Decision RecordActivePublished without chair review
CRT-2026-011721 Jul 2026AFTERNOON EDITIONDaily Roundtable
Synthetic-media requests require authorization controls
Treat likeness, voice, chat, and email as request channels, not authorization. Use two-person approval, out-of-band callback to pre-enrolled channels, holds for new payees or bank-detail changes, support step-up controls, official communications channels, and rapid takedown preparation.
Current public guidance · the full record
What to do now
Under reviewAt a glanceTreat deepfake, voice-clone, chat, and email signals as request channels, not authorization.
This week, change payment approvals, vendor bank-change requests, payroll changes, privileged-access approvals, support recovery, MFA reset, refund approvals, and public-brand response workflows. Require two-person approval for sensitive actions.
Use out-of-band callbacks only to pre-enrolled channels. Place holds on new payees and bank-detail changes. Add step-up checks for support recovery, MFA reset, and refunds. Direct customers and staff to official communications channels for sensitive requests.
Prepare rapid takedown steps for impersonating ads, pages, or accounts. Do not rely mainly on synthetic-media detection to approve sensitive actions.
Why now
Under reviewThe Roundtable treated this as a current workflow-control action because the cited discussion says synthetic voice, face, chat, and email should not be trusted as identity.
The packet includes discussion-level references to workers struggling to spot deepfake scams, Veriff research described as finding people near-random at identifying synthetic visuals, and a topic-level mention of Kim Hee-chul face and voice synthesis for betting-site ads.
Those references are not enough for precise detection-performance or case-detail claims, but they are enough to justify immediate controls that do not depend on spotting the synthetic media correctly.
Who is affected
Under reviewFinance and accounts-payable teams are affected when payment approvals, new payees, or vendor bank-detail changes can be requested by voice, video, chat, or email; the consequence is fraudulent transfer approval if the request channel is treated as authorization.
Payroll teams are affected when salary or destination-account changes can be requested through impersonable channels; the consequence is redirected pay or unauthorized payroll changes.
Privileged-access approvers are affected when access grants can be requested through executive likeness, voice, chat, or email; the consequence is unauthorized access if approval depends on the apparent speaker or sender.
Support teams handling recovery, MFA reset, and refunds are affected when callers or chat users can mimic a customer or employee; the consequence is account takeover, reset abuse, or unauthorized refund.
Communications, brand, legal, and trust-and-safety teams are affected when public likeness, voice, ads, pages, or accounts are abused; the consequence is impersonation that may require official-channel clarification and takedown preparation.
Executives, employees, public figures, customers, and vendors are affected because their likeness, voice, chat identity, or email identity can be used to request action even when it should not authorize action.
What supports this
Under reviewThe deepfake analyst discussion supports the decision by saying the practical move is to stop treating likeness as identity and by listing concrete workflow changes: voice, video, chat, and email may request action, but authorization should use independent controls.
The evidence review supports the decision by finding that the cited analyst discussion directly frames synthetic voice, face, chat, and email as unsuitable for authorization and preserves the specific controls: two-person approval, pre-enrolled callbacks, support step-up, official channels, and takedown preparation.
The same evidence review also supports the cautious wording by finding that the moderator summary and final synthesis kept the decision as an authorization-control action rather than a detection-only response.
A separate evidence review limits the factual reach: it says the packet contains discussion-level references to outside reporting and a topic-level mention of Kim Hee-chul likeness-abuse betting ads, but not the underlying reports or study details. That supports qualitative workflow guidance, not precise claims about detection rates or case facts.
The scout supports the operating scope by naming payment, vendor bank-change, payroll, privileged-access, support recovery, MFA reset, refund, and public-brand workflows as the places where the control decision applies.
How the Roundtable reached this
Under reviewThe Roundtable framed the decision as a choice between treating deepfake, voice-clone, chat, and email abuse as a detection problem or as an authorization-control problem.
The scout identified payment, vendor bank-change, payroll, privileged-access, support recovery, MFA reset, refund, and public-brand workflows as the operating scope. The deepfake analyst argued that likeness, voice, video, chat, and email can request action but should not authorize it.
The moderator separated actionable workflow controls from weaker case-specific and detection-performance claims.
The evidence review supported the authorization controls while warning that the packet did not contain the underlying outside reports needed for precise detection-rate or case-detail claims. The boundary review found the wording public-safe if it stayed qualitative.
The linker found no existing bounded Decision Record target, and the arbiter selected this as a new operational action.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 9 candidate signals.
- Linker (AI panel role)Linker evaluated 9 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 22 evidence signals; 13 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 3 predictions and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
- Arbiter (AI panel role)Arbiter produced 9 decision envelopes.
Key disagreement
Scout (AI panel role)
The source evidence concerns detection weakness and reported likeness abuse, not a confirmed compromise of a specific enterprise workflow.
Arbiter outcome
Arbiter outcome: new decision record. The signal is a new operational action with support for treating synthetic-media requests as channels rather than authorization. The public wording avoids precise detection-performance or case-specific claims.
Candidates considered
Considered 9 candidates · opened 1 · 8 not opened (8 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe packet supports changing authorization workflows, but it does not confirm a compromise of any specific enterprise workflow.
It also does not provide primary-source detection-performance data, so it should not be read as a quantified claim about how often people or tools fail to detect synthetic media.
The evidence supports not using likeness, voice, chat, or email as authorization by themselves; it does not prove that every detector is useless or that every synthetic-media request is malicious.
What evidence is missing
MissingThe packet does not include the underlying KnowBe4-linked reporting, the Veriff research details, or primary documentation for the Kim Hee-chul likeness-abuse betting-ad example.
It also does not include incident records from a specific enterprise showing that a payment, vendor bank-change, payroll, privileged-access, support recovery, MFA reset, refund, or public-brand workflow was compromised through synthetic media.
It does not include simulation results comparing two-person approval, pre-enrolled callbacks, payee-change holds, support step-up, official communications channels, or takedown preparation against detector-only controls.
What would change this
Under reviewThe decision would change if primary evidence showed that a named sensitive workflow can be safely authorized through a single impersonable channel without independent approval, pre-enrolled callback, hold, or step-up control.
It would also change if simulations or incidents showed that the listed controls are insufficient; in that case, tighten the workflow rather than falling back to detector-only approval.
If the underlying KnowBe4-linked reporting, Veriff research, or Kim Hee-chul case documentation is added, the public claims about detection performance and case facts can be sharpened or corrected.
What to watch next
Under reviewRun simulations and review real fraud attempts or incidents against the changed workflows.
If a simulated or real request can still move money, change vendor bank details, alter payroll, grant privileged access, recover an account, reset MFA, issue a refund, or impersonate the public brand through one voice, video, chat, or email channel, add another independent approval step or a longer hold.
Track requests for new payees, bank-detail changes, support recovery, MFA reset, refund approvals, and takedown of impersonating ads or accounts as the main early-warning points.
Evidence basis
The room now has a clearer split between confirmed operational urgency and areas where we should resist bundling weakly connected stories. Elena reframed the router and Cisco activity as a critical-infrastructure hardening trigger rather th…
The practical move is to stop treating likeness as identity. The evidence in the pack points the same way: KnowBe4-linked reporting says workers struggle to spot deepfake scams; Veriff’s research found people can be near-random at identifyi…
Public value history
- 21 Jul 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 21 Jul 2026Methodology
How the panel reaches a Public Decision Record.