Why AI Deepfakes Are Harder to Spot Than Ever,and What Experts Say You Should Do
As artificial intelligence makes deepfakes and voice cloning increasingly realistic, the old tricks for spotting fraud,poor spelling, robotic voices, suspicious links,no longer work reliably. Security experts now warn that the best defense isn't looking for technical glitches; it's pausing to verify before acting on any unexpected request, especially those involving money or sensitive information.
What Makes AI-Powered Fraud So Convincing Now?
Deepfakes, voice cloning, and AI-generated phishing messages are becoming so sophisticated that people can no longer rely on the visual and audio red flags that once exposed scams. Amer Sharaf, chief executive of the Cyber Security Systems and Services Sector at Dubai Electronic Security Centre (Desc), explained that AI is allowing attackers to automate and accelerate methods that previously required significant manual effort.
The threat extends beyond simple email scams. Cybercriminals now combine publicly available information from social media, company announcements, and professional profiles with AI-generated voice cloning and impersonation techniques to create convincing requests from trusted colleagues. These attacks can succeed without ever breaching an organization's systems.
Michael Kelly, the Emmy-nominated actor known for roles in "House of Cards" and "Jack Ryan," described the technology as both "terrifying" and "encouraging" during a cybersecurity conference. He shared how similar deepfake technology was used legitimately during production of "Jack Ryan" when he tested positive for COVID on the final day of filming. His face was scanned and seamlessly placed on another actor's body, demonstrating the technology's dual nature as both a tool and a threat.
How Can You Actually Protect Yourself Against AI Deception?
Rather than teaching people to spot technical imperfections that are disappearing as AI improves, security experts are shifting focus to behavioral defenses that remain effective regardless of how realistic the deception becomes. The key is recognizing contextual warning signs and pausing before acting.
- Double-check unexpected requests: Any email or message asking you to transfer funds, share credentials, or take unusual action should be verified through a separate, trusted channel. Call the person directly or visit their office before proceeding with financial transactions.
- Establish safe words with family and friends: As voice and video cloning technology becomes more sophisticated, agree on secret phrases or questions with loved ones that only you would know. This helps confirm whether a call or video message is genuinely from them.
- Pause when you feel urgency: Scammers deliberately create time pressure to bypass your logical thinking. If someone is asking you to do something and especially if they're creating a sense of urgency, stop for five seconds and think about why they're asking before responding.
- Keep devices updated: Software updates often contain fixes for newly discovered security vulnerabilities. Staying current is a simple but critical defense layer.
- Use two-factor authentication and password managers: These tools add friction that makes attackers' jobs harder, even when they have convincing deepfakes or cloned voices.
"If you're unsure about something, or if someone's asking you to do something, and certainly if someone's giving you a sense of urgency, stop. Take five seconds, think about why they're asking you, and just allow your logic brain to engage," said Solomon Gilbert, a former hacker who now advises UK government and police forces on cyber security.
Solomon Gilbert, Former Hacker and Cybersecurity Advisor to UK Government and Police
What New Tools Are Being Deployed to Detect Deepfakes?
Recognizing the urgency of the threat, security organizations are developing AI-powered detection tools. Desc announced the launch of Saraab, an AI model developed by an Emirati team specifically designed to detect deepfake videos. The tool scans videos frame by frame and uses heat maps of facial features to identify signs of manipulation that are difficult for humans to detect visually.
Saraab will be made available as an open-source tool, meaning organizations and individuals can download and use it without cost. This democratization of detection technology reflects the recognition that deepfake threats affect everyone, not just large enterprises.
Beyond detection tools, organizations are also turning to behavioral training. Living Security, a human risk management firm, is expanding its 2026 Cybersecurity Awareness Month program with two new interactive experiences designed to help employees practice recognizing and resisting AI-powered deception.
Why Is Employee Training Becoming Critical in the AI Era?
Living Security's research reveals a troubling pattern: 74.8% of risky behavior traces to just 10% of the workforce, yet two in three people in this year's riskiest 10% were not on last year's list. This means human risk is concentrated but constantly shifting, making one-time awareness training insufficient.
The company's new interactive programs, called "Verified" and "Trust No One," place employees in realistic scenarios where they must evaluate information and make decisions rather than simply consuming awareness content. "Verified" is a live 30-minute game-show challenge where participants navigate increasingly convincing AI-powered threats across three interactive rounds. "Trust No One" is a team-based investigation where employees retrace a sophisticated fraud attempt to understand how attackers combined public information with AI-generated voice cloning to create a convincing scam.
"Technology is changing rapidly, but one principle remains constant: verify before you trust. These experiences give employees hands-on opportunities to recognize deception, question assumptions, and practice the behaviors that reduce human risk," said Ashley Rose, CEO and Co-Founder of Living Security.
Ashley Rose, CEO and Co-Founder of Living Security
What Should You Know About Using Public AI Services?
Security experts also warn about a different kind of AI risk: the data you submit to publicly available AI tools. Jan D'Herdt, a certified instructor at the SANS Institute, a cybersecurity research and training organization, noted that most people don't understand how the information they enter into AI tools can be used.
If you submit data to a publicly facing AI service without a private subscription, that data is typically considered public and may be used to train the AI company's models. This means sensitive business information, personal details, or proprietary data could inadvertently become part of an AI system's training data. The biggest immediate risk isn't AI itself but how people choose to use it.
"The number one mistake is that people are going out there using AI and they're not knowing which AI they're using. Anything that is publicly facing, if you submit data to it and it's not a private subscription you have with them, it's public," explained Jan D'Herdt.
Jan D'Herdt, Certified Instructor at SANS Institute
As AI-powered threats continue to evolve, the consensus among security leaders is clear: no technological fix alone will protect you. The human behaviors of pausing, verifying, and questioning assumptions remain your most reliable defense, even as the threats become more convincing and harder to distinguish from reality.