clic para entrar
← back to blog
Artificial intelligence

Deepfake detection: the arms race

Deepfake detection: the arms race

In 2020, major platforms and research labs launched open challenges to see who could build the best deepfake detector: videos and audio generated with artificial intelligence that put words in the mouths of people who never said them. The result left a clear lesson. Detecting fake content is possible, but it’s a constant race: every time a detector improves, the generators do too, and vice versa. No one wins definitively.

For a Mexican small business this isn’t science fiction or a problem exclusive to celebrities and politicians. Today anyone can clone your director’s voice to request an urgent transfer, fabricate a video that damages your reputation, or impersonate a customer on a video call. The good news is that you don’t need to win the technological race: you need clear, simple processes that keep a deception from succeeding even if the fake content is convincing.

What a deepfake is and why it matters to you

A deepfake is synthetic content (image, video, or audio) created by AI to imitate a real person. What once required a studio and weeks of work is now achieved with accessible tools and a few seconds of reference: an Instagram story, a WhatsApp audio, a YouTube interview.

The risk to your business is rarely “a viral video.” It’s usually something much more direct and quiet:

  • CEO fraud: a call or audio imitating an owner or manager requesting an urgent payment “outside the normal process.”
  • Supplier impersonation: emails or messages that seem to come from a trusted supplier changing, for example, a bank account.
  • Reputational damage: false content circulating on social media attributing to your brand statements or events that never happened.
  • Social engineering against your team: a supposed colleague or customer who, on video, convinces someone to share access or sensitive information.

It’s not about detecting every forgery, but about building processes where a forgery, on its own, isn’t enough to cause harm.

Illustration of a digital face divided between the real and the AI-generated
Deepfake detection is a constant race: every advance on one side pushes the other.

Detection helps, but it isn’t a silver bullet

There are tools that analyze technical clues (unnatural blinking, artifacts at the edges, audio inconsistencies) to estimate whether content was generated by AI. They work, and they improve every year. But as the 2020 challenges showed, no detector gets it right 100% of the time, and the generators learn quickly to hide those clues.

That’s why the most solid defense for a company isn’t purely technological: it’s organizational. Technology detects; processes decide. When every sensitive operation depends on a single channel (a call, an audio, an email), a good deception can slip through. When it depends on several verification steps, the deepfake is left powerless.

How to protect your brand and your operation

The best investment isn’t buying the most expensive detector, but organizing your processes so that verification is a natural part of the work:

  • Double confirmation for money: any payment, account change, or urgent transfer is confirmed through a second channel agreed on in advance (a call to an already-known number, never the one that arrives in the message).
  • Internal code words: a simple code between partners or departments to validate “urgent” requests from the boss. Cheap and surprisingly effective.
  • Brief team training: everyone should know that voice and video can now be faked. Half an hour of awareness prevents most frauds.
  • Monitor your brand: periodically review what’s being published about your company so you can react quickly if fake content appears.
  • Protect your public material with judgment: understand that photos, voice, and videos of your spokespeople are raw material for a deepfake, without stopping communicating.

Start shielding your brand

You don’t have to solve it all today. Start with what protects you most for the least effort:

  • This week: define a written double-confirmation rule for any movement of money and share it with your team. It’s your biggest shield and costs nothing.
  • This month: give a short talk to the team about deepfakes and voice fraud, and agree on a code word to validate urgent requests.
  • When the need grows: integrate verification into your systems (for example, into the software you already operate with), so the confirmation steps stay within the flow and don’t depend on a person’s memory.

These verifications work best when they live inside your tools and not on a sheet of rules no one reads. At Normandia Web we build custom software that adapts to how your company works, and we can help you get double confirmation and code words embedded within the flow, without slowing your operation. Let’s talk it through: the technological race will continue, but your business doesn’t have to run it alone.

Ready to put it to work in your company?

Tell us what’s costing you time, money or control. We’ll help you figure out where to start.

Start your consultation →