The clearest signs are low concern paired with weak preparation. In the article, many leaders believe deepfakes will have high impact, yet a sizable share still think their organisation is not taking the threat seriously enough. Another warning sign is reliance on legacy checks alone, especially when teams have not revised policies, budgets, or verification workflows for AI-enabled deception.
What weak preparation looks like in practice
Underestimating deepfake risk is usually visible in the gap between awareness and action. Leaders may say the threat is serious, but the organisation still relies on old approval habits, informal voice verification, and manual judgement that were designed before synthetic audio and video were cheap, fast, and convincing.
That gap matters because deepfakes rarely succeed by “looking perfect” in a forensic sense. They succeed when teams trust a familiar channel, move too quickly, or assume a call, recording, or video clip is authentic because it sounds or looks operationally routine.
One useful warning sign is overconfidence in a single check. If the current process expects staff to recognise a voice, trust a video meeting, or confirm a request through the same channel that was used to make it, the organisation is treating identity verification as if deception has not changed.
- Approval paths are still optimized for convenience rather than verification.
- High-value requests can be authorised without a separate call-back or out-of-band check.
- Policies mention synthetic media, but escalation steps and budgets have not changed.
Signals that the organisation has not adapted its controls
A more concrete sign is that policies, tooling, and training have not kept pace with the risk narrative. Teams may discuss deepfakes in awareness sessions, yet there is no revised process for payment changes, executive impersonation, incident escalation, or evidence review when a message, recording, or live call is disputed.
That is where deepfake risk becomes operational, not theoretical. When verification workflows remain unchanged, the organisation is depending on humans to spot deception after the fact instead of making the request hard to abuse in the first place. Current guidance from AI governance and cyber-control frameworks consistently points toward layered verification rather than single-channel trust.
The article’s strongest signal is the combination of high perceived impact and weak practical readiness. That is the classic underestimate pattern: people agree the hazard exists, but they have not funded, assigned, or operationalised the response.
- Budgets have not been allocated for stronger verification or fraud escalation.
- Executives and finance teams have not rehearsed synthetic-media scenarios.
- Detection tools exist, but response ownership is unclear.
What practitioners should look for next
Practitioners should focus on whether the organisation has changed decision-making, not just awareness. If leaders cannot show updated approval thresholds, documented verification steps for sensitive requests, and a clear exception path for suspected impersonation, then the response is still immature even if the risk is widely acknowledged.
If the organisation is handling voice, video, or message authenticity as a “common sense” problem, that is a sign the threat model is too optimistic. The right question is not whether deepfakes are understood in principle, but whether the workflow remains safe when a realistic synthetic request reaches a busy employee at the wrong moment.
Practitioner takeaway: Treat deepfake underestimation as an execution gap, not an awareness gap, and prioritise whether sensitive requests can still be verified independently when audio and video can no longer be trusted on their own.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST AI RMF, CIS Controls v8, NIST SP 800-63 and NIST AI 600-1 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Deepfake underestimation is a governance and risk prioritisation problem. |
| Recommendation — Update risk decisions, funding, and escalation criteria for synthetic-media abuse. | ||
| NIST AI RMF | GOVERN 2.3 — AI Risk Management Culture | The question concerns whether AI-enabled deception risk is being taken seriously enough. |
| Recommendation — Embed synthetic-media risk into governance, accountability, and training. | ||
| CIS Controls v8 | 6.3 — Require MFA for Externally-Accessible Applications | Deepfake impersonation often targets human trust in access and approval workflows. |
| Recommendation — Add independent verification steps for high-risk requests and approvals. | ||
| NIST SP 800-63 | 5.2.7 — Phishing Resistance | Weak deepfake preparedness often means relying on non-resistant human verification. |
| Recommendation — Prefer phishing-resistant, out-of-band verification for sensitive identity checks. | ||
| ISO/IEC 42001:2023 | A.5 — AI Risk Treatment | Deepfake risk is an AI governance issue when organisations deploy or face synthetic media. |
| Recommendation — Define treatment actions, owners, and review cadence for synthetic-media threats. | ||
Related resources from NHI Mgmt Group
- What are the signs that human risk controls are not working in a healthcare organisation?
- What are the signs that an organisation’s API security programme is not keeping up with risk?
- What are the signs that password risk is still spreading across an organisation?
- What are the signs that an organisation is not ready for AI-driven security risk?