For most of the history of business communication, people authenticated each other with informal signals: a familiar voice, a writing style, a face on a video call, knowledge of internal context. Security teams knew these signals were imperfect, but they were expensive to fake at scale, so procedures quietly leaned on them. The wire release that “requires a phone call” assumed the voice on the phone meant something.
That assumption has expired. Generated voice can carry a specific person’s tone with seconds of sample audio. Generated video is good enough for a low-resolution conference call. Generated text reproduces a colleague’s style more consistently than the colleague does. None of this requires a sophisticated adversary anymore; it requires a subscription.
What actually changed
The important shift is not that fraud got more convincing. It is that the cost of personalization collapsed. Attacks that once required research effort per target can now be produced per thousand targets: reconnaissance summarized automatically from public sources, pretexts written in fluent context-aware language, follow-ups that respond intelligently to replies. The economics that made highly targeted attacks rare have inverted.
This lands hardest on the procedures that route money and access. Payment changes, payroll redirects, urgent vendor requests, credential resets, and physical-access exceptions are all mediated by human judgment about authenticity, exactly the judgment that generated media defeats.
The uncomfortable audit
Leadership teams should walk their highest-consequence procedures and ask one question at each step: does this step assume a human can recognize another human? Every yes is now a finding.
The fixes are rarely technical novelties. They are procedural: callback to independently known numbers rather than numbers provided in the request. Verification codes established out of band. Dual authorization thresholds that do not bend for urgency, because urgency is precisely the lever the attacker pulls. Explicit rules for what executives will never ask staff to do by phone or message, communicated so that refusing a convincing impersonation is safe for the employee who refuses.
AI inside the enterprise
The same technology arriving as a threat is also being adopted as infrastructure, and the two exposures compound. Enterprise AI assistants and agents hold credentials, read internal data, and increasingly take actions. Each one is a new identity with entitlements, a new data flow, and a new target. An organization that cannot inventory its human and machine identities will find that its AI systems made the problem strictly harder.
The governance questions are familiar because they are identity questions: what can this system access, who approved it, what actions require a human, and how would misuse be detected? Organizations that answer them now, while adoption is still legible, will spend far less than those that reconstruct the answers after an incident.
Trust signals are not coming back. Procedures that assumed them need to be found and rebuilt deliberately, before an attacker demonstrates where they are.