Jessica Entwistle
September 18 2026
Meta's Oversight Board has ruled that the company must remove AI-generated deepfake videos of a UK Labour councillor and a young Muslim woman from Facebook, and has criticised Meta's safeguards against fake content as inadequate. One video falsely depicted a Scottish Labour councillor making inflammatory comments about refugees, while another targeted a Muslim campaigner. The Oversight Board found that Meta was wrong to leave the content online and has called on the company to strengthen its policies and enforcement mechanisms for identifying and removing AI-generated misinformation. The ruling highlights ongoing concerns about the effectiveness of platform moderation in the face of increasingly sophisticated synthetic media.
Deepfake technology is becoming more accessible, realistic and harder to detect. While this case involves political figures, the same techniques can be used to impersonate executives, manipulate business communications, undermine trust in video evidence or support social engineering attacks. The ruling also underscores that platform moderation remains inconsistent and reactive, meaning organisations cannot rely solely on social media companies to identify and remove malicious or misleading content targeting their staff, brands or stakeholders. This creates reputational, operational and security risks that organisations need to anticipate and prepare for. Deepfakes can be used to damage trust in leadership, manipulate financial transactions, support fraud or phishing campaigns, or create confusion during incidents. The speed at which synthetic media can be created and distributed means that organisations need to be able to respond quickly and confidently when deepfakes targeting their people or brand appear online.
Organisations should review whether they have considered the risk of deepfake impersonation targeting senior leaders, customer-facing staff or brand reputation. Consider whether staff are aware of deepfake risks, whether verification processes exist for high-stakes communications such as payment authorisations or sensitive instructions, and whether incident response plans account for synthetic media being used in attacks or disinformation campaigns. Organisations should also consider whether they have processes for identifying and reporting deepfakes, whether they have relationships with platforms and law enforcement that can support rapid takedown requests, and whether they have considered how to communicate clearly and transparently if deepfakes targeting the organisation appear online. Training and awareness programmes should include examples of deepfake risks and practical guidance on how to verify the authenticity of video and audio communications.
Source: The Guardian