A photo of a politician "arrested in the street". A voice note from your "boss" asking for a transfer. A product review written by someone who has never existed. All three can be generated in under a minute, for free — and in 2026 the fakes are good enough that "it looks real" no longer means anything.

Here's the working method: what to look for in each format, and — more importantly — what to do when your eyes can't tell, because increasingly they can't.

Start with the source, not the pixels

Before you zoom into anyone's earlobes, ask the boring questions first. They catch more fakes than any visual trick:

  • Who posted this, and where did it appear first? A dramatic image that exists only on one anonymous account, with no coverage anywhere established, is suspicious regardless of how it looks.
  • Does a reverse image search find it? Google Lens or TinEye will show you if the "breaking" photo is actually three years old, from a different country, or debunked already. This is the single highest-value free check.
  • Is anyone reputable reporting it? Real events leave multiple traces. Fakes usually have exactly one.

If a piece of content makes you feel a strong emotion and asks you to act fast — share, click, send money — treat that urgency itself as a red flag. It's the same pattern we cover in how to spot phishing emails: manufactured pressure is the tell.

AI images: where the generators still slip

Image generators have mostly fixed the six-fingered hands, but they still struggle with the boring details:

  • Text inside the image. Signs, labels, jerseys, book spines — AI text often melts into almost-letters. Zoom in on anything written.
  • Repeating patterns. Fences, bricks, crowds, teeth, keyboard keys: look for tiles that repeat unnaturally or merge into each other.
  • Physics of light. Mismatched shadows, reflections that don't match the scene, jewellery or glasses that blend into skin.
  • Backgrounds. The subject gets the model's attention; the background gets the artifacts. Blurry half-objects, warped architecture, floating limbs in crowds.
  • Too clean. Real photos have noise, dust, awkward framing. A "news" photo with flawless studio lighting deserves suspicion.

None of these prove anything alone. A real photo can have weird lighting; a fake can have none of these flaws. They're probability signals, not verdicts.

Deepfake video: watch the edges

  • The mouth. Lip-sync that's slightly off, teeth that blur or change shape, a jaw that doesn't quite track the words.
  • Face boundaries. Flickering at the hairline, ears, and where the face meets the neck — especially when the head turns.
  • Blinking and micro-expressions. Unnaturally regular blinking, or a face that stays eerily still between sentences.
  • Consistency across the clip. Glasses that subtly change, earrings that vanish, lighting on the face that doesn't match the room.
  • The cut length. Many deepfakes are short, cropped clips with no context — the surrounding footage would give them away.

For anything consequential, apply the source test again: where's the full video? Who else has it?

AI text: detectors don't work — read for behavior instead

Honest answer: automated AI-text detectors are unreliable. They flag human writing (especially by non-native speakers) and miss edited AI output. OpenAI shut down its own AI-text classifier back in 2023 for exactly this reason — low accuracy. Don't trust a percentage score from any of them, and don't accuse a student or writer based on one.

What actually helps is reading for behavior:

  • Verify the checkable facts. AI text confidently invents citations, statistics, case studies and quotes. Pick two claims and check them — fabricated specifics are the most reliable tell there is.
  • Generic smoothness. Perfectly balanced paragraphs that say nothing concrete, hedge every claim, and could have been written about any topic.
  • No lived detail. Real experts leave fingerprints: specific numbers, tool names, failure stories. AI-written "reviews" and "testimonials" stay vague about everything a real user would remember.
  • The account behind it. A reviewer who posted 40 reviews in one day, a "journalist" with no history — the metadata of the author beats the style of the text.

Cloned voices: the family scam

Voice cloning needs only seconds of audio, and the classic attack is a panicked call or voice note — a relative in trouble, a boss needing an urgent transfer. Defenses that work:

  • Call back on the number you already have. Not the one that just called you.
  • Ask something the caller can't know. Or agree on a family code word in advance — it's low-tech and it works.
  • Treat urgency + secrecy + money as an automatic stop, whatever the voice sounds like.

The checks that outlast the arms race

Every visual tell in this guide will get weaker as models improve. These won't:

  1. Reverse image search (Google Lens, TinEye) — free, instant, catches recycled and out-of-context media.
  2. Content Credentials (C2PA). A growing standard where cameras and editors cryptographically sign media. Paste an image into contentcredentials.org/verify to see its history if it carries credentials. Adoption is partial, but when credentials are present, they're strong evidence.
  3. Watermark checks. Some generators embed invisible watermarks (like Google's SynthID) that their own tools can detect. Absence proves nothing; presence settles it.
  4. Corroboration. The oldest one. Real events have multiple independent sources. One source = unverified, however sharp the video looks.

The honest bottom line

You will not win a pixel-by-pixel war against 2026 generators — nobody's eyes are that good. Change the question from "does this look real?" to "can this be verified?". Source first, reverse search second, corroboration third, and treat urgency as an attack. That habit beats any detection trick — and it works on next year's fakes too.

_Worth reading next: how to spot phishing emails — the same manipulation patterns, in your inbox — and cybersecurity basics for small businesses._