Fastvue

Deepfakes in Schools: A Practical Guide to Prevention, Detection and Response

A child's silhouette stands before a screen filled with multiple social media icons.

by

Bec May

Deepfake abuse in schools is not an emerging risk. It is already here.

In Australia, 21 girls at a long-established independent day and boarding school were identified by police as victims after AI-generated pornographic images were allegedly shared in a boys' group chat.

In the United States, two 14-year-old boys at an exclusive private college-preparatory school in Pennsylvania used AI to create around 350 fake nude images of at least 59 girls under 18, using photographs sourced from school materials and social media.

And the scale goes much further.

A 2026 investigation by WIRED and Indicator identified more than 600 young victims across around 90 schools in 28 countries since 2023.

Separate research from UNICEF, ECPAT International and INTERPOL found that across 11 countries, at least 1.2 million children aged 12 to 17 reported having their images manipulated into sexually explicit deepfakes in a single year. In some countries, that was as high as one in 25 children.

This is happening in private schools, public schools and alternative school communities across continents. The technology is cheap, accessible and requires little technical skill. An ordinary selfie, school photograph or social media image can be enough to target a student.

By the time an explicit deepfake reaches a group chat, it is too late to determine who needs to act.

Who supports the student? Who records the incident? What evidence should be preserved? When do parents, police or online safety authorities need to be involved? How does the school stop further distribution without inadvertently spreading the material itself?

The deepfake cat is out of the digital bag, and there is no stuffing it back in.

Schools need a roadmap for understanding deepfake technology, educating students about the risks, monitoring for concerning activity and, when an incident occurs, containing its spread, supporting the person targeted, investigating what happened, and feeding lessons learned back into school policies and procedures.

This guide is designed to provide one.

Download the Deepfakes in Schools Guide

Prefer something you can save, share with your safeguarding team or keep on hand for an incident?

Download the practical guide to preventing, monitoring and responding to deepfakes in schools.

What are deepfakes?

Deepfakes are synthetic or manipulated photos, videos, or audio recordings created using artificial intelligence. They can make a real person appear to say or do something that never happened.

A deepfake might take the form of:

  • An AI-generated or manipulated image, such as a “nudified” image that places a student’s face onto a fabricated sexual image.

  • A manipulated video, such as footage that makes a student or staff member appear to say or do something that never happened.

  • A cloned or synthetic voice recording, such as a deepfake audio message that appears to come from a principal, teacher, parent, or student.

  • A face-swapped or lip-synced video, where an existing video is altered to make another person appear to be speaking.

  • A synthetic video call, where a person’s face, voice or both are generated or manipulated to impersonate someone in real time.

Not every AI-generated image is a deepfake. The term refers to synthetic media that uses the likeness or voice of a real person to create a convincing but false depiction.

Some applications are also legitimate. Deepfake technology can be used in film production, accessibility tools, education and historical recreations. After his death in 2025, Val Kilmer's AI likeness went on to star in a film he had signed up for long before his death, with the blessing of his estate and family. Questions of artistry and what defines real aside, the point is that the risk of deepfakes lies in their ability to deceive, impersonate, humiliate, threaten, or exploit another person without their consent.

How deepfakes can impact schools

Deepfake incidents can create consequences well beyond the content itself. For schools, the impact can extend across reputation, legal exposure, finances, safeguarding and day-to-day operations.

Reputational damage

A deepfake incident can quickly become a public test of how a school responds. Media coverage, parent criticism and scrutiny of safeguarding procedures can damage confidence in the school, particularly if families believe concerns were handled slowly or poorly.

For independent schools, reputational damage can also affect retention, future enrolments and the school’s standing in the wider community.

Deepfake incidents may trigger obligations relating to child protection, image-based abuse, privacy, mandatory reporting, criminal conduct and evidence handling.

The exact requirements depend on the jurisdiction, the age of the person depicted, the nature of the content and whether it was shared.

Financial impact

The cost can include legal advice, investigations, counselling, communications support, additional cybersecurity controls and significant staff time.

Deepfake impersonation can also cause direct financial loss when a cloned voice or fake video is used to authorise payments, change banking details, or obtain sensitive information.

Safeguarding and wellbeing

For the student or staff member targeted, the effects can include anxiety, humiliation, fear, social isolation and concerns about where the content may appear next.

The impact can extend to attendance, learning, peer relationships and staff wellbeing, requiring support long after the original content has been removed.

Operational disruption

A serious incident can quickly involve leadership, safeguarding, IT, communications, legal advisers and external agencies.

Teams may need to preserve evidence, investigate activity, contact families, manage reporting obligations and coordinate removal of harmful content, all while normal school operations continue.

Loss of trust

Deepfakes can undermine confidence in digital evidence itself. Students, staff and parents may become less certain that an image, video or audio recording is genuine.

That creates a second risk: authentic content can also be dismissed as fake, making verification increasingly important.

How are deepfakes created?

The first generation of deepfakes was technically demanding.

Earlier deepfake techniques often relied on deep learning models known as generative adversarial networks, or GANs. One part of the system generated the fake content while another assessed how convincing it was. Repeating this process helped the output become progressively more realistic. It also made creating deepfakes time-consuming, technically complicated, and inconsistent.

Modern deepfakes are a different proposition.

If you've ever given image generation tools a go, you'll know that generative AI has significantly lowered the technical barrier to creating deepfakes.

Diffusion models can generate or manipulate images from text prompts. Face-swapping technology can replace one person’s face with another. Lip-sync tools can alter the appearance of a person speaking. Voice-cloning technology can generate synthetic speech that resembles a real person.

In some cases, all the user needs is one image or, for audio deepfakes, just three seconds of audio.

A photograph taken from a student’s social media profile, school sports page, or class photograph can serve as source material for AI image manipulation. In July 2026, both the IWF in the UK and eSafety in Australia warned schools that publicly available school photographs were increasingly being harvested and manipulated, including staff headshots being used in fake videos, face swaps, and fabricated social media content.

Nudify tools take this a particularly harmful step further. A user uploads an ordinary photograph of a clothed person, and AI generates a fake nude or sexualised version of the image.

According to eSafety, these tools can turn a single photograph into sexualised deepfake content within seconds, with little or no technical expertise. This lack of guardrails means a lapse of judgment and a mobile phone can lead to image-based abuse before a teen has even realised what they have done.

How to detect deepfakes

There is no single test that proves an image, video or audio recording is genuine. Visual clues can help, but verification matters more.

Look for visual and audio inconsistencies

Depending on the type and quality of the content, warning signs can include:

  • Audio that does not align with lip movements

  • Changes in lighting or shadows around a face

  • Unnatural facial movements or expressions

  • Inconsistencies around hairlines, jewellery, teeth, hands or ears

  • Facial features that change between frames

  • Body language that does not match the speech or situation

  • Sudden changes in audio quality or background noise

  • Blurred edges, flickering skin tones or unnatural boundaries around a face

While these can all be signs that content has been manipulated, compression, poor lighting, filters and low-quality video can create similar artefacts in genuine content. A sophisticated deepfake may also contain none of these obvious clues.

Three images of Tom Cruise. Can you spot the deepfake?

Two Truths and an AI: Two of these images are real. One is AI-generated. Can you tell which one?

Automated detection has similar limitations. NIST's 2026 deepfake research found that current detection systems can experience performance degradation of 45 to 50 per cent when moving from academic testing into operational use.

A deepfake detector can provide evidence. It should not provide the verdict.

Find the original source

Try to locate the earliest available version of the image, video or recording.

A screenshot, forwarded video or screen recording may have lost useful metadata and context. Establish when the content first appeared, who shared it and how it reached the school community.

For an investigation, the distribution chain can be as important as the media itself.

Verify the person independently

If a recording appears to show a principal, teacher, parent or student saying or doing something concerning, verify it through another trusted channel.

Call the person using a known phone number, speak to them directly or contact them through an established school account. Do not verify suspicious content through the same account or channel that supplied it.

Check whether the surrounding story makes sense

Look beyond the image or recording itself.

When was it supposedly created? Where? Who else was present? Does the timeline fit? Are there independent sources that confirm the event?

A technically convincing deepfake can still fall apart when the circumstances surrounding it don't add up.

Check provenance where available

Content Credentials, based on the C2PA standard, can provide information about where digital content originated and how it has been edited.

They are not a truth detector. Their absence does not prove something is fake, and their presence does not prove every claim attached to the content is true.

They provide another useful layer of evidence when verifying suspicious media.

Treat detection as one part of the investigation

When a deepfake issue lands on your desk, the question is not simply, “Can we prove this is AI?”

It is also: Who may be at risk? How far has the content spread? What evidence can we preserve? Who needs to be informed? What action needs to happen now?

Generative AI technology and Deepfake abuse in schools

Deepfake incidents in schools are not limited to fake nude images. Harmful AI-generated content can be used to impersonate, threaten, deceive, and damage the reputation of students and staff, without the content being sexualised.

For schools, that broadens the issue well beyond image-based abuse. Deepfakes can become a student wellbeing concern, a cyberbullying incident, a disciplinary matter, a fraud risk, a reputational crisis, a legal matter, or all of the above.

Deepfake pornography and fake nudes

Sexualised deepfakes remain the most serious and concerning applications of deepfake technology in schools. A photo of a student taken from social media platforms or even the school website can be uploaded to a 'nudify' service and manipulated to create an explicit image or video, even if the student has never taken or shared an intimate image of themselves.

For the student depicted, the fact that the image is fake changes very little; the humiliation, loss of control, and fear about who has seen and shared it are very real.

This is not just a school issue. Across the world, laws are increasingly recognising sexualised deepfakes of children under 18 as a form of child sexual abuse or exploitation material, carrying serious criminal consequences for creating, possessing, or sharing them.

Fake images, fake allegations, and reputational harm

Increasingly, teachers and principals are becoming the target of deepfake impersonation. Manipulated content can make staff appear to make a discriminatory remark, threaten somebody, behave inappropriately, or endorse something they never said or did. For a school, the speed at which this content can spread creates an obvious problem: a false allegation can travel far before anyone has time to establish that it is false.

Between January and March 2026, eSafety received more than 100 reports involving anonymous accounts targeting Australian schools and their staff. In almost every case, imagery was taken from the school website or social media accounts to create AI-generated videos, face swaps, memes, and fabricated stories about school leaders.

Deepfake cyberbullying

Not every malicious deepfake involves sexual content. A student's face can be inserted into a humiliating image or video; manipulated content can make it appear as though they are taking drugs or behaving violently; and fake audio can make them appear to say something offensive that never left their mouth.

This rearranges the mechanics of cyberbullying. A perpetrator no longer has to wait for an embarrassing photo, compromising message, or genuine video to exist—deepfake applications now do the hard work for them.

While the content itself may be synthetic, the bullying behaviour around it often looks very familiar. Humiliation, exclusion, gossip, pile-ons, anonymous accounts, and repeated sharing all follow the same patterns schools already know from more traditional forms of cyberbullying. The technology is new. The social dynamics are not.

The minimisation can be familiar too. The student who created the content may call it a joke. Others may insist that “everyone knows it’s fake”, that “no one actually believes it”, or that the student targeted is overreacting. Those responses shift attention away from the behaviour and the harm it has caused, while making it easier for the abuse to continue.

Whether the content is real or synthetic, the consequences can still include humiliation, gossip, exclusion, reputational damage and the fear that the image or video will resurface months or years later.

Deepfake scams and financial fraud

Deepfakes can make familiar scams far more convincing. A fake voice or video could appear to show a principal authorising a payment, a parent requesting a change to bank details, or a supplier asking finance staff to redirect an invoice.

For schools, the takeaway is simple: voice and video are no longer proof of identity. Unusual payment or information requests should always be verified through a second trusted channel.

Misinformation, fake news and the problem of trust

Deepfakes also bring with them a broader educational problem.

Students need to understand that just because an image, audio, or video clip seems real, it does not mean it is. Just because it has been shared online, possibly by a reputable source, or features a well-known figure, does not make it verifiable.

But integrating deepfake education into your wider digital citizenship curriculum isn't as simple as telling kids 'everything could be fake!'

Taken too far, that message can contribute to a phenomenon known as the liar's dividend: once people know convincing fakes exist, genuine evidence becomes easier to dismiss as fake simply because it is inconvenient, uncomfortable, or challenges what they already believe.

Students should learn to:

  • Trace an image, video, or claim back to its original source

  • Check the date, location, and surrounding context

  • Use lateral reading by comparing what trusted, independent sources are reporting

  • Recognise when a clip or screenshot has been stripped of important context

  • Look for provenance tools such as Content Credentials where available

  • Ask 'How can I verify this?' before jumping to 'Is this fake?'

This gives students the ability to think critically about the information they see online, rather than becoming blanket sceptics.

What should schools do to combat deepfakes?

Deepfake incidents are much easier to manage when your school already has a clear action plan. Waiting until an explicit image is circulating through Year 10 to decide how to respond is like writing the fire evacuation plan after the building is on fire.

Schools should integrate deepfakes into their existing policies, education, and reporting processes.

Raise awareness of AI-generated content and the harms of deepfake technology

Deepfake education should sit alongside existing classroom discussions on consent, respectful relationships, cyberbullying, digital literacy, and the responsible use of AI tools.

  • Creating a fake image or video of someone without consent can cause serious harm, even when everyone knows it is fake.

  • Sharing or forwarding harmful AI-generated content can compound that harm.

  • Sexualised deepfakes involving children can have serious legal consequences.

  • A student can be targeted using an ordinary selfie, a school photograph, or a social media image.

  • If they receive harmful content, the safest response is not to forward it, even to show someone what has happened.

  • They should know exactly where and how to report it.

Have a deepfake response plan

Decide in advance who will lead the response, who needs to be informed and when the incident should be escalated beyond the school. The plan should cover safeguarding, evidence preservation, parent communication, law enforcement, online content removal and ongoing support for the person targeted.

Staff should also know what not to do, including circulating the content internally, asking the student to repeatedly show it or conducting an informal investigation that could compromise evidence.

Update existing policies

Schools do not necessarily need a standalone deepfake policy. Existing child protection, safeguarding, cyberbullying, acceptable-use, generative AI, social media, and incident-response policies should explicitly cover synthetic and manipulated content.

Policies should make clear that creating, sharing and resharing harmful deepfakes may all carry consequences, even when the content itself is fabricated.

Review what your school publishes

Review how identifiable photographs, videos, and audio of students and staff are published online. This does not mean removing every image from the school website, but schools should consider what needs to be public, who can access it and how much identifying information is attached.

In the past month, both Australian and UK authorities have warned about the growing risks associated with publicly available images. In July 2026, eSafety warned schools that student and staff photographs were being harvested from school websites and social media to create deepfakes, face swaps, sexualised images and fabricated content. Between January and March alone, eSafety received more than 100 reports involving anonymous accounts targeting schools and staff, with almost all using imagery sourced from school websites or social media.

The UK's Internet Watch Foundation and National Crime Agency issued a similar warning in July, reporting an increase in offenders exploiting openly available photographs of children to create AI-generated sexual abuse material. The IWF identified 3,443 AI-generated child sexual abuse videos in 2025, up from just 13 in 2024.

Consent processes, social media practices and publicly available student and staff imagery should now be reviewed through the additional lens of AI manipulation and deepfake risk.

What should schools monitor for deepfake activity?

Deepfake tools evolve rapidly, with new applications popping up across the web as quickly as they disappear. The guardrails in legitimate AI platforms can also be easily circumvented to create deepfakes.

Rather than simply trying to block known deepfake tools, a better strategy is to monitor for a range of indicators associated with the creation, distribution, or concealment of deepfake content. Monitoring and alerting on these signals can help schools identify concerning activity earlier and intervene before content spreads.

Monitor deepfake and AI manipulation tools

Depending on your school's systems:

  • Nudify and AI undressing services

  • Face-swapping tools

  • AI image manipulation

  • Image-to-video generators

  • AI video generators

  • Lip-sync tools

  • Voice cloning and synthetic speech

  • AI avatar and impersonation services

  • File-sharing platforms

Access alone does not prove wrongdoing. The aim is to provide accurate data and enough context to distinguish legitimate use of AI tools from activity that may require investigation.

Monitor relevant searches

Again, how this works will depend on your technical setup; however, useful terms to monitor include:

deepfake

deep fake

nudify

nudifier

undress AI

remove clothes AI

fake nude

AI nude

face swap

AI face swap

voice clone

clone someone's voice

AI voice generator

lip sync AI

image to video AI

AI video generator

how to make a deepfake

Look for distribution, not just creation

Review whether the content was distributed through school email, messaging, cloud storage, file-sharing services or school-managed accounts.

Look for attempts to bypass controls

Review VPN, proxy, and other filtering-bypass activity that appears alongside relevant AI tools, searches, or file-sharing activity.

Make sure your logs can answer the basic questions

During an investigation, schools should ideally be able to establish:

  • Who accessed the service?

  • What device was used?

  • When did it happen?

  • What domain, application or URL was involved?

  • Was access allowed or blocked?

  • Were files uploaded or downloaded?

  • Were VPNs or proxies involved?

  • Was school-managed email or chat involved?

Network evidence can help establish a timeline, but it cannot prove that a particular user created a deepfake. Visibility also depends on what passes through monitored systems and what the firewall or other platforms actually log. 

How should your school respond to a deepfake incident?

When a deepfake incident occurs, the first objective should always be to protect the targeted student and prevent further harm.

1. Prioritise immediate safety and wellbeing

Speak privately with the affected student or staff member. Establish whether they feel safe and whether there have been threats, coercion, blackmail, extortion or pressure to provide money or further content.

Do not minimise the incident because the content is AI-generated. Follow your school’s child safety, wellbeing, and mandatory reporting procedures, and avoid repeatedly asking the person to show or describe the material.

2. Appoint one person to coordinate the response

Inform the principal and appoint a clear response lead. This helps prevent conflicting instructions, unnecessary disclosure and harmful material from being passed around internally.

Bring in the right people on a need-to-know basis, which may include child safety and wellbeing, IT, legal advisers, the education authority, and the police.

3. Stop further distribution

Tell students and staff clearly not to forward, download, repost or privately share the content, even if they are trying to warn someone or identify the creator.

Every additional copy increases the spread and can compound the harm to the person depicted.

4. Preserve evidence carefully

Record useful evidence such as account names, platforms, URLs, timestamps, message links, accompanying threats or demands, and relevant school network, email or chat activity.

Avoid unnecessarily downloading, storing or circulating explicit material. Where police are involved, follow their instructions about preserving evidence and securing devices.

5. Report potential criminal conduct to local law enforcement

If the deepfake depicts a child in a sexual context, involves threats, coercion, extortion, stalking or other potentially criminal behaviour, contact the appropriate local law enforcement agency and follow any mandatory reporting requirements that apply to your school.

Record any incident, case or reference number provided and follow law enforcement instructions about preserving evidence, securing devices and conducting further enquiries.

6. Report the content through the appropriate online safety pathway

Where harmful deepfake content has been shared online, report it to the platform involved and use the appropriate reporting or removal service for your country.

  • Australia: Report image-based abuse, serious cyberbullying or illegal content to the eSafety Commissioner. eSafety specifically accepts reports involving fake or altered intimate images, including deepfakes, and advises schools to report potentially criminal incidents to the police as well.

  • United Kingdom: Sexual deepfake content involving children can be reported to the Internet Watch Foundation (IWF), which accepts reports of AI-generated child sexual abuse images as well as real imagery. Young people under 18 can also use Report Remove, operated by Childline and the IWF, to seek removal of sexual images or videos of themselves. In 2025, 21% of Report Remove reports involved faked imagery.

  • United States: Suspected online child sexual exploitation, including incidents involving generative AI and nudify tools, can be reported to the National Centre for Missing & Exploited Children (NCMEC) CyberTipline. NCMEC is the designated US reporting system for suspected online child sexual exploitation and refers relevant reports to law enforcement.

Schools elsewhere should follow their national pathways for child protection, law enforcement, and online content reporting. The platform hosting or distributing the material should also be reported directly, as platform removal may be one of the fastest ways to limit further spread.

7. Communicate carefully

Keep the affected student, staff member, and family informed about what the school is doing, while protecting their confidentiality.

If broader communication is required, focus on expected behaviour, reporting pathways and the school’s response. Avoid details that could encourage others to search for the content or identify the person targeted.

8. Continue support after the content is removed

Removal does not necessarily end the incident. The person targeted may still worry that copies have been saved, reposted or believed by others.

Consider ongoing wellbeing support, attendance, peer relationships, classroom impacts and the risk of further harassment. Removal is an important step. Recovery can take much longer.

Be ready before a deepfake incident happens

From student education and monitoring to evidence preservation, reporting and response, keep the key guidance in one place.

Download the Deepfakes in Schools Guide for your safeguarding and IT teams.

Build a clearer picture of online activity

Fastvue turns data from supported school firewalls and Microsoft 365 services into user-level online safety reports and alerts.

Monitor access to AI applications and relevant prompts, identify searches associated with deepfake activity, and investigate related Microsoft 365 email and Teams activity. Give safeguarding and IT teams the context they need to build a clearer timeline, investigate concerning behaviour and respond to deepfakes, cyberbullying, self-harm, violence and other online safety concerns.

Explore Fastvue Reporter for Education or contact sales

This article provides general information for schools and is not legal advice. Schools should follow the legislation, reporting obligations, and education-sector procedures that apply in their jurisdiction.

Don't take our word for it. Try for yourself.

Download Fastvue Reporter and try it free for 14 days, or schedule a demo and we'll show you how it works.

  • Share this story
    facebook
    twitter
    linkedIn