Stop Detecting Deepfakes: Make the Fraud Irrelevant by Design

The video call looked entirely ordinary. A finance worker in the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House and the Beijing National Stadium, sat in front of a screen filled with familiar faces. The company's chief financial officer, based in the United Kingdom, was there. So were several other colleagues, recognisable, talking, moving, present. There had been an email a few days earlier, supposedly from that same CFO, asking for a confidential transaction. The worker had been suspicious. Emails lie. But now here was the CFO himself, on camera, and the request was repeated with the easy authority of a senior executive. Reassured by what he could see and hear, the employee did as he was asked. Over the following days he made fifteen separate transfers, roughly 200 million Hong Kong dollars in total, around 25 million US dollars, into five different bank accounts.
Every other person on that call was a fabrication. The CFO was a deepfake. The colleagues were deepfakes. The entire meeting, the nods and the small talk and the instructions, had been synthesised from publicly available footage of real Arup staff. The only human being in the room was the victim. The fraud was not uncovered by clever technology or a sharp-eyed analyst. It surfaced later, in the most mundane way imaginable, when the employee happened to check in with the company's actual headquarters about the secret payment he had been making. By then the money was gone. Two years on, none of it has been recovered, and nobody has been publicly identified or charged.
The Question We Keep Answering Wrongly
The instinct, reading a story like that, is to ask how the worker could have been fooled, and then to reach for a solution shaped like a better fool-detector. Train staff to spot deepfakes. Buy software that scans video streams for the tell-tale artefacts of synthesis. Teach everyone the current list of giveaways, the unnatural blinking, the odd lighting around the hairline, the faint smear where a jaw meets a neck. This is the reflex of an entire industry, and it is the wrong reflex. It commits us to an arms race we are structurally certain to lose, and it quietly loads the entire weight of defence onto the least reliable component in any system, which is a human being looking at a screen and deciding whether to believe their own eyes.
There is a different question, and it is the one this piece is about. As synthetic deception becomes not merely good but effectively perfect, should our goal be to get better at spotting lies, or to redesign the relationships and everyday processes that currently depend on our ability to detect them at all? The wager here is that the second path is not only possible but already, quietly, winning in the places where people have had the sense to try it. The trick is a reframing so simple it sounds glib until you follow it through. Treat every incoming request as a requirements problem in which the attacker has helpfully written out their preferred solution in advance. Then refuse that solution and satisfy the underlying legitimate need through a channel the attacker cannot reach.
The stakes are not marginal. Long before deepfake video calls entered the picture, the plainest version of this fraud, business email compromise, in which a criminal impersonates a trusted party to redirect a payment, had become one of the most lucrative crimes on earth. The FBI's Internet Crime Complaint Center titled a 2024 advisory “Business Email Compromise: The $55 Billion Scam,” reflecting more than 55 billion US dollars in reported losses worldwide over roughly a decade. The trend since has not bent downwards. The Bureau's report for 2025 records 1,008,597 complaints and 20.877 billion dollars in reported losses, a rise of 26 per cent on the year before, with business email compromise accounting for 3.05 billion of that total, the second costliest category of cyber-enabled fraud after investment scams. Every one of those losses turned on someone believing a message that appeared to come from a party they trusted.
That report also does something none of its predecessors did. For the first time it puts a number on the synthetic contribution specifically, attributing more than 30 million dollars of business email compromise losses to scams involving AI, and more than 5 million to distress scams in which voice cloning was used to imitate a relative. Those sums look modest beside the totals, and it would be a mistake to read them as the measure of the problem. They are a floor rather than a ceiling. A victim can only report what they noticed, and the entire purpose of a competent synthetic is that nobody notices; a cloned voice that works leaves behind a complaint about an ordinary fraud, if it leaves behind a complaint at all. What the figures establish is not the scale of the thing but its arrival in the official ledger. Synthetic voice and video do not invent this problem. They industrialise it, removing the last few grammatical tells and stilted phrasings that once let a careful reader smell a rat. If the defence was already asking too much of human vigilance when the bait was a slightly-off email, it is hopeless now that the bait is a flawless face.
An Arms Race Engineered to Be Lost
Start with why detection fails, because the failure is not a temporary shortfall of engineering effort. It is baked into the mathematics.
Deepfake detection is a contest between two systems, a generator that makes synthetic media and a discriminator that tries to tell real from fake. This is not a metaphor. It is close to a literal description of how many generative models are trained in the first place, with a generator and a discriminator locked in competition, each improving at the other's expense. The problem for the defender is that the generator gets the last move. Any detector you deploy becomes, the moment it exists, a training target. Its outputs can be used to refine the next generation of fakes until they slip past. A recent survey of the field described the situation bluntly as an unwinnable arms race, noting that as generative models approach a near-perfect emulation of real data, a discriminator becomes fundamentally limited in its ability to separate the two.
The empirical record is just as discouraging. Detection systems that post impressive accuracy figures in the laboratory tend to collapse in contact with the real world. Studies have found that detectors trained on the output of one generation model can lose up to 60 per cent of their accuracy when shown content from a different model, and that laboratory performance rarely survives the ordinary indignities of the internet, the recompression, the resizing, the screenshotting that real media undergoes before anyone sees it. A detector is only ever trained on yesterday's fakes. The fraudster is always using tomorrow's.
So the asymmetry is total. The defender must catch every fake, in real time, against generators they have never seen, using tools trained on obsolete examples. The attacker needs to win once. Committing your safety to that contest is like proposing to win a footrace against something that accelerates every time you do.
The Dividend That Rewards the Liar
There is a second, subtler cost to leaning on detection, and it deepens the more successfully you evangelise it. The legal scholars Bobby Chesney and Danielle Citron gave it a name in work that began circulating in 2018 and appeared in the California Law Review the following year: the liar's dividend. Their insight was that deepfakes are dangerous not only because they can manufacture convincing falsehoods, but because their mere existence hands a gift to the genuinely guilty. Once the public knows that any video might be synthetic, anyone captured on real footage doing something damaging can simply claim the recording is fake.
The perverse consequence is that the dividend grows in proportion to public awareness. The harder we work to teach everyone that deepfakes are everywhere and undetectable, the more cover we hand to every liar who wants to wave away authentic evidence.
That was a prediction when it was made. It is now a measured effect. A 2024 study in the American Political Science Review put the proposition to more than fifteen thousand people across five survey experiments, and found that politicians who met a scandal by calling the evidence fabricated held on to more support than those who apologised or said nothing. The dividend was largest against written reporting and smallest against video, which is the single crumb of comfort in the finding, and a crumb with an obvious shelf life given where the technology is heading.
It has migrated into the courtroom too. Lawyers acting for Tesla, presented with recordings of Elon Musk making claims about the safety of self-driving cars, declined to confirm that the recordings were authentic, on the reasoning that a man that famous is a natural target for deepfakes. The judge was unimpressed, noting that the argument would let public figures say whatever they liked and afterwards disown it, and ordered Musk to sit for a deposition. In the first trial arising from the January 6 attack on the Capitol, defence counsel pressed an FBI agent on whether the video evidence might have been deepfaked or otherwise altered. Neither attempt succeeded, and that is rather the point: the manoeuvre is now a standard thing to reach for, and it costs nothing to try. A world trained to distrust its own eyes is not a safer world. It is one where truth and falsehood have been flattened into a shrug, and where the burden of proof quietly dissolves.
This is the trap of detection as a strategy. Even when it works it corrodes the thing it was meant to protect, which is a shared confidence that some things can be known. We need an approach that does not require anyone, ever, to look at a piece of media and adjudicate its authenticity.
Reading a Request as an Attacker's Rough Draft
Here is the reframe that changes everything, and it comes not from security folklore but from the discipline of requirements engineering.
When a request arrives, an email from the CFO, a phone call from a panicked relative, a login page asking for your password, it always arrives bundled with a proposed solution. The email does not merely state a need. It prescribes a method: wire the funds to this account, using these details, in this way, now. Security-minded design treats that prescription with the deepest suspicion, because in a fraud the request and the attack are the same object. The attacker has stated their preferred solution up front. The trusted channel, the video call, the caller ID, the familiar logo, is not incidental to the con. It is the payload.
So do not evaluate whether the request is genuine on its own terms. That is playing on the attacker's chosen ground, which is precisely the ground of perception and trust that synthetic media has poisoned. Instead, extract the legitimate underlying requirement, the thing a real CFO would actually need, which is that an authorised payment reaches the right destination, and then satisfy that requirement through a completely different path. A path the attacker never proposed, never expected, and cannot occupy. You do not try to prove the video call was fake. You make it irrelevant by deciding, as a matter of process, that video calls are simply not how payments get authorised. The attacker's carefully crafted solution is invalidated not because it was detected but because it was never a valid channel in the first place.
This is the whole game. Design the channel out. What follows are the places where people already have.
The Phone Call That Would Have Saved Arup
Return to the Hong Kong office and imagine one small rule in place. Any payment instruction above a threshold, no matter how it arrives and no matter how convincing the person delivering it appears, must be confirmed by an outbound call from the finance team to the requesting executive, on a phone number already held in the company directory, not one supplied in the request. This is out-of-band verification, and it is the plainest form of channel invalidation there is.
Notice what it does to the deepfake. The synthetic CFO can be flawless. It can pass every visual test, defeat every detector, sustain a full conversation without a flicker. It changes nothing, because the decision to release funds no longer lives on the video call at all. It lives on a separate channel, initiated by the defender, reaching a destination the attacker does not control. The fraudster has spent enormous effort perfecting a solution to the wrong problem. They optimised for being believed on the call. The process never asked the call to be believed.
The critical detail is the direction and the source of the confirmation. It must be outbound, dialled by the person doing the paying, and it must use contact details established in advance, never details helpfully provided within the suspicious request itself. A fraudster who can insert their own callback number has simply extended their channel, not been forced off it. This is the difference between verification that closes the loop through trusted ground and verification that lets the attacker draw the loop for you. The tragedy of Arup is that the fraud eventually came to light through exactly this kind of independent check, an employee contacting the real headquarters, only after the money had left, rather than before it as a condition of release.
A Word Only Your Family Knows, and a Taxi You Book Yourself
The same logic scales all the way down to the most intimate fraud of the age. Criminals can now clone a person's voice from as little as three seconds of audio, scraped from a social media clip, and use it to call an older relative with a manufactured emergency. A grandchild in a cell, a child in a crash, a frightened voice that sounds unmistakably like family, and an urgent demand for money before anyone can think. In the United Kingdom the messaging version, the “Hi Mum” scam, has run for years, and newer variants now layer cloned voice notes on top of the text. The figures that exist are grim and almost certainly too small. Action Fraud logged around 1.5 million pounds of losses in under twenty weeks of 2022, and half a million in seventeen weeks of 2023. Researchers at University College London, who spent thirteen weeks in conversation with the scammers themselves and were asked for 577,792 pounds in that period alone, put the minimum true annual loss in Britain at 2.3 million. Every one of those numbers is a floor. This kind of fraud is heavily under-reported, partly because victims take it to their bank rather than to the police, and partly because very few people want to sit down and compose a formal statement explaining that they were talked out of their money by somebody pretending to be their child.
You cannot out-listen this. A parent will not reliably distinguish a three-second clone of their own child from the real thing, and asking them to try is cruel and futile. So both the FBI and the Federal Trade Commission now recommend something that has nothing to do with detection at all: a family safe word. A single unguessable phrase, agreed in advance, never posted online, that anyone claiming a genuine emergency must be able to produce. The advice pairs it with a second habit, hanging up and calling the person back on a number you already have.
Look at the structure and it is identical to the corporate case. The requirement is to know that the person in distress is really your kin. The attacker's proposed solution is the recognisable voice, the channel they have poisoned. The safe word invalidates that channel by moving the proof to a shared secret the voice clone does not possess, and the callback moves it to a line the impersonator does not hold. A perfect clone of a voice that does not know the word is a perfect clone of nothing. The synthesis, however good, is aimed at a lock that is no longer on the door. And unlike a training programme in scepticism, which decays and demands constant vigilance, the safe word asks almost nothing of the frightened person on the receiving end. They do not have to stay calm, or reason clearly, or resist a masterful performance of panic. They have to remember to ask one question that the machine on the other end cannot answer.
There is something stronger still, and it is stronger precisely because it does not depend on the safe word working. Every authentication test can fail in two directions. It can admit an impostor, and it can shut out the very person it was built to admit. A frightened teenager in a police station at three in the morning may simply not retrieve an agreed phrase under that much adrenaline, and a competent fraudster arrives already carrying a reason the phrase cannot be produced, a borrowed handset, an officer listening in, a story assembled in advance to explain the gap.
To see why that matters, picture the call as it actually arrives, rather than as it looks in a leaflet about scam awareness. It is three in the morning. You have had a long day, a heavy meal and a few glasses of wine, and you surface from sleep into a conversation that is already under way. It is your daughter. The voice is hers, not an approximation of hers, and she is upset in the particular way you have heard her be upset since she was nine years old. She has been out in the city, she has lost her purse, her phone is nearly dead, and she cannot get home. A cab at that hour will be about a hundred pounds. Nothing in the story is exotic. Nothing in the sum is alarming. You are not being asked to authorise a seven-figure transfer to an unfamiliar corporate account in another jurisdiction, with all the natural friction that such a request would meet. You are being asked for a taxi fare by your own child, which is one of the most ordinary transactions in family life, and the only unusual feature of the entire exchange is the hour, which is exactly the hour at which somebody would lose a purse in a city.
That modesty is not an accident of the story. It is where the economics of the attack have driven it, and the reasoning is worth following because it runs directly against the folklore. A usable clone of a voice now takes something on the order of three seconds of audio. Once that pipeline exists, the marginal cost of producing one more call is effectively nothing. Not low. Nothing worth counting. And when the cost of an attempt falls to nothing, the attempt stops being a craft and becomes a volume business. There is no longer any reason to research one wealthy family for a fortnight and stake the whole operation on a single rehearsed performance, when software that can place a call, hold a conversation and improvise around an answer can be pointed at a list and left running. Whether the true figure is dozens of such calls a day or many thousands is beside the point, and nobody should pretend to know it. The point is that nothing in the cost structure argues for restraint. None of this requires a statistic to see. It follows from the shape of the ledger.
Now follow what free volume does to the size of the ask, because it inverts the oldest tell in the genre. When each attempt is expensive, the demand has to be large to be worth making, and the classic emergency scam duly demanded a great deal. I need two thousand pounds tonight or I am going to prison carries its own warning, because the magnitude is itself the thing that makes a parent stop, breathe and telephone somebody else. Suspicion is triggered by size. A hundred pounds for a taxi triggers nothing whatsoever. It sits beneath the threshold at which anyone begins to interrogate a request, and beneath the threshold at which most people would feel able to interrogate it even if they wished to, since demanding proof of identity before releasing a cab fare feels grotesquely out of proportion to the amount at stake. A small ask therefore converts at a far higher rate than a large one, and when volume is free, the conversion rate is the only variable that matters. A modest sum extracted often will comfortably out-earn a spectacular sum extracted once in a hundred attempts.
So the incentives push the whole category in a single direction, towards requests that are small, plausible, emotionally ordinary and entirely unremarkable. That is precisely the region in which human suspicion is least likely to fire, and precisely the region in which the standard advice, watch for the red flags, is at its most useless, because there is no flag to watch for. The story is mundane. The sum is trivial. The voice is your daughter's. The only thing wrong with the request is that it is not true, and that is the one property of it you cannot observe.
Which is why the answer cannot live in the assessment of the request at all. Push the reframe that runs through this entire argument one level deeper, from who is calling to what is being asked for. Send a hundred pounds to this account, right now, is not a need. It is a proposed solution, drafted by whoever is on the line, and in a fraud the proposal is the attack. Beneath it sits a requirement, and requirements can nearly always be satisfied in more than one way. Your daughter, stranded across the city at three in the morning, does not need a hundred pounds in an account you have never seen before tonight. She needs to get home safely. So book the taxi yourself, from your own phone, to your own address, and tell the caller that the car is coming. Or get into your own car and go and fetch her.
The same is true of the other everyday version of the call. Your mother telephones from the supermarket. Her card has been declined at the checkout, the trolley is full, there are grandchildren hanging off the side of it and a queue lengthening behind her, and she needs a hundred and fifty pounds. This is genuinely distressing and entirely credible, because cards fail for a dozen dull reasons and invariably choose the worst possible moment to do it. But she does not need a hundred and fifty pounds. She needs her shopping paid for, and a supermarket is perfectly capable of taking payment from you over its own telephone, on a number you have looked up yourself rather than one you have been given. Someone under arrest does not need bail money within the hour either. They need legal representation, which is arranged through a solicitor and confirmed on the police station's own published number. In every case the need survives intact. Only the payment route disappears.
Consider now the two people who might be at the other end of that call. A real relative is usually relieved. They named a sum because money looked like the obvious instrument, not because money was the point, and a cab already on its way solves their night rather better than a transfer they would still have to spend. A fraudster can accept none of it, and cannot say why. Their requirement was never transport or a solicitor or a trolley of shopping. It was irreversible funds landing in an account they control, and a taxi paid for by somebody else satisfies precisely none of that. So they have to argue. Why the cab will not do, why the shop cannot be telephoned, why the solicitor is not an option, why it has to be this account and it has to be now, and why every safe route to the very thing they said they needed is somehow the one route that will not work. That escalating refusal to let the stated need be met by any other means is the tell, and it is the process that produces it rather than the ear.
This is the family protocol at its most complete, because at no point does it require you to decide whether the voice is real. The safe word still poses a question and waits on an answer that may never come. Meeting the requirement instead of the request asks nothing of your judgement at all. You can be entirely taken in at three in the morning, believe every syllable, and be out nothing but the twenty minutes it took to book a cab that nobody climbed into. It also keeps compassion intact under uncertainty, which is what the standard advice quietly sacrifices, since hanging up on somebody who might be your child in real trouble is a hard thing to ask of anybody, and asking it of them at three in the morning is harder still. The real emergency is answered at once. The manufactured one collapses, not because anybody saw through the fake but because the one thing the attacker wanted was the one thing never on offer. And note that none of it turns on the size of the request, which matters more than it first appears now that the economics have driven the asking price down below the level at which anyone thinks to be suspicious. The move works identically at a hundred pounds and at twenty five million dollars, because it never once asks whether the amount looks wrong.
The Bank That Stopped Trusting the Name on the Screen
Financial infrastructure has been quietly rebuilding itself along these lines for years, largely out of public view. Two examples stand out because they attack fraud not by spotting bad actors but by removing the conditions the fraud depends on.
The first is Confirmation of Payee, the account-name-checking service that has been mandatory across the British payments system since 2020. When you set up a payment, the scheme checks whether the name you have entered actually matches the name on the destination account, and warns you when it does not. Authorised push payment fraud, the category that includes most impersonation scams, relies on the victim believing they are paying a trusted party while the money in fact flows to the criminal. Confirmation of Payee attacks the join between the story and the destination. It does not care how persuasive the fraudster was. It checks, mechanically, whether the account the victim is about to pay belongs to who they think it does. After introducing it, Lloyds reported a 31 per cent reduction in this kind of fraud, and by late 2024 the regulator had extended coverage to the overwhelming majority of British bank transfers, with millions of checks running every day.
It would be wrong to present that as a cure. Confirmation of Payee shut one specific gap, the mismatch between the name a victim believes they are paying and the account that actually receives the money, but authorised push payment fraud has gone on growing and mutating around it, and the researchers who documented the “Hi Mum” scam describe it as an entirely new species of the same crime, one a name check does nothing to stop, because the fraudster supplies the account name along with the number. No single control ends a category of fraud, which is precisely why the argument here is for a layered design discipline rather than for one clever mechanism.
The second is positive pay, a long-standing corporate banking service in the United States, worth studying because its default is so instructive. A company sends its bank a list of the cheques it has legitimately issued, with the numbers, amounts and payees. When a cheque is presented, the bank pays it only if it matches the list. Anything that does not match is not paid pending review. The default is no. Trust is not extended and then withdrawn on suspicion. It is withheld until a positive, pre-established match grants it. A forged cheque does not need to be recognised as forged. It simply fails to appear on the list of things the account holder said they would honour, and that absence, not any act of detection, is what stops it.
There is a third move in British payments, and it is not a mechanism at all. Since 7 October 2024, payment firms have been obliged to reimburse victims of authorised push payment fraud up to 85,000 pounds a claim, with the cost of that reimbursement split equally between the firm that sent the money and the firm that received it. Read the split carefully, because it is the whole of the idea. The receiving firm, the one that banked the fraudster, had until then no particular financial reason to care very much who it was banking. It now pays half of whatever its customer takes.
This is the liability version of designing the channel out. It stops asking whether the victim ought to have known better, which is the same losing question as whether they ought to have spotted the fake, and places the cost on the institutions that designed the process the victim was moving through. The people who can actually change the architecture are handed a direct financial reason to change it. Incentive follows design responsibility, and it is remarkable how rarely anybody arranges things that way round.
The early evidence is that this works in the dull, mechanical fashion good incentives tend to. An independent evaluation for the regulator, published this July, found that losses within the scheme's scope had fallen by an estimated 73 million pounds a year, that the number of scams had dropped by nearly thirty-five thousand, that reimbursement of in-scope claims had reached 97 per cent, and, most tellingly of all, that the largest improvements came from precisely those firms with the worst fraud levels before the rule existed. Predictions that firms would flee the market or that consumers, insured against their own carelessness, would become reckless did not materialise. Nobody in this story got better at recognising a fraudster. The bill simply began arriving at the address where the design decisions were made.
The Login That Cannot Be Phished
The most complete example of detection-independent design is one that billions of people now use without knowing its name. It is the passkey, and the standards beneath it, FIDO2 and WebAuthn, are worth understanding precisely because they make an entire category of attack structurally impossible rather than merely detectable. The scale has stopped being niche while nobody was watching. On World Passkey Day this May the FIDO Alliance put the number in circulation worldwide at around five billion, with 75 per cent of the people it surveyed having enabled one on at least one account and 90 per cent now aware the things exist at all.
Password phishing is the original synthetic-deception fraud. A fake page impersonates a real one, and the human, unable to tell the counterfeit from the genuine article, hands over their credentials. Two decades of defence have consisted largely of asking people to look harder, to inspect the address bar, to hover over links, to develop a sixth sense for the fraudulent. It has not worked, because it is the same losing bet as deepfake detection, human perception against an adversary who controls the appearance of things.
FIDO2 refuses the bet entirely. When you register a passkey, your device generates a cryptographic key pair. The private key never leaves your hardware, protected inside a secure element. The website only ever receives the public half. When you log in, the site sends a challenge, your device signs it with the private key, and, this is the load-bearing part, the signature is cryptographically bound to the exact web origin making the request. Your browser will not release a credential to a domain that does not match the one it was created for. Full stop. There is no dialogue box, no judgement call, no moment where a tired human decides whether the site looks right. If a phishing page is even one character off in its address, the credential is simply never offered. The user cannot be tricked into handing it over because there is no longer anything to hand over and no human decision in the loop to subvert. The American standards body has since written the architecture into its rulebook, the current NIST Digital Identity Guidelines treating synced passkeys as phishing-resistant for exactly this reason, that the key pair is constrained to the domain in which it was created, and admitting them up to the second of its three assurance levels.
The results are not theoretical. Google mandated physical security keys for its entire workforce, more than 85,000 people, in early 2017, and subsequently reported that not a single employee had been successfully phished on their work account since. Not few. None. That is what it looks like when you stop trying to detect an attack and instead engineer away the conditions that let it exist. The phishing page can be a flawless replica. It is aimed at a lock that no longer accepts the key it is trying to steal.
Signing Reality Instead of Interrogating It
Even where the goal is to know whether a piece of media is authentic, the winning approach inverts the problem. Rather than examining a photograph or a video after the fact for signs of fakery, an unwinnable inspection, you attach a verifiable record of provenance at the moment of creation and carry it forward through every edit.
This is the work of the Coalition for Content Provenance and Authenticity, known as C2PA, an open standards body formed in 2021 by founding members including Adobe, Arm, the BBC, Intel, Microsoft and the verification firm Truepic, and now steered by a roster that has grown to include Amazon, Google, Meta, OpenAI, Sony and others under the umbrella of the Linux Foundation. Its output is a technical specification, Content Credentials, that records who made a piece of content, when, with what tools, whether AI was involved, and every meaningful edit since. Crucially, that record is cryptographically hashed and signed, making it tamper-evident. Alter the media and break the seal, and the tampering shows.
The philosophical move here is exactly the one this whole argument turns on. As the standard's own advocates put it, Content Credentials do not tell you whether a piece of content is true. They tell you where it came from and what has been done to it. Provenance replaces perception. Instead of asking the impossible question, is this image fake, which pits the viewer against the full power of a generator, you ask an answerable one, does this image carry an intact, signed chain of custody back to a source I trust. The absence of credentials is not proof of forgery, and the presence of them is not proof of virtue, but the framework shifts the ground from the ungrounded adjudication of pixels to the verifiable adjudication of cryptography. It is significant enough that national security agencies have begun publishing guidance recommending exactly this approach for defending the integrity of multimedia in the generative era, and that image generators such as OpenAI's now attach these credentials to what they produce.
Until very recently the obvious objection to all this was that it is voluntary, and that a standard nobody is obliged to implement is a standard the fraudulent will simply decline to use. That objection is expiring. The coalition passed six thousand members and affiliates in January of this year. Credential creation has moved out of professional tooling and into ordinary consumer hardware, with Google's Pixel 10 signing photographs in the camera application itself and Samsung's Galaxy S25 range attaching credentials to images its own AI tools have altered. And the practice is turning into a legal requirement. Article 50 of the European Union's AI Act, which obliges providers to mark synthetic audio, image, video and text in a machine-readable format, applies from 2 August, which is now a matter of days away. California's AI Transparency Act, originally due to commence in January, was amended to begin on that same date.
Notice what that says about the direction of travel. Nobody has legislated a duty to detect deepfakes, because no such duty could be discharged; you cannot write into law an obligation to win an arms race. What is being legislated instead is a duty to declare provenance at the moment of creation, which can be discharged, by machines, at scale, without asking a single human being to look at an image and adjudicate. That is what it looks like from the outside when a detection-independent approach wins the argument.
Never Trust, Always Verify, at Machine Scale
The most systemic expression of this philosophy has a name that has become a corporate buzzword and deserves rescuing from it: zero trust. Codified by the American National Institute of Standards and Technology in its Special Publication 800-207 in 2020, the model rests on a phrase that sounds paranoid until you realise it is simply the mature response to undetectable deception. Never trust, always verify.
Traditional security built a hard perimeter and trusted everything inside it, the digital equivalent of checking identity at the front door and then letting anyone who got past it roam the building. Zero trust abolishes the inside. Every request for a resource, regardless of where it originates, must be authenticated, authorised and continuously validated, and is granted only the minimum privilege required to do the specific task at hand. No actor is trusted by default on the strength of appearing to belong.
Read that through the lens of synthetic fraud and it is the same design principle industrialised. A deepfake, a cloned voice, a spoofed email, a stolen session, all of them are attempts to appear to belong, to be trusted on the basis of how they present. A system that extends no default trust to presentation, that insists on fresh cryptographic proof for every action and confines every actor to least authority, is a system to which a convincing appearance simply buys nothing. The impersonation may be perfect. Perfection of appearance is precisely the currency the architecture refuses to accept.
Five Principles for a World You Cannot Verify by Eye
Pull these examples together and a coherent design discipline emerges, one that any organisation, and to a surprising degree any family, can adopt without waiting for better detectors that are never going to arrive.
The first principle is to verify the requirement, not the requester. Do not spend your effort deciding whether the person or the message in front of you is genuine, a judgement the attacker has spent their entire effort corrupting. Identify the legitimate need underneath the request and satisfy it through a channel of your own choosing. The Arup callback, the family safe word and the whole logic of out-of-band confirmation live here. So does the harder version, satisfying the stated need by a route of your own, since a caller who will accept only one route has told you what the request was really for.
The second is to prefer structural impossibility over probabilistic detection. Wherever you can, choose designs that make an attack fail by construction rather than designs that try to notice it happening. A passkey that cannot be surrendered to the wrong domain is categorically safer than a filter that tries to spot the wrong domain, because the former has no failure mode that depends on being observant at the right instant.
The third is to make the default deny, and require positive, pre-established confirmation to proceed. Positive pay honours only what was declared in advance. Confirmation of Payee refuses to let a mismatched name pass silently. A system whose resting state is no, released only by an affirmative match, does not have to recognise a threat in order to stop it. It only has to fail to recognise a friend, which is a far safer way to be wrong.
The fourth is to choose provenance over perception. When authenticity genuinely matters, bind a verifiable, tamper-evident record to the thing at the point of creation and check that record, rather than interrogating the finished artefact with your senses. Cryptographic chains of custody are the answer to a world in which the artefact itself can be perfectly counterfeited.
The fifth, underpinning all the others, is to refuse to make the human the last line of defence. Every design above shares a refusal to load the final, irreversible decision onto a person's ability to detect a fake under pressure. Google did not train 85,000 people to spot better phishing pages. It removed the possibility that spotting was required. The safe word does not ask a frightened grandparent to become a forensic audio analyst. It gives them a rule a machine cannot satisfy. The kindest and most robust systems assume the human will be fooled, because eventually, against a good enough fake, they will be, and they arrange things so that being fooled is not catastrophic.
Designing So That Belief Is No Longer Load-Bearing
None of this means detection has no place. A deepfake screener at the edge of a video platform, a provenance signal in a newsroom, a filter that culls the most obvious fraud before it reaches a human, all have value as friction, as triage, as one layer among many. The error is to make detection the thing your safety rests on, to treat the arms race as winnable and the human eye as a reliable sensor. It is neither.
The deeper shift is almost philosophical. For most of history, trust between people and institutions has been mediated by perception. We believed a face we recognised, a voice we knew, a letterhead, a familiar login screen. Synthetic media has quietly severed the link between how something appears and what it is, and no amount of squinting will reconnect it. The mature response is not to squint harder. It is to stop making belief load-bearing. To build relationships and processes in which the question is never whether this looks real, but whether it can complete a path that a counterfeit cannot walk, a callback answered on a known line, a word only kin possess, a need met by a route the caller did not choose, a signature bound to the true domain, an account name that matches, a credential that cannot be surrendered to a stranger.
The engineers who fell victim in Hong Kong were not foolish. They were placed, by a process that trusted appearances, in a position no human should be asked to occupy, adjudicating in real time the authenticity of a flawless fabrication, with millions of dollars riding on the guess. The lesson is not that they should have looked harder. It is that they should never have had to look at all. Every incoming request already contains the attacker's preferred solution, stated plainly and dressed in whatever trust the moment allows. Our task is not to see through the disguise. It is to build a world where the disguise, however perfect, opens nothing.
References
- CNN Business, “Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee,” 16 May 2024. https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
- Internet Crime Complaint Center (IC3), “Business Email Compromise: The $55 Billion Scam,” 11 September 2024. https://www.ic3.gov/PSA/2024/PSA240911
- Federal Bureau of Investigation, Internet Crime Complaint Center, “2025 Internet Crime Report,” 2026. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- arXiv, “The Unwinnable Arms Race of AI Image Detection,” 2025. https://arxiv.org/html/2509.21135
- Robert Chesney and Danielle Citron, “Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security,” California Law Review, vol. 107, 2019. https://www.californialawreview.org/print/deep-fakes-a-looming-challenge-for-privacy-democracy-and-national-security
- Kaylyn Jackson Schiff, Daniel S. Schiff and Natalia S. Bueno, “The Liar's Dividend: Can Politicians Claim Misinformation to Evade Accountability?,” American Political Science Review, 2024. https://www.cambridge.org/core/journals/american-political-science-review/article/liars-dividend-can-politicians-claim-misinformation-to-evade-accountability/687FEE54DBD7ED0C96D72B26606AA073
- Thomson Reuters Institute, “Deepfakes on trial: How judges are navigating AI evidence authentication,” 8 May 2025. https://www.thomsonreuters.com/en-us/posts/ai-in-courts/deepfakes-evidence-authentication/
- American Bar Association, “Deepfakes and Digital Evidence at Trial: Who Are You Going to Believe, the AI or Your Lying Eyes?,” 2024. https://www.americanbar.org/groups/gpsolo/resources/magazine/2024-may-june/deepfakes-digital-evidence-trial/
- Federal Communications Commission, “'Grandparent' Scams Get More Sophisticated.” https://www.fcc.gov/consumers/scam-alert/grandparent-scams-get-more-sophisticated
- CBS News, “AI voice scams are on the rise. Here's how to protect yourself.” https://www.cbsnews.com/news/elder-scams-family-safe-word/
- Sharad Agarwal, Emma Harvey, Enrico Mariconti, Guillermo Suarez-Tangil and Marie Vasek, “'Hey mum, I dropped my phone down the toilet': Investigating Hi Mum and Dad SMS Scams in the United Kingdom,” 34th USENIX Security Symposium, 2025. https://www.usenix.org/conference/usenixsecurity25/presentation/agarwal-sharad
- Pay.UK, “Confirmation of Payee.” https://www.wearepay.uk/what-we-do/overlay-services/confirmation-of-payee/
- Payment Systems Regulator, “PSR finalises plans for the wider implementation of fraud prevention tool, Confirmation of Payee.” https://www.psr.org.uk/news-and-updates/latest-news/news/psr-finalises-plans-for-the-wider-implementation-of-fraud-prevention-tool-confirmation-of-payee/
- Payment Systems Regulator, “PS24/7 Faster Payments APP scams reimbursement requirement: Confirming the maximum level of reimbursement,” 2 October 2024. https://www.psr.org.uk/publications/policy-statements/ps247-faster-payments-app-scams-reimbursement-requirement-confirming-the-maximum-level-of-reimbursement/
- Payment Systems Regulator, “Payment fraud falls by GBP 73m following PSR reimbursement scheme,” 1 July 2026. https://www.psr.org.uk/news-and-updates/latest-news/news/payment-fraud-falls-by-73m-following-psr-reimbursement-scheme/
- Regions Bank, “Positive Pay: Detect & Prevent Check Fraud.” https://www.regions.com/commercial-banking/treasury-management/fraud-prevention-resources/positive-pay
- FIDO Alliance, “FIDO Alliance Reports Accelerating Global Passkey Adoption on World Passkey Day 2026,” 7 May 2026. https://fidoalliance.org/fido-alliance-reports-accelerating-global-passkey-adoption-on-world-passkey-day-2026/
- National Institute of Standards and Technology, “Digital Identity Guidelines: Authentication and Authenticator Management,” NIST Special Publication 800-63B-4, August 2025. https://pages.nist.gov/800-63-4/sp800-63b.html
- Krebs on Security, “Google: Security Keys Neutralized Employee Phishing,” 24 July 2018. https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/
- Content Authenticity Initiative, “The State of Content Authenticity in 2026,” 18 January 2026. https://contentauthenticity.org/blog/the-state-of-content-authenticity-in-2026
- C2PA, “Providing Origins of Media Content.” https://c2pa.org/
- National Security Agency, “Strengthening Multimedia Integrity in the Generative AI Era,” January 2025. https://media.defense.gov/2025/Jan/29/2003634788/-1/-1/0/CSI-CONTENT-CREDENTIALS.PDF
- European Union Artificial Intelligence Act, “Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems.” https://artificialintelligenceact.eu/article/50/
- California Legislative Information, “SB 942: California AI Transparency Act.” https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942
- National Institute of Standards and Technology, “Zero Trust Architecture,” NIST Special Publication 800-207, August 2020. https://csrc.nist.gov/pubs/sp/800/207/final

Tim Green UK-based Systems Theorist & Independent Technology Writer
Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.
His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.
ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk
Listen to the free weekly SmarterArticles Podcast