Deepfakes Are Not Just Fake Videos. They Are a Crisis of Trust.

At the Billington CyberSecurity Summit, the question was no longer whether synthetic media can be stopped. It was whether society can learn to recognize, absorb and respond to deception before it causes real-world harm.

By Ashley Greer

AI TRANSPARENCY: This article was developed from the author’s original reporting and notes from the 2026 Billington CyberSecurity Summit. AI was used to assist with organization, drafting and editing. The reporting, observations and editorial judgment are the author’s.

WASHINGTON D.C. — For years, the public conversation around deepfakes has centered on video: a politician appearing to say something he never said, a celebrity's face placed onto another person's body, or a fabricated clip spreading across social media.

But that may already be an outdated way of thinking about the threat.

At the 17th Annual Billington CyberSecurity Summit in Washington on Tuesday, I attended a breakout session titled Deepfakes and Digital Deception: Protecting Federal Agencies in the Age of Synthetic Media. The discussion was part of a much larger conference organized around the theme “Reducing Risk in an Age of AI-Enabled Threats.” Billington expects more than 3,000 attendees, 250 speakers and more than 50 sessions during the three-day gathering.

What emerged from the deepfake discussion was something more complicated than a technological problem.

We are entering an era in which seeing — and increasingly hearing — is no longer necessarily believing.

And the most important defense may not be another piece of software.

It may be a more resilient society.

The Voice on the Phone

One point from the discussion stayed with me: the voice call is less understood and less addressed than visual deepfakes.

That deserves considerably more attention.

Synthetic audio can be extraordinarily persuasive because telephone conversations occupy a peculiar position in our psychology. We routinely act on voices without seeing the person speaking. A familiar voice creates its own form of authentication.

That assumption is becoming dangerous.

Voice cloning introduces obvious possibilities for fraud and extortion, but the national-security implications extend further. Imagine a convincing call apparently coming from a superior, government official, family member or trusted colleague. The objective does not necessarily have to be stealing money. It could be extracting information, inducing someone to take an action, or simply creating confusion at exactly the right moment.

Deepfakes therefore intersect with something cybersecurity professionals have worried about for decades: social engineering.

The technology is new. The vulnerability is ancient.

We trust other people.

The Mouse Has Become the Cat

Another line from my notes captured the change particularly well:

“Playing cat and mouse, right now we are the mouse. We need to be the cat.”

For years, cybersecurity has largely operated reactively. Someone discovers an attack. Defenders identify it. Organizations develop a mitigation. Attackers change tactics.

Artificial intelligence accelerates that cycle.

The challenge is no longer merely identifying individual pieces of false content. AI allows adversaries to produce deception faster, cheaper and at greater scale. Defenders therefore have to become faster as well.

That means using AI to counter AI.

But technology alone will not solve the problem. Federal agencies are enormous organizations, and changing institutional behavior can be considerably slower than changing software. Awareness programs have to evolve along with detection systems. Employees need to understand not simply that phishing exists, but that the person calling them may sound exactly like their boss.

And the problem does not stop at government employees.

One of the strongest points of the session was that awareness must extend beyond schools and workplaces to people of all ages.

Civilians are part of the attack surface now.

When a Deepfake Becomes a Weapon

There is another reason to stop thinking of deepfakes merely as embarrassing fake videos.

Consider an evacuation during a military conflict.

A fabricated message could instruct civilians to follow a particular evacuation route. If that route led people toward danger — or even through a minefield — synthetic media would cease to be merely an information problem.

It would become part of the weapon.

That raises difficult questions involving freedom of expression, civilian protection and international humanitarian law. Democratic governments cannot simply eliminate synthetic speech or broadly suppress content because it might be deceptive. The defense against manipulation cannot itself destroy the freedoms it is intended to protect.

The objective, then, is not necessarily a world without deepfakes.

It is a world capable of responding to them quickly enough that deception does not become catastrophe.

That is a very different cybersecurity objective.

It is harm reduction.

The Problem of Too Much Information

Deepfakes also connect to another problem I have repeatedly encountered while reporting on national security and artificial intelligence: the sheer volume of information.

The challenge is increasingly not scarcity.

It is saturation.

Bad actors do not necessarily need to persuade everyone that a false story is true. Sometimes flooding an information environment is sufficient. Contradictory narratives, fabricated images, synthetic audio and authentic information can become almost indistinguishable in the torrent.

Eventually the citizen stops asking, “Which one is real?”

They begin asking, “Can I know what is real at all?”

That may be the more dangerous outcome.

A successful deepfake does not merely make someone believe something false. At scale, synthetic media can make people distrust something true.

That distinction transforms the problem from misinformation into something closer to an attack on the infrastructure of trust.

The Human on the Screen

One sentence in my notebook is underlined:

Need to see the human on screen.

There is something revealing about that instinct.

As synthetic media becomes better, societies will increasingly look for signals of human authenticity. Sometimes those signals will be technological: provenance systems, authentication, digital credentials or other methods of establishing where information originated.

But sometimes they will be social.

Who delivered the message?

Where did it come from?

Can it be independently verified?

Does the institution communicating it have an established channel?

The future of cybersecurity may therefore depend as much upon verification architecture as detection technology.

“Trust but verify” is beginning to acquire a very literal meaning.

Estonia and the Architecture of Trust

Estonia offers an interesting glimpse of where this could lead.

The country has spent years building a highly digitized government around secure digital identity and public trust. In June, Estonia announced plans to develop digital identities for AI agents, allowing an AI system acting for a person or organization to operate within defined limits while remaining verifiable and auditable.

That is significant because it changes the question.

Instead of endlessly asking whether something looks human, a digital system can increasingly ask whether an entity is authorized to act.

Estonia's broader 2026 cyber-resilience doctrine similarly emphasizes something other than perfect prevention. Its objective is a society capable of continuing to function under sustained attack — including defending democratic trust through transparency and public resilience.

That may ultimately be the more realistic model for deepfakes as well.

We probably cannot build a society in which synthetic deception never occurs.

We can build one in which deception has a harder time succeeding.

The New Cybersecurity Skill: Doubt

There is a danger here, however.

If the lesson people take from deepfakes is simply “believe nothing,” the adversary has already won.

A functioning society requires trust. Governments, journalists, emergency officials, businesses and ordinary people have to communicate with one another. Permanent suspicion is not resilience.

The better skill is calibrated doubt:

Trust, but verify.

Pause before acting on an unusual request.

Confirm important instructions through another channel.

Recognize that a familiar face or voice is no longer sufficient proof of identity.

And teach those habits not merely to cybersecurity professionals, but to everyone.

The technological arms race will continue. Detection will improve. Generation will improve. Authentication will improve. Attackers will adapt again.

But underneath that contest sits a much older human problem.

People generally want to help one another. We respond to authority. We recognize familiar voices. We react quickly when someone we care about appears to be in danger.

Those are not bugs in human psychology. They are characteristics that allow societies to function.

They are also vulnerabilities that machines can now imitate.

The challenge of the synthetic-media age is therefore not teaching people to stop trusting one another.

It is teaching us how to keep trusting in a world where trust itself can be manufactured.

Previous
Previous

CIA Deputy Director Michael Ellis: AI Is Changing the Speed of Intelligence

Next
Next

America Should Stay in the Room. France International Space Summit