What it means
Deepfake covers a spectrum: swapping a face into existing footage, cloning a voice from a short sample, or generating video of a person from scratch. What used to require a studio now takes consumer tools and a small amount of source material — a voice can be cloned from seconds of audio scraped from anywhere the person has spoken publicly.
The honest framing is that detection is not a solved counter-measure and is unlikely to become one; detectors and generators improve against each other. The more durable response is provenance — cryptographically signing content at capture and carrying that signature through editing, which is the approach behind content credentials. That establishes what *is* authentic rather than trying to catch everything that isn't.
Why it matters
The most common real-world harm is not political disinformation but fraud: a cloned voice authorising a payment, or a fabricated video call impersonating an executive. Organizations that rely on hearing a familiar voice as authentication have an urgent, concrete problem, and it is addressable with process rather than technology.
The secondary harm is subtler — as fabrication becomes plausible, genuine evidence can be dismissed as fake. That erosion of the default trust in recordings affects everyone, not only targets.
In practice
The practical defense is procedural: verify consequential requests through a separate channel, and never treat a voice or a face as proof of identity. For published media, look for content credentials rather than relying on your own eye.