Decision RecordActivePublished without chair review

Synthetic-media requests require authorization controls

Deepfake and voice-clone authorization controls

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 0/9 backed · 2 gaps · panel
Severity
Medium
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated 28 days ago
Last revised 2026-07-21
Active4 evidence references · Published 21 Jul 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Treat likeness, voice, chat, and email as request channels, not authorization. Use two-person approval, out-of-band callback to pre-enrolled channels, holds for new payees or bank-detail changes, support step-up controls, official communications channels, and rapid takedown preparation.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

Under reviewAt a glance

Treat deepfake, voice-clone, chat, and email signals as request channels, not authorization.

This week, change payment approvals, vendor bank-change requests, payroll changes, privileged-access approvals, support recovery, MFA reset, refund approvals, and public-brand response workflows. Require two-person approval for sensitive actions.

Use out-of-band callbacks only to pre-enrolled channels. Place holds on new payees and bank-detail changes. Add step-up checks for support recovery, MFA reset, and refunds. Direct customers and staff to official communications channels for sensitive requests.

Prepare rapid takedown steps for impersonating ads, pages, or accounts. Do not rely mainly on synthetic-media detection to approve sensitive actions.

02

Why now

Under review

The Roundtable treated this as a current workflow-control action because the cited discussion says synthetic voice, face, chat, and email should not be trusted as identity.

The packet includes discussion-level references to workers struggling to spot deepfake scams, Veriff research described as finding people near-random at identifying synthetic visuals, and a topic-level mention of Kim Hee-chul face and voice synthesis for betting-site ads.

Those references are not enough for precise detection-performance or case-detail claims, but they are enough to justify immediate controls that do not depend on spotting the synthetic media correctly.

03

Who is affected

Under review

Finance and accounts-payable teams are affected when payment approvals, new payees, or vendor bank-detail changes can be requested by voice, video, chat, or email; the consequence is fraudulent transfer approval if the request channel is treated as authorization.

Payroll teams are affected when salary or destination-account changes can be requested through impersonable channels; the consequence is redirected pay or unauthorized payroll changes.

Privileged-access approvers are affected when access grants can be requested through executive likeness, voice, chat, or email; the consequence is unauthorized access if approval depends on the apparent speaker or sender.

Support teams handling recovery, MFA reset, and refunds are affected when callers or chat users can mimic a customer or employee; the consequence is account takeover, reset abuse, or unauthorized refund.

Communications, brand, legal, and trust-and-safety teams are affected when public likeness, voice, ads, pages, or accounts are abused; the consequence is impersonation that may require official-channel clarification and takedown preparation.

Executives, employees, public figures, customers, and vendors are affected because their likeness, voice, chat identity, or email identity can be used to request action even when it should not authorize action.

04

What supports this

Under review

The deepfake analyst discussion supports the decision by saying the practical move is to stop treating likeness as identity and by listing concrete workflow changes: voice, video, chat, and email may request action, but authorization should use independent controls.

The evidence review supports the decision by finding that the cited analyst discussion directly frames synthetic voice, face, chat, and email as unsuitable for authorization and preserves the specific controls: two-person approval, pre-enrolled callbacks, support step-up, official channels, and takedown preparation.

The same evidence review also supports the cautious wording by finding that the moderator summary and final synthesis kept the decision as an authorization-control action rather than a detection-only response.

A separate evidence review limits the factual reach: it says the packet contains discussion-level references to outside reporting and a topic-level mention of Kim Hee-chul likeness-abuse betting ads, but not the underlying reports or study details. That supports qualitative workflow guidance, not precise claims about detection rates or case facts.

The scout supports the operating scope by naming payment, vendor bank-change, payroll, privileged-access, support recovery, MFA reset, refund, and public-brand workflows as the places where the control decision applies.

05

How the Roundtable reached this

Under review

The Roundtable framed the decision as a choice between treating deepfake, voice-clone, chat, and email abuse as a detection problem or as an authorization-control problem.

The scout identified payment, vendor bank-change, payroll, privileged-access, support recovery, MFA reset, refund, and public-brand workflows as the operating scope. The deepfake analyst argued that likeness, voice, video, chat, and email can request action but should not authorize it.

The moderator separated actionable workflow controls from weaker case-specific and detection-performance claims.

The evidence review supported the authorization controls while warning that the packet did not contain the underlying outside reports needed for precise detection-rate or case-detail claims. The boundary review found the wording public-safe if it stayed qualitative.

The linker found no existing bounded Decision Record target, and the arbiter selected this as a new operational action.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 9 candidate signals.
  • Linker (AI panel role)Linker evaluated 9 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 22 evidence signals; 13 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 3 predictions and rejected 2 claims.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 9 decision envelopes.

Key disagreement

Scout (AI panel role)

The source evidence concerns detection weakness and reported likeness abuse, not a confirmed compromise of a specific enterprise workflow.

Arbiter outcome

Arbiter outcome: new decision record. The signal is a new operational action with support for treating synthetic-media requests as channels rather than authorization. The public wording avoids precise detection-performance or case-specific claims.

Candidates considered

Considered 9 candidates · opened 1 · 8 not opened (8 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Missing

The packet supports changing authorization workflows, but it does not confirm a compromise of any specific enterprise workflow.

It also does not provide primary-source detection-performance data, so it should not be read as a quantified claim about how often people or tools fail to detect synthetic media.

The evidence supports not using likeness, voice, chat, or email as authorization by themselves; it does not prove that every detector is useless or that every synthetic-media request is malicious.

07

What evidence is missing

Missing

The packet does not include the underlying KnowBe4-linked reporting, the Veriff research details, or primary documentation for the Kim Hee-chul likeness-abuse betting-ad example.

It also does not include incident records from a specific enterprise showing that a payment, vendor bank-change, payroll, privileged-access, support recovery, MFA reset, refund, or public-brand workflow was compromised through synthetic media.

It does not include simulation results comparing two-person approval, pre-enrolled callbacks, payee-change holds, support step-up, official communications channels, or takedown preparation against detector-only controls.

08

What would change this

Under review

The decision would change if primary evidence showed that a named sensitive workflow can be safely authorized through a single impersonable channel without independent approval, pre-enrolled callback, hold, or step-up control.

It would also change if simulations or incidents showed that the listed controls are insufficient; in that case, tighten the workflow rather than falling back to detector-only approval.

If the underlying KnowBe4-linked reporting, Veriff research, or Kim Hee-chul case documentation is added, the public claims about detection performance and case facts can be sharpened or corrected.

09

What to watch next

Under review

Run simulations and review real fraud attempts or incidents against the changed workflows.

If a simulated or real request can still move money, change vendor bank details, alter payroll, grant privileged access, recover an account, reset MFA, issue a refund, or impersonate the public brand through one voice, video, chat, or email channel, add another independent approval step or a longer hold.

Track requests for new payees, bank-detail changes, support recovery, MFA reset, refund approvals, and takedown of impersonating ads or accounts as the main early-warning points.

Sources & context

Evidence basis

4 references
Context
The room now has a clearer split between confirmed operational urgency and areas where we should resist bundling weakly …

The room now has a clearer split between confirmed operational urgency and areas where we should resist bundling weakly connected stories. Elena reframed the router and Cisco activity as a critical-infrastructure hardening trigger rather th…

Observed 21 Jul 2026
Context
The practical move is to stop treating likeness as identity. The evidence in the pack points the same way: KnowBe4-linke…

The practical move is to stop treating likeness as identity. The evidence in the pack points the same way: KnowBe4-linked reporting says workers struggle to spot deepfake scams; Veriff’s research found people can be near-random at identifyi…

Observed 21 Jul 2026
Context
Summary: The panel assesses today’s main decision point as exposed trust infrastructure: remote-access gateways, AI exec…
Observed 21 Jul 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 21 Jul 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.