Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security

AI is finding vulnerabilities faster. Who is funding the people expected to fix them?

4 September 2026 at 12:33

Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human effort.

In many ways, that’s positive. Finding vulnerabilities is an essential part of making software more secure. But there is another side to this that deserves much more attention. Every vulnerability report has to go somewhere.

Someone needs to assess whether the issue is genuine. If it is, engineers need to understand its severity, develop a fix, test that fix and manage disclosure appropriately. AI can increase the speed at which potential problems are discovered. It does not automatically increase the number of experienced engineers available to deal with them. That imbalance could become a serious issue for open-source security.

Finding a vulnerability is only the beginning

There is an understandable tendency to treat vulnerability discovery as the success story. An AI system finds something humans missed. That makes a compelling headline. But identifying a potential weakness and resolving it are very different tasks.

A report might represent a serious vulnerability. It might be something already understood. It might be technically correct but have limited real-world security impact. It might simply be wrong. Working out which of those is true requires expertise. Then, if there is a genuine vulnerability, somebody has to fix it.

Over the past 12 months we received a little over 400 vulnerability reports. 43 resulted in a published CVE. Roughly one in ten. The other nine still had to be read, understood, reproduced where we could, and answered. A report that turns out not to be a vulnerability consumes much the same expert attention as one that is — sometimes more, because establishing that something cannot be exploited is often harder than confirming that it can.

For a commercial software company with large security teams, increasing the number of reports may be manageable. For an open-source project with limited resources, a sudden increase can create a very different problem. The technology for finding possible vulnerabilities is becoming cheaper and more accessible. However, the expertise required to investigate them is not.

Businesses depend on projects they may barely know exist

This connects to a much older problem with open-source. Most technology companies know they use open-source software. What is less clear is whether they understand exactly which projects their products and services depend upon. That distinction matters.

Open-source components can sit deep inside software stacks. They work quietly, so organisations may have little reason to think about the people maintaining them. Then something goes wrong.

Heartbleed was an important moment for OpenSSL because it exposed the gap between the importance of open-source infrastructure and the resources available to support it. The industry responded. Investment increased and organisations began paying much more attention to the sustainability of critical open-source projects.

My concern is that some of those lessons are beginning to fade, and AI could make the consequences of that particularly visible.

AI changes the economics of vulnerability discovery

There is an asymmetry developing. The cost of searching code for potential security weaknesses is falling. The volume of reports can therefore rise significantly. But the other side of the process remains stubbornly human. Experienced engineers still need to understand the code. They need to judge whether the finding matters and decide how it should be fixed without creating another problem somewhere else.

Those people are a scarce resource. This means the question organisations should be asking about AI and cybersecurity isn’t only: “What can AI find?” It should also be: “Who is going to deal with everything it finds?”

For open-source projects, that leads directly to questions about sustainable funding. If businesses depend on a project as part of their critical infrastructure, supporting the health of that project should be viewed as part of resilience, not philanthropy.

Regulation only gets us part of the way

Governments are understandably looking at how regulation can improve cyber resilience. That matters, but regulation cannot maintain software. Europe provides some interesting examples of a different approach. OpenSSL Foundation has received support from Germany’s Sovereign Tech Agency, which invests directly in open digital infrastructure.

That recognises something important: if technology is critical to the functioning of the digital economy, somebody needs to invest in the people maintaining it. I’d like to see more of that conversation in the UK. Cyber resilience isn’t only about telling organisations what standards they should meet. We also need to consider the health of the technology underneath the services we’re trying to protect.

Organisations need to know what they depend on

There is something businesses can do immediately. Understand your open-source dependencies. If a critical vulnerability appeared tomorrow in a project your organisation relies on, could you identify where that software was being used?

Would you know which products and services were affected? Would you know who maintains the project? And would you have any relationship with the community responsible for fixing it? If the answer is no that is a resilience gap.

Organisations don’t necessarily need to contribute code themselves. There are other ways to support projects, including funding, engineering resources and participation in the communities maintaining the technology they depend upon. The important shift is recognising open source as infrastructure rather than free software that simply appears.

We need to talk about the people behind the code

AI will continue getting better at analysing software. That’s exciting, and it has the potential to make technology significantly more secure. But more findings do not automatically produce more security. The benefit comes when we have the expertise and resources to act on what those tools discover. That makes this a human question as much as a technology question.

How do we sustain the communities maintaining critical open-source infrastructure? How should businesses support the projects they depend on? What happens when vulnerability discovery accelerates faster than our ability to respond?

The post AI is finding vulnerabilities faster. Who is funding the people expected to fix them? appeared first on IT Security Guru.

Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White

11 August 2026 at 12:21

Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage. 

Geoff White is an award-winning investigative journalist whose reporting has taken him inside global hacking networks, cryptocurrency thefts and modern money-laundering operations.  

A former Technology Correspondent for Channel 4 News, he has also reported for the BBC and The Sunday Times. Geoff co-created and presented the BBC World Service podcast The Lazarus Heist and has written three books on cybercrime and organised crime. Champions Speakers 

In this exclusive interview for the IT Security Guru conducted by the Cyber Security Speakers Agency, Geoff explains how cybercrime became a mature global industry, why segmentation remains critical against ransomware and how criminals are using AI in practice. He also examines why stolen data has become one of their most useful assets. 

What drove the convergence of lone hackers, organised crime gangs and state actors into today’s global cybercrime ecosystem? 

Geoff White: “Hacking has always been a thing with computers. From the earliest days, there were people who hacked, which originally didn’t necessarily mean criminal behaviour. 

“Hacking something together is an engineering term. If all you’ve got is some gaffer tape and string, you make the engine work. That was the principle behind hacking in the early days. 

“The apple in the Garden of Eden was money. As soon as websites such as eBay and Amazon started getting set up, credit cards began flooding onto the web. That’s where organised crime gangs started to become interested in the technology. 

“What’s happened since has been an evolution. You started to see organised crime gangs become interested in cyber and hacking. Governments also became interested because getting hold of secrets and manipulating other nations is very useful. 

“You also had lone hackers, what they call hacktivists, the classic kid in a hoodie in a bedroom somewhere. 

“Over time, these movements have moved together and learned from each other. Governments realised that the tactics used by bedroom hackers and activists could be used effectively to push other nations around. 

“Organised crime gangs have sometimes obtained incredibly powerful cyber tools from government hackers. 

“We’re starting to see all these different types of groups coming together. If you want to know why cyber has risen up the agenda, that’s the real explanation.” 

Ransomware now operates like a mature industry. Why do major organisations remain vulnerable, and what defence matters most once attackers get inside?

Geoff White: “The thing to realise about ransomware is that this is a very mature industry, and it is an industry. There are hundreds of people working in it. 

“It’s been through its start-up phase, seed-funding phase and venture-capital phase. It is now a fully fledged industry. 

“At the last count, I found 62 different groups on the dark web who were all carrying out ransomware attacks. They’re extremely strategic. 

“They will say: “Today, we are going to target the transport sector.” They will find companies in that sector and work out which ones are vulnerable, which are most valuable and which are juicy targets. 

“The next day, they might decide to target pharmaceuticals. They are very strategic in how they work and will target those organisations until they find a way in. 

“Unfortunately, the likelihood is that a ransomware gang will get inside your organisation. The only thing you can do to prevent the damage becoming much worse is segmentation. 

“Make sure that if attackers get into one part of your organisation, they can’t access everything. If they break into one department, they shouldn’t be able to move into other departments. 

“Segmentation, breaking things apart and introducing barriers for attackers, is your best defence.” 

How are cybercriminals using AI in practice, and is the threat currently outpacing cyber defence? 

Geoff White: “Like all industries, the cybercrime industry is looking very hard at artificial intelligence. Our working practices are gradually being revolutionised by AI, and the cybercrime space is no exception. 

“However, there’s some good news. 

“If you look at how cybercriminals are using AI in practice, rather than theoreticals, hypotheticals or unverified services being offered on the dark web, it’s the same stuff we’re using it for. 

“They’re using it to improve their emails, audit their code and conduct reconnaissance on targets they might want to hit. That’s not reinventing the wheel. 

“I would contrast that with what’s happening on the defensive side of cyber. AI has always been used in cyber defence. We used to call it machine learning. 

“The cyber-defence industry is using AI at scale and pace. I think we’re in a good place. 

“If we can double down on those AI wins in cyber defence now, we can hopefully stave off the day when cybercriminals start using AI at scale as well.” 

What makes stolen data more useful to cybercriminals and nation states than assets such as cash or cryptocurrency? 

Geoff White: “Cybercriminals have realised that the one thing organisations possess that is easy to obtain and use is data. 

“I can get hold of credit cards as a crook, but then I’ve got to wash the credit card money. I can steal Bitcoin, but then I’ve got to put the Bitcoin somewhere. 

“If I steal data, I’ve got an instant win. I can go on the dark web and sell it. If it’s customer data, I can contact people and send them phishing emails. 

“I can also contact the organisation and say: “I’ve got a bunch of your data. Pay me and I won’t leak it.” 

“There are many different ways data can be used. This isn’t limited to criminals. Nation states have become involved as well. 

“We’ve seen massive data leaks and government hackers breaking into organisations. One famous example was the Democratic Party during the 2016 US presidential election. Incredibly sensitive data was stolen and then weaponised to cause damage. 

“Data has become the new currency for cybercrime gangs in the same way it became the new currency for organisations.” 

 When audiences hear the stories behind your investigations, what do you want them to understand about cybercrime and how to confront it? 

Geoff White: “When I give talks, I’m lucky as a journalist because I have these amazing stories. 

“Regardless of how technical this becomes or how much financial crime might appear to concern spreadsheets, it’s always about people. 

“There’s always a set of characters behind it who are interesting, sometimes crazy and sometimes extremely quirky. 

“I look at the people and their motivations. Then we examine how they work and the lessons organisations need to learn to fight them. 

“I hope people leave my talks with a thumping good story and some valuable, applicable lessons that they can start putting in place to stop the bad guys winning.” 

The post Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White appeared first on IT Security Guru.

Examining the Unintended Consequences of the Online Safety Act

24 July 2026 at 07:43

The 25th July 2026 marks one year since the Online Safety Act’s landmark child safety duties came into force, making it a natural moment to assess what’s changed, what’s worked and what challenges remain. Although the Act itself received Royal Assent in October 2023, its requirements were introduced in phases, with 25th July 2025 being the date many of the most visible obligations on platforms took effect.

The child safety duties require platforms likely to be accessed by children to introduce stronger protections, including effective age assurance, child risk assessments and measures to reduce exposure to harmful content. 

One year on, has the Online Safety Act fundamentally changed the internet for UK users, or has it simply shifted the challenges elsewhere? We spoke to cybersecurity experts for a short series of reports to find out more.  

Today, we’re examining the unintended consequences of the Act… 

Professor George Loukas, Head of Centre for Sustainable Cyber Security, University of Greenwich, said: “Ofcom has moved from consultation to enforcement. Naturally, the larger adult sector platforms have been the most visible early targets, and there have been lots of discussions on whether that led to a shift to more VPN usage as well as to non-compliant adult websites. These were all predictable though.”

Uptick in VPN Usage 

For many, the enforcement date signalled a natural (if not predictable) shift towards VPN usage to get around age verification tests. The evidence backs up this hypothesis: Proton VPN’s 2025 end of year report revealed that one of the biggest spikes in VPN sign-ups globally was seen in the UK from the 25th July. 

Konstantin Levinzon, co-founder of Planet VPN, noted that the real issue is people seeking out ‘free’ or not reputable VPNs, posing a significant security risk: “The biggest unintended consequence has been pushing people towards less secure tools, not more careful online behaviour. Age verification requirements have driven a significant increase in VPN adoption, but many users don’t seek out reputable providers – they simply download the first free VPN they find. Those services are often the ones leaking DNS requests, harvesting telemetry or relying on weak security practices, creating a worse privacy outcome than the legislation was designed to prevent.”

Sanjeev Malhotra, chief information security officer at TSG, emphasised the security risk: “People engaging with unvetted VPNs are potentially opening themselves up to serious risks, including malware infections, phishing attempts and personal data harvesting. At the end of the day, it’s still going through a server somewhere, and most people don’t stop to think about who’s operating it, where that data is going or what safeguards are actually in place. In some cases, people may be trading one privacy concern for another without realising it.”

A Lack of Measurable Outcomes? 

But is the ban on children accessing adult sites actually working? Some experts argue that there’s no hard evidence to back it up.

Elle Todd, Partner and Co-chair of the Entertainment & Media Industry Group at Reed Smith LLP, said:  “Ofcom’s recent age assurance report found that the proportion of children encountering harmful content online has not substantially improved despite widespread implementation efforts. The uncomfortable truth is that, based on this report, significant investment in compliance and technologies has not yet translated into measurable improvements in safety outcomes.”

Brian Higgins, Security Specialist at Comparitech, noted that, despite some non-compliance fines being handed out, there are still notable enforcement gaps: Stats from Ofcom summarising their activities during the first twelve months of the Online Safety Act include the launch of 30 investigations, and fines for statutory violations in the region of £4 million GBP. Unfortunately they have also identified ‘enforcement gaps’ where AI and algorithmic content are concerned.”

This item, in particular, could be a precursor to more widespread enforcement action in the future but a brief investigation into the facts reveals that their twelve-month fine collection figure only stands at £55,000. Couple that with their fairly embarrassing skirmish with the American platform 4chan, where their interjurisdictional service of a £520,000 financial penalty notice was rather infamous met with a picture of a hamster and a heavy dose of internet ridicule and it becomes rather obvious that they aren’t performing particularly well.”

Examining Data Storage and Verification System Security

Boris Cipot, principal security engineer, Black Duck, argues that we should be looking beyond whether checks are working and to whether the software behind the systems doing those checks is actually secure: “For many organisations, the focus has been on whether age checks are working. But an equally important question is whether the software behind those systems is secure and properly maintained. If a vulnerability, misconfiguration or compromised third-party component allows age checks to be bypassed, then this is not just a cybersecurity problem anymore but can quickly become a regulatory one as well.”

Sarah Bone, Co-Founder of YEO Messaging, notes the growing number of specialist identity providers: The biggest unintended consequence has been a shift in where trust actually sits. Before the Online Safety Act, platforms largely carried the responsibility for verifying users themselves. Now we’ve got a growing ecosystem of specialist identity providers, each holding highly sensitive personal information. That’s strengthened online safety, but it’s also concentrated trust into fewer organisations, which makes them increasingly attractive targets for attackers.”

So what should age verification providers be doing?

Martin Wegrostek, Cyber Security Portfolio Manager at cybersecurity specialist OryxAlign, said: “Businesses should work on the assumption that breaches are a matter of when, not if. The question is whether providers have built their services with security and privacy by design. That means collecting the minimum amount of information needed to verify age, encrypting data both in transit and at rest, enforcing strong access controls, continuously monitoring for suspicious activity and having a well-rehearsed incident response plan. Organisations relying on third-party age-assurance services should also carry out regular security assessments and review the resilience of their supply chain, rather than assuming a compliant provider is automatically a secure one.”

On Trust and Risk

The conversation should also focus on human risk, said Tim Ward, CEO and co-founder, Redflags: “Content moderators, trust and safety teams, and customer support staff at in-scope platforms are, for the first time, routinely processing government ID documents, facial scans, and other highly sensitive data belonging to minors as part of their everyday work. That’s a substantial new category of human risk, from simple mishandling to targeted social engineering aimed at staff with access to this data, and it’s had almost no public discussion compared to the technical side of compliance.”

“Organisations that have spent the past year focused on the verification system itself should be asking whether the humans downstream of it have had the same level of scrutiny and support,” Ward noted. 

 

The post Examining the Unintended Consequences of the Online Safety Act appeared first on IT Security Guru.

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider

15 July 2026 at 12:17

Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC. 

As the founder of Resilia Connect and author of the Practical Post-Quantum Transition Framework, Moona works with organisations preparing for the security risks created by quantum computing. Her work focuses on post-quantum migration, crypto-agility and helping leaders turn complex technical threats into practical action. 

In this exclusive interview conducted by the Cyber Security Speakers Agency, Moona explains why the quantum threat is already taking shape, where organisations go wrong when preparing for post-quantum cryptography, and why businesses need to begin strengthening their security architecture now. 

Why does quantum computing remain an underestimated cybersecurity threat for many organisations? 

Moona Ederveen-Schneider: “Quantum computing is not simply a future threat. Adversaries are already harvesting encrypted data with the intention of decrypting it once quantum computers become powerful enough. 

“Most organisations have not yet started preparing for that transition. 

“I developed a practical post-quantum transition framework to explain the issue clearly, cut through market hype and vendor noise, and make the process manageable for organisations and their teams. 

“I also run tabletop exercises that teach organisations how to become crypto-agile. I poll participants at the beginning and again at the end of these sessions. The shift in the room is remarkable. 

“People often arrive feeling that the challenge is unmanageable. They leave with greater confidence and a clear understanding of what they need to do next.” 

How close is the quantum threat, and how urgently should organisations begin preparing? 

Moona Ederveen-Schneider: “The UK National Cyber Security Centre says organisations should complete detailed planning by 2028 and be fully migrated by 2035. 

“Google has set its own internal migration deadline of 2029, citing faster-than-expected advances in quantum computing. That reflects the wider sentiment I am seeing and the increasingly strong guidance being issued by governments globally. 

“Google is one of the organisations building these machines, so its decision deserves serious attention. 

“Large organisations typically need at least five years to complete a full cryptographic overhaul, while some may need twice that long. A 2035 deadline is therefore not generous. Organisations need to begin acting now. 

“My practical post-quantum transition framework is designed to deliver security improvements from the first day. It provides a clear starting point and a route through the process without overwhelming teams or budgets. 

“Organisations are also not preparing for a future threat in isolation. They are building more resilient architectures that can improve protection against current threats, including ransomware, AI-enabled attacks and supply chain compromise.” 

What mistakes do organisations make when beginning a post-quantum cryptography migration, and what should they do differently? 

Moona Ederveen-Schneider: “The first common mistake is treating post-quantum cryptography migration as a technology project and handing responsibility solely to the security team. 

“It is a whole organisational transformation. 

“The data that needs protecting sits across HR, legal and finance, not only within what DORA defines as critical business processes. 

“The second common mistake is beginning with the cryptographic inventory. 

“Contrary to the approach commonly repeated across the industry, I advise organisations to strengthen their data security posture first. 

“They must answer a fundamental business question: what are we protecting, and how long does it need to remain secret? 

“My practical post-quantum transition framework begins with that question and is designed to deliver security improvements immediately. It can be adapted for organisations and teams of any size.” 

The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.

Q&A: Solving Synthetic Media Challenges Before All Trust is Lost

1 July 2026 at 05:14

Synthetic media has moved from technical curiosity to mainstream threat in just a few years, with deepfakes now cheap enough to produce that a free app and a handful of seconds of scraped audio can generate convincing fakes. The consequences stretch well beyond political misinformation: corporate fraud running into tens of millions of dollars, biometric security checks being bypassed, and a largely under-reported epidemic of non-consensual intimate imagery. As regulation in the EU, UK and US begins to catch up with the scale of the problem, the question facing businesses and platforms alike is no longer whether synthetic media is a risk, but how quickly they can build the means to verify what they see and hear. 

We sat down with Ruth Azar-Knupffer, Co-founder of VerifyLabs.AI, to unpack the detection arms race, the regulatory landscape now taking shape, and why she believes treating verification as infrastructure rather than a single party’s responsibility is the only way organisations will stay ahead of the threat. 

How widespread is synthetic media on social platforms today, and how has that changed in the last two or three years?  

“It has gone from curiosity to a feature of the landscape. The most widely cited figures put roughly 500,000 deepfakes shared across social platforms in 2023, with estimates of around 8 million by the end of 2025 — close to 900% growth a year. Voice is the part most people underestimate: Pindrop recorded voice deepfakes rising nearly 700% year-on-year in 2024.  

The change over two or three years is not really about volume, though. It is about access and quality. Three years ago a convincing fake took skill, time and a decent machine. Today it takes a free app and a few seconds of someone’s voice scraped off a podcast or an earnings call. And the output now clears the bar where ordinary viewers can no longer tell. Studies consistently find that most people can no longer reliably distinguish a high-quality fake video from a real one. We have crossed from ‘spot the fake’ into ‘assume nothing.’” 

As deepfake generation gets more sophisticated, how do verification technologies keep pace? Is it a winnable race?  

“It is winnable, but not in the way people want it to be. There is no finish line where deepfakes are ‘solved.’ It is an arms race in the same sense that anti-virus or spam filtering is — you win by staying operationally ahead, not by ending the contest.  

The mistake is to chase artefacts alone — the tell-tale blink, the warped ear, the audio glitch. Those tells close fast with every new model. The more durable approach is layered: detection models that look at signals humans cannot, combined with provenance — knowing where a piece of content came from and whether it has been altered since capture. Standards like C2PA and the content-labelling rules now coming through regulation push verification upstream, to the point of creation. Detection at the point of consumption will always matter, but if the only defence is catching fakes after they spread, you are permanently a step behind”. 

Beyond political misinformation, what are the most damaging real-world consequences that people might not be thinking about?  

“Politics get the headlines; the money and the harm are elsewhere.  

The corporate one is fraud. The Arup case — a finance employee in Hong Kong wired roughly $25.6 million after a video call in which every “colleague,” including the CFO, was synthetic — is the example everyone cites, and it will not hold the record for long. Deloitte projects generative-AI-enabled fraud in the US alone rising from around $12 billion in 2023 to $40 billion by 2027.  

Then there is an identity. Deepfakes are now used to defeat the biometric checks banks rely on; bypass attempts on liveness detection have jumped more than 700%.  

But the consequence people think about least is the most personal. A vast and under-reported category of malicious deepfakes is non-consensual intimate imagery, which overwhelmingly targets women and girls. The recent investigations into “nudify” tools are a glimpse of the scale. That is the human cost that rarely makes cybersecurity panel”. 

Where does the burden of detection fall — platforms, users, or third-party verifiers? Who should own this problem? 

“No single party can own it, and pretending otherwise is how it falls through the cracks.  

Platforms have to carry detection and provenance at scale, because that is where content travels and they are the only ones with the reach. Independent verifiers — and yes, that includes us — exist because nobody should be asked to mark their own homework; you need assessment that is auditable and not conflicted by who owns the content. And users need tools simple enough to actually use, plus the basic literacy to know the question is worth asking.  

Think of it as infrastructure rather than ownership. Nobody ‘owns’ road safety — you have manufacturers, regulators, and drivers, each responsible for a layer. Verification is the same. The failure mode is everyone assuming someone else has it covered”. 

Even without a specific viral incident, does the existence of the technology erode trust in authentic content?  

“Yes, and this is the part that worries me most. You do not need a single famous fake to do the damage. Once people know convincing fakes are possible, the ground shifts under everything.  

The sharper danger is the inverse of what most people picture. It is not only that false things get believed — it is that true things get dismissed. Real footage of genuine wrongdoing can now be waved away with ‘that’s a deepfake.’ Researchers call it the liar’s dividend, and it is corrosive precisely because it requires no technical skill at all. The World Economic Forum has ranked AI-amplified misinformation among the top global risks for good reason: when audio and video stop being trusted by default, a shared basis for facts starts to dissolve”. 

In a breaking-news environment where content spreads in minutes, how do you balance verification speed with the accuracy to make a call with confidence?  

“You stop pretending the answer is binary. The honest output of any serious system is a probability with evidence attached, not a stamp that says ‘fake’ or ‘real.’ 

In a fast-moving story we work in tiers. An initial automated assessment can return in seconds and is enough to flag something as warranting caution. A higher-confidence judgement — the kind you would attach your name to — takes longer and may involve human review. The skill is being explicit about which one you are giving and never letting speed inflate certainty.  

The cost of getting it wrong runs both ways. Miss a fake and it spreads; wrongly brand something authentic as synthetic and you have manufactured a different harm. In breaking news the responsible move is often a clearly labelled provisional read, openly updated, rather than a confident verdict you cannot yet support”.  

Is verification a tool for journalists and enterprises, or does it need to reach everyday users to move the needle?  

“Both, but the needle only really moves at consumer scale. Newsrooms and enterprises are the early, high-stakes adopters, and they should be. They are not where the volume of harm sits.  

Most people encounter synthetic media on a phone, in a feed, in a message from a relative — not in a verification suite. If checking authenticity is harder than sharing, sharing wins every time. That is why we built VerifyLabs to be API-first and to work across iOS, Android and the browser: the verification has to live where people already are, not in a specialist tool they will never open. A capability locked inside enterprise contracts protects institutions while leaving the public exposed. Closing that gap is the actual job”.  

What does the regulatory landscape look like, and are laws keeping up?  

“It is moving faster than people assume, though unevenly.  

The EU is setting the pace. Under the AI Act, Article 50 requires AI-generated or substantially manipulated content to be clearly disclosed and machine-detectable, with the relevant obligations landing in August 2026. Breaching those transparency duties carries fines of up to €15 million or 3% of global turnover; the headline €35 million or 7% figure people quote applies to the Act’s prohibited practices, not to synthetic-media labelling. A Code of Practice on transparency — including a proposed common ‘AI’ label for synthetic content — is being finalised alongside it.  

The UK has gone further than disclosure. Sharing non-consensual intimate deepfakes was already criminal under the Online Safety Act; since February 2026 it has also been a criminal offence to create one, or to ask someone else to, under the Data (Use and Access) Act 2025. Creation, not just distribution, now carries liability. In the US there is no single federal framework, but the Take It Down Act mandates 48-hour removal of non-consensual intimate imagery, the Defiance Act — which would give victims a federal civil right of action — has passed the Senate and is awaiting the House, and more than 45 states have their own laws.  

Are laws keeping up? On disclosure and on naming harms, increasingly yes. On enforcement, no. A duty to label synthetic content means little if neither the regulator nor the platform has a reliable way to tell what is synthetic in the first place. Rules without the means to detect and prove manipulation are obligations on paper. The legislation needs detection infrastructure underneath it, or it has no teeth”. 

What happens when legitimate content gets flagged as synthetic, and how do you think about the reputational risk of a false accusation?  

“This is the hardest problem in the field, and the one I judge our own seriousness by.  

A false positive and a false negative are not symmetric in their consequences. Miss a fake and you have failed to catch something; wrongly brand a real video as fabricated and you have actively defamed someone and handed every genuine bad actor a ready-made excuse. The second error can be more damaging than the first.  

So the discipline is to never issue a bare ‘fake’ verdict. We return a confidence assessment with the evidence behind it, set conservative thresholds, route uncertain cases to human review, and treat the right to challenge a result as part of the product, not an afterthought. Verification that cannot show its working, or that hides behind a binary label, does not deserve to be trusted — and we do not want it to be”. 

What does the threat landscape look like in five years, and what should organisations be preparing for now that most aren’t?  

“Three things are coming. Real-time, interactive deepfakes good enough to hold a live video call — the Arup attack, but on demand and at scale. Fully synthetic identities engineered to pass the KYC and biometric checks that gate finance and onboarding. And provenance becoming default infrastructure, with content signed at the point of capture, much as HTTPS quietly became standard for the web.  

What most organisations are not doing yet is treating this as an operational risk rather than an awareness topic. Concretely: build verification and provenance into the workflows that matter; mandate out-of-band confirmation for payments and sensitive instructions, so no transfer is ever authorised on the strength of a voice or a face alone; and run drills, not slideshows — a face your employee recognises asking for money behaves nothing like an awareness module.  

The uncomfortable truth is that business has always run on a simple assumption: if I can see and hear someone, I know it is them. Payments, approvals, instructions, decades of compliance — all of it rests on that. Synthetic media breaks the assumption, and not at some distant point on the horizon but in the incident reports being filed right now. The organisations that come through this are the ones that stop treating their own eyes and ears as proof, and build the means to verify in their place”. 

The post Q&A: Solving Synthetic Media Challenges Before All Trust is Lost appeared first on IT Security Guru.

❌
❌