One deepfake problem is happening to your company. The other one, your own team is causing on purpose. They need completely different responses.
Deepfakes at work are two separate problems. The first is fraud: someone outside your company using a cloned voice or a fabricated video to trick an employee into acting. The one control that reliably stops it is a callback verification protocol on a separate, pre-agreed channel, not better deepfake detection. The second is your own team’s use of synthetic media (AI voiceovers, avatar presenters, de-aged or touched-up photos) which the EU AI Act’s Article 50 transparency rules, in force since 2 August 2026, now require labelling in many cases. This piece covers what deepfakes can actually do now, both problems separately, what the August rule change means if you make synthetic content, the ethical line that sits before the legal one, a policy template, and a short list of what to actually do this week.
Picture a finance director getting a call that sounds exactly like her CEO’s voice, tone and cadence included, asking her to approve an urgent wire transfer before a call in ten minutes. Two years ago that scenario needed a skilled impressionist and a good phone line. Now it needs a few minutes of publicly available audio, which almost every executive has, sitting in earnings calls, conference talks, and LinkedIn videos.
That’s the honest state of voice cloning: convincing on a phone call, especially a rushed one, and available to someone with no special technical skill. Video is close behind for a short, well-lit clip, but real-time video deepfakes, the kind that would let someone impersonate a person live on a video call convincingly for several minutes, are still noticeably harder to pull off than a cloned voice on an audio-only call. That gap matters for where the real risk sits right now: audio fraud over the phone, and pre-recorded video, are the two categories actually being used against companies at scale. Live video impersonation on a call is a real and growing threat, but currently a less common attack path than the other two.
What deepfakes still can’t reliably do: hold up under a direct, specific question the real person would be expected to know off the top of their head, especially something outside what’s publicly available online. That gap is exactly where the one working defense in this piece, covered in the section on being targeted, actually lives.
Almost every article about deepfakes at work is really an article about fraud: the cloned CEO voice, the fake video call, the wire transfer that shouldn’t have gone through. That’s a real and growing problem. It’s also only half of what “deepfakes at work” now means, and treating it as the whole picture leaves a second, completely different problem unaddressed.
| Problem 1: Fraud | Problem 2: Your own synthetic media | |
|---|---|---|
| Who’s doing it | Someone outside your company, targeting it | Your own marketing, training, or communications team, on purpose |
| The harm | Financial loss, data exposure, reputational damage from a successful scam | Misleading an audience who doesn’t know they’re looking at synthetic content, plus legal exposure under new labelling rules |
| What actually fixes it | Verification protocols and employee training on the specific fraud pattern | A synthetic media policy and disclosure practices, not fraud training |
The same word, two different risks, two different owners inside most companies. A single “deepfake policy” that only covers one of these rows leaves the other one exposed.
Fraud defense and content policy are different jobs. One protocol can’t do both.
Security teams tend to own the first row and have never been asked about the second. Marketing and L&D teams are actively creating the second row’s content and have rarely been told the first row exists as a threat to plan around. Neither team is wrong to focus where they have. The gap is that almost nobody owns both halves of the picture at once, which is exactly how a company ends up with a phishing-awareness policy that never mentions AI avatars, sitting next to a marketing team that’s been using one for six months without telling legal.
The FBI’s Internet Crime Complaint Center tracked AI as a distinct factor in reported cybercrime for the first time in its 2025 annual report. The numbers are worth sitting with, not as a scare figure but as a scale check: more than 22,000 complaints referenced AI, with adjusted losses over $893 million.[1] Inside that total, the report specifically calls out voice cloning being used to request wire payments or impersonate an employee, layered into business email compromise scams that already existed before AI made the follow-up call sound convincing. Businesses reported losses over $30 million in 2025 to BEC scams with a confirmed AI component.[1]
The report also flags something less discussed: voice spoofing showing up during job interviews, where an interviewee’s on-camera lip movement doesn’t quite match what’s being said, a sign of a candidate using real-time voice or video manipulation during hiring itself.[1] That’s a version of this fraud most companies haven’t thought to guard against at all, because it doesn’t fit the “CEO fraud” story that dominates the coverage.
Here’s the part that matters most for what to actually do about it: none of these scams beat good judgment. They beat urgency. Every version of this fraud, the wire transfer, the interview, the distress call from a “family member” using cloned audio, works by creating time pressure that discourages the one step that would catch it. A few patterns show up across most of these cases:
A framework for the pattern, not a measured finding. Print it, put it near finance and HR desks, and treat it as the default response to any urgent request arriving by voice or video.
This is the one control that actually works, and it’s worth being specific about why: it doesn’t depend on anyone being able to tell a real voice from a cloned one, which is a skill getting harder every year. It depends on never trusting the channel the request arrived on, which stays true regardless of how good the fake gets.
If your company makes any AI-generated video, audio, or image content, and most that do any modern marketing or training now do, the European Commission’s Article 50 transparency obligations under the EU AI Act took effect on 2 August 2026, and they apply regardless of where your company is based if that content reaches EU audiences.[2]
The Commission’s own guidance defines a “deepfake” using three cumulative criteria, and all three have to be true for the rule to apply:
| Criterion | What it means in practice |
|---|---|
| Resemblance | The content closely resembles a specific person, object, place, entity, or event |
| Existing | The thing being simulated is real, could plausibly be real, or could plausibly have existed |
| False appearance of authenticity | It would plausibly deceive a reasonably informed viewer into thinking it’s real or truthful |
All three criteria have to be met. Background scene generation, special effects, and standard production touch-ups are explicitly carved out by the Commission’s own guidance, so not every AI-touched asset counts.
If your content clears that bar, the obligation is on whoever deploys it, which the guidance defines broadly: a company using an AI system in a professional or commercial capacity counts as a deployer, and its individual employees, digital animators, or contractors working under its direction don’t count as separate deployers themselves.[2] The label has to be clear and understandable at first exposure, and it can’t rely only on invisible machine-readable watermarking baked in by the tool that generated it. If a viewer wouldn’t notice the disclosure without special tools, it doesn’t satisfy the rule.
There’s a real, useful exemption worth knowing: evidently artistic, satirical, or fictional work only needs disclosure “in an appropriate manner that does not hamper the display or enjoyment of the work,” a lighter bar than a straight corporate training video making a false claim of authenticity. And there’s a genuine grace period specifically for the machine-readable marking obligation on systems already on the market before 2 August 2026, extending to 2 December 2026, though the visible, human-facing disclosure duty on deployers doesn’t get that same runway.[2] Content made and published before 2 August 2026 doesn’t need retroactive labelling, though the Commission’s own guidance encourages it where practical. Fines for non-compliance can reach 15 million euros or 3% of a company’s global annual turnover.[2]
A training team building a compliance video with an AI presenter reading a script is clearing the Article 50 bar easily, as long as the avatar is disclosed. That’s the legal line. The ethical line sits earlier, and it’s worth naming because plenty of content will pass the law and still feel wrong to the people watching it.
Say a company builds an AI avatar of a well-liked, long-departed employee to deliver onboarding training, without ever asking that person’s permission or telling new hires the person hasn’t worked there in two years. It’s disclosed, technically compliant, and it’s still going to unsettle anyone who finds out, because the ethical question was never “did we label it,” it was “should we have made a synthetic version of a real, identifiable person doing something they never agreed to and never actually did.”
Ask the ethical question before the legal one on any content using a real, identifiable person’s voice, image, or likeness, whether that’s a current employee, a former one, or a well-known external figure. Consent, once it would clearly matter to the person being represented, isn’t a nice-to-have sitting on top of legal compliance. It’s the actual test, and it’s a stricter one than the law currently requires in most jurisdictions.
Most companies either have no synthetic media policy at all, or one written for the fraud half of the problem that never mentions what the marketing or training team is allowed to build.
| Field | Filled in for a mid-size company |
|---|---|
| What counts as synthetic media here | Any AI-generated or AI-modified voice, video, image, or avatar used externally or in training content |
| Who can approve using a real person’s likeness | Named legal and communications leads, sign-off required before production starts, not after a draft exists |
| Disclosure standard | A visible, on-screen label at first exposure in every piece of published synthetic content, meeting the Article 50 bar as a floor, not a ceiling |
| The fraud-response protocol | The callback verification steps from earlier in this piece, distributed to finance, HR, and anyone with wire authority |
| Review cadence | Quarterly, given how fast both the technology and the regulation are moving |
Fill in the right column for your own company. The two rows people tend to leave blank are the fraud-response protocol and who specifically approves using a real person’s likeness, both of which is where the ethical failures in this piece actually happen.
If a viewer could reasonably mistake it for real, it needs a label, whether or not you meant to deceive anyone.
For whom this policy actually matters, specifically: a marketing lead needs the likeness-approval field before greenlighting an AI-voiced ad. An L&D manager needs the disclosure standard before publishing an avatar-narrated course. A finance director needs the fraud-response protocol laminated at her desk. One document, three different people who each need a different section of it more than the others.
You don’t need a full policy rollout to reduce real risk this week. Four things, in order:
None of this requires an outside consultant to start. It requires treating the two problems in this piece as genuinely separate, and giving each one an owner who actually knows it exists.
Under the EU AI Act’s Article 50, a deepfake is AI-generated or manipulated image, audio, or video content that meets three cumulative criteria: it closely resembles a real, plausible, or once-real person, object, place, entity, or event; that subject actually exists or could plausibly exist; and the content would falsely appear authentic or truthful to a reasonably informed viewer. Background effects, standard production touch-ups, and evidently artistic or satirical work are treated differently under the same guidance.
If it meets the deepfake criteria above and reaches an EU audience, yes, as of 2 August 2026, with disclosure required in a clear, human-noticeable way at first exposure, not just through invisible watermarking. Evidently artistic, satirical, or fictional content has a lighter disclosure standard. Outside the EU’s jurisdiction, requirements vary, but treating visible disclosure as a floor rather than a compliance ceiling is the safer default given how fast this area is moving.
The single most effective control is a callback verification protocol: never verify an urgent request for money, credentials, or sensitive data on the same channel it arrived on. Call back on a number already saved in your directory, not one provided in the request, and ask something only the real person would know that wouldn’t appear in a public recording. This works regardless of how convincing the fake gets, because it doesn’t depend on detecting the fake at all.
It can be legal with clear consent and proper disclosure, but legal isn’t the same as ethical. Using a real, identifiable person’s likeness, current or former employee, without their explicit permission raises a consent question that sits before any labelling requirement. Get direct consent before building the avatar, not just before publishing it, and disclose its use clearly to anyone who sees it.
Not as a primary defense. Detection tools are in a constant arms race with generation tools, and a company relying solely on technical detection will eventually face a fake that beats it. Verification protocols that don’t depend on spotting a fake, like the callback method in this piece, are more reliable precisely because they work whether or not the fake itself is convincing.
The FBI figures in this piece (22,364 AI-related complaints, $893,346,472 in adjusted losses, $30 million-plus in AI-linked BEC losses, and the employment-interview voice-spoofing pattern) are quoted directly from the FBI’s 2025 IC3 Annual Report, read in full on 1 September 2026, not from a summary of it. The Article 50 details are quoted directly from the European Commission’s own FAQ page on transparency obligations under Article 50 of the AI Act, last updated 24 July 2026 and read directly on 1 September 2026. Two widely circulated deepfake statistics, a claimed 900% annual growth rate and a $2.19 billion total-loss figure, were deliberately excluded: every version found during research traced back to security-vendor marketing blogs citing each other, with no primary source that could be independently confirmed. The two-problems framing, the callback verification protocol, and the policy template are Future Factors’ own synthesis, not a finding from either cited source.