AI Reputation · October 3, 2026

What to Do When an AI Deepfake Impersonates Your Business

Steps to verify synthetic media, protect accounts and payments, report impersonation, warn customers, and restore a trusted source of truth.

Business security and reputation team comparing suspicious executive video and audio for signs of AI impersonation
Short answer

Treat a suspected AI deepfake as both a security incident and a reputation incident. Preserve the original post or message, verify the executive through a separate trusted channel, pause related payments or account changes, and secure affected accounts. Then report the exact content through the platform’s impersonation, fraud, privacy, or synthetic-media process and publish one short correction on verified company channels when customers or employees could be misled. Do not amplify the fake unnecessarily or claim it is synthetic before confirming the facts.

A deepfake is synthetic or altered audio, video, or imagery that can make a real person appear to say or do something that did not happen. The FBI warns that criminals use generative AI in fraud, including fake executive video calls, cloned voices, false identification, and misleading promotions. Synthetic media is not automatically illegal, but it can support harmful conduct.

The first question is not whether the clip looks strange. It is whether the claimed message is authentic. Compression, editing, old footage, parody, and ordinary technical problems can all create confusion. Confirm the person, source account, date, original file, and surrounding claim before making a public accusation. Detection tools may help an investigation, but no single score should be treated as conclusive proof.

Available options depend on the platform, content, speaker, location, and harm. The FTC’s current rule addresses government and business impersonation, while privacy, publicity, trademark, defamation, fraud, and election laws vary. Individual-likeness rights are not identical everywhere. This guide is general education, not legal advice. Seek qualified counsel for significant loss, threats, extortion, disputed ownership, or formal legal claims.

A practical step-by-step approach

01Verify the person through a separate channel

Do not reply using contact details that delivered the suspicious media. Reach the executive or an authorized colleague through a known directory, saved number, or internal system. For payment, password, payroll, or vendor changes, require the company’s normal callback and approval process even if the voice or face seems convincing.

02Preserve the original evidence without spreading it

Save the URL, username, profile ID, timestamps, caption, messages, email headers, call details, and full file when safely available. Record the first appearance and material copies. Restrict financial, employee, and customer data. Preserve original media because edits and reposts can remove useful context.

03Stop the immediate security and financial risk

Pause related transfers, account recovery, password resets, data releases, or contract changes. Alert finance, security, legal, communications, and support as appropriate. Review access, sessions, forwarding rules, users, and recovery methods. Contact the financial institution quickly if money moved, and keep account and transaction details out of public warnings.

04Define the false claim and affected audience

Write one factual summary: who is imitated, what the media appears to request or endorse, where it circulates, and who may act on it. Separate a private payment scam from a public false endorsement. This determines whether to prioritize internal containment, customer warning, platform reporting, law enforcement, or coordinated action.

05Use the platform route that matches the harm

Read the current policy before filing. A fake account may require an impersonation report, a payment scheme a fraud report, and a realistic cloned face or voice a privacy or synthetic-media process. YouTube allows an identifiable person or legal representative to request review of realistic altered content that looks or sounds like that person. Outcomes are not guaranteed.

06Publish a short source-of-truth notice when needed

If people could reasonably be misled, place a dated notice on the official website and verified profiles. Identify the unauthorized message or account, list the company’s real channels, explain what it will never request, and give one verification method. Avoid embedding the fake, naming an unverified suspect, or repeating harmful details.

07Report fraud and preserve legal options

In the United States, financial fraud can be reported to the FBI’s Internet Crime Complaint Center, and impersonation scams to ReportFraud.ftc.gov. Other countries have different authorities. Counsel can assess preservation, trademark, privacy, defamation, publicity, or other claims. Submit truthful reports and do not use legal processes as shortcuts when rights are uncertain.

08Build verification habits before the next attempt

Require dual approval and separate confirmation for sensitive requests. Give staff an escalation contact and practice a voice or video impersonation scenario. Keep leadership pages, contact details, and verified profiles current. Monitor important names and claims, log copies, and update one public notice rather than creating conflicting explanations.

Information to gather

A clear record makes it easier to choose the right channel, communicate accurately, and avoid unnecessary repetition. Start with:

  • Original URL, account ID, username, timestamps, captions, messages, call details, and media file
  • Trusted confirmation from the impersonated person or an authorized company representative
  • Payment, payroll, credential, vendor, customer, and account changes connected to the incident
  • Platform policy section, reporting route, confirmation number, decision, and follow-up date
  • Approved incident summary, customer notice, internal alert, and media-response owner
  • Financial-institution, insurer, counsel, law-enforcement, or regulator contacts when relevant
  • Ongoing copy monitoring, access review, dual approvals, callback rules, and staff training

What not to do

Pressure can lead to decisions that create a second reputation problem. Avoid:

  • Following contact instructions contained inside the suspicious message or video
  • Calling something a deepfake publicly before confirming the source and facts
  • Reposting the full fake so widely that the response becomes its main distribution channel
  • Using an automated detector score as the only proof that media is authentic or synthetic
  • Sending employees, customers, or supporters to attack an account or mass-report content
  • Making false privacy, trademark, copyright, criminal, or platform-policy claims
Important: Outcomes depend on the facts, evidence, publisher or platform rules, search engines, applicable law, and other third parties. This article is educational information and is not legal advice.

Frequently asked questions

How can a business tell whether a video or voice recording is an AI deepfake?

Start with source verification rather than visual guesses. Contact the person through a separate trusted channel, inspect the original account and file, compare the message with normal procedures, and review surrounding evidence. Unusual motion, audio, or metadata can be clues, but compression and editing can create similar effects. A detection tool may support an investigation, but one result is not conclusive.

Should a company immediately post the suspected deepfake on social media to warn people?

Usually not in full. Reposting can expand the audience, expose private details, and make later copies harder to track. When people face a real risk, publish a concise notice on official channels that identifies the unauthorized message or account without reproducing unnecessary harmful content. Link customers to the company’s real contact and verification process.

Can YouTube remove an AI-generated video that copies an executive’s face or voice?

YouTube’s current privacy guidance allows an identifiable person or legal representative to request review of realistic altered or synthetic content that looks or sounds like that person. YouTube considers factors including identifiability, realism, disclosure, parody, satire, and public interest. Not every request results in removal, and a company should review the live instructions before filing.

Is an AI deepfake automatically illegal?

No. Synthetic or altered media can have lawful uses, and legal treatment depends on the content, intent, harm, location, and people or rights involved. Fraud, extortion, impersonation, privacy, publicity, trademark, defamation, and other laws may apply in some cases. Obtain qualified legal advice for the specific facts rather than assuming the technology alone decides legality.

Can a reputation agency guarantee removal of a deepfake?

No. A responsible agency can help preserve evidence, organize the response, prepare accurate platform reports, coordinate trusted public information, and monitor copies. Outcomes depend on the content, evidence, account owner, platform policies, applicable law, publishers, search engines, regulators, and other third parties. No provider can guarantee removal, reach, rankings, or timing.

Primary resources

Policies and features can change. Review the current source before submitting a request:

Related guides