenesses of deceased public figures without estate consent or accuracy controls.
The pattern

- Identity verification infrastructure is the new front line. The Spain arrest, the UK children's data, and the Glucksmann deepfake all share a common thread: the systems built to verify that a person, an image, or a video is real are being outpaced by the tools that fake them. A man in Murcia fooled a live video KYC system with consumer software and a desk lamp. Children's photos scraped from social media are being turned into CSAM faster than platforms can remove them. A state-backed disinformation unit replicated an entire media outlet to host a synthetic video. The attack surface is identity itself, and the verification systems sitting in front of it were designed for a pre-generative world.
- Provenance infrastructure is arriving from every direction at once. Last week this space covered the EU AI Act's Article 50 becoming enforceable. This week, the first major text-level watermarking implementation shipped in response, Substack launched an AI content scanner, and YouTube tightened monetization rules against AI-generated content farms. On the regulatory side, 29 US states now have election deepfake laws in effect, with approaches ranging from outright bans to detailed disclosure requirements. The consensus that synthetic content needs to be traceable is hardening into regulation, code, and commercial practice simultaneously.
- The 2026 midterm cycle is the first real stress test for this patchwork. The Glucksmann deepfake shows what a well-resourced state actor can build for a democratic election. The Axios mapping shows that American voters face dramatically different levels of protection depending on where they live, with two states' laws already struck down on First Amendment grounds and Congress offering no election-specific floor. AI-generated campaign content is already circulating. The regulatory infrastructure is still being assembled while the election is underway.
Watching next week
- xAI preliminary injunction hearing (August 19). The Minnesota nudification ban is in effect after surviving xAI's emergency motion, but the broader constitutional challenge continues. The August 19 hearing will be the first substantive judicial review of whether the law's strict liability framework survives a First Amendment challenge.
- EU AI Act Article 50 first compliance disputes. With transparency rules now enforceable and Anthropic's watermarking live, the first concrete questions about what "labeling" looks like on specific platforms and whether existing implementations satisfy the regulation should emerge.
- DEFIANCE Act clock before August recess. The bill, which would give victims of deepfake NCII a federal civil remedy to sue creators and distributors, remains stalled in the House. Whether it reaches the floor before the recess will determine whether the legislation survives this Congress.
- Potts Law Firm xAI litigation trajectory. With three suits filed in two weeks and more families expected to come forward from the Bloodworth investigation, the pace and pattern of filings will signal whether the strategy is building toward broader accountability or remaining case-by-case.
The Deepfake Watchlist publishes every Friday. Subscribe to receive it in your inbox, or follow Zohaib Ahmed on LinkedIn for the weekly social companion. Track every documented incident in the Resemble Deepfake Incident Database, and read the full methodology in our 2026 Midyear Deepfake Threat Report.

