
The single line item buried in most enterprise deepfake-detection RFPs is "ISO/IEC 30107-3 conformance." The attack that took $25.6 million out of Arup in February 2024 was an injection attack, which 30107-3 does not test for. CEN/TS 18099, the first standard that does, was published in 2024 and is still almost entirely absent from procurement language. We build deepfake defense at Veriprajna because the gap between what enterprises are buying and what is actually compromising them is wide enough to drive a wire-transfer queue through.
The Arup story is by now familiar in cybersecurity briefings, but the technical mechanic is usually softened in retelling. A Hong Kong-based finance employee joined a Zoom call with the CFO and several senior executives, received a sequence of urgent transaction instructions, and authorised 15 wire transfers totaling $25.6 million across five accounts. Every face on the call except the employee's was a real-time synthetic. No malware was deployed. No credentials were stolen. No network was breached. The compromise was a feed of GAN-generated frames pushed into the Zoom data stream through virtual-camera software — most likely an OBS VirtualCam build, with training data scraped from public conference videos and LinkedIn for under $50.
That distinction — virtual-camera feed versus held-up screen in front of a real camera — is the line most enterprise procurement does not yet draw. Presentation attack detection (the ISO/IEC 30107-3 family) looks for the artefacts of a screen, a printed photo, or a mask being shown to a webcam. Injection attack detection, the CEN/TS 18099 family, looks for synthetic frames being injected into the conferencing client's video pipeline regardless of what hardware is connected. The first set of controls catches an attack you can see; the second catches an attack you cannot. Sensity AI's research, which catalogued a 255% rise in injection attacks during 2023 and a 704% rise in face-swap attacks, was the early warning. Two years later, most "deepfake detection" line items in vendor RFPs still spell 30107-3 and stop there.
The Arup breach was not a technology failure. It was a process failure exploited by convincing technology.
We say this on the enterprise deepfake detection solution page and we mean it operationally. The single highest-ROI control against video-call wire fraud is not a detection vendor. It is a pre-registered out-of-band callback policy that requires any financial instruction above a defined threshold to be confirmed through a separate channel — a known phone number, an encrypted message line, a counterparty whose number was written down before today's call started. This costs nothing. It catches every variant of synthetic-media fraud because it does not depend on the call itself. The reason it is missing from most treasury workflows is not that CFOs disagree with it; it is that the operational discipline of pausing a wire transfer to call back has been eroded by a decade of "speed of business" cultural pressure, and reinstating it requires executive air cover that most CISOs are still trying to negotiate.
The detection accuracy data nobody quotes in the pitch deck

Vendors selling deepfake detection cite lab benchmarks in the 96–99% accuracy range. Purdue University's 2025 production benchmark, replicated in Brightside AI's independent analysis, put real-world accuracy at 50–65% across leading commercial tools when tested against current-generation deepfakes outside controlled conditions. That delta is the gap between a slide deck and a wire-transfer authorisation.
A 60% probabilistic flag on a $25 million transaction is not a control. It is a coin flip.
The accuracy degradation is structural. Detection models are trained on yesterday's deepfakes; generative models advance on a cycle measured in weeks, and the adversarial arms race means a detection model deployed in January is operating on a different sample distribution by April. The vendors that are honest about this — Reality Defender's product team has discussed it publicly, and GetReal Security, which raised $17.5M in Series A from Forgepoint, Cisco Investments and Capital One Ventures, has built their roadmap around continuous retraining — treat detection as an input to a decision, not the decision itself.
This is why we structure deepfake defense in three layers, only one of which the buyer's procurement team usually budgets for. The first layer is process: a pre-registered callback roster, a dual-authorisation gate above a dollar threshold, and a written policy that pauses a wire transfer until the out-of-band channel confirms it. That layer is what carries certainty against the attack, because it does not depend on detecting anything. On top of that sit the detection technologies — multimodal video and audio analysis, device attestation, biometric liveness — which raise confidence on borderline cases and shorten the gap between a suspicious signal and an analyst's eyes. Around both runs the forensic and red-team work: sanctioned synthetic-media exercises against the organisation's own workflows, producing the empirical evidence procurement and internal audit need to know the first two layers are calibrated. Skip the process layer and the other two are decoration.
The vendor landscape, read for what each one actually covers

The deepfake detection market has grown from $170M in 2024 toward a projected $1.55B by 2034 (Astute Analytica), and roughly 20 vendors now compete for enterprise budget. The honest summary of the landscape is that no single vendor covers all the relevant attack surfaces, and the right architecture is almost always a combination — chosen against the specific gap each enterprise is trying to close.
Reality Defender's Zoom Marketplace integration is the most-cited real-time meeting option and analyses video, audio and image streams server-side; the latency tradeoff and incomplete injection-attack coverage are the constraints procurement should ask about before signing. For telephony-heavy environments the strongest pure-audio option remains Pindrop, with $100M+ in ARR, a Zoom Contact Center integration arriving March 2026, and the most-cited industry benchmark — a documented 1,300% year-over-year fraud surge in their Voice Intelligence Report. iProov holds NIST presentation-attack certification and is the right answer at identity onboarding and login, though it was not designed for continuous in-meeting authentication; selling it as such mismatches the vendor to the workflow. At the device-attestation layer, Beyond Identity's RealityCheck Zoom plugin confirms the webcam stream is coming from physical hardware — which breaks an OBS VirtualCam injection at the source but does not inspect the content of the stream. The newest entrant, GetReal Security, is closest in design intent to the integrated approach our clients ask for, with the caveat that a $17.5M Series A and a limited at-scale track record argue for piloting before depending on it.
The vendors enterprise procurement should be slowest to over-budget against are the Big Four and the large systems integrators. Their deepfake engagements run $500K to $5M+ for governance documents, framework recommendations, and policy decks; almost none of them build or integrate detection tooling. They are useful for board reporting and external attestation. They are not where the technical defense gets built.
Adaptive Security sits in a category of its own — it is not a detection tool but a simulated-attack training platform, and the most-honest use of its $146.5M in cumulative funding is to assume employees will fail the simulations the first time. That is the point of running them. Once an attacker chooses a target, what those simulation results look like in production is the 1,300% year-over-year surge Pindrop has been documenting.
Insurance no longer cleans up after the failure

Until January 2026, deepfake fraud sat ambiguously inside cyber-insurance policies — sometimes paid out under social-engineering coverage, sometimes contested. As of this year, the major carriers have closed the ambiguity in the opposite direction. Standard cyber policy forms now carry "AI-generated intermediary" exclusions; D&O, E&O and EPL forms are adding broad AI exclusions of their own. Standalone deepfake endorsements have appeared at the $500–$3,000 annual premium range for small businesses, with named-peril language that is materially narrower than what a CISO will recognize as needed coverage. Coalition's December 2025 reputational-harm endorsement is the most generous of the early products and still leaves substantial gap.
The implication for enterprise risk is concrete. A $680K average enterprise deepfake loss — the reference number we publish on the page — was uncomfortable. The same loss against a policy that now explicitly does not cover the loss type is a board-level uninsured exposure, and the SEC cybersecurity disclosure rule that took effect in December 2023 requires material incidents — which a multi-million-dollar deepfake fraud usually is — to be reported on Form 8-K within four business days. The control gap and the disclosure gap arrived in the same fiscal year.
What the regulators are about to tell you to have already done

The EU AI Act's Article 50 transparency obligations for AI-generated content take effect August 2, 2026, with the Code of Practice expected to land in May or June. Penalties run up to €35M or 7% of global turnover. Most of the AI-Act compliance attention in enterprise programs has focused on high-risk system classification under Article 6; Article 50 has been comparatively under-attended, and it carries enforcement risk for any organisation deploying AI in customer-facing workflows that could be confused with human communication. C2PA content credentials — the Adobe-led provenance standard, with certificate costs running roughly $289 a year — provide the technical layer most likely to satisfy auditors once enforcement begins.
Behavioural biometrics, which several vendors push as the next layer beyond audiovisual detection, sit in a different regulatory minefield. Illinois BIPA generated 107+ class actions in 2025 and produced settlements in the eight-figure range (Clearview AI at $51.75M, Speedway at $12.1M). GDPR Article 9 treats biometric data as a special category requiring explicit consent. Deploying keystroke or mouse-pattern analysis across an enterprise workforce without the consent architecture is a different kind of breach — one the legal team will catch later if security does not catch it first.
The CISO who internalises this is no longer making a single procurement decision. They are making a layered architecture choice where each technical control is calibrated against an attack vector, a regulatory regime, and an insurance exclusion, all moving in the same direction at the same time.
What we build, and the part we hope buyers do without us

Our work at Veriprajna on enterprise deepfake defense is shaped around the gaps the vendor market doesn't fill: integrated architecture across video, audio, behavioural and device-attestation signals; vendor-neutral evaluation against the specific stack and threat model of the client (we resell nothing); out-of-band workflow design for treasury, M&A and counterparty-onboarding flows; custom detection pipelines for high-security environments where the 50–65% real-world accuracy of off-the-shelf tools is not acceptable; and sanctioned red-team exercises that produce the empirical evidence procurement, internal audit, and the board actually use to fund the next year's program. The full architecture and controls catalog live on the enterprise deepfake detection page.
The intervention we most often urge clients to make before they call us is the one that costs nothing: print the callback roster, tape it above the wire-transfer workstation, write the dollar threshold for mandatory out-of-band verification into policy, and rehearse it the same way the fire drill gets rehearsed. We have watched enterprise programs spend six figures on detection tooling and skip the policy change that costs nothing, and the post-incident review is always the same conversation. If your organisation is building toward a deepfake defense posture this year, we would like to compare notes on which combination of controls is holding up in production against current attacks. The vendor-neutral evidence base is still thin, and the buyer side will accelerate fastest when CISOs share what is and isn't working.