In early 2024, a finance employee in the Hong Kong office of engineering firm Arup joined a video conference that appeared to include the company's chief financial officer and several colleagues. After receiving instructions during the call, the employee authorized multiple transfers totaling roughly $25 million. The other apparent participants were synthetic representations. Seeing is no longer believing.
Many organizations have not yet translated that shift into their payment, personnel and incident response procedures. The hard problem with deepfakes is managing what happens in the minutes after someone believes one.
Synthetic media compresses the time between fabrication and harm. A convincing fake can now trigger a wire transfer, an employee suspension, a market moving rumor, or a viral political clip faster than any verification process can catch up. Three characteristics drive the risk. Ease: Synthetic content is inexpensive, rapid, and increasingly available as a service. Attackers can adapt voices, images, documents, and narratives during a live interaction rather than relying on a single prerecorded fake. Plausibility: Voice and video clones can satisfy the visual and auditory cues people have historically trusted. A convincing fake can override intuition. Attribution: Once a fake circulates, establishing its origin, determining how it was manipulated, and identifying who is responsible can be slow, expensive, and incomplete. Analysts have called this a growing threat to a shared baseline of truth.
The fakes are out there. The organization's exposure turns less on the existence of the fake than on the decisions made in response to it. That reframing moves deepfakes out of the security team’s inbox and into enterprise risk. The exposure lies in payment approvals, personnel investigations, public statements, access decisions, crisis communications, and, where the risk is material, established board-reporting and oversight structures.
The same technology creates different legal problems depending on who gets fooled and what happens next.
No single body of law governs synthetic media. Depending on the conduct and the resulting injury, a deepfake dispute may implicate state publicity and privacy rights, defamation, fraud, employment law, platform obligations, criminal prohibitions, and sector-specific regulation. Each addresses only part of the problem.
Deepfake losses often expose process gaps as much as technology gaps. The recurring failures:
The through line is that deepfakes exploit weak identity verification and weak decision hygiene, not just weak firewalls. The essential control is independently verifying identity and authenticity before making a consequential decision based on a request, recording, or other digital content.
Treat synthetic media as an enterprise control problem and help structure the cross-functional response:
Detection is not the control. Verification is. Assume some synthetic content will evade initial detection. The goal is that no single message can trigger a consequential decision without independent verification.
The legal exposure is already here. Right-of-publicity, fraud, defamation, and the federal takedown regime apply now, even as election deepfake doctrine and proposed federal likeness rights keep developing.
For questions about deepfake risk, synthetic media incident response, and building an AI governance program, please contact the Jones Walker Privacy, Data Strategy and Artificial Intelligence team. Stay tuned and subscribe for continued insights from the AI Law and Policy Navigator.
