This site only uses technical cookies required for it to work: no tracking, no profiling. Cookie Policy

Skip to content
All terms

What is a deepfake and why does it concern your company?

AI-generated synthetic voice or face, used for corporate fraud like the fake-CEO phone call: defended with process, not detection.

A deepfake is synthetic audio or video content, generated or altered by AI to credibly impersonate a real person: their voice, their face, their way of speaking. Voice-synthesis techniques are now accessible with just a few minutes of sample audio, often taken from a public LinkedIn video or an interview, and that has shifted the risk from political disinformation, the most discussed use case, to something far more concrete for a company: fraud. The most common scenario is not a sophisticated video, but a short phone call or video call designed to create urgency and get an immediate action before the recipient has time to verify the request. The typical target is not a mass audience but a single employee with signing power or access to finance systems, chosen precisely because they know the voice or face the AI is impersonating and therefore trust it more readily.

Fraud wearing a real company's face

The most feared scheme is the "fake CEO": a cloned voice (or a deepfake video call) instructing an employee to make an urgent wire transfer, often with tones of urgency and confidentiality designed to bypass normal controls. Cases reported by the press in Italy include an attempted phone scam targeting minister Guido Crosetto (February 2025, using a cloned voice) and a 750,000 euro wire transfer authorized in the Veneto region after a video call with a fake CEO. These are different episodes, but they share the same mechanism: trust placed in a familiar voice or face is exploited against the company's process.

How you defend against it

There is no 100% reliable deepfake detector fit for production: the defense that works is a matter of process, not technology. The rule that matters is out-of-band verification: any request for payment or sensitive data arriving by phone or video, especially if urgent or unusual, must be confirmed on a different, already-known channel (call back a saved number, not the one the call came from). On top of that comes AI literacy for finance and HR staff, the most exposed roles. The AI Act also imposes transparency obligations on synthetic content (labeling deepfakes), but that is a downstream measure: the real protection remains the verification process upstream of the transaction. The same technology has a declared use, enterprise generative video: there the Article 50 disclosure duty bites when the content resembles real persons or events closely enough to pass as authentic, while machine-readable marking of the output stays with whoever supplies the model.

  • AI literacy (Art. 4 AI Act) · An AI Act duty already in force: providers and deployers must take measures to build their staff's AI literacy.
  • Shadow AI · The use of AI tools at work without approval or oversight: employees pasting company data into ChatGPT and the like.
  • AI governance · The policies, roles and controls governing AI use in a company: system inventory, risk classification, approval flows and monitoring.
  • C2PA · A provenance standard that signs a content's origin and edits, but not enough on its own for AI Act Article 50 compliance.
  • Synthetic content disclosure (AI Act Article 50) · AI Act Article 50(2) duty to mark synthetic images, audio, video and text in a machine-readable format.

A term that hits close to home? Let's talk.

CONTACT ME