In this piece, Ajay Patel explores why traditional detection techniques fail against AI deepfakes and how corporate finance teams can combine zero-knowledge identity proofs with strict treasury controls to protect against high-stakes impersonation fraud.
According to Deloitte, fraud losses from generative AI tactics such as deepfakes could reach US$40 billion in the United States alone by 2027. It’s a sobering projection and demonstrates just how much of an operational threat deepfake fraud has become for businesses, their CFOs and their finance teams.
One of the most high-profile cases involved a finance employee in Hong Kong who joined a video with what appeared to be his CFO and several colleagues. The worker was instructed to transfer $25 million into five different bank accounts across 15 transactions, only to discover later he was the only real person on the call – all the others were deepfakes.
This case, and others like it, can’t be attributed to individual carelessness. This was a process failure; one where adequate safeguards weren’t put in place and scammers capitalized.
It’s no coincidence deepfake-centered attacks are overwhelmingly targeting CFOs and their finance teams. Sitting within the core operation of a business, this department is one of the most powerful – it has the authority to approve payments, change supplier details and move significant sums of money. This makes them highly susceptible to scammers, who understand this reality and vulnerability.
As deepfake scams continue to proliferate, what steps can finance teams take to combat this emerging challenge?
There are several detection techniques finance leaders can teach their teams to help identify manipulated media, such as deepfakes.
The first is identifying visual inconsistencies. Current deepfakes often have characteristics such as unnatural blinking, overly smooth or inconsistent skin textures, mismatched lighting and shadows, face blurring and audio-video sync issues.
The second is spotting audio anomalies in voice deepfakes. Cloned voices often exhibit telltale signs, such as robotic undertones, flat or unnatural speech patterns, a lack of natural pauses or breaths, and background audio that sounds artificial or mismatched with the environment.
If individuals notice any of these signs or even suspect they’re interacting with a deepfake, there is an obvious need to report it immediately.
However, these should be treated as a snapshot of current gaps rather than a fixed checklist. Once a flaw becomes widely known, scammers are using newer models of technology to close them up. As the detection methods improve, so does the generated deepfake.
Therefore, detection alone cannot solve the deepfake problem. As generation technology improves, detection will always lag behind – so this can’t be seen as the full solution for finance teams. In an era where AI can fabricate convincing media in seconds, a more robust approach is needed to build verification into the communication itself. Preventing in the first place gets finance teams out of the cat-and-mouse game of detecting deepfakes while bad actors continually modify their approach.
To truly combat deepfakes, financial teams can go beyond detection and adopt a human verification mindset. Rather than asking “is this video manipulated?” the question should shift to “Is there a real human behind the screen, and is the face I’m seeing real?”
This is the foundation of proof of human technology, and it could be an answer to the deepfake problem for finance teams. Rather than trying to determine whether video content has been manipulated, it can establish cryptographic proof that a real, unique human is behind an interaction.
Unlike systems that can be spoofed or databases that can be breached, proof of human happens through privacy-preserving cryptography such as zero-knowledge proofs. The financial sector represents a strong use case as this sector in particular faces consequential impersonation and fraud risks.
Proof of human can help protect high-stakes conversations by adding a stronger signal of trust: that a real human, rather than an AI-generated impersonation, is participating in the interaction.
Other precautions individuals can take include reverse-searching suspicious images and videos, enabling multi-factor authentication and limiting the personal media shared publicly to reduce the risk of convincing impersonation.
Whether it’s the CFO, the manager or the controller, each member of the finance team operates in a high-pressure environment and needs to have confidence that their digital connections are as real as their physical ones.
Clear procedures and the right technology can help reduce and, in some cases, eliminate that uncertainty while protecting employees from the heavy weight burden and guilt that comes with fraud.
The value of regular training can’t be forgotten here either. Equipping finance teams with the latest knowledge and tools must be an ongoing practice, and not a one-off compliance exercise.
Transitioning to new ways of operating is never linear or straightforward, but proof of human technology could form a foundation of a broader strategy to help finance teams regain trust and properly combat the deepfake threat.