Pillaraxis Cyber law, privacy & security — read plainly
Vol. 2 · 2026
Kochi, India
Brief No. 016
Law & Policy

Deepfakes Are a Legal Problem, Not Just a Technical One

The Arup fraud and cases like it are usually filed under cybersecurity. The harder questions they raise — evidentiary standards, corporate liability, verification duties — belong to lawyers as much as engineers.

It is tempting to treat deepfake fraud purely as a technology problem awaiting a technology solution — better detection tools, watermarking standards, liveness checks on video calls. Those things matter, but they treat the symptom. The Arup case and others like it raise questions that sit squarely in legal territory, and the law has been slow to catch up with them.

Start with evidentiary standards. Corporate authorisation processes, court testimony, and even some regulatory filings have historically treated video and voice as inherently more reliable than text — a recorded call has long functioned as stronger proof of authorisation than an email chain. Generative AI has quietly inverted that hierarchy for anyone relying on it as a verification mechanism, and most institutional processes have not been rewritten to reflect that. A signature can be forged, but forging a signature does not scale; producing a convincing deepfake video call, once the training footage exists, increasingly does.

Generative AI has quietly inverted a legal hierarchy that assumed a recorded call was stronger proof of authorisation than an email. Most institutional processes have not caught up.

Then there is corporate liability. When an employee is defrauded through a deepfake impersonating their own CFO, who bears the loss, and under what theory? Arup's insurers, its board, and the finance employee involved all have different answers to that question, and existing corporate fraud and negligence frameworks were not written with synthetic media in mind. Regulators are beginning to respond at the margins — the EU AI Act's transparency obligations under Article 50 require certain synthetic content to be marked as AI-generated, and several jurisdictions are drafting deepfake-specific criminal provisions — but a comprehensive framework for allocating loss when a corporate authorisation process is defeated by synthetic media does not yet exist anywhere.

The practical response available today is procedural rather than technical: high-value authorisation processes need an out-of-band verification step that cannot be spoofed by a video call alone — a callback to a pre-verified number, a code word established through a separate channel, a mandatory delay on unusual requests regardless of how convincingly they are presented. None of that requires new law. But designing it well requires the same instinct a good contract drafter already has: assume the counterparty you are looking at might not be who they claim to be, and build the process so that claim has to be independently verified rather than simply witnessed.

← OlderWhy India's New Turnover-Based Licensing Rules Reshaped an Entire Compliance Industry