Agentic AI
A $25M deepfake loss is an authorisation failure wearing a detection costume
The Arup case keeps being cited as evidence that synthetic media detection matters. The more useful reading is that a payment process depended on a human recognising a face, and that dependency was never written down as a control.
The deepfake fraud against engineering firm Arup, reported at $25 million, is usually filed under synthetic media. That framing points remediation in an expensive and largely ineffective direction.
Detection is the wrong layer
Deepfake detection is an arms race in which the defender has to win continuously and the attacker has to win once. Generation quality improves faster than detection, detection degrades under compression and re-encoding, and the deployment surface — every video call every employee takes — is impractically large.
More to the point: a detector that works perfectly still leaves the underlying weakness untouched. The weakness is that a payment of that size could be authorised on the strength of a synchronous conversation.
If a control can be defeated by convincing one person in real time, the control is that person, and nobody wrote it down as one.
The implicit control nobody documented
Every organisation has payment controls on paper: thresholds, dual authorisation, segregation of duties. Those controls are routinely satisfied by a video call, because face-to-face confirmation has been treated as strong evidence of identity for the entire history of commerce. Nobody wrote down that assumption, because until recently it was not an assumption. It was just true.
That is what changed. A whole class of process control silently depended on the infeasibility of real-time impersonation, and that infeasibility expired without any document being updated.
Controls that do not depend on recognition
The remediation is boring and it works. Authorisation for high-value movements must require an out-of-band factor bound to something other than appearance or voice: a callback to a number from the directory rather than one supplied in the conversation, a signed approval in a system of record, a second approver with an independent channel and a mandatory delay.
Note the shape of that fix. It removes synchronous social pressure from the critical path. Almost every large-scale authorisation fraud, with or without synthetic media, depends on urgency compressing the time available to verify. Detection does nothing about urgency. A mandatory delay does.
The audit question worth asking
There is a generalisable exercise here, and it extends well past payments. Walk your control catalogue and, for each control, ask what capability an attacker would need for it to fail. Where the answer is a human recognising a person, recognising a voice, or judging that a message sounds right, you have found a control whose strength was set by a technological constraint that no longer holds.
Those controls did not weaken because anyone made a mistake. They weakened because the world moved underneath them, quietly, and the documentation never said what they were standing on.
Sources
Written by the Devence Lab research team.