Deepfakes and Perfidy: Whose Voice, What Protection?

deepfakes and perfidy
Photo by Pablo Merchán Montes on unsplash.com

Estimated reading time: 11 minutes


A synthetic video can now put a commander’s face and voice on words he never spoke. For judge advocates, this raises a practical question about deepfakes and perfidy. Does Article 37 of Additional Protocol I (AP I) still separate lawful ruse from prohibited perfidy in the right place?

My answer is that it does, and that the reason is structural. Every machine-generated deception aimed at a person carries two layers. The first is a borrowed identity: whose face or voice the fabrication uses. The second, present only in some cases, is a claimed protection: what protection under international humanitarian law (IHL) the fabrication asserts. Article 37 reads only the second layer. That is why the test has absorbed each new deception technology. It is also why a recent classification of synthetic surrender orders as perfidy does not hold.

This post addresses machine-generated deception aimed at people; deception aimed at machines is the subject of a companion post, and deception by conventional means is outside the scope of both. For that reason, I leave aside reports that a US strike on a suspected drug boat in September 2025 used an aircraft painted to resemble a civilian one. Whatever their legal merits, such questions concern the appearance of a crewed platform, which is conventional deception.

The analysis applies to international and non-international armed conflict alike. Additional Protocol II contains no perfidy provision, because it was removed from the draft shortly before adoption. Customary law covers both nonetheless. The International Committee of the Red Cross (ICRC) states the prohibition of perfidy (Rule 65) and the permission of ruses (Rule 57) as customary in each.

I. The Article 37 Test

Article 37 does not prohibit deception. It prohibits one kind of deception: betraying an adversary’s confidence in the protection that IHL affords. Article 37(1) AP I defines perfidy as “[a]cts inviting the confidence of an adversary to lead him to believe that he is entitled to, or is obliged to accord, protection under the rules of international law applicable in armed conflict, with intent to betray that confidence”. Its four examples begin with “the feigning of an intent to negotiate under a flag of truce or of a surrender”.

Ruses are the lawful counterpart. Under Article 37(2), they may mislead an adversary or induce recklessness. They must break no rule, and they “do not invite the confidence of an adversary with respect to protection under that law”. Misinformation is one of the listed examples.

The ICRC Commentary names three elements of perfidy: inviting confidence, intending to betray it, and an objective element. That element is “the existence of the protection afforded by international law applicable in armed conflict” (at para 1500, p. 435). Ruses are also intended to mislead, so intent alone does not separate the two. What separates them is that, in perfidy, both the confidence invited and the intent to betray it concern protection under the law.

The prohibition applies only where perfidy is used to kill, injure or capture. The Commentary acknowledges the room this leaves: feigning aimed only at a tactical disadvantage falls outside Article 37(1) (at para 1492, pp. 432–433).

On capture, the United States departs from AP I. The US Department of Defense (DoD) does not read customary law as prohibiting capture by perfidy (DoD Law of War Manual, § 5.22.2.1, at p. 329). German doctrine includes capture in the prohibition (ZDv A-2141/1, Humanitäres Völkerrecht in bewaffneten Konflikten, para 481, at p. 63).

Everything that follows turns on that reference to protection. A deception is perfidious only if it claims protection under the law.

II. Two Layers in Every Synthetic Deception

Whose voice, what protection

The law has long treated the borrowed-identity layer as a ruse. Deceiving an adversary about the source or truth of a message, including a call to surrender, sits on the lawful side of Article 37. This position is consistent across the ICRC, expert and State treatments. The ICRC Commentary lists as a ruse “using the enemy wavelengths, passwords and wireless codes to transmit false instructions” (at para 1521, p. 443). The Tallinn Manual 2.0 treats bogus orders purporting to come from the enemy commander in the same way (Rule 123, commentary para 2, at p. 496).

State manuals point the same way. The DoD Manual lists bogus messages planted for the enemy to intercept among permitted ruses (§ 5.25.2, at pp. 337–338). Its ruse section also lists inducing surrender through false claims of military superiority (§ 5.25.1.1, at p. 336). German doctrine permits spreading even false news to undermine the adversary’s will to resist, and calling on enemy forces to surrender (ZDv A-2141/1, para 487, at p. 64).

Synthetic media changes none of this. A cloned voice makes a bogus order more convincing. It does not change what kind of act the order is.

Two cases

Two cases show that perfidy attaches to the claimed protection and to nothing else. The first comes from Eric Jensen and Summer Crockett. A commander receives a fabricated video of his own Chief of Defence Staff. The video announces that the enemy has surrendered and orders his forces to stand down. Enemy forces then enter the city and attack. Jensen and Crockett classify this as perfidy: the attack succeeds only because the victims trust the protection the law gives to surrender.

Seen through the two layers, the result is clear. The borrowed identity is the victim’s own Chief of Defence Staff. The claimed protection is the enemy’s feigned surrender, the first example in Article 37(1). Perfidy attaches to the second layer. Without it, the video would be a bogus order.

The second case comes from David Allen. He poses a voice-cloned call in which a unit commander believes his own superior is ordering him to surrender (at p. 34). On my reading, only the first layer is present here. The deceiver claims no protection for itself. If it accepts and honours the surrender, it has betrayed no confidence in protection, and the call is a bogus order. If it attacks those who have surrendered, the breach lies in Article 41 AP I, which protects persons hors de combat. It does not lie in the perfidy rule.

Where a 2025 classification goes wrong

Running the two layers together produces a misclassification in one 2025 treatment. Berkant Akkuş describes a synthetic video in which an enemy commander orders surrender or withdrawal as clear perfidy. His reason is that it invokes the protection owed to persons hors de combat (at § 2.6). He treats fabricated orders that move troops into a compromised position in the same way (at § 2.5).

That classification places perfidy in the borrowed identity. It departs from the ICRC, expert and State treatments above. It also departs from Jensen and Crockett, who regard a synthetic order from a commander moving forces as a mere ruse. Akkuş’s own first example reaches the opposite result: he assesses a fabricated retreat order as lawful (at § 2.5). A fabricated surrender order invokes protection, but if the deceiver honours the surrender, it betrays none.

In operational terms, what current AI chiefly makes cheap is the borrowed identity. By 2022, widely accessible tools could produce convincing synthetic video in under an hour (Allen, at p. 61). The practitioner reading is that the technology enlarges the space of lawful deception far more than the space of perfidy. Perfidy still requires a claimed protection in the content, as it always has. That does not make every synthetic deception short of perfidy lawful. Section III turns to the rules that apply when no protection is claimed.

III. What Remains Regulated When No Protection Is Claimed

A deception that claims no protection escapes Article 37, but not the rest of the law.

The protective emblems are the clearest case. Article 38 AP I prohibits their improper use absolutely, regardless of result (Commentary on Article 38, at para 1532, p. 448). Even the stricter camp among the Tallinn experts treats electronic reproductions of the emblems as covered (Rule 124, commentary paras 5–6, at p. 498). On that reading, a synthetic video displaying the red cross falls within the prohibition. A voice-cloned fake ICRC delegate who displays no emblem does not, because a bare claim of protected status is not emblem misuse (ibid., para 4, at pp. 497–498). Used to kill, injure or capture, it may instead be perfidy.

Enemy uniforms differ. Article 39(2) AP I restricts their use, but the Tallinn experts read “emblems, insignia or uniforms” as concrete visual objects only (Rule 126, commentary para 3, at p. 500). Whether a synthetic depiction of an enemy uniform counts as “use” is therefore open.

A fabricated armistice tests the limits of Article 37 itself. As Section I noted, feigning without such a result falls outside Article 37. The Commentary’s example is raising the white flag solely to delay an attack (at para 1492, pp. 432–433). In its 1999 assessment of information operations, the DoD General Counsel considered a computer-morphed broadcast in which the enemy’s head of state announces an armistice. The assessment concluded: “If false, this would also be a war crime” (at p. 473). In my view, that goes further than Article 37. The borrowed identity is the adversary’s own head of state; the claimed protection is a suspension of hostilities. Where killing, injury or capture follows, Article 37 applies. Where none does, the case falls outside Article 37, like the white flag, and closer to the good-faith rules on truces and the flag of truce (DoD Manual, §§ 12.2 and 12.4.2.1, at pp. 854 and 857).

IV. Is the Frame Too Narrow?

The strongest objection accepts everything so far. Dominika Kuźnicka-Błaszkowska and Nadiya Kostyuk agree that synthetic media in war should generally be treated as ruses. Their point is that this narrow view misses the harm such media can do to individuals and societies. Citing impersonated humanitarian officials and fabricated evacuation calls, they call for explicit prohibitions on deceptive media aimed at civilians (at “Regulating deepfakes at the international level”). Jensen and Crockett themselves list a treaty ban on publicly available synthetic media in armed conflict among possible solutions.

Part of this harm is already regulated. Where deception aimed at forces spills over onto civilians, the obligation of constant care applies. In Jensen and Crockett’s scenario, civilians leave their places of safety because of the fake surrender. The authors see a possible breach of that obligation. As Hitoshi Nasu notes, disseminating synthetic media will rarely be an attack, so targeting law seldom applies. As part of a military operation, however, it remains subject to constant care, an obligation of due diligence (Article 57(1) AP I).

The threat limb of Article 51(2) reaches further than the debate usually allows. Its second sentence prohibits “[a]cts or threats of violence the primary purpose of which is to spread terror among the civilian population”. The Commentary on Article 51 stresses that threats are covered as well as acts (at para 1940, p. 618). Tallinn Rule 98 adds that communicating a threat of kinetic attack by cyber means is equally prohibited (commentary para 6, at p. 434). The ICRC states the rule as customary in both kinds of conflict (Rule 2). Akkuş nonetheless treats a fabricated conversation between leaders announcing a nuclear strike, spread to incite panic, as a lawful non-attack (at § 2.5). He reaches that result by asking only whether it is an attack.

In my view, the threat limb reads the content, as Article 37 does, and not the borrowed identity. Whether synthetic content threatens violence turns on the message its civilian audience receives, not on its form. A false report of an attack can carry an implicit threat of more to come. The Tallinn experts’ false tweet about a spreading disease is sound on its stipulated facts (Rule 98, commentary para 3, at p. 433). It reports a natural event. It does not show that false reports can never be threats. Primary purpose remains a separate requirement. That keeps genuine warnings, which Article 57(2)(c) AP I requires, outside the prohibition.

What remains is narrower than the critique assumes: synthetic content aimed at civilians that neither attacks nor threatens violence. Within IHL, only constant care governs it, and only where it forms part of a military operation. Deception aimed at civilians as such lies outside this post, so I identify the gap here without analysing it.

As I see it, no new law is needed, but clarity would help. The DoD Law of War Manual already treats propaganda as a military operation and restates the prohibition of terror-spreading threats (§ 5.2.2 and § 5.2.2.1, at pp. 190–191). Other States could confirm the same in their manuals, and add one point: synthetic media change none of these rules. A synthetic threat falls under Article 51(2) like any other; synthetic propaganda is judged like any other. That will not solve every problem, but it keeps the law focused on content, where Article 37 has always focused it.

Conclusion

The debate on deepfakes and perfidy has mostly asked what the technology can do. The legal test asks what the fabrication claims. Article 37 reads the protection a deception claims, not the identity it borrows, so machine-generated deception aimed at people is perfidious only when its content feigns protection under IHL. Much of what AI makes cheap is therefore lawful ruse. Much of what remains harmful is caught by other rules: the emblem rules, the threat limb of Article 51(2) and constant care.

The conclusion on regulation mirrors the one I reached for autonomous weapon systems. There, too, a new treaty was neither necessary nor effective, and more flexible instruments did the work better. For synthetic deception, those instruments are the manuals that judge advocates already apply.

Next, a companion post turns from people to machines. It asks whether deceiving an adversary’s automated systems can be perfidy.

About the author

With more than 25 years of experience, Andreas Leupold is a lawyer trusted by German, European, US and UK clients.

He specializes in intellectual property (IP) and IT law and the law of armed conflict (LOAC). Andreas advises clients in the industrial and defense sectors on how to address the unique legal challenges posed by artificial intelligence and emerging technologies.

A recognized thought leader, he has edited and co-authored several handbooks on IT law and the legal dimensions of 3D printing/Additive Manufacturing, which he also examined in a landmark study for NATO/NSPA.

Connect with Andreas on LinkedIn