
Most enterprise deepfake-detection programs I have reviewed in the last year are calibrated against an attack that did not steal $25.6 million from Arup. I have spent the last eighteen months sitting with CISOs, treasury leads and cyber-insurance brokers who all assumed they were buying the same thing, and what I have learned is that the line between presentation attack and injection attack is the line between a control that catches a deepfake and a control that politely watches one go past. The page where we lay this out is our enterprise deepfake detection solution page; what follows is the version I tell over coffee, with the moments I am still thinking about.
The CISO whose own team broke her vendor shortlist

I had a long conversation last quarter with the CISO of a mid-sized financial-services firm who, two weeks after the Arup story made it into her board pack, had short-listed three deepfake-detection vendors and authorised a paid pilot of all three. Her team is good — better than most — and they did something the vendors did not love: they ran their own injection. They stood up an OBS VirtualCam build, trained a face-swap model on roughly an hour of YouTube footage of their own CFO, joined a sanctioned Zoom test call with the model wired into the data stream, and waited to see what the vendor consoles would say.
All three said no anomaly detected.
That moment is when I stopped using lab benchmarks in any vendor conversation. Purdue's 2025 production benchmark, replicated by Brightside AI, has been telling us in writing for a year that real-world deepfake-detection accuracy across leading commercial tools runs 50–65% against current-generation deepfakes outside controlled conditions, even when the same tools sit at 96–99% in the vendor demo. Reality Defender, Pindrop, iProov, GetReal Security — every one of them I respect, and every one of them sits in a vendor landscape where the test conditions in the slide deck are not the test conditions in the breach. The reason her test caught all three was simple: most "deepfake detection" line items in enterprise RFPs ask for ISO/IEC 30107-3 conformance, which is presentation attack detection — the screen-in-front-of-the-camera attack. The Arup-pattern attack is an injection attack, fed through virtual-camera software into the conferencing client. CEN/TS 18099, the 2024 standard that actually tests for injection, is still missing from almost every procurement document I read.
A 60% probabilistic flag on a $25 million transaction is not a control. It is a coin flip.
That is the framing I started using with her board, and it is the one I want every CISO sitting on a 2026 deepfake-defense budget to use.
The empty hook above the wire-transfer workstation

A few months later I was walking through a Hong Kong office of a different client — a treasury operation, regulated, audited, no part of the Arup story but the same kind of seat. I noticed that the laminated callback roster that had been taped above the wire workstation a year ago was no longer there. I asked about it. The operations lead, who I like, said the team had taken it down because the new Zoom plugin handled that part now and there had been some friction with auditors about the paper.
The new Zoom plugin she was referring to is real. Beyond Identity's RealityCheck is a legitimate piece of device-attestation work — it confirms the webcam feed is coming from physical hardware, which is exactly the kind of control that would have stopped the OBS VirtualCam injection my CISO friend's team built. But device attestation does not authenticate the human on the other end of the call. It tells you the camera is real. It does not tell you the face in front of the camera is the CFO. The team had unintentionally traded a process control that worked against every variant of the attack for a technology control that worked against one part of one variant, and the failure mode I worry about most in 2026 is exactly that trade, made quietly, in offices where nobody had a strong opinion about the laminated piece of paper.
I asked our client to put the roster back. We added a written threshold above which any wire instruction has to be confirmed through a pre-registered out-of-band channel before execution — a phone number written down before today's call started, a counterparty whose voice the treasury team has heard on the line before. The roster cost nothing. It catches every injection attack, every presentation attack, every audio-only deepfake, every modality I have not seen yet because it does not depend on detecting anything. The reason it had come down had nothing to do with security and everything to do with the fact that paper has friction and the new tool felt like progress.
The renewal email with "AI-generated intermediary" in yellow

The third moment is one I still find harder to talk about than the first two. In January 2026, one of our enterprise clients forwarded me their cyber-insurance renewal. The broker had highlighted, in yellow, the phrase "AI-generated intermediary" in a new exclusion clause. Across the major carrier base, standard cyber forms have closed the ambiguity that used to let deepfake fraud slip into social-engineering coverage, and they have closed it in the wrong direction — the loss is now explicitly excluded. D&O, E&O and EPL forms are doing the same in parallel. Standalone deepfake endorsements have appeared at the $500–$3,000 annual premium range for small businesses, with named-peril language that is materially narrower than what an enterprise CISO will recognize as needed coverage. Coalition's December 2025 reputational-harm endorsement is the most generous early product I have read, and it still leaves substantial gap.
The math the client and I worked through that week is the math more boards should be doing now. The reference number we publish on the page is a $680K average enterprise deepfake loss; the Arup number, public on the high end, is $25.6 million. Both are now sitting in the uninsured column for most policies written before January 2026. The SEC cybersecurity disclosure rule that took effect in December 2023 requires material incidents to be reported on Form 8-K within four business days, and a multi-million-dollar deepfake fraud is material for any firm that has to disclose it. The control gap and the disclosure gap and the insurance gap arrived in the same fiscal year, and the year is not yet halfway through.
The Article 50 conversation I keep having

Most of the AI-Act compliance work my legal and product friends are doing right now is on high-risk system classification under Article 6. The conversation I keep having that nobody started a workstream for is Article 50 — the transparency obligations for AI-generated content that take effect August 2, 2026, with the Code of Practice expected to land in May or June and penalties up to €35M or 7% of global turnover. The enforcement risk Article 50 carries is highest exactly where most enterprises have been least careful: AI in customer-facing workflows that could plausibly be confused with human communication. C2PA content credentials, the Adobe-led provenance standard, are the technical layer most likely to satisfy auditors once enforcement begins, and at roughly $289 a year per credential the math is not the obstacle. The obstacle is that nobody in most enterprise organisations has been told to own this yet.
The harder regulatory conversation is the one about behavioural biometrics. Several vendors I respect are pushing keystroke-pattern and mouse-movement analysis as the next layer beyond audiovisual detection, and the underlying signal is real. The exposure is also real. Illinois BIPA generated 107+ class actions in 2025 and produced settlements in the eight-figure range — Clearview AI at $51.75M, Speedway at $12.1M. GDPR Article 9 treats biometric data as a special category requiring explicit consent. The way I have been advising clients is to put the consent architecture in place before the detection technology lands in HR's procurement queue, because the order in which those two things happen determines whether the company is buying a control or a liability.
What I tell CFOs when they ask where to start

The question I get most often from CFOs — not CISOs, CFOs — is "what would have stopped Arup?" The honest answer is not the answer they want, because it costs nothing and it is not a vendor purchase. It is a written, rehearsed, mandatorily-enforced out-of-band verification policy for any financial instruction above a defined threshold, with a pre-registered callback roster taped above the workstation, treated with the same operational seriousness as the fire drill. Detection technology is what raises confidence on the cases that survive the policy; the policy is what stops the case. The work we do at Veriprajna around enterprise deepfake defense — integrated architecture across video, audio, behavioural and device-attestation layers; vendor-neutral evaluation against the specific stack; custom detection pipelines for environments where 50–65% real-world accuracy is not acceptable; sanctioned red-team exercises against the organisation's own workflows — is the work that surrounds and reinforces that policy. It does not replace it. The architecture sits on the solution page for anyone who wants the controls catalog version.
What I am still thinking about is the empty hook above the wire workstation. The team that took the roster down did not do anything wrong by their own logic. They had a new tool, the auditors were happy, the policy had friction, the friction went away. If I am honest, the failure mode I am most worried about for 2026 is not the deepfake. It is the quiet, well-intentioned removal of the cheap controls in favour of the expensive ones, and the assumption that the expensive ones cover the same ground. They do not. If you are running treasury, M&A or counterparty onboarding inside a serious organisation this year, I would genuinely like to know whether the roster is still on the wall.