Deepfakes and digital evidence: how AI is changing evidence management and litigation

Summary

Generative artificial intelligence has made it easy to create fake yet extremely credible videos, audio, and documents. Although deepfakes do not yet represent a mass caseload in Italian courtrooms, the conditions for their systemic impact on litigation are already fully present: on the one hand, digital reproductions can be contested as manipulated; on the other hand, the unregulated use of AI in legal research risks introducing non-existent judgments into legal documents. In both cases, the main challenge concerns the reliability and traceability of sources.

In this article, we analyze the evolution of digital threats (distinguishing between large corporate fraud and the implications for civil and criminal trials), the new regulatory framework (from Article 612-quater of the Criminal Code to the obligations for deployers in the AI Act), and best practices for safeguarding evidence. We also examine how to ensure the reliability of both factual evidence and sources of law, reducing the risk of hallucinations in legal research.

The evolution of threats: when digital content is no longer reliable

From photo editing to synthetic identity

For years, the manipulation of digital content required technical skills and time, and often left traces recognizable to an expert eye. Today, generative AI models are capable of cloning a voice, replacing a face in a video, or creating realistic images and documents from scratch, using tools within anyone's reach.

Two famous recent cases illustrate the impact of deepfakes in the corporate world and financial fraud, although they were not judicial disputes born in court. In 2024, an employee at the Hong Kong office of the British engineering company Arup executed 15 transfers totaling 200 million Hong Kong dollars (approximately 25 million US dollars) after a video call in which the participants were synthetic reconstructions. In Italy, in 2026, a similar episode occurred to the detriment of Fideuram, with an attempted theft of large sums led by forged emails and the cloned voice of a well-known business lawyer, who was entirely unrelated to the facts (here the reconstruction by Cybersecurity360 ).

Even though these episodes originate as extra-judicial scams and extortions, they are highly indicative for law firms: they demonstrate the ease with which the identity of a professional or executive can be impersonated and foreshadow the disputes that will soon become commonplace in civil and labor lawsuits as well.

The new regulatory framework: art. 612-quater c.p. and AI Act

The Italian legislator intervened with Law of September 23, 2025, no. 132, in force since October 10, 2025, which introduced into the Criminal Code the art. 612-quater , entitled “Illicit dissemination of content generated or altered with artificial intelligence systems”. The law punishes with imprisonment from one to five years anyone who causes unjust harm to a person by transferring, publishing, or disseminating without their consent images, videos, or voices falsified or altered with AI and capable of misleading regarding their authenticity. The same law has introduced a common aggravating circumstance for crimes committed using artificial intelligence systems, when these constitute an insidious means, hinder defense, or worsen the consequences of the crime. For an in-depth analysis of the new legal provision, we point out the analysis published by Altalex .

At the European level, Article 50 of the Regulation (EU) 2024/1689 (AI Act) establishes precise transparency obligations. However, it is necessary to distinguish between AI system providers and those who use them in a professional context (deployers): the obligation to declare that audio, photo, or video content constitutes a deepfake rests with the deployer when using the system for professional or public purposes. The regulation excludes purely personal use and provides attenuated disclosure requirements for content with artistic, satirical, or entertainment purposes. Providers, on the other hand, remain responsible for implementing technical markings on systems released to the market. For an overview of the deadlines reinforced by the Digital Omnibus, please see our guide to the AI Act 2026 .

What changes for those who need to prove a fact

In civil proceedings, computer reproductions constitute full proof of the facts represented if the party against whom they are produced does not deny their conformity (art. 2712 c.c.). With order no. 1254 of January 18, 2025, the Court of Cassation confirmed that even screenshots of WhatsApp messages fall under this regulation. The denial, to be effective, must be specific and detailed: a generic dispute is not enough. But when it is effective, the reproduction loses its value as full proof and becomes an element freely assessable by the judge, and the party who produced it must demonstrate its authenticity by other means, for example, a computer forensic analysis.

The spread of deepfakes makes it easier to argue for a circumstantial denial and produces a dual effect. The first is evident: false content can enter the record and influence a decision. The second is more subtle and is what US jurists Robert Chesney and Danielle Citron, in a 2019 essay published in the California Law Review, called the “liar’s dividend”: authentic and compromising content can be discredited simply by claiming it was generated by AI. In both cases, for the lawyer, the difference is made by the ability to demonstrate where evidence comes from and what has happened to it since it was acquired.

The importance of certified sources in legal proceedings

Chain of custody and data integrity

Digital evidence is reliable when its origin can be reconstructed with certainty and its unalterability can be demonstrated. In criminal proceedings, Law 48/2008, which ratified the Budapest Convention on Cybercrime, amended articles 244 and 247 of the Code of Criminal Procedure, among others, providing that operations on computer systems must be carried out by adopting technical measures aimed at ensuring the preservation of original data and preventing their alteration. In civil litigation, there is no equivalent rule, but the same principle is the most solid way to resist a disavowal.

Specifically, the tools that make digital evidence more defensible are:

  • Forensic acquisition : complete copy of the support or content, performed with documented procedures according to international guidelines on the collection and preservation of digital evidence (ISO/IEC 27037 standard), instead of a simple screenshot or a file sent via chat.
  • Hash fingerprint : a code that uniquely identifies the file and changes if the file is modified even by a single bit.
  • Timestamp and digital signature : they certify the fixed timestamp of the file's crystallization and the identity of the person applying the signature (e.g., the studio or consultant who performs and certifies the extraction of the screenshot), ensuring that the file has not been modified from that moment onward, without, however, certifying the authenticity of the original content prior to its acquisition.
  • Metadata preservation : data, device, geolocation, and modification history are often the element that helps unmask manipulation.
  • Content provenance credentials : the C2PA standard (Content Credentials) embeds the history of its creation and modifications directly into the file. It is already supported by some professional cameras from Leica, Sony, Nikon, and Canon, as well as certain smartphones like the Google Pixel 10, but adoption remains partial, and these credentials attest only to the file's origin rather than the truth of what it depicts.

All this requires an infrastructure capable of storing data securely and traceably. It is the same issue we address when talking about document management software for law firms and of Digital signature integrated into the cloud management system .

From factual evidence to sources of law: the second chain of trust

The credibility of a legal act rests on two distinct chains of trust: that of factual evidence and that of legal sources. If deepfakes call the former into question, the reckless use of non-specialized generative AI tools risks compromising the latter. This is the case with so-called "hallucinations," i.e., citations of invented norms or rulings. The relevant Italian case is the order of March 14, 2025, from the Court of Florence (Business Section), which found in a pleading the presence of completely non-existent or misrepresented rulings from the Court of Cassation, generated by ChatGPT during research and not verified before filing. This is a phenomenon related to the reliability of legal research and not to the manipulation of evidence or deepfakes, but it addresses the same underlying problem: the absence of source validation. A detailed analysis of the provision is published by Agenda Digitale .

The point is not to give up AI, but to know what sources it uses. A generalist chatbot produces plausible text based on what it has learned, without any guarantee that the cited judgment exists or says what is attributed to it. This is why we have already warned law firms about the risks of Shadow AI , i.e., the use of unauthorized tools that, in addition to errors, can expose confidential client data.

Risks and safeguards: an operational summary

Content type Main risk Recommended focus
Audio and voice messages Voice cloning Forensic acquisition of the device, hash, metadata preservation
Videos and video calls Synthetic faces and identities Verification of the original source and, if available, C2PA credentials; technical expertise
Screenshots and chats Fabrication or alteration of text Forensic or certified acquisition instead of simple screen capture
Documents and contracts Content or signature forgery Digital signature, timestamp, document management with versioning
Judgments and cited regulations Generative AI hallucinations Legal AI that cites verifiable sources, human control of every citation

Ensuring the chain of trust on legal sources: the Lexroom approach

Why a vertical AI and not a generalist chatbot

To strengthen the chain of trust in legal sources, the adoption of vertical AI engines dedicated to the legal sector offers specific guarantees compared to generalist models. Platforms such as Lexroom operate, in fact, on closed and verified regulatory and jurisprudential databases, providing answers directly linked to the official source and allowing immediate verification of every citation.

The use of specialized AI does not eliminate the responsibility for professional control, which always remains with the lawyer, but provides a work structure oriented towards the analytical verification of references, fundamentally reducing the risk of hallucination errors in documents.

Secure your evidence: integrate certified and verified research into your workflow

Preserving the credibility of an act requires timely intervention on the study procedures related to both chains of trust (facts and law). Key steps include:

  1. Defining internal policies for evidence acquisition : establish when to resort to certified analyses and acquisitions. Lanpartners supports firms in defining these organizational procedures and facilitates collaboration with qualified forensic consultants for expert operations on IT support.
  2. Preserve originals and metadata in a secure document management system, with versioning, tracked access, and immutable backups, according to the principles we describe in our guide to business continuity and backup .
  3. Adopting a vertical legal AI that cites verifiable sources instead of generalist chatbots for jurisprudential research and drafting, always maintaining human control over every citation.
  4. Train lawyers and collaborators to recognize the signs of manipulation and verify AI-generated citations before including them in a deed.
  5. Introduce verification procedures for urgent requests , especially if they arrive by phone or video call: after the Arup and Fideuram cases, a familiar voice or face is no longer enough to confirm an identity.
  6. Provide for a response procedure for cases where the firm or a client is the victim of a deepfake: the first moments are decisive, as we explain in the guide to Incident Response in the first 24 hours .

Do you want to understand how to integrate Lexroom and secure evidence management procedures into your firm's workflow? Contact us for an assessment and a demo of the platform built on your real cases. Discover also all our services of Artificial intelligence for firms and professionals .

FAQ: deepfakes, digital evidence, and AI in litigation

What is a deepfake and why is it a problem for evidence in court?

A deepfake is an image, video, or audio generated or altered with artificial intelligence to look authentic. It is a problem for the trial process because it makes it easier to challenge any digital content: the party producing a recording or a video must be ready to prove its origin and integrity.

What does art. 612-quater of the Criminal Code provide?

Introduced by Law 132/2025 and in force since October 10, 2025, it punishes with imprisonment from one to five years anyone who causes unjust harm to a person by assigning, publishing, or disseminating without their consent images, videos, or voices falsified or altered with AI and capable of deceiving as to their authenticity.

Does the AI Act require disclosure of deepfakes?

Article 50 of the AI Act provides for a transparency obligation on deployers (those who use the system for professional reasons) when they disseminate content that constitutes a deepfake, indicating its artificial nature, with exemptions for personal use or for artistic and satirical purposes.

Are a screenshot or a voice message valid evidence?

Yes, as computer reproductions pursuant to Article 2712 of the Civil Code, which constitute full proof unless specifically disowned. If the opposing party effectively disowns them, their authenticity must be demonstrated by other means: forensic or certified acquisition, with a hash fingerprint, timestamp, and preserved metadata, makes the evidence much more solid.

What are AI hallucinations in the legal field?

These are fabricated references, such as nonexistent rulings, legal principles, or laws, that a generative AI system presents as true. The Court of Florence described them in the order of March 14, 2025, regarding a legal brief that cited nonexistent Supreme Court rulings or ones with content different from what was reported.

How does Lexroom help reduce the risk of hallucinations?

According to the company's statement, Lexroom responds based on a closed corpus of verified Italian legal sources and links each statement to the official source, which can be consulted and downloaded. No AI completely eliminates the risk of error: the final check remains with the lawyer, but it starts from citations linked to their sources rather than a text that is merely plausible.

Where can a law firm start to protect its digital evidence?

From an internal policy on evidence acquisition, a secure storage system for originals and metadata, verification procedures for urgent requests, the adoption of legal AI that cites verifiable sources, and team training. Lanpartners can assist the law firm in each of these steps.