
AI deepfakes demand low-tech, scalable defenses for enterprise security
Published by AINave Editorial • Reviewed by Ramit
AI deepfakes have made it impossible to trust what you see and hear on a video call. In January 2024, an employee at professional services firm Arup joined a video call with what they believed was the company's CFO and authorized 15 wire transfers totaling about $25 million. Every participant on the call was an AI-generated clone created from public appearances and earnings calls of Arup executives. The incident is a clear signal that traditional detection methods no longer work, and the most effective AI deepfake defense strategies are deliberately low-tech.
Why visual and audio tells no longer work
Security experts and government agencies have concluded that relying on visual or audio tells is no longer viable. A University College London study found listeners could accurately identify deepfakes only about 73% of the time, and training improved accuracy by just 3.84%. A later aggregation of 56 studies by researchers from the University of Duisburg-Essen and Indiana University found human detection rates were closer to chance. The NSA, FBI, and CISA jointly ruled out traditional automated detection protocols that visualize evidence of manipulation in voice or video content. As GrackerAI CEO Deepak Gupta told ZDNET, "Seeing and hearing someone is no longer proof they are real."
What this means for AI builders
For teams building AI products or managing enterprise workflows, this means any system that relies on perception-based identity verification is broken. The threat extends beyond one-off financial scams to long-term infiltration, as seen in the KnowBe4 incident where a North Korean operative was hired after standard interviews and screening. Builders need to design systems that assume deepfakes can bypass human and automated checks. The defense must shift from detection to prevention through process controls.
Practical defense strategies
Hardware MFA and verbal passphrases
Hardware-based multi-factor authentication using FIDO2 or PIV credentials is now recommended by CISA as the gold standard for MFA. These credentials cannot be phished or cloned through deepfake techniques. For voice and video calls, secret verbal passphrases shared between participants provide a simple but effective check. The FBI recommends this approach. However, passphrases only work if enforced consistently. Security experts advise making the control automatic and no-exception, and running simulated deepfake calls as part of employee training.
Out-of-band verification and dual authorization
For high-value transactions, a single passphrase is not enough. The recommended approach combines out-of-band callbacks (authenticating through a second communication channel) and dual authorization (requiring a second employee to validate the request). This confines friction to high-risk workflows rather than adding it everywhere.
Passphrase management best practices
Passphrase management should follow password best practices: use random word lists from the Electronic Frontier Foundation, implement role-based passphrases for different transaction tiers, and rotate passphrases on evidence of compromise or role change rather than on a fixed schedule. NIST guidelines now advise against the 90-day reset rule because it creates predictability. Password managers like Keeper Security can store company credentials.
Caveats and trade-offs
These low-tech defenses are not without trade-offs. Employees often skip security checks when intimidated by a superior, so a no-exception policy is critical. Scalability can be an issue for large organizations, but role-based passphrases and password managers help. The evidence in this article is based on a single high-profile incident and expert commentary; broader deployment constraints and user friction are not fully explored. Builders should pilot these controls in high-risk workflows before rolling out organization-wide.
FAQs
Sources
- A low-tech solution from the past may be your best defense against AI deepfakes
- A low-tech solution from the past may be your best defense...
- The Best Defense Against AI Deepfakes Might Be Human Training
- The War On What's Real - Fast Company
- Combating AI Deepfakes: ASU's Innovative Voice Authentication
- What Is The Three-Finger Test? How A Deepfake... | IBTimes UK
- Defending Against AI Deepfakes: Challenges... | Adaptive Security
- They Used AI to Destroy My Brand" A Ugandan... - YouTube
- What are deepfakes? How to identify and prevent fake videos
- A low-tech solution from the past may be your best defense ...
- Protect Against Deepfakes: Essential Defense Strategies
- Ivy Enterprises | A low-tech solution from the past may be ...





















