Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What are the signs that an organisation is…
Identity Beyond IAM

What are the signs that an organisation is underestimating deepfake risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Identity Beyond IAM

The clearest signs are low concern paired with weak preparation. In the article, many leaders believe deepfakes will have high impact, yet a sizable share still think their organisation is not taking the threat seriously enough. Another warning sign is reliance on legacy checks alone, especially when teams have not revised policies, budgets, or verification workflows for AI-enabled deception.

What weak preparation looks like in practice

Underestimating deepfake risk is usually visible in the gap between awareness and action. Leaders may say the threat is serious, but the organisation still relies on old approval habits, informal voice verification, and manual judgement that were designed before synthetic audio and video were cheap, fast, and convincing.

That gap matters because deepfakes rarely succeed by “looking perfect” in a forensic sense. They succeed when teams trust a familiar channel, move too quickly, or assume a call, recording, or video clip is authentic because it sounds or looks operationally routine.

One useful warning sign is overconfidence in a single check. If the current process expects staff to recognise a voice, trust a video meeting, or confirm a request through the same channel that was used to make it, the organisation is treating identity verification as if deception has not changed.

  • Approval paths are still optimized for convenience rather than verification.
  • High-value requests can be authorised without a separate call-back or out-of-band check.
  • Policies mention synthetic media, but escalation steps and budgets have not changed.

Signals that the organisation has not adapted its controls

A more concrete sign is that policies, tooling, and training have not kept pace with the risk narrative. Teams may discuss deepfakes in awareness sessions, yet there is no revised process for payment changes, executive impersonation, incident escalation, or evidence review when a message, recording, or live call is disputed.

That is where deepfake risk becomes operational, not theoretical. When verification workflows remain unchanged, the organisation is depending on humans to spot deception after the fact instead of making the request hard to abuse in the first place. Current guidance from AI governance and cyber-control frameworks consistently points toward layered verification rather than single-channel trust.

The article’s strongest signal is the combination of high perceived impact and weak practical readiness. That is the classic underestimate pattern: people agree the hazard exists, but they have not funded, assigned, or operationalised the response.

  • Budgets have not been allocated for stronger verification or fraud escalation.
  • Executives and finance teams have not rehearsed synthetic-media scenarios.
  • Detection tools exist, but response ownership is unclear.

What practitioners should look for next

Practitioners should focus on whether the organisation has changed decision-making, not just awareness. If leaders cannot show updated approval thresholds, documented verification steps for sensitive requests, and a clear exception path for suspected impersonation, then the response is still immature even if the risk is widely acknowledged.

If the organisation is handling voice, video, or message authenticity as a “common sense” problem, that is a sign the threat model is too optimistic. The right question is not whether deepfakes are understood in principle, but whether the workflow remains safe when a realistic synthetic request reaches a busy employee at the wrong moment.

Practitioner takeaway: Treat deepfake underestimation as an execution gap, not an awareness gap, and prioritise whether sensitive requests can still be verified independently when audio and video can no longer be trusted on their own.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST AI RMF, CIS Controls v8, NIST SP 800-63 and NIST AI 600-1 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyDeepfake underestimation is a governance and risk prioritisation problem.
Recommendation — Update risk decisions, funding, and escalation criteria for synthetic-media abuse.
NIST AI RMFGOVERN 2.3 — AI Risk Management CultureThe question concerns whether AI-enabled deception risk is being taken seriously enough.
Recommendation — Embed synthetic-media risk into governance, accountability, and training.
CIS Controls v86.3 — Require MFA for Externally-Accessible ApplicationsDeepfake impersonation often targets human trust in access and approval workflows.
Recommendation — Add independent verification steps for high-risk requests and approvals.
NIST SP 800-635.2.7 — Phishing ResistanceWeak deepfake preparedness often means relying on non-resistant human verification.
Recommendation — Prefer phishing-resistant, out-of-band verification for sensitive identity checks.
ISO/IEC 42001:2023A.5 — AI Risk TreatmentDeepfake risk is an AI governance issue when organisations deploy or face synthetic media.
Recommendation — Define treatment actions, owners, and review cadence for synthetic-media threats.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org