Everyone’s talking about Muck Rack’s 2025 State of Journalism report. It’s a doozy. But too many takeaways stop at the surface. “Don’t be overly promotional.” “Pitch within the reporter’s beat.” “Keep it short.” All true. All timeless. But if you work in crisis communications or anywhere near the intersection of trust, media, and AI, those are just table stakes. The real story is what the report says about disinformation and AI’s double-edged role in modern journalism. Here’s where every in-house and agency team should be paying the closest attention: 🧨 The Risk Landscape: What Journalists Are Actually Worried About: 🚨 Disinformation is the #1 concern Over 1 in 3 journalists named it their top professional challenge—more than funding, job security, or online harassment. 🤖 AI is everywhere and largely unregulated 77% of journalists use tools like ChatGPT and AI transcription; but most work in newsrooms with no AI policies or editorial guidelines. 🤔 Audience trust is cracking Journalists are keenly aware of public skepticism, especially when it comes to AI-generated content on complex topics like public safety, politics, or science. 🤖 ‼️ Deepfakes and manipulated media are on the rise As I discussed yesterday in the AI PR Nightmares series, the tools to fabricate reality are here. And most organizations aren’t ready. 🛡️ What Smart Comms Teams Should Do Next 1. Label AI content before someone else exposes it: → Add “AI-assisted” disclosures to public-facing materials—even if it’s just for internal drafts. Transparency builds resilience. 2. Don’t outsource final judgment to a tool: → Use AI to draft or summarize, but ensure every high-stakes message—especially in a crisis—is reviewed by a human with context and authority. 3. Get serious about deepfake detection: → If your org handles audio or video from public figures, execs, or customers, implement deepfake scanning. Better to screen than go viral for the wrong reasons. 4. Set up disinfo early warning systems: → Combine AI-powered media monitoring with human review to track false narratives before they go wide. 5. Build your AI & disinfo playbook now: → Don’t wait for legal or IT to set policy. Comms should lead here. A one-pager with do’s, don’ts, and red flag escalation rules goes a long way. 6. Train everyone who touches messaging: → Even if you have a great media team, everyone in your org needs a baseline understanding of how disinfo spreads and how AI can help or hurt your credibility. TL/DR: AI and misinformation aren’t future threats. They’re already shaping how journalists vet sources, evaluate pitches, and report stories. If your communications team isn’t prepared to manage that reality (during a crisis or otherwise), you’re operating with a blind spot. If you’re working on these challenges—or trying to, drop me a line if I can help.
Understanding Deepfake Risks
Explore top LinkedIn content from expert professionals.
-
-
The New Corporate Threat: Deepfakes That Even Experts Can't Detect Welcome to the new reality where AI doesn’t just generate content, it manufactures convincing lies. You’ve probably seen it: - A CEO announces a fake acquisition. - A politician "says" something they never did. - A voice note "from your boss" requests a fund transfer. It all looks real. But it’s not. It’s a deepfake AI-generated audio, video, or images designed to deceive. Why it matters: Deepfakes are no longer just internet tricks or entertainment. They’re now: - Financial fraud enablers (voice clones used to scam employees) - Corporate risk vectors (fake news impacting stock prices) - Political weapons (manipulated clips used to sway public opinion) - Personal threats (identity misuse, blackmail, defamation) How to spot a deepfake Look for: - Unnatural blinking or awkward lip sync - Plastic skin or weird lighting - Robotic tone or emotionless speech - Out-of-character statements - No credible source backing the video If it feels off, it probably is. What you can do: - Pause before sharing - Use tools like Deep ware, Microsoft Video Authenticator, or Adobe Verify - Train your teams especially PR, legal, and finance - Push for content provenance in your organization In the GenAI era, trust is currency. Don’t spend it on content you didn’t verify. #artificialintelligence
-
Just ten seconds of speech and your voice is now mine. I spoke to CNN's Clare Duffy about surging deepfake voice fraud and how we can protect ourselves. The feeling of hearing a familiar voice at the end of the phone can reflexively comfort or put us at ease, but in 2026, that reflex is being hijacked at an industrial scale. The same dynamics apply to deepfake voice cloning or 'vishing' attacks as many other forms of AI weaponisation. Increasing access, output realism, and efficiency of voice cloning models has led to criminals rapidly adopting them to execute on well established fraud tactics, in this case fraud and impersonation. The reason they're doing it, as always, is that it works. As Clare reports, Americans lost over $893m last year to AI powered fraud, including voice cloning attacks. With decreasing latency for generating voices and improvements in more sophisticated voice cloning tools for voice skinning (being able to speak in near real time with someone else's voice), I cannot see this number going anywhere but up. So what can we do about it? As I stressed to Clare, advising people how to protect themselves can be a difficult balance to strike. The research is clear that when it comes to distinguishing AI generated voices from authentic ones, we're only marginally better than a coin flip, and that's in experimental conditions when participants are actively looking for them. Increased awareness and vigilance is of course important, but we absolutely cannot rely on a future where our ears alone are the ultimate guide. As I say in the piece, “For the everyday person, it is just not fair to expect them to be able to spot this stuff,”. So what can we do? One often provided solution (which I believe I was one of the first to suggest back in 2019 in the Financial Times) is what I called at the time a 'semantic passphrase'. A pre-agreed phrase or word with close colleagues, friends, or loved ones that only they could know. There's value in this approach (which several banks have actively endorsed to their customers), but the reality is the number of these semantic passwords you'd need to remember could be challenging! Another is to remember the basics. AI powered or not, deepfake fraud is still social engineering. If you're receiving calls from unrecognised numbers, being rushed or harried into sending money, or just get the feeling something isn't right from how someone appears to be speaking, either verify through a secure channel or use a pass phrase/ask for information only they could know. Ultimately, as I put it to Clare: “If you suspect that something might not be right, it is much better to have your mum or your brother or your friend laugh at you for thinking that they’re a robot,” Ajder said, “than it is to potentially be running to an ATM.” (In hindsight, maybe "running to your crypto wallet" may have been the more appropriate scenario for the deepfake age!)
-
When a patient hears from a “doctor,” they shouldn’t have to wonder if it’s real. AI deepfakes are already blurring that line - impersonating physicians, promoting unproven treatments, and putting patients at risk. When a physician’s identity is hijacked, it doesn’t just harm one clinician. It undermines the credibility of care itself. That’s why the AMA is calling for clear, enforceable protections against AI-driven impersonation. We’ve outlined a framework grounded in a simple idea: a physician’s identity is not a public utility. It’s a protected right. What does that mean in practice? • No use of a physician’s name, likeness, or voice without explicit, informed, and revocable consent. • Clear labeling and transparency for any AI-generated clinical content. • Shared accountability across platforms, vendors, and institutions. • Real enforcement mechanisms to stop impersonation and protect patients. This isn’t simply about stopping bad actors. It’s about defining the rules of trust in a digital health system. If identity can be manufactured today, what anchors trust in health care tomorrow? #AI #DigitalHealth #PatientSafety #Deepfakes
-
As organizations transition from pilots to enterprise-wide deployment of Generative and Agentic AI, it's crucial to recognize that GAI risks differ significantly from traditional software risks. Towards that, it is important to go back to basics and this publication from 2024 by National Institute of Standards and Technology (NIST)'s Generative AI Profile does a great job! 🌐 Here are the four highest-impact risks and the mitigation actions every organization should implement:- 1. Systemic Risk: Algorithmic Monocultures & Ecosystem-Level Failures When multiple industries depend on the same foundation models, a single unexpected model behavior can lead to correlated failures across the ecosystem. ⚡ Mitigation: - - Build model diversity and avoid single-model dependencies. - Maintain fallback systems and contingency workflows. - Apply stress tests that simulate sector-wide shocks. 2. Human-Originating Risks (Misuse, Over-Trust, Manipulation) Many GAI incidents stem from human behavior, including misuse, over-reliance, indirect prompt injection, and flawed assumptions. ⚡ Mitigation:- - Implement continuous user education on limitations and safe use. - Enforce access controls, privilege separation, and plugin vetting. - Maintain audit trails and logging to identify misuse early. 3. Content Integrity Risks (Hallucinations, Synthetic Media, Provenance Failure) GAI increases the scale and believability of fabricated content, from medical misinformation to deepfake-enabled harms. ⚡ Mitigation:- - Invest in content provenance, watermarking, and metadata tracking. - Require pre-deployment testing for hallucination profiles across contexts. - Use cross-model verification before high-stakes outputs are acted upon. 4. Security Risks (Prompt Injection, Data Leakage, Model Extraction) NIST highlights increasingly sophisticated attack surfaces unique to LLMs: indirect prompt injection, data extraction, and plugin-initiated compromise. ⚡ Mitigation:- - Apply secure-by-design reviews for all LLM integration points. - Red-team regularly using GAI-specific attack methods. - Log inputs/outputs via incident-ready documentation so breaches can be traced. 🔐 The bottom line:- AI risk management is not a technical afterthought, it is now a core capability. Organizations that operationalize governance, provenance, testing, and incident disclosure (NIST’s four focus pillars) will be the ones that deploy AI safely and at scale. 💬 If you’d like to explore Gen AI and Agentic AI risks, practical mitigation strategies, or how to operationalize the NIST AI RMF for your organization, feel free to comment or DM. Let’s build safer AI systems together! #AI #GenAI #AIGovernance #NIST #AIRMF #RiskManagement #AITrust #ResponsibleAI #AILeadership
-
Fraud no longer hides in the shadows. It might show up disguised as someone you know. Like when the CEO calls and her voice on the phone sounds exactly right. Her urgency feels real, and the wire transfer request to a new bank account seems legitimate, so accounting releases the funds. And just like that, the company loses $20k to a fraudster who weaponized AI. This isn't science fiction. It's happening right now to individuals and organizations alike. Fraudsters are creating disturbingly real AI deepfakes that can fool even the most cautious people. And companies need strategies to combat them. Because those audio and visual cues we've relied on for decades are no longer reliable indicators of authenticity when it comes to AI deepfakes. Organizations can fight back with these defense strategies: ✔ Stay cautious and be wary of anyone requesting money or personal information, even if they look or sound like someone you trust. ✔ Don’t send money or share sensitive data in response to a single phone or video call. Phone numbers can be spoofed, so always verify a person’s identity by contacting them separately at a number you trust. ✔ Use small action requests, like asking a person to turn their head, blink repeatedly, or hum a song while on a video or phone call. If they decline, freeze up, or go silent, it could be a fraudster. ✔ Establish a safe word that only your inner circle knows to confirm the identity of someone claiming to be a colleague, family member, or friend. ✔ Use strong passwords. Enable multifactor authentication (MFA) on all company devices and accounts whenever possible. And don’t forget to report AI deepfakes to law enforcement and any relevant social media channels, websites, and other platforms where the encounter took place. All of these tips ALSO work for individuals too because hackers like causing havoc with anyone they can. The question isn't whether AI deepfakes will target your organization. It's whether your organization will be ready when it does. Food for thought as we kick off Cybersecurity Awareness Month. ♻ Share our infographic to help companies combat AI deepfakes.
-
My dad almost sent 50,000 to "me" yesterday. Except it wasn't me. It was a deepfake. AI scams aren't coming, they're already here. And our parents are the most vulnerable targets. The technology is now so good that even tech-savvy people can't detect deepfake videos or voice clones. If YOU can't tell, your parents definitely can't. Here's what I told my parents (please share this with yours or post this screenshot): If you EVER get a video, voice call or message from your family member asking for money: → Stop. Take 10 seconds. Ask ONE deeply personal question. Not their birthday. Not their address. Scammers can find that online. Ask something only you two would know: • What did we fight about at Diwali party 2019? • What's the name of your childhood pet that we never posted about? • What was the last meal we cooked together? The rule in our family now: No money moves without the secret question. Even in "emergencies." I know it feels awkward. I know in a crisis, we don't think rationally. But that's exactly what scammers count on. Sit with your parents THIS WEEK. Create 2-3 questions together. Write them down. Make it a pact. This 5-minute conversation could save them from losing their life savings. Let's protect the people who protected us. #CyberSecurity #DeepfakeSafety #AIScams
-
Deepfakes aren’t a tech story. they’re a trust story A few days ago, a doctor in Hyderabad lost money to a #deepfake video that showed a cabinet minister “endorsing” an investment scheme on #Instagram. If that sounds distant, it isn’t. This is the new fraud funnel: authority, urgency, proof… all manufactured at scale. As #communicators and leaders, we can’t outsource this to compliance or IT. #Trust is now an operational KPI. What we as communicators need to do? • Treat digital hygiene like fire safety. Run quarterly drills that teach people how fakes travel and how to report them • Publish an authenticity sheet. List official handles, verified domains, escalation numbers and a simple “how to verify” flow for customers and employees • Watermark outbound content and adopt content credentials where possible. Make the real easier to prove than the fake is to spread. • Rewrite influencer and media contracts with an “authenticity clause” and takedown SLAs. If your face or footage is misused, minutes matter. • Stand up a rapid debunk protocol. Pre-approved copy, visuals, spokespeople and a single public link that carries all corrections. • Close the platform loop. Nominate a trust lead who keeps warm lines with platform policy teams so your takedown requests don’t start cold. Silence helps the scammer. Clarity helps the vulnerable. What would you add to this deepfake playbook? If you’ve seen a convincing fake lately, share it below and let’s decode why it worked. #digitalsafety #misinformation #brandprotection #reputationmanagement #contentauthenticity #aiethics #factchecking #onlinescams #communications
-
𝘋𝘦𝘦𝘱𝘧𝘢𝘬𝘦𝘴 𝘢𝘳𝘦 𝘵𝘩𝘦 𝘣𝘪𝘨𝘨𝘦𝘴𝘵 𝘦𝘹𝘪𝘴𝘵𝘦𝘯𝘵𝘪𝘢𝘭 𝘵𝘩𝘳𝘦𝘢𝘵 𝘵𝘰 𝘥𝘪𝘨𝘪𝘵𝘢𝘭 𝘵𝘳𝘶𝘴𝘵 𝘵𝘰𝘥𝘢𝘺.”— 𝘛𝘪𝘮 𝘊𝘰𝘰𝘬 Few weeks ago, a Hong Kong CFO transferred $25M to “his CEO” after a video call. The catch? The “CEO” was a deepfake. The voice, mannerisms, and background were flawless. The money? Gone forever. 𝗪𝗵𝘆 𝗗𝗲𝗲𝗽𝗳𝗮𝗸𝗲𝘀 𝗕𝗿𝗲𝗮𝗸 𝗧𝗿𝗮𝗱𝗶𝘁𝗶𝗼𝗻𝗮𝗹 𝗗𝗲𝗳𝗲𝗻𝘀𝗲𝘀 – 𝗛𝘂𝗺𝗮𝗻𝘀 𝗮𝗿𝗲 𝗵𝗮𝗿𝗱𝘄𝗶𝗿𝗲𝗱 𝘁𝗼 𝘁𝗿𝘂𝘀𝘁 𝘃𝗶𝗱𝗲𝗼/𝗮𝘂𝗱𝗶𝗼: 74% of employees wouldn’t question a CEO’s video directive (MIT, 2024). – 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻 𝘁𝗼𝗼𝗹𝘀 𝗹𝗮𝗴: 80% of generative AI detection software fails against new models (Stanford). – 𝗦𝗰𝗮𝗹𝗲𝘀 𝗳𝗮𝘀𝘁: One deepfake template can spawn 10,000 custom scams in minutes. 𝗕𝘂𝗶𝗹𝗱 𝗮 𝗛𝘂𝗺𝗮𝗻 𝗙𝗶𝗿𝗲𝘄𝗮𝗹𝗹 → 𝗧𝗿𝗮𝗶𝗻 𝘁𝗲𝗮𝗺𝘀 𝘁𝗼 𝘀𝗽𝗼𝘁 𝘁𝗵𝗲 𝘂𝗻𝗰𝗮𝗻𝗻𝘆 • Host red team exercises with fake phishing videos. • Teach “glitch checks”: Unnatural eye blinks, mismatched shadows, AI lip-sync errors. → 𝗜𝗺𝗽𝗹𝗲𝗺𝗲𝗻𝘁 𝘃𝗲𝗿𝗶𝗳𝗶𝗰𝗮𝘁𝗶𝗼𝗻 𝗱𝗲𝗮𝗱𝗹𝗼𝗰𝗸𝘀 • Codeword protocols for wire transfers (changed weekly). • Mandate 2FA for 𝘢𝘭𝘭 sensitive actions, even post-login. → 𝗗𝗲𝗽𝗹𝗼𝘆 𝗔𝗜 𝘁𝗼 𝗳𝗶𝗴𝗵𝘁 𝗔𝗜 • Tools like Microsoft’s Video Authenticator analyze pixel-level artifacts. • Blockchain timestamps for official media (Adobe’s Content Credentials). 𝗧𝗵𝗲 𝗦𝘁𝗮𝗸𝗲𝘀 • Gartner predicts 60% of enterprises will face deepfake scams by 2026. • 89% of people can’t spot a high-quality deepfake (MIT Media Lab). • Companies with detection training reduce fraud losses by 63% (IBM). Don’t wait for a deepfake crisis to act. Your face—and your brand—are already being cloned. #CyberSecurity #Deepfake #RiskManagement
-
The FBI recently issued a stark warning: AI-generated voice deepfakes are now being used in highly targeted vishing attacks against senior officials and executives. Cybercriminals are combining deepfake audio with smishing (SMS phishing) to convincingly impersonate trusted contacts, tricking victims into sharing sensitive information or transferring funds. This isn’t science fiction. It is happening today. Recent high-profile breaches, such as the Marks & Spencer ransomware attack via a third-party contractor, show how AI-powered social engineering is outpacing traditional defenses. Attackers no longer need to rely on generic phishing emails; they can craft personalized, real-time audio messages that sound just like your colleagues or leaders. How can you protect yourself and your organization? - Pause Before You Act: If you receive an urgent call or message (even if the voice sounds familiar) take a moment to verify the request through a separate communication channel. - Don’t Trust Caller ID Alone: Attackers can spoof phone numbers and voices. Always confirm sensitive requests, especially those involving money or credentials. - Educate and Train: Regularly update your team on the latest social engineering tactics. If your organization is highly targeted, simulated phishing and vishing exercises can help build a culture of skepticism and vigilance. - Use Multi-Factor Authentication (MFA): Even if attackers gain some information, MFA adds an extra layer of protection. - Report Suspicious Activity: Encourage a “see something, say something” culture. Quick reporting can prevent a single incident from escalating into a major breach. AI is transforming the cyber threat landscape. Staying informed, alert, and proactive is our best defense. #Cybersecurity #AI #Deepfakes #SocialEngineering #Vishing #Infosec #Leadership #SecurityAwareness