Deepfakes Enter the Evidence Room: What New Zealand Legal Teams Need to Preserve Now

Deepfakes are no longer only a concern for celebrities, elections and online misinformation. They are becoming a practical issue for lawyers, investigators and organisations relying on photographs, voice recordings, CCTV footage, video calls and social media content as evidence.

The issue became particularly timely in New Zealand following the introduction to Parliament in late October 2025 of the Deepfake Digital Harm and Exploitation Bill.

The Member’s Bill proposes changes to the Crimes Act 1961 and the Harmful Digital Communications Act 2015. It would expand the definition of an intimate visual recording to include material that has been created, synthesised or altered to depict a person without their consent.

The proposed legislation focuses on harmful intimate imagery. It does not create a general framework for determining whether digital evidence is authentic. However, its introduction reflects a wider challenge for the legal system. Digital content can no longer be assumed to be genuine simply because it looks or sounds convincing.

Courts Are Already Confronting Fabricated Evidence

In September 2025, the Superior Court of California addressed this issue directly in Mendones v Cushman & Wakefield, Inc. The self-represented plaintiffs submitted a range of material in support of a summary judgment application, including videos that appeared to show witness testimony, altered images and other manipulated records. The court identified several indicators that the material was not genuine. These included unnatural facial movements, repeated video sequences, audio and lip movements that did not align, and metadata that was inconsistent with the account provided by the plaintiffs. The court concluded that false evidence had been intentionally submitted. It imposed a terminating sanction, struck the plaintiffs’ complaint and dismissed the case with prejudice.

The decision demonstrates that synthetic evidence is not a theoretical future risk. It can enter active proceedings and may only be detected after significant time and cost have already been incurred.

Deepfakes also create the opposite problem. A party may attempt to challenge a genuine recording by claiming that it was generated or altered using artificial intelligence. This makes the history and provenance of digital evidence increasingly important.

The Original File Matters More Than the Screenshot

A screenshot, forwarded video or downloaded social media clip may show what the content looked like at a particular time. However, it may not preserve the information needed to determine where the material came from or whether it has been changed. Where potentially important digital material is identified, legal and investigation teams should consider preserving:

  • the original file in its native format;
  • the device, account or platform from which it originated;
  • available creation, modification and access metadata;
  • messages, emails or cloud records showing how the file was transmitted;
  • information identifying who created, captured or received the material;
  • related versions of the file; and
  • a documented record of how the evidence was collected, handled and copied.

Where proportionate and legally authorised, a forensic copy should be created as early as possible. Cryptographic hash values can then be used to demonstrate that the collected file has not changed during examination or review. However, a matching hash does not prove that the file was authentic when it was originally created. It only confirms that the file remains the same as it was when the hash was calculated. Metadata must also be interpreted carefully. File timestamps may reflect downloading, synchronisation, conversion or movement between systems rather than the original creation of the content.

Deepfake Detection Tools Are Not a Complete Answer

Automated deepfake detection tools can assist an investigation, but they should not be treated as definitive. The reliability of detection can vary depending on the type of content, the AI model used, the quality of the recording and any changes made after creation. Compression, cropping, reformatting and transmission through messaging or social media platforms may also remove or alter useful information.

The United States National Institute of Standards and Technology has found that no single technical approach provides a complete solution. Detection, watermarking and content provenance methods can all contribute useful information, but their effectiveness depends on the context in which they are used. An automated detector result should therefore be treated as one analytical indicator rather than a final finding.

A sound examination may require a combination of:

  • metadata and file-structure analysis;
  • comparison with earlier or related recordings;
  • examination of the originating device or account;
  • review of platform and transmission records;
  • timeline reconstruction;
  • assessment of visual and audio inconsistencies; and
  • witness evidence about how the material was created or received.

The question should not only be, “Does a detection tool think this is fake?” It should also be, “Where did the file come from, how was it created, who had access to it, and can its history be independently verified?”

Raise Authenticity Issues Early

Potential authenticity disputes should be identified early in litigation or an investigation rather than shortly before a hearing. Parties should consider whether audiovisual material is likely to be challenged, whether the original device is still available and whether specialist examination may be required.

Early action allows relevant devices, cloud records and account information to be preserved before they are deleted, overwritten or lost through normal retention processes. This is particularly important in workplace investigations, fraud matters, insurance claims, regulatory inquiries, relationship property disputes and cases involving social media or messaging applications.

The Takeaway

The Deepfake Digital Harm and Exploitation Bill is an important indication that New Zealand’s legal framework is beginning to respond to synthetic media. However, the proposed Bill addresses a specific category of harmful intimate material. It does not resolve the wider evidential challenges created by AI-generated or AI-altered images, audio, video and documents.

For legal teams, the most effective protection remains strong evidence handling. Preserve original files, collect relevant devices and accounts where proportionate, document the chain of custody and seek forensic assistance before authenticity becomes a contested issue.

How Forensic Tech Can Help

Forensic Tech assists legal teams and investigators with the preservation, collection and examination of digital evidence. This includes forensic acquisition of computers and mobile devices, cloud and messaging-platform collections, metadata and timeline analysis, digital evidence authentication, and the preparation of clear and defensible findings for litigation, investigations and regulatory matters.


Facing a question about whether digital evidence is genuine? Contact us or call 0800 WITNESS (0800 948 637).

Related services: Forensic Technology · Forensic Collection · Government Inquiries & Independent Reviews

Sources

New Zealand Parliament, Deepfake Digital Harm and Exploitation Bill

New Zealand Parliament, Daily progress for Thursday, 23 October 2025

Mendones v Cushman & Wakefield, Inc, order imposing terminating sanctions

Judge Scott Schlegel, “What happens when AI deepfakes fool a judge?”

National Institute of Standards and Technology, Reducing Risks Posed by Synthetic Content

Scientific Working Group on Digital Evidence, Best Practices for Digital Evidence Acquisition, Preservation, and Analysis from Cloud Service Providers