Ryan Brack is a Center for AI Strategy Advisor and co-founder of Moon Howl Media.
The World Economic Forum’s Global Cybersecurity Outlook 2026 found that cyber-enabled fraud has overtaken ransomware as CEOs’ top cyber concern, with 73% of respondents saying they or someone in their organization was affected by cyber-enabled fraud. AI-generated impersonation is quickly becoming part of that threat landscape.
For comms teams, that changes the job. We’ve spent decades preparing for real-world crises. AI means preparing for fabricated events that can create very real consequences.
Build your playbook before you need it
A deepfake playbook should answer a few simple questions before an incident occurs:
- Who verifies suspicious content?
- Who activates the crisis team?
- Who owns the first public statement?
- Who contacts legal, security, investor relations and platform trust and safety teams?
Those decisions shouldn’t be made while a fake video is spreading. Build the playbook now.
Give people a way to verify what’s real
A denial may not be enough. Your executives should have established, verified channels, and your company should have one place where employees, reporters and customers know they’ll find authenticated information.
If you’re using Content Credentials or other provenance tools, introduce them before a crisis. The Coalition for Content Provenance and Authenticity (C2PA) and Adobe’s Content Authenticity Initiative are developing standards that help establish where digital content came from and whether it has been altered.
When trust is under attack, evidence beats reassurance.
Write your first statement now
Don’t draft your holding statement during the incident.
“We’re aware of [the content]. We’re verifying [it]. Updates will come through [our official channels at…]”
Something along these lines buys your team time to investigate without disappearing from the conversation. The strongest responses balance speed with verification: acknowledge quickly, confirm facts as they emerge and keep stakeholders informed.
Test the plan with a drill
Run a tabletop exercise.
It’s 8:15am on a Tuesday. A convincing AI-generated video shows your CEO announcing layoffs hours before earnings. Employees are sharing it internally. Reporters are calling. Investor relations is fielding emails. Your CEO is on an international flight.
Now answer four questions:
- Who verifies the content?
- Who approves the response?
- Who hears from you first: employees or the media?
- How quickly can your team move from “Is this real?” to a coordinated response?
Run the exercise. In one hour, you’ll learn whether your approval process is too slow, whether roles are unclear and whether your team knows where to go for the truth. It’s far better to discover those gaps in a conference room than while a deepfake is spreading online.
Deepfakes are a communications challenge with real business consequences. You may not be able to stop someone from targeting your organization. But you can decide whether your team spends the first hour debating what to do…or doing it.




