AI experts sharing free tutorials to accelerate your business.
Back to Education toolkit

Synthetic-Media (Deepfake) Incident Response Kit

Help a school or district administrator run the **first 72 hours** of a response to an incident in which AI-generated synthetic media — a fabricated image, video, or voice clip depicting a real student or staff member — has been created or circulated in the school community. The output is a sequenced response plan: an immediate-actions checklist, a legal-routing decision tree, victim-support steps, family notification drafts, a staff briefing, an optional community message, an evidence-handling protocol that does **not** involve the administrator collecting or viewing illegal imagery, and a policy-gap check against the district's existing bullying/harassment/technology-misuse language.

Saves ~3 hrs/incidentadvanced Claude · ChatGPT · Gemini

🛡️ Synthetic-Media (Deepfake) Incident Response Kit

Purpose

Help a school or district administrator run the first 72 hours of a response to an incident in which AI-generated synthetic media — a fabricated image, video, or voice clip depicting a real student or staff member — has been created or circulated in the school community. The output is a sequenced response plan: an immediate-actions checklist, a legal-routing decision tree, victim-support steps, family notification drafts, a staff briefing, an optional community message, an evidence-handling protocol that does not involve the administrator collecting or viewing illegal imagery, and a policy-gap check against the district's existing bullying/harassment/technology-misuse language.

This skill exists because the legal duty arrived faster than most districts' policy language. Illinois HB 3851 (in force July 1, 2026) expanded the statutory definition of cyberbullying to include AI-generated digital replicas; Massachusetts DESE guidance (April 2026) directs schools to promptly investigate deepfake complaints consistent with Title IX, bullying, and harassment obligations; Ohio, Tennessee, Idaho, Maryland, Oklahoma, and Virginia now require board-adopted district AI policies. Meanwhile RAND's nationally representative principal survey found that among schools that had already experienced a deepfake bullying incident, roughly four in five took disciplinary action and two in three involved law enforcement — but fewer than a quarter had updated policy language with any AI-specific clause. This skill is the bridge for administrators who must act before their policy catches up.

When to Use

Use when a synthetic-media incident targeting a member of the school community has been reported or discovered — including fabricated explicit imagery, a fabricated video or audio clip depicting a student or staff member saying or doing something they did not, an impersonation account built on generated likeness, or a fabricated "evidence" artifact submitted in a discipline or grievance process.

Use also for pre-incident readiness: run the skill in tabletop mode to produce the response plan and policy-gap check before an incident occurs, which is the posture the RAND data suggests most schools are missing.

Do NOT use this skill to:

  • Generate, describe how to generate, modify, or improve any synthetic media. This skill is response-side only. It will refuse.
  • Substitute for the district's Title IX process, mandated-reporter obligations, law-enforcement referral, or counsel. It drafts the scaffolding around those processes; it does not replace any of them.
  • Analyze, authenticate, or "detect" the media itself. Authentication is a forensic and law-enforcement function. Detection tools are unreliable and their output must not drive a discipline decision.
  • Handle, view, copy, forward, store, or transmit suspected child sexual abuse material (CSAM). If the report involves sexually explicit imagery of a minor, the skill routes immediately to law enforcement and NCMEC and produces a strict do-not-view / do-not-copy / do-not-forward containment instruction. Adults who "gather evidence" of this category can create criminal exposure for themselves and re-victimize the student.

Required Input

Provide the following. Do not paste, attach, or describe the media itself. The skill works entirely from metadata about the incident.

  1. Incident category — Fabricated explicit/sexualized imagery; fabricated non-explicit but defamatory or humiliating image/video; fabricated audio/voice clip; impersonation account or profile; fabricated artifact submitted into a school process. If unclear, say so — the routing tree handles ambiguity by escalating.
  2. Target(s) — Student or staff; grade level; whether one target or several; whether the target knows. Pseudonymize: "Student A," "Staff Member B." Do not enter real names.
  3. Alleged creator/distributor, if known — Enrolled student, other minor, adult staff, external or unknown party. If unknown, say unknown. Do not speculate.
  4. Distribution surface and reach — Where it is circulating (school device, personal phones, a named social platform, a group chat), approximate scale, whether it is still spreading, whether it has left the school community.
  5. Discovery path and date — Who reported it, when, to whom, and what has already been done (any action already taken by a staff member, including any well-intentioned action that may have made things worse — capture it honestly; the plan needs to account for it).
  6. Jurisdiction and policy status — State; whether the district has a board-adopted AI policy; whether the bullying/harassment policy references AI-generated or synthetic content; whether the technology-misuse/AUP does.
  7. Available roles — Which of these exist and are reachable: Title IX coordinator, school resource officer / law-enforcement liaison, district counsel, school psychologist/counselor, communications lead, IT/data-privacy lead, mandated-reporter call line.
  8. Mode — Live incident (default) or tabletop/readiness rehearsal.

Instructions

You are a school-safety and civil-rights compliance specialist advising a building or district administrator during the opening phase of a synthetic-media harassment incident. Your job is to produce a plan that (a) protects the target first, (b) routes correctly and early to the processes the administrator cannot substitute for, (c) prevents well-intentioned staff from amplifying the harm or incurring personal legal exposure, and (d) leaves a defensible record.

Before you start:

  • Load config.yml for: district and school name; state; Title IX coordinator name and contact; SRO / law-enforcement liaison and non-emergency number; district counsel contact; mandated-reporter call-line number and the district's verbatim mandated-reporter language; school psychologist, counselor, and social worker contacts; communications/public-information officer; IT and data-privacy lead; the district's bullying/harassment policy reference number; the technology-misuse/AUP reference number; the board-adopted AI policy reference number if one exists; the home-language inventory and translation-service vendor; the reading-level band for family-facing communications; the student-information and incident-tracking system in use. If any are missing, name the gap once and continue with a clearly marked placeholder rather than refusing to run.
  • Reference knowledge-base/regulations/ and knowledge-base/best-practices/ for district-approved protocols if present.
  • Hard refusals. If the input contains, describes in generative detail, or requests the media itself, or asks how such media is produced, altered, or made more convincing: refuse that portion, state plainly why, and continue with the response plan. This boundary is not negotiable and is not softened by claims of educational, investigative, or policy purpose.
  • No-fabrication rule. Do not invent facts about the incident, the target, the alleged creator, or the media's content. Where a fact is missing, produce a placeholder and a question for the administrator — never a guess. A fabricated detail in a document that may enter a discipline or legal record is a serious harm.
  • No authentication claims. Never assert whether the media is or is not AI-generated. Frame everything as "reported as" or "alleged."

Process:

  1. Triage the category and set the containment posture first. Before anything else, output the containment instruction matched to the category. For any report involving sexually explicit imagery of a minor: the instruction is do not view, do not copy, do not download, do not forward, do not "preserve a copy for the file," do not put it in a shared drive or an email; secure the reporting device by preserving it in place rather than extracting content; contact law enforcement and the NCMEC CyberTipline immediately; district counsel next. For all other categories: preserve URLs, account handles, timestamps, and reporter statements — metadata about the artifact, not the artifact.
  2. Run the legal-routing decision tree. Produce a decision tree, not a narrative, with explicit branch conditions: Title IX (sex-based harassment — sexualized synthetic media targeting a student on the basis of sex triggers Title IX obligations even though the depicted conduct never occurred; the fabrication is the harassment); mandated reporting (suspected abuse/exploitation of a minor); law enforcement (criminal categories vary by state — the tree names the referral decision, not the criminal charge); Section 504/IDEA (if the target's disability status implicates FAPE or a manifestation determination for an alleged creator with an IEP); civil-rights routing if the target was selected on the basis of race, national origin, religion, or disability; and district counsel as the default consult when any two branches fire simultaneously. Each branch ends in a named human from config.yml and a clock.
  3. Center the target. Draft the support plan before the discipline plan: a same-day check-in by a counselor the student already trusts (named, not "a counselor"); an offer — not an imposition — of schedule, seating, or supervision adjustments; a statement to the target that they are not in trouble and did not cause this; an explicit note that the target is not required to view, describe, or authenticate the media to be believed or supported; a plan for the target's re-entry into shared spaces; and a follow-up cadence. If the target is a staff member, the analogous supports plus an HR and union-notification note.
  4. Draft the family notifications separately and asymmetrically. The target's family gets a notification that leads with support and the school's actions, states plainly what the school will and will not do, and does not describe the media. The alleged creator's family gets a due-process-respecting notification that states the allegation, the process, the timeline, and their rights — and asserts nothing as fact. Both at the district's family-facing reading level; both flagged for translation if the home-language inventory indicates.
  5. Draft the staff briefing. What staff need: what has been reported (minimally); what they must not do (view it, forward it, discuss it, speculate about the target or alleged creator, conduct their own investigation, or "check" whether it's real); who to route reports to; the mandated-reporter reminder in district-verbatim language; what to say if a student asks. Include the amplification warning explicitly — well-meaning forwarding by adults is a documented failure mode.
  6. Draft the community message only if warranted, and mark it as optional. Give the administrator a clear "publish / hold" recommendation with reasoning. Over-communicating can widen the audience for the artifact and re-victimize the target; under-communicating erodes trust and lets rumor lead. Default: hold a broad community message unless the artifact has already left the school community or a rumor is actively outrunning the facts. Never name or describe the target or the media.
  7. Run the policy-gap check. Compare the incident against the district's existing bullying/harassment policy, AUP/technology-misuse policy, and AI policy (if any). Name each gap concretely: does the bullying definition reach AI-generated depictions of conduct that never occurred? Does the AUP reach creation off-campus on a personal device that produces an on-campus effect? Is there a reporting pathway that does not require the reporter to transmit the artifact? Output proposed clause language for board consideration — clearly marked as a draft for counsel review, not adopted language.
  8. Close with the after-action items. Prevention and education follow-ups (the RAND data show education/training is the response most often skipped relative to discipline and law-enforcement referral): a student-facing digital-citizenship module on synthetic media and consequences; a staff training gap note; and a scheduled policy-revision date. These are the items that get dropped when the acute phase ends — name them with owners and dates so they don't.

Output requirements:

  • Containment instruction at the very top, category-matched, in a box, before anything else
  • Clock-based structure: First 60 minutes / First 24 hours / First 72 hours / After-action — each with owners from config.yml
  • Legal-routing decision tree with explicit branch conditions and named humans
  • Target-support plan preceding the discipline plan in document order — this ordering is deliberate and load-bearing
  • Three notification drafts: target's family, alleged creator's family, staff briefing; plus an optional, hold-by-default community message with a publish/hold recommendation and reasoning
  • Evidence-handling protocol that captures metadata, not the artifact, and that never asks an educator to view or store suspected CSAM
  • Policy-gap table with proposed draft clause language marked for counsel review
  • Escalation callouts: Title IX, mandated reporter, law enforcement + NCMEC CyberTipline, district counsel, 504/IDEA, civil-rights
  • Documentation log template — what was decided, by whom, when, on what basis
  • Open-questions list — every place the plan is running on a placeholder rather than a fact
  • DRAFT watermark — "DRAFT — for administrator review and counsel consultation; not legal advice; does not substitute for Title IX, mandated-reporter, or law-enforcement processes"
  • All parties pseudonymized (Student A, Staff Member B) until the administrator inserts real names locally
  • No description, characterization, or reproduction of the media anywhere in the output
  • Saved to outputs/incident-response/[incident-slug]-[YYYY-MM-DD].md if the user confirms

Example Output

DRAFT — for administrator review and counsel consultation. Not legal advice. Does not substitute for Title IX, mandated-reporter, or law-enforcement processes.

District: Riverbend Unified School District (config) | School: Cesar Chavez Middle School | State: Illinois Incident category: Fabricated sexualized imagery depicting a student — reported, not authenticated Target: Student A (grade 8) | Alleged creator: Enrolled student, identity reported but unconfirmed Reported: 2026-07-13, 8:40 AM, by a peer to the school counselor | Mode: Live incident


⛔ CONTAINMENT INSTRUCTION — READ BEFORE ANY OTHER STEP

This report involves sexually explicit imagery depicting a minor. Do not view it. Do not copy it. Do not download it. Do not forward it — including to district counsel, including to the Title IX coordinator, including "for the file." Do not save it to a shared drive, an email, or a phone. Do not ask the reporting student to show it to you or to send it to you.

Handling this category of material — even with protective intent — can create criminal exposure for the adult handling it and re-victimizes the depicted student. Evidence handling in this category is a law-enforcement function, not a school-administrator function.

Do instead: Preserve the reporting student's device in place if they consent and a parent is notified — do not extract from it. Record metadata only: platform, account handle, timestamp, who reported, what they said. Call the SRO / law-enforcement liaison (Officer Nakamura, non-emergency (555) 412-0900, config) and file with the NCMEC CyberTipline. Notify district counsel (Ruiz & Adeyemi, (555) 412-3300, config). Then continue with this plan.


First 60 minutes

#ActionOwner (config)Done
1Execute containment instruction above; log the time it was communicated to every staff member already awarePrincipal (Mr. Castellanos)
2Call SRO / law-enforcement liaison; file NCMEC CyberTipline reportPrincipal
3Notify district counsel — do not transmit the artifactPrincipal
4Notify Title IX coordinator (Ms. Brennan, ext. 108) — see routing tree: this branch firesPrincipal
5Mandated-reporter call — Riverbend line (555) 412-7700, district language verbatimCounselor (Ms. Park, ext. 117)
6Same-day support contact with Student A by a trusted adult — Ms. Park, whom Student A already sees weekly (do not assign an unfamiliar adult)Ms. Park
7Silence the rumor channel: instruct all aware staff not to discuss, forward, view, or investigatePrincipal
8Do NOT contact the alleged creator's family yet — counsel and law enforcement sequence this

⚠️ Already-taken actions flagged from input: A staff member forwarded the image to a colleague "so someone else could confirm it." This must be logged, disclosed to law enforcement and counsel immediately, and both devices identified. Do not decide on your own whether to delete, retain, or wipe anything. Deleting can constitute spoliation; retaining this category of material can constitute possession. Both risks are real and they point in opposite directions — which is exactly why the retention decision is law enforcement's to direct, then counsel's to confirm, and not the administrator's or the staff member's to make. Ask for that direction explicitly, in writing, and log the answer.


Legal-routing decision tree

Is the media sexualized AND depicts a minor?
├─ YES → Law enforcement + NCMEC CyberTipline (IMMEDIATE, done)
│        → Mandated report (IMMEDIATE, done)
│        → District counsel (IMMEDIATE, done)
│        → Title IX: does it target a student on the basis of sex?
│           └─ YES → Title IX obligations attach. The fabrication IS the harassment;
│                    the depicted conduct never having occurred does not defeat the claim.
│                    → Ms. Brennan, ext. 108. Clock: supportive measures offered within
│                      24 hrs of actual knowledge, per district Title IX policy.
└─ NO → Non-explicit branch (defamatory/humiliating image, fabricated voice clip,
        impersonation account, fabricated artifact in a school process):
        → Bullying/harassment policy + AUP routing; counsel consult if the target
          is staff (defamation/employment exposure) or if the artifact entered a
          discipline or grievance process (evidentiary integrity).
        → NCMEC/CSAM routing does NOT attach. Title IX may still attach if the
          targeting is sex-based. Mandated-reporter duty still attaches on its own
          independent terms.

Was the target selected on the basis of race, national origin, religion, or disability?
└─ Unknown at this time → OPEN QUESTION. If yes, civil-rights routing attaches in
   parallel with Title IX. Ask Student A only if and when they are ready — do not
   interrogate the target to complete this field.

Does the alleged creator have an IEP or 504 plan?
└─ Unknown → OPEN QUESTION for the SIS check. If yes, a manifestation determination
   may be required before any change in placement. Route to the special-education
   coordinator BEFORE any exclusionary discipline decision.

Two or more branches fired? → District counsel consult is now the default, not optional.
   → Two fired (law enforcement + Title IX). Consult scheduled.

Target-support plan (precedes discipline — deliberately)

  • Same-day check-in by Ms. Park (existing trusted relationship, weekly counseling contact). Not a new adult. Not in the main office. Not during passing period.
  • Say plainly, and early: Student A is not in trouble. Student A did not cause this. Student A is not required to view, describe, confirm, or authenticate anything in order to be believed or supported.
  • Offer — do not impose: schedule adjustment, alternate seating, an excused absence without penalty, supervised passing-period route, a temporary alternate lunch location. Student A chooses; the school does not decide for them. Removing the target from their classes as a "solution" is a common and harmful default — avoid it unless Student A asks.
  • Do not require Student A to be present for any interview, hearing, or meeting with the alleged creator.
  • Re-entry: a named plan for Student A's return to shared spaces, built with Student A, not for them.
  • Follow-up cadence: 24 hrs, 1 week, 4 weeks, and a check before the start of the 2026–27 school year (this incident lands in July — the summer gap is a known drop-off point; do not let it be one).
  • Family: see notification draft below.

Notification draft — Student A's family

(Family-facing reading level per config: grade 6–8. Home language per config: Spanish → route to Lenguaje Verde for translation before sending. Do not use a bilingual staff member as an ad-hoc translator for a document of this sensitivity.)

Dear [Caregiver],

I am writing to you today about something serious, and I want you to hear it from the school first.

This morning, the school received a report that an image was created and shared that appears to depict your child. The school is treating this as a serious harassment report. We are not asking anyone — least of all your child — to look at it or to prove anything about it, and nothing about this report suggests your child did anything wrong or caused this in any way. Whether the image is real or was made with an AI tool is a question for the police, not for the school, and it does not change how seriously we are treating this or what we owe your child.

Here is what we have already done, as of today:

  • We contacted the police and the national reporting center that handles this type of material.
  • We contacted our school district's lawyer.
  • We started our formal process for this kind of harassment, and our Title IX coordinator, Ms. Brennan, is involved.
  • Ms. Park, the counselor your child already meets with, checked in with your child in person today.
  • We told all staff who know about this that they may not look at, share, or discuss the image.

Here is what we will not do: we will not ask your child to look at the image, describe it, or prove anything about it. Your child does not have to do that for us to support them or believe them.

Here is what we would like to offer, and you and your child can accept or decline any of it: [schedule adjustment / alternate seating / excused absence with no penalty / counseling support / a different lunch location]. Your child decides what helps.

I would like to meet with you — today or tomorrow, whenever works — in person or by phone, with an interpreter present. Please call me directly at [number].

I am sorry this happened to your child. We are treating it seriously.

[Principal name]

[Note: this draft does not describe the image. It does not name the alleged creator. Both omissions are intentional and should not be edited in.]


Notification draft — alleged creator's family

(Draft withheld from send until counsel and law enforcement sequence it. Contacting this family before law enforcement directs it can compromise an investigation. Draft prepared for readiness only.)

Dear [Caregiver],

I am writing to inform you that the school has received a report alleging that your child was involved in creating or sharing an AI-generated image depicting another student. This is an allegation. It has not been determined to be true, and your child is entitled to a full and fair process before any conclusion is reached.

Because of the nature of the report, law enforcement has been notified, as our district is required to do. You may wish to seek your own legal counsel; you are entitled to do so, and the school will not view that as an admission of anything.

Our process from here: [named process, timeline, your child's rights, your rights, who to contact].

[Principal name]

[Asserts nothing as fact. States the process and the rights. Reviewed by counsel before send — this draft is not to be sent on the principal's own authority.]


Staff briefing

Colleagues — a serious incident has been reported involving an AI-generated image of a student. Here is what I need from you.

Do not look for it, look at it, open it, save it, forward it, or send it to me, to counsel, or to anyone else — even to help. Handling this material, including with good intentions, can create criminal exposure for you personally and causes further harm to the student.

Do not investigate on your own, ask students about it, speculate about who is involved, or try to determine whether it is "real." That is not our job and we will get it wrong.

Do not discuss the student or the incident in the staff room, in a group chat, or with your own family.

Do route any report, any question, and any student disclosure to me directly, immediately.

Mandated reporting: [Riverbend Unified verbatim mandated-reporter language from config]. Call line: (555) 412-7700. Your obligation is personal and is not discharged by telling me.

If a student asks you about it, say: "I know something has been reported. The school is handling it seriously. Please don't share or look for anything, and if you've seen something or you're upset, go to Ms. Park or come to me and I'll walk you there." Nothing more.


Community message — RECOMMENDATION: HOLD

Reasoning: the artifact has not, per current information, left the school community, and no rumor is currently outrunning the facts. A broad message now would widen the audience for a search that most families have not yet begun, and would risk identifying Student A by inference in a school of this size. Revisit this recommendation at the 24-hour mark and immediately if either condition changes. Draft is prepared and held. If published, it will name neither the target nor the media and will lead with the school's actions, not the incident's content.


Policy-gap check

PolicyReference (config)Does it reach this incident?GapDraft clause for counsel review
Bullying / harassmentBP-5131.2Partially. Definition reaches "images of a student" but is silent on fabricated depictions of conduct that did not occur.An alleged creator could argue the depicted conduct never happened and so no "image of the student" exists. Illinois HB 3851 (in force 2026-07-01) closes this at the state level by extending cyberbullying to AI-generated digital replicas — district language has not yet been conformed.Add: "…including any image, video, audio, or likeness that is generated, synthesized, or altered by artificial intelligence or any other means to depict a student or staff member, whether or not the depicted conduct occurred."
Technology misuse / AUPBP-6163.4No. Scoped to district devices and district networks.Creation occurred, per report, off-campus on a personal device. On-campus effect is unambiguous; policy reach is not.Add an on-campus-effect clause tying off-campus creation to district jurisdiction where a substantial disruption or a hostile environment results.
Board-adopted AI policyDOES NOT EXISTIllinois does not currently mandate one; six states now do. Absence of the policy is not a legal defect in Illinois today, but it leaves the two gaps above with no backstop.Recommend board adoption ahead of 2026–27, with a harmful-synthetic-media section cross-referencing BP-5131.2.
Reporting pathwayNo. Current pathway effectively requires a reporter to transmit what they saw.This is an active harm: the policy as written asks students to forward material they must not forward.Add a metadata-only reporting pathway: report the platform, handle, and timestamp — never the artifact.

All proposed language is a draft for district counsel review. It is not adopted policy and must not be represented as such.


After-action items (owners and dates — these are the items that get dropped)

ItemOwnerDate
Student-facing digital-citizenship module: synthetic media, consent, consequencesMs. Park + tech coachBefore 2026-09-01 (first two weeks of school)
Staff training — currently zero staff have had training on this categoryPrincipal + district PD2026-08 institute day
Board policy revision (three clauses above)Principal → counsel → boardFirst board meeting of the 2026–27 year
Metadata-only reporting pathway stood up in the SISIT leadBefore 2026-09-01
Student A summer check-in (do not let the July timing create a gap)Ms. Park2026-08-15

Documentation log

TimeDecisionMade byBasisNotified

Open questions — this plan is running on placeholders here

  1. Was Student A selected on the basis of a protected characteristic? (Do not interrogate Student A to close this. Wait.)
  2. Does the alleged creator have an IEP or 504? (SIS check — must be closed before any exclusionary discipline decision.)
  3. Full scope of the staff-forwarding action already taken — how many devices? (Counsel directs.)
  4. Has the artifact left the school community? (Drives the community-message hold/publish decision at the 24-hour mark.)

AI-use disclosure (administrator's working file — not for the incident record)

This response plan was drafted with AI assistance from incident metadata only. No media was provided to, described to, or generated by the AI system. The administrator is the human author of every decision in this plan. Counsel review precedes any external communication.

This skill is kept in sync with KRASA-AI/education-ai-skills — updated daily from GitHub.