On 16 March 2022, a video appeared on the hacked website and broadcast ticker of Ukrainian TV network Ukrayina 24. In it, a figure resembling President Volodymyr Zelensky told Ukrainians to lay down their weapons. The video was crude: the head was oversized and more pixelated than the body, and the voice was deeper than the president’s. The real Zelensky responded on Instagram, calling it a “childish provocation.” Meta and YouTube removed the video for violating policies against misleading manipulated media. The BBC reported that the fake was “ridiculed by many Ukrainians” and that the Ukrainian Center for Strategic Communications had warned the Russian government might use deepfakes to convince Ukrainians to surrender.

That incident is often treated as a footnote — a bad fake, quickly debunked, an easy takedown. But for legal and policy readers, the more consequential question is what standard it set. The Zelensky deepfake did not test whether a synthetic video could fool a mass audience. It tested whether a wartime information ecosystem could verify a claim fast enough to prevent it from being acted upon. The answer, in March 2022, was yes — but only because the fake was technically poor and the response was immediate. That is not a durable standard. It is a warning.

What the record shows

The BBC’s technology report, published 18 March 2022, documents the distribution chain. The transcript first appeared on the ticker of Ukrayina 24 during a live broadcast on Wednesday, 16 March. A screenshot and full transcript later appeared on the network’s website. Ukrayina 24 confirmed both the website — inaccessible for most of the day — and the ticker had been hacked. The video was then shared on Russian-language Telegram and VK, and from there to Facebook, Instagram, and Twitter. Meta’s security-policy head, Nathaniel Gleicher, said the company “quickly reviewed and removed” the deepfake for violating its policy against misleading manipulated media. YouTube said it removed the video for violating misinformation policies.

Nina Schick, author of Deepfakes, told the BBC the takedown was “an easy win” for platforms because the video was so crude and easily spotted as fake even by “semi-sophisticated viewers.” She added a caveat that has aged into a policy problem: “Even though this video was really bad and crude, that won’t be the case in the near future.” Sam Gregory, program director at WITNESS, called it “a best-case deepfake problem” — not very good, easily detected, debunked by Ukraine, and rebutted by Zelensky on social media, making it “an easy policy takedown for Facebook.”

Gregory also pointed to a harder case: an online detector had suggested a genuine video of a senior politician in Myanmar, apparently confessing to corruption, was a deepfake. Debate remains over whether it was a real statement or a forced confession. “The lack of 100% proof either way and people’s desire to believe it was a deepfake reflects the challenges of deepfakes in a real-world environment,” he said. That is the standard the Zelensky case did not meet. It was resolved by obvious technical failure, not by a verification protocol that would work when the artifact is competent.

Why the legal stakes are not hypothetical

Ukraine’s war crimes docket is active. The International Criminal Court’s situation page for Ukraine (ICC-01/22) records that the investigation was opened on 2 March 2022, following a referral from Lithuania on 1 March and a coordinated joint referral from 39 states on 2 March, with additional referrals from Japan and North Macedonia on 11 March, Montenegro on 21 March, and Chile on 1 April. The page lists arrest warrants issued on 17 March 2023 for Vladimir Putin and Maria Lvova-Belova for the war crime of unlawful deportation and transfer of children under Articles 8(2)(a)(vii) and 8(2)(b)(viii) of the Rome Statute — the treaty that establishes the ICC and defines war crimes, crimes against humanity, and genocide. Further warrants followed on 5 March 2024 for Sergei Kobylash and Viktor Sokolov for directing attacks at civilian objects and causing excessive incidental harm, and on 24 June 2024 for Sergei Shoigu and Valery Gerasimov for alleged international crimes committed from at least 10 October 2022 until at least 9 March 2023.

Those cases depend on visual evidence: satellite imagery of strikes, drone video of munitions, photographs of debris, archival records. The Zelensky deepfake did not enter a courtroom. But it established a public expectation that visual claims in this war can be checked. When that expectation is not met — when a synthetic or manipulated artifact circulates without a documented verification chain — the damage is not only to public trust. It is to the evidentiary environment in which war crimes cases are built. If everything can be faked, as Schick warned, then the authentic record becomes contestable by default.

The verification gap the deepfake exposed

The response to the Zelensky video relied on three things: the fake was visually poor, the Ukrainian government had pre-warned that deepfakes might be used, and the president himself could rebut it on a platform with reach. None of those is a generalizable standard.

Consider what a competent deepfake would require. A verification protocol would need to establish provenance — where the video came from, who captured it, and whether the file has been altered. It would need to document the distribution chain — which accounts shared it, when, and with what amplification. It would need a public, timestamped rebuttal from a recognized authority. And it would need a way to preserve the artifact for later legal use, because a removed video is not necessarily a preserved one.

The Zelensky case produced the first three in an ad hoc way. It did not produce the fourth. Platforms removed the video. The BBC documented the distribution. Zelensky rebutted it. But the removal itself can complicate preservation. For legal readers, that is the operational lesson: takedown and preservation are different functions, and a takedown without a preservation protocol can erase the evidence of the information operation even as it stops the harm.

What a wartime verification standard should include

The following is a recommendation, not a finding of any institution. It is drawn from the gaps the Zelensky incident exposed and from the evidentiary requirements of the ICC’s Ukraine docket.

1. Provenance capture at first contact. When a suspect video appears, the first responder should capture the URL, the upload timestamp, the account identifier, and a hash of the file before any platform action. This is a preservation step, not a publication step. It creates a record that can be authenticated later.

2. Chain-of-custody documentation. For satellite imagery, drone video, and munitions debris, the same logic applies. Who collected it, when, where, and how was it transferred? The ICC’s evidentiary standards require authentication, and a visual artifact without a custody record is weaker than one with it.

3. A named rebuttal authority. The Zelensky case worked because the president could rebut directly. In cases where the subject cannot or does not, the verification standard needs a designated authority — a government communications unit, a fact-checking organization, or a court — whose rebuttal is timestamped and public.

4. Synthetic-media labeling that survives removal. Platform policies against misleading manipulated media are necessary but not sufficient. If a video is removed, the label and the reason should remain accessible in a transparency report or archive. Otherwise the public record shows only that something disappeared.

5. Distinguish satire from disinformation. Gregory noted that a Putin deepfake was widely regarded as satire, but “there is a thin line between satire and disinformation.” A verification standard should not treat all synthetic media as equivalent. Intent, context, and amplification matter.

What the deepfake did not change

The BBC report notes that “old videos and doctored memes remain the most common and effective misinformation tactic in this war.” The Zelensky deepfake was notable because it was a deepfake in a war, not because it was the most effective piece of false content. That distinction matters for policy. A verification standard that focuses only on synthetic media will miss the cheaper, more common manipulations: recycled footage, mislabeled images, and out-of-context clips.

The ICC’s Ukraine page shows the legal machinery is moving. The evidentiary machinery — the protocols for capturing, authenticating, and preserving visual material — is less visible. The Zelensky deepfake set a standard by accident: it showed that a crude fake can be beaten by a fast, coordinated response. The next one may not be crude. The standard should not depend on that.

FAQ

What was the Zelensky deepfake?
A manipulated video that appeared on 16 March 2022 on the hacked website and ticker of Ukrayina 24, showing a figure resembling President Zelensky telling Ukrainians to surrender. It was removed by Meta and YouTube for violating policies against misleading manipulated media.

Was it convincing?
No. The BBC reported the head was oversized and more pixelated than the body, and the voice was deeper. It was “ridiculed by many Ukrainians” and described by experts as a “best-case deepfake problem” because it was easily detected.

Why does it matter for war crimes cases?
War crimes cases at the ICC (ICC-01/22) rely on visual evidence — satellite imagery, drone video, photographs, debris. A manipulated video that circulates without a verification chain weakens the evidentiary environment by making authentic material easier to contest. The deepfake did not enter a courtroom, but it set a public expectation about verification that the legal system depends on.

What should platforms and investigators do differently?
Preserve the artifact before removal, document the distribution chain, designate a rebuttal authority, and keep synthetic-media labels accessible after takedown. These are recommendations, not current requirements.

Did the deepfake change platform policy?
The BBC report documents that Meta and YouTube removed the video under existing policies against misleading manipulated media and misinformation. It does not document a new policy created specifically in response. The incident tested existing policies rather than expanding them.