Will it run?
Models

A low-tech solution from the past may be the best defense against AI deepfakes

By Ilse Brandt Clawpit staff
A low-tech solution from the past may be the best defense against AI deepfakes

AI-driven identity theft has reached a level of sophistication where traditional tells — background noise, synthetic modulation, missing breaths — are no longer reliable. Security experts are recommending a return to simple, almost outdated protocols as a more practical line of defense than any automated detection tool.

The incident that changed the picture

In January 2024 an employee at professional-services firm Arup joined a video call believing the company’s chief financial officer was on the other end. No real person was present: every participant was an AI-generated double built from public appearances and investor calls by Arup executives. The result was 15 bank transfers to third-party accounts totaling about $25 million. “Seeing and hearing someone is no longer proof they are real,” said Deepak Gupta, chief technology officer at GrackerAI. Any protocol that relies on “I recognized the face and voice” is broken by design.

Research shows humans cannot detect them

A University College London study found listeners identified deepfakes with only 73% accuracy. Training and prior exposure to examples improved accuracy by just 3.84%. A year later, a meta-analysis by the University of Duisburg-Essen and Indiana University, aggregating 56 similar studies, showed human detection rates hovering near random chance. James Scobey, chief technology officer at cybersecurity firm S2i2, said, “Visual cues have only marginal value as a supplementary signal, but relying on them as an effective control teaches employees to trust their own perception.”

Automated tools fail too

A joint fact sheet from the NSA, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) dismissed traditional automated detection protocols that hunt for statistical traces of manipulation in audio or video. “The assumption that such traces can be found and catalogued no longer necessarily holds,” the sheet stated. The problem worsens as attacks shift from one-off fraud to long-term infiltration of organizational systems. Gupta pointed to a 2024 incident at security-training company KnowBe4, which fell victim to identity fraud when it hired an attacker posing as a legitimate employee — proof that even security organizations are not immune.

The recommendation: go back to basics

Faced with the failure of technological detection, Gupta and Scobey point to low-tech protocols: multi-channel verification (for example, a separate phone call to a verified number), internal approval through an enterprise identity-management system, and authorization procedures requiring signatures from two independent parties for any transfer above a set threshold. These are not flashy solutions, but they do not depend on senses that AI already knows how to fake. The bottom line: when the attacker controls the face and the voice, the only thing they cannot easily forge is an organizational process that demands more than a single communication channel