Responding to deepfakes and synthetic media is not only a technical challenge. These issues sit within a wider information environment in which trust can be undermined by AI-generated images and videos, cloned audio, fabricated claims, misleading rhetoric, and genuine content shared out of context. This article looks at how DETECTOR’s training, education and capacity-building work can help professionals respond to that challenge.

A wider challenge than detection alone

In many cases, the underlying harms are not entirely new. Deception, impersonation, fraud, harassment and evidential distortion have long existed. What is changing is the speed, scale and realism with which content can now be created, adapted and circulated. This increases both the volume and the complexity of the material that law enforcement, public institutions, researchers, and the media must assess.

Recent events and politicised situations show that deepfakes, synthetic media and other forms of misleading content can be used to reinforce narratives of fear, decline and distrust, particularly when they are attached to emotionally charged topics such as crime, migration, public disorder or crisis events. At the same time, not all such content is produced with an obvious strategic or political objective. Some is created simply to attract attention, generate engagement or go viral, even if it later becomes absorbed into more divisive narratives.

How misleading media can appear in practice

Examples of misuse and abuse include the fabrication of synthetic media, the recirculation of genuine content out of context, the selective framing of authentic material, and the use of cloned or synthesised audio for impersonation and deception.

These may include:

These examples show that synthetic media is only one part of the wider challenge. The issue is not simply that AI can generate false images or videos, but that multiple forms of deceptive and misleading content can coexist in the same information environment, making it harder to assess authenticity, context, and evidential value.

Some of this activity may fall within the broader area often described as hybrid threats: actions intended to exploit vulnerabilities, undermine trust and create social or institutional instability. However, it is equally important to recognise that not all misleading media is linked to organised criminality, hostile state activity or explicit political intent. Large volumes of content are created simply to entertain, provoke reaction or generate views, while still contributing to confusion and distrust.

From identifying fakes to assessing evidence

For investigators, institutions and the public, the question is therefore not only whether a piece of content is fake. It is also whether it is authentic, accurately contextualised and reliable as evidence. A genuine image, subtly altered and used falsely, can be just as misleading as a fully fabricated one and, in some circumstances, more harmful.

This is the context in which DETECTOR’s work becomes especially important. Strengthening resilience against manipulated and synthetic media requires more than detection tools alone. It also depends on the ability of professionals to recognise emerging abuse vectors, understand the evidential risks they pose, apply appropriate methods for verification and response and ensure that the evidence is acceptable at court. The training programme will therefore cover tools and techniques for identifying altered media, including video, audio and text manipulations. That is why training, education and capacity-building are essential to the project. They help ensure that technical innovation is matched by practical knowledge, institutional readiness and informed professional judgement.

Within the project, DETECTOR will address these challenges in a range of ways, including through active engagement with sister projects and organisations already working across this wider ecosystem.

Different needs, different levels of support

This work will be structured across different levels so that training materials and resources can reflect the differing needs of practitioners across domains and levels of experience. A frontline responder dealing with a wide range of offences will require different knowledge, tools and decision-support from a specialist working in areas such as identity fraud, counter-terrorism or digital forensics. Because of this breadth, DETECTOR cannot attempt to address every relevant area. Instead, the project aims to work closely with actors in the EU security landscape to connect with complementary actions and existing expertise.

A key part of the approach is therefore to connect materials and resources that already deliver value. Through signposting, referencing and structured mapping, DETECTOR aims to identify existing resources, amplify useful practice, and highlight gaps where additional content or resources are needed. In doing so, the project will also follow the EU’s FAIR principles, supporting research data management that makes outputs as Findable, Accessible, Interoperable and Reusable as possible, while applying restrictions where necessary.

In practical terms, this work is likely to result in materials available in electronic learning formats that can be readily adapted for country-specific use. The project also aims to explore engaging delivery methods, including introductory forms of gamification where appropriate, to support early-stage learning and encourage participation. Alongside this, DETECTOR will support more advanced audiences by producing content that reflects current research and state-of-the-art developments in the identification and assessment of deepfake and synthetic media. Establishing these foundations will help the project support future improvements as the field continues to evolve.

Ethical and legal considerations are a necessary part of this work. You can read more about how DETECTOR approaches these issues in the following article: https://detector-project.eu/deepfake-detection-eithos/

Understanding practitioners’ needs

DETECTOR has already taken initial steps in this area by launching a survey to understand current training provision, identify operational gaps, and gather practitioners’ needs and preferences regarding capacity-building in this rapidly evolving field. The survey was shared through the DETECTOR consortium and relevant networks and communities, including the CYCLOPES Cybercrime Network, Europol’s Innovation Lab, EACTDA, ECTEG, CEPOL and ENFSI.

The survey deadline was 30th April 2026, and the project team will now review the responses to help inform the forthcoming curriculum and related training outputs. If you have relevant knowledge, resources or materials that should be considered as part of this review, please contact the DETECTOR team at contact@detector-project.eu.

Making technical outputs usable in practice

It is also important that DETECTOR’s tools and technologies are understandable and accessible to practitioners. For that reason, the project will also provide supporting materials to explain how its technological outputs work and to demonstrate their operational utility.

To read more about DETECTOR’s technical actions, see our previous articles on multimodal detection, forensic datasets and the project’s ethical and legal approach.