Skip to content

Billie Eilish deepfake case shows growing risks from AI-generated media

Billie Eilish deepfake case shows growing risks from AI-generated media

A viral collection of AI-manipulated images depicting Billie Eilish drew about 11 mn views on TikTok before the platform removed it. The incident became an early example of how generative AI tools could be used to create sexualized fake content involving celebrities.

The episode occurred in December 2022, rather than 2024 as some later accounts have claimed. Vice reported that the TikTok post used Eilish’s face on artificially generated or manipulated bodies and spread through the platform’s recommendation system within four days.

Deepfakes and other forms of synthetic media have since become a larger issue for performers whose faces and voices are widely available online. Improved image, audio and video generators have reduced the technical barriers to creating convincing impersonations.

The risk extends from misleading social posts to unauthorized sexual imagery and commercial misuse of a person’s likeness. For actors, musicians and other public figures, questions over consent and control of digital replicas have consequently become part of negotiations around AI.

Scarlett Johansson brought similar concerns into focus in 2024 after saying an OpenAI voice used for ChatGPT sounded similar to hers. OpenAI paused use of the “Sky” voice, while SAG-AFTRA publicly supported Johansson and called for stronger legal protections against unauthorized digital replicas.

AI companies have responded partly through provenance technology intended to show where synthetic media originated. OpenAI now embeds C2PA Content Credentials and SynthID watermarks in supported images generated through ChatGPT, Codex and its API.

OpenAI also provides a verification tool that checks images and supported audio for provenance signals associated with its systems. The service can indicate whether media contains an OpenAI-linked watermark or trusted C2PA data, but it doesn’t determine whether arbitrary online content is genuine or identify every deepfake created with other tools.

Earlier OpenAI research also tested an image classifier focused specifically on DALL-E 3 output. In internal testing announced in 2024, the classifier identified about 98% of DALL-E 3 images, although performance was lower when distinguishing them from images produced by other AI systems.

Those limitations illustrate a persistent problem with automated deepfake detection. A detector trained on one generation system may perform differently when confronted with content from another model, while compression and editing can remove or weaken some provenance signals.

Anthropic has taken a different approach centered on preventing misuse of Claude through model safeguards and enforcement systems.

The company says its protections combine policy controls, model training, testing and real-time enforcement, while its threat intelligence teams monitor attempts to misuse Claude.

The company has also documented cases in which attackers tried to use Claude for cybercrime and other malicious activity. Anthropic’s published material focuses on preventing abuse of its own models rather than operating a general-purpose service for detecting celebrity deepfakes across social networks.

For social platforms, provenance tools offer one method of identifying synthetic content before or after publication. They work best when generation systems attach durable signals and platforms retain or recognize those signals after files are uploaded.

Platforms still need policies governing manipulated media, while performers and unions continue seeking legal and contractual protections covering digital replicas.

SAG-AFTRA has made unauthorized use of performers’ voices and likenesses a recurring policy issue. Its response to the Johansson case called for legislation protecting people against digital replication without appropriate authorization.

The Billie Eilish case showed how quickly manipulated celebrity content could reach millions of users even before today’s more capable generation systems became widely available.

New provenance and verification systems provide additional ways to identify some AI-generated media, but no existing detector provides universal identification of deepfakes from every model or platform.