10 min read

The Deepfake Rule That Won’t Exist Until 2028

The Deepfake Rule That Won't Exist Until 2028

THE TECHNOLOGY BLIND SPOT

On the morning of January 17, 2024, Eric Eiswert’s voice went out to 261,000 people, saying things Eric Eiswert never said. The clip surfaced on an Instagram crime account and spread through the Pikesville High School community within hours: their principal, apparently caught behind closed doors, disparaging Black students’ test scores and Jewish teachers. Baltimore County Public Schools removed him from the building the same day. Death threats followed. So did a patrol car, parked outside his house to protect his family.

The voice was his. The words were not. The school’s athletic director, Dazhon Darien, angry that Eiswert planned not to renew his contract, had recorded a private conversation with the principal in 2023, bought a subscription to a voice-cloning website with his PayPal account, and generated the rant. He emailed it to teachers under a fake name, and the internet did the rest. Everyone who knew Eiswert’s voice authenticated the clip instantly, in their own heads, by the only test they had: it sounded like him.

That test is also, roughly, the one the Federal Rules of Evidence would apply. Under Rule 901(b)(5), any witness familiar with a speaker’s voice can authenticate a recording by saying the voice matches. The threshold for authenticity under Rule 901(a) asks only for evidence “sufficient to support a finding” that the item is what its proponent claims. The jury sorts out the rest. Maura Grossman, a research professor at the University of Waterloo who studies AI evidence, put the problem in one sentence: almost any deepfake will pass that.

A standard that permissive was rational when the rules adopted it in 1975. Forging a voice recording then meant physically splicing tape, and the splice left artifacts an examiner could find with ordinary equipment. Faking a film meant a studio. Evidence law priced authentication cheaply because forgery was expensive, and the price structure held for five decades. It has now inverted. Generating a convincing voice costs a monthly subscription and a sample of the target speaking; proving the voice false costs a forensic laboratory and weeks. The rules still bill at 1975 rates, in the only market where the fraud got cheaper than the audit.

None of this is news to the federal judiciary. Its evidence rules committee has spent three years writing the fix. In May, for the third time, it decided not to act, and its own reporter has told the committee that even a proposal approved tomorrow could not take effect before December 2028. The fabricated file that reaches a courtroom between now and then will carry someone’s voice: a client’s, a spouse’s in a custody fight, a child’s, or yours.

The Rule in the Drawer

The fix exists. It has text, a committee note, and a name: proposed Rule 901(c). Its mechanism is a burden shift. A party claiming that evidence is an AI fabrication must first produce evidence sufficient to support a finding of fabrication; a bare cry of “deepfake” earns nothing. But once that showing is made, the burden flips, and the proponent must persuade the judge that the item is more likely than not authentic, the preponderance standard of Rule 104(a), rather than the featherweight prima facie standard that governs today. The design answers both failure modes at once: it blocks opportunistic fake-crying, and it stops treating a cloned voice like a cassette tape.

Since 2023, the committee has refined that language across six meetings. In May 2025 it declined to recommend the rule, reasoning that few courts had actually confronted a deepfake. On May 7, 2026, it declined again, this time with better data on the table. A Federal Judicial Center survey of 931 federal judges found that just over half believe the authentication rules should change to address deepfakes. Only 2 percent reported having faced a deepfake challenge, and members disagreed over whether the threat was ripe enough to justify rulemaking. The committee scheduled a deeper study session for its fall meeting, with technologists invited. Its companion proposal, Rule 707, which would have applied expert-reliability standards to machine-generated evidence, was not advanced to the Standing Committee either.

Daniel Capra, the Fordham professor who serves as the committee’s reporter, counted at least seven rulings on deepfake challenges in the past year and did the arithmetic on the rulemaking calendar: even a proposal approved at the May meeting could not have taken effect until December 2028. “It seems likely that by that time, deepfakes will have more regularly reached the courts, and possibly in substantial numbers,” he wrote. The existing rule, he added, is “so permissive” that it leaves “almost all authenticity questions to the jury.”

Sit with the mismatch. Voice-cloning tools improve on a monthly release cycle. The rulemaking process runs on a thirty-month cycle, and it has not started the clock.

The Custody File

The courtroom version of this problem did not wait for the committee. In 2019, in a confidential UK custody proceeding, a mother produced an audio recording of her husband, a Dubai resident, making direct and violent threats against her. She argued the recording proved he was dangerous and should not see his children. The husband insisted he had never said the words, while conceding the voice sounded exactly like him, his intonation, his accent, his phrasing.

His lawyer, Byron James of Expatriate Law, did the one thing that saved the case: he demanded the original file. The metadata showed the mother had edited the recording after the call took place, and showed which segments she had assembled from consumer software and online tutorials. The court threw the recording out, and the father kept his access to his children.

Notice what the rescue depended on. An original file existed, the court ordered it produced, and the edits left scars a forensic examiner could find. Each of those conditions is generational. Modern voice synthesis does not edit an original; it generates a new file with nothing to compare against. The next fabricated custody exhibit will not carry metadata confessing its own assembly. And the parents producing such files will not need technical skill, because Darien needed none: a grudge, a sample of the target’s voice, and a subscription. Parents have already heard what the technology does with a child’s voice. Jennifer DeStefano of Scottsdale, Arizona, told the Senate Judiciary Committee in June 2023 about answering a call in which her daughter’s cloned voice sobbed that kidnappers had taken her. The daughter was safe. The sobbing was synthetic, and it was perfect. [See The Voice on the Phone Was Not Your Client, The Technology Blind Spot (2026).]

Judges Improvise

With no rule, courts are inventing standards case by case, and the inventions do not match. In State v. Puloka, a murder trial in King County, Washington, defense counsel offered a bystander’s cellphone video “enhanced” by an AI tool to support a self-defense claim. Judge Leroy McCullough excluded it in March 2024, in what experts called a first-of-its-kind ruling, because the software used “opaque methods to represent what the AI model ‘thinks’ should be shown” and would spawn “a time-consuming trial within a trial.” That result looks right, and it took a Frye hearing, dueling experts, and a judge willing to engage the technology to reach it.

Other courts have set the bar elsewhere. Grossman reviewed the recent rulings and found a spread: “You’ve got a standard that’s too low and then a standard that became impossible, that almost nothing would pass it.” The same clip, offered in two courtrooms, can be evidence in one and contraband in the other. A patchwork like that does not merely produce inconsistent outcomes. It teaches litigants to forum-shop their fabrications, and it teaches honest parties that the cost of authenticating truthful evidence is a lottery.

State courts inherit the vacuum. Most states model their evidence rules on the federal template and wait for federal rulemaking before amending their own. Florida built a statewide certification rule this spring for AI-fabricated citations, the first uniform state answer to hallucinated case law, but no state has adopted an authentication standard for AI-fabricated recordings. The gap is national, and it runs through every family court where the first fabrications have already surfaced.

The mirror-image risk compounds it. As juries learn that anyone can fake audio, every genuine recording becomes deniable; scholars call it the liar’s dividend. A defendant caught on tape needs only to whisper “deepfake” to buy doubt. Proposed Rule 901(c) was built to price that move correctly, demanding an evidentiary showing before any fabrication inquiry begins. Shelving the rule postpones the answer to both cheats at once.

The Case for Waiting

Patience has a serious defense here, and it deserves a full hearing. Rulemaking is deliberate by design; the Rules Enabling Act process exists so that evidence law changes slowly, publicly, and with the benefit of accumulated cases rather than ahead of them. Only 2 percent of surveyed judges have seen a deepfake challenge. The courts that have faced the issue, Puloka among them, resolved it with tools that already exist: Frye, Daubert, Rule 403, Rule 104. A rule drafted against a technology this young could calcify around today’s failure modes and misfit tomorrow’s, and an amendment adopted in haste is harder to repair than a gap. Committee members who counsel patience can point to a century of evidence law absorbing photography, tape, and digital images without a bespoke rule for each.

Where the argument fails is in what the 2 percent actually measures. It counts detected challenges, not fabrications. Falsifying the Eiswert clip took the director of a national media-forensics center, and the fake still cost the principal his job because his employer moved faster than the analysis. The UK file fell only because the forger left an original to compare. A survey of judges cannot count the fabrications nobody caught, and the arrival rate of the ones that get caught is accelerating on Capra’s own numbers: from fifteen judges reporting encounters in one survey cycle to seven written rulings in a single year. Waiting for the caseload to prove ripeness means waiting until courts have already decided the unprovable cases.

One limit needs naming. The empirical incidence of deepfake evidence in American courtrooms today is genuinely low, and this piece’s urgency rests on trajectory, not volume. If the trajectory breaks, the committee’s patience will look like wisdom. Nothing in the tooling curve suggests it breaks.

Your Thursday Action

Three edits, all inside documents you already use. First, in your standard discovery requests and ESI protocol, demand native original files with intact metadata for any audio or video, and name the request: exports, screen recordings, and re-encodings are not originals. Second, in your proposed case-management or Rule 26(f) submissions, add a pretrial notice provision for authenticity challenges to audio and video, so a fabrication fight surfaces before trial instead of mid-testimony; you will be borrowing the notice concept from the committee’s own shelved draft. Third, change one intake habit: when a client hands you a recording, your first question is no longer what it says. It is where the original file lives and what device made it. If any part of your practice touches the family docket, make these edits this week rather than this quarter; custody files are where the first fabrications landed, and where the next ones will.

Eric Eiswert got his vindication because his union paid three forensic experts and the analysis came back in two days, and the vindication still could not outrun the clip. He resigned from Pikesville, sued his own school system, and watched Darien serve four months for a misdemeanor. That is the current price structure: fabrication is a subscription, detection is a specialist, and the rule that would rebalance them is sitting in a drawer in Washington with a 2028 effective date it has not yet earned. Until then, the next fabricated file will meet the same test the first one did: people who know the voice, deciding that it sounds like him. Son, wife, daughter, or career. The voice on that file will belong to someone you know. The only open question is which one.

About the Author

JD Morris is Co-Founder and COO of LexAxiom, an Agentic AI platform for the business of law. Over a 25-year career, he has built and scaled enterprise technology products across Dell, EMC, VMware, and Cisco, including the first exabyte eDiscovery platform. He holds dual MBAs from Columbia Business School (Finance) and UC Berkeley Haas (Marketing), a Master of Legal Studies in Cybersecurity Law from Texas A&M, and a Master of Engineering from George Washington University. He writes The Technology Blind Spot on the intersection of emerging technology and law. Connect with him on LinkedIn at www.linkedin.com/in/jdavidmorris, on X at @JDMorris_LTech, or on Bluesky at @JDMorris-ltech.bsky.social.

References

1. Advisory Comm. on Evidence Rules, Report to the Standing Committee (May 17, 2026), https://www.uscourts.gov/sites/default/files/document/advisory_committee_on_evidence_rules_may_2026.pdf.

2. Advisory Comm. on Evidence Rules, Agenda Book (May 2026), https://www.uscourts.gov/sites/default/files/document/2026-05-evidence-rules-agenda-book.pdf.

3. Fed. R. Evid. 104(a), 901(a), 901(b)(5).

4. As Deepfake Evidence Spreads, Rulemaking Efforts Stay Stuck in Development, Law.com (May 7, 2026), https://www.law.com/legaltechnews/2026/05/07/as-deepfake-evidence-spreads-rulemaking-efforts-stay-stuck-in-development-/.

5. Former School Athletic Director Gets 4 Months in Jail in Racist AI Deepfake Case, AP News (Apr. 29, 2025), https://apnews.com/article/racist-ai-recording-maryland-high-school-487ea673b0449077cb23e7970546cb9f.

6. Dylan Segelbaum & Kristen Griffith, Ex-Pikesville Principal Speaks After Dazhon Darien’s Plea in AI Case, Balt. Banner (Apr. 28, 2025), https://www.thebanner.com/community/criminal-justice/dazhon-darien-plea-deal-pikesville-high-school-ai-55EGPRMUT5DEHJT4W2MC2OV2TU/.

7. Ian Round, Man Accused of Pikesville High School Principal Deepfake Agrees to Plea Deal, Daily Rec. (Apr. 28, 2025), https://thedailyrecord.com/2025/04/28/dazhon-darien-pikesville-high-ai-deepfake-sentencing/.

8. Patrick Ryan, ‘Deepfake’ Audio Evidence Used in UK Court To Discredit Dubai Dad, The National (Feb. 8, 2020), https://www.thenationalnews.com/uae/courts/deepfake-audio-evidence-used-in-uk-court-to-discredit-dubai-dad-1.975764.

9. CJ McKinney, Watch Out for ‘Deepfake’ Evidence Forgery, Family Lawyer Warns, Legal Cheek (Jan. 31, 2020), https://www.legalcheek.com/2020/01/watch-out-for-deepfake-evidence-forgery-family-lawyer-warns/.

10. State v. Puloka, No. 21-1-04851-2 KNT (Wash. Super. Ct. Mar. 29, 2024) (order excluding AI-enhanced video evidence).

11. Washington State Judge Blocks Use of AI-Enhanced Video as Evidence in Possible First-of-Its-Kind Ruling, NBC News (Apr. 2, 2024), https://www.nbcnews.com/news/us-news/washington-state-judge-blocks-use-ai-enhanced-video-evidence-rcna141932.

12. Oversight of A.I.: Principles for Regulation: Hearing Before the S. Comm. on the Judiciary, 118th Cong. (2023) (statement of Jennifer DeStefano).



Originally published on LinkedIn Newsletter — The Technology Blind Spot

Leave a Reply

Discover more from The Technology Blind Spot

Subscribe now to keep reading and get access to the full archive.

Continue reading