Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
AI deepfake creator tools put executive likeness in systems you do not control. Learn the five exposures your own teams create and what to require before adoption.

AI deepfake creator tools now run in browser tabs, and the teams using them do not report to security. An agency clones your founder's voice to localize a keynote. An employee uploads an all-hands clip to a free face-swap app to see what happens. Neither needs budget or approval, and both deposit an executive's voice and face into systems you do not control.
More than 80% (opens in new tab) of workers use AI tools their employer never approved, and executives use them most regularly. Your organization ends up manufacturing the raw material for its own impersonation, and no security review looks for it.
This article covers the five exposures your adoption creates, why review misses them, and what to require before adoption.
Your teams are already using these tools, in three tiers: approved enterprise platforms someone bought, free consumer apps nobody bought, and open models anyone can run on a laptop.
An AI deepfake creator tool generates synthetic video, audio, or imagery of a real person from a small sample of their likeness, the capability behind deepfake voice and video (opens in new tab) scams.
Only the first tier reaches security review. Approved platforms arrive with contracts, SOC 2 audits, SSO, and audit logs, and they define what happens to the source sample after upload.
Consumer apps and open models arrive through individual users: a free app may need only an email address, and an open model runs on a laptop with no watermark restrictions and no record of what it made.
Each tier solves a real problem for a team that is not thinking about security. AI dubbing has made localized voice tracks cheap enough for training content and sales videos, executives address employees abroad in their own languages through avatars, and learning teams build avatar-based security awareness (opens in new tab) courses with little production work.
None of it triggers a procurement event, so security rarely learns which tools are in use.
Generating synthetic media in-house creates five exposures:
Once a source sample leaves your perimeter, you cannot pull it back. Vendor agreements routinely authorize (opens in new tab) vendors to aggregate uploaded data for broad purposes and retain copies after the agreement ends, and a vendor that trains a model on your sample can serve it to other clients, competitors included.
A voice is a credential you cannot reset (opens in new tab).
Consent to appear in a corporate video does not extend to a rendered clone. An employee in an onboarding module has not agreed that a team can clone their voice for multilingual delivery or feed their likeness to a vendor's model.
California's digital replica law requires contracts licensing a voice or likeness to carry a reasonably specific description (opens in new tab) of intended uses. In the EU, the employer-employee power imbalance undercuts whether employee consent (opens in new tab) is freely given at all.
Your clone library is a ready-made impersonation (opens in new tab) kit for anyone already inside. All-hands recordings, earnings calls, and rendered clones sit in shared drives, and cloning lowers the barrier (opens in new tab) to insider abuse (opens in new tab) by someone you already trust.
An insider can fabricate inflammatory statements in a leader's voice, and contractors with the same access under weaker controls extend that exposure outside your walls.
Every rendered clone you publish makes it easier to dismiss a real recording as a fake, which is the liar's dividend (opens in new tab) working against you.
Routinely producing synthetic executive content proves the capability sits within your own reach, weakening any provenance argument for a genuine earnings call or recorded authorization.
Your AI policy is not the only place you have called this capability governed. Cyber insurance applications carry AI governance sections, financial regulators expect your own AI use inside the same cybersecurity program obligations (opens in new tab) as attacker-driven AI threats, and YouTube, TikTok, and Meta condition distribution on disclosure.
Ship an undisclosed clone through an unapproved tool with no permission on file, and the control environment you described is not the one you run.
Your controls work exactly as designed, and that is the problem. Three gaps let likeness data through: free tools rarely trigger procurement, likeness data falls outside the categories you track, and review arrives after the clone exists.
Any one gap is survivable. Together they let an executive's likeness leave without tripping a control, and because nobody paid for the tool, no record exists.
Publishing synthetic executive content compresses the stage an attacker works hardest on. In the social engineering attack chain (opens in new tab), Setup (opens in new tab) is where an adversary gathers likeness material, studies reporting lines, and builds a pretext long before anyone gets a message.
Your output hands them three things.
Teaching employees how deepfake detection (opens in new tab) works closes part of the gap, but each of these hands an attacker time and credibility they would otherwise buy.
Five requirements govern these tools: name whose likeness may be used and for what, assign an owner to each clone, set retention and destruction rules for source samples, disclose synthetic content that reaches an audience, and gate executive likeness like a credential. Together they supply the scope, accountability, and control that separate a governed use from a liability.
Get written, specific consent before your team uploads any source sample, covering the media, duration, permitted uses, and revocation path. Performer contracts and state digital replica laws point to the same template: tie consent to a specific description of use, and keep it renewed as uses change.
Someone must be accountable for each rendered clone by name: where it is stored, who can invoke it, and when it is retired. Without an owner, the clone becomes an orphaned asset, copied into other systems and models, with nobody left to enforce the permission you asked for (opens in new tab).
Get the vendor's retention and destruction terms in writing before the first upload, and confirm they cover the uploaded file, the derived clone, and any model fine-tuned on it.
Illinois requires anyone collecting biometric identifiers to publish a written retention schedule (opens in new tab) and destroy them once the purpose is satisfied, a workable default even where no statute applies.
Label rendered clones wherever an audience encounters them. Article 50 transparency (opens in new tab) requirements under the EU AI Act apply from August 2, 2026. New York has required conspicuous disclosure (opens in new tab) of synthetic performers in advertising since June 9, 2026, and the major platforms ask the same.
Treat a request for an executive's rendered clone the way you treat credential issuance: explicit approval, a log of every invocation, and revocation when the role changes. A convincing clone of your CFO can move money if your controls read a familiar voice as a trusted request.
Doppel is the AI-native Social Engineering Defense (opens in new tab) (SED) platform that unifies Digital Risk Protection (opens in new tab) and Human Risk Management (opens in new tab), built for the impersonation problem these tools accelerate.
Four capabilities map to the exposures above.
Govern synthetic-media tools the way you govern anything that touches identity: defined scope, a named owner, and control over where a copy of a real person ends up. Then a clone of your CEO stays inside a boundary you set, and Doppel extends that boundary outward, dismantling the impersonation that escapes it.
Request a Demo (opens in new tab) to see how that works against the campaigns targeting your brand.
BLOG
Modern social engineering is a relentless, AI-orchestrated lifecycle. Learn how to map the five-stage attack chain—from setup to contact—and why a unified defense platform is the only way to outpace AI-driven social engineering attacks.
by Bobby Ford, Rahul Madduluri, and Alvin Lin