Deepfakes in elections. Impact and how to combat them.
The 2024 cycle was the first where AI-generated audio reached voters at scale. What happened, and what defends against it.
In the 2024 cycle, AI-generated audio reached voters at scale for the first time, from a robocall imitating President Biden in New Hampshire to manipulated candidate clips across roughly a dozen democracies. The clips typically dropped days before voting and spread through private channels. Combating them relies on rapid detection, provenance standards, voter pre-bunking, and newsroom access to detection tools.
For most of the deepfake era, the worry about elections was hypothetical. In 2024 it stopped being hypothetical. Audio is the cheapest medium to fake convincingly, it needs no video budget and no lip-sync, and it spreads fastest through the exact channels that are hardest to moderate. That combination is why voice, rather than video, was the surprise of the cycle, and why it deserves its own playbook rather than being folded into general misinformation guidance.
What happened in 2024
The category opened with the New Hampshire primary in January 2024, when an AI-generated robocall imitating President Biden urged voters to skip the primary. The robocall reached thousands of phones before authorities intervened, and it prompted the US Federal Communications Commission to confirm that AI-generated voices in robocalls are illegal under existing law. From there, similar incidents surfaced across a range of democracies through 2024, including Slovakia, Indonesia, India, the United Kingdom, and Pakistan. The specifics differed, but the shape of the attack was consistent enough to describe as a single pattern.
| Tactic | Why it works | Countermeasure |
|---|---|---|
| Late-cycle drop | No time to rebut before the vote | Rapid detection, pre-bunking |
| Private-channel spread | Platforms cannot moderate in time | Provenance, voter awareness |
| Targeted segments | Reaches those least likely to have tools | Detector access for newsrooms |
| Plausible deniability | Attribution is slow and contested | Documented, citable verdicts |
Patterns observed across the cycle
- Late-cycle release. Deepfaked audio tended to drop 48 to 72 hours before voting, when the news cycle is too short for a rebuttal to catch the original claim.
- Distribution through unofficial channels. Clips moved through messaging apps and encrypted groups, gaining reach before any platform could moderate them.
- Plausible deniability. Some material was produced by campaigns, some by supporters acting independently, which made attribution slow and contested.
- Targeted demographics. The clips were often aimed at specific voter segments, such as older voters or language minorities, who were least likely to have detection tools to hand.
The uncomfortable part, to me, is the asymmetry. A convincing clip takes minutes to make and seconds to share, while verifying and correcting it takes a newsroom hours it does not have on election eve. I do not think detection alone closes that gap. What closes it is preparation: a detection workflow already in place, reporters who know the pattern, and voters told in advance that late audio is suspect. Detection turns a viral rumor into a checkable claim, which is necessary, but the resilience has to be built before the clip drops, not after.
Where a detector helps, and where it does not
A detector answers one narrow question well: once a specific recording surfaces, is it synthetic? Running a suspicious clip through a detector returns a probability, a confidence level, and, where recognized, the source model, usually in under half a second. That is enough to inform a newsroom decision or a fact-check before a story runs.
What a detector cannot do is stop the clip from being made or shared, and the category is asymmetric: attackers ship at scale while detection is inherently reactive. The honest framing is that detection is one instrument in a wider response, not a solution on its own. It is most valuable when it is fast, because in an election the difference between a verdict in minutes and a verdict the next day is the difference between a defense and a footnote.
One structural detail is worth drawing out. Because the clips travel through private and encrypted channels, the usual platform safeguards, labels, downranking, and takedowns, arrive late or not at all. That is why the response has shifted upstream, toward pre-bunking voters and building provenance into authentic media, rather than relying on after-the-fact removal. Detection sits in the middle of that chain: it converts a viral rumor into a checkable claim, which is what lets a fact-check or a correction move at the speed the clip already has.
How to combat deepfakes in elections
- Rapid response. Detection within hours, not days. Election-integrity teams increasingly run continuous monitoring on social channels so a clip can be assessed while it is still spreading.
- Provenance standards. Genuine campaign audio should carry verifiable origin data. The C2PA content-provenance standard is the most credible candidate, making authentic media trivially distinguishable from unverified clips.
- Pre-bunking. Voters told in advance that deepfakes are likely become more skeptical of late-cycle audio. Public-awareness campaigns measurably reduce the impact.
- Detection access for journalists. Newsrooms covering elections should have a detection workflow in place before the cycle, not during it.
If I could change one instinct in how this gets covered, it would be the reflex to debunk after the fact. By the time a correction lands, the clip has already done its work, and I have watched true rebuttals lose to false originals simply because they arrived second. The leverage is upstream, in the unglamorous infrastructure: a detection step wired into the newsroom before the cycle starts, provenance on genuine campaign audio, and an audience primed to treat last-minute recordings with suspicion. None of that is as satisfying as catching a fake, but it is what actually moves the outcome.
Ensuring election integrity
A detector is a small part of a larger system. It cannot prevent a deepfake from being created; it can only verify a specific recording once it appears. The harder, slower work is building voter resilience: public awareness, faster platform moderation, and provenance infrastructure that makes verified audio easy to tell apart from the unverified. For the acoustic tells worth listening for, see AI voice vs human voice, and for the verification workflow see how to verify AI audio. The 2024 cycle was the first at this scale. It will not be the last, which is why this work is now permanent rather than seasonal.
Frequently asked questions
What was the first major election deepfake?
The most-cited early example was the January 2024 New Hampshire robocall using an AI-generated voice of President Biden to discourage primary voting, which led the FCC to confirm such robocalls are illegal.
Why are election deepfakes released so close to voting?
Timing is the attack. A clip released 48 to 72 hours before a vote leaves too little time for a rebuttal to compete with the original, so the false claim shapes opinion before it can be corrected.
Can a detector stop election deepfakes?
No. A detector can verify whether a specific recording is synthetic once it surfaces, but it cannot prevent creation or distribution. It is one fast instrument within a broader response that includes provenance, moderation, and voter awareness.
How can newsrooms prepare for the next cycle?
Have a detection workflow in place before the cycle, train reporters on the common patterns, and pair detection with provenance checks so authentic campaign audio can be confirmed as quickly as fakes are flagged.
What is C2PA and how does it help?
C2PA is a content-provenance standard that attaches tamper-evident origin data to media. It complements detection by proving what authentic audio is, so unverified clips stand out by contrast.
Detection verifies a recording once it surfaces. Preventing the harm takes provenance, moderation, and voter resilience working together.