Deepfakes: the dark side of generative AI
When the first deepfakes appeared in 2018, many saw them as an internet curiosity: videos where one person’s face was swapped for another’s with unsettling naturalness. What started as a technical experiment became, in a short time, a sign of where generative artificial intelligence was heading. Today that same technology can imitate a voice, recreate a face, or write a message that seems written by someone you trust.
For a Mexican small business, the question isn’t whether this sounds scary, but what to do about it without slowing down daily operations. The good news is that most of the risks aren’t solved with fear, but with clear processes and decisions made with reliable information. At Normandia Web we see it this way: generative AI is a powerful tool, and like any powerful tool, it’s worth knowing how it’s used against you in order to shield what matters.
What a deepfake is and why it concerns you
A deepfake is synthetic content—video, audio, or image—created by AI to pass something false off as real. You don’t need to be a public figure to be a target: it’s enough for someone to want to impersonate your CEO on a call, imitate a supplier’s voice to divert a payment, or forge an ID in a customer onboarding process.
The underlying problem is trust. For years we assumed that seeing or hearing someone was sufficient proof that it was that person. Deepfakes break that assumption, and the companies that depend on remote procedures, transfers, or identity validation are the most exposed.
Where it hits a company
The most common scenarios in the context of a small business are concrete and everyday:
- CEO fraud: a voice or video message pretending to be an executive requesting an urgent transfer or sensitive data.
- Supplier impersonation: emails or audio that imitate a real contact to change a bank account for payment.
- Fake identities at onboarding: altered documents or selfies to get past customer or employee registration filters.
- Reputation: false content circulating on social media attributed to your brand or your staff.
The defense isn’t technological, it’s about processes
It’s tempting to think the answer is buying a magic deepfake detector. In practice, what best protects a small business is redesigning its processes so no important decision depends on a single channel or a single proof of identity.
The best defense against a fake identity isn’t a better detector, it’s a better verification question.
This means establishing a second confirmation for sensitive actions—a transfer, a change of bank details, the creation of a user—through a different, previously agreed channel. Custom software helps here because it lets you integrate those verifications into your flows, keep your history, and leave a trace of who authorized what, without relying on anyone’s good memory.
How to start protecting yourself
You don’t need to transform your entire company at once. The advisable thing is to start with what’s concrete and verifiable:
- Identify your critical processes. What action, if carried out by an impostor, would cost you money or customers? Start there.
- Define a double-confirmation rule. For payments and changes to sensitive data, require verification through an alternate channel agreed on in advance.
- Train your team. Most frauds enter through a rushed person. An honest conversation about these risks is worth more than any filter.
- Leave a trace of everything. Record authorizations and changes in a system of your own; when something looks off, the history is your best ally.
- Automate with judgment. Integrate the validations into your software so security doesn’t depend on remembering to do it, but on the system asking for it on its own.
Deepfakes are part of the landscape and they’re not going away. But a company with clear processes and a system that verifies what’s important doesn’t work in fear: it validates identity before moving a single peso. At Normandia Web we can sit down with you to review where you’re most exposed and design those verifications inside your own software, starting with the process it would hurt the most to lose. Let’s talk and take that first step.
Ready to put it to work in your company?
Tell us what’s costing you time, money or control. We’ll help you figure out where to start.
Start your consultation →