
How generative AI is expanding identity risk beyond credentials, accounts, and access controls.
Organizations have spent years hardening identities at login. Meanwhile, generative AI has created an entirely new way to impersonate people without compromising a single account. Security teams are protecting credentials while attackers are exploiting trust itself.
Gartner predicts that by 2027 AI agents will cut the time required to exploit exposed accounts by 50%, while also making deepfake-enabled social engineering more effective. Gartner also expects technology-enabled social engineering to target more executives and other trusted individuals.
Further, CrowdStrike’s 2025 Global Threat Report found a 442% increase in vishing (voice phishing), growing use of AI-generated deception, attackers creating convincing fake social profiles, deepfake videos used in social engineering and identity-based attacks continuing to rise. All proving that identity—not malware—is increasingly the attack surface.
Identity Security Is Entering a New Phase
Identity security traditionally focuses on accounts, passwords, credentials, access, and authentication. Those controls remain critical, but generative AI is changing what identity risk looks like.
Attackers can now create convincing images, videos, profiles, and other synthetic content that appears to come from a trusted person. The risk is no longer limited to compromised accounts or stolen credentials.
A person’s face, image, reputation, and public identity can now be used as tools for fraud, manipulation, and social engineering. Executives, creators, public figures, spokespeople, recruiters, and sales leaders are all impacted.
The Identity Threat Model Has Changed
Traditional identity security assumes attackers must compromise systems before impersonating people. Generative AI breaks that assumption.
Bad actors using simple AI tools can create believable content that appears to come from a CEO, CFO, politician, celebrity, creator, or any industry expert or pundit. That synthetic content can be used to trick the audience into believing the image or voice is coming from that person or entity they trust. This can erode trust and do tremendous damage to reputation or somebody’s business, or worse.
The fake does not need to fool everyone. It only needs to fool the right person at the right moment. This makes likeness abuse a practical security concern, not just a media or reputational issue. That is why the conversation needs to move beyond the narrow language of “deepfakes.”
This Is Bigger Than Deepfakes
Harmful identity misuse can include fake endorsements, synthetic ads, impersonation profiles, altered images, fraudulent recruiting content, and manipulated posts. The more important security question is whether the use of someone’s likeness was authorized.
Security teams already understand the importance of authorization in systems, applications, and data access. Similar thinking now needs to apply to public identity and likeness. When unauthorized identity use creates trust, it can quickly become a vehicle for fraud, scams, social engineering, and even election manipulation.
How Likeness Abuse Creates Real Security Risk
Synthetic impersonation can support several familiar threat categories. These aren’t hypothetical future risks. They map almost perfectly onto attacks security teams already combat today.
Fake CEO videos leverage AI-generated videos or cloned voices of executives used to convince finance teams to authorize wire transfers, instruct employees to bypass approval processes, announce fake acquisitions or company news and influence investors or markets.The Hong Kong finance worker case in 2024 is probably the best-known example, where an AI-generated video conference leading to a $25M transfer,
Recruiting scams are also becoming increasingly common. We see fake recruiters using cloned LinkedIn profiles with AI-generated recruiter headshots. These lead to fake interview invitations, fake offer letters, fake onboarding portals and “work-from-home” scams
And of course Celebrity endorsement scams happen constantly. Elon Musk crypto scams, Taylor Swift giveaway scams, Tom Hanks publicly warning about AI-generated ads using his likeness, MrBeast deepfake investment ads and Warren Buffett investment scams
The larger lesson shows that if a person’s identity creates trust, it can also create risk.
Why Platform Takedowns Are Not Enough
Platform enforcement is necessary, but it is not a complete security strategy. Organizations don’t outsource phishing prevention entirely to Microsoft or Google. Likewise, they shouldn’t outsource identity protection entirely to TikTok, LinkedIn, Meta, YouTube, or X.
Most takedown processes begin after harmful content has already been discovered. The burden often falls on the person or organization being impersonated. Each platform has different rules, workflows, timelines, and enforcement standards.
AI-generated content can spread quickly, be reposted, or move across platforms before action is taken.
Consent and Authorization Are Becoming Security Controls
Security practitioners already work with concepts like permissions, access rights, approvals, revocation, and policy enforcement. Those same concepts should now apply to image and likeness use.
Organizations don’t need new AI legislation before acting. Most can begin using familiar security governance practices today. Organizations should be able to answer:
- Who is allowed to use an executive’s image?
- In what context?
- On which channels?
- For what purpose?
- With what approval?
- What uses are explicitly prohibited?
- Who owns escalation when misuse appears?
Instead of trying to stop every AI-generated piece of content or identity misuse, the goal is to create clear systems of permission, control, and accountability. That starts with practical steps before an incident occurs.
Practical Steps Security Teams Can Take Now
Identify high-risk people: Start with individuals whose likeness carries authority, trust, or public visibility. This may include CEOs, CFOs, HR leaders, investor relations, recruiters, spokespeople, creators, ambassadors, athletes, and customer-facing executives.
Maintain an approved identity asset library: Keep track of official headshots, bios, video assets, social profiles, spokesperson materials, and approved public images. This gives teams a baseline for what legitimate content looks like.
Define prohibited uses: Clarify what unauthorized likeness use means for the organization.
Examples include fake endorsements, synthetic ads, impersonation accounts, fraudulent recruiting content, manipulated executive images, or posts implying false approval.
Create an escalation and response playbook. Begin by defining who reviews suspected misuse. Identify who captures evidence. Decide who contacts platforms. Clarify when legal, communications, HR, or executive protection should be involved. And prepare employee or customer notifications when appropriate.
Train employees to verify synthetic media: Security training should evolve beyond suspicious links and fake invoices. Employees need to understand that images, video, and voice can also be manipulated. High-risk requests should require independent verification through trusted channels.
Build cross-functional ownership: AI likeness abuse cuts across security, finance and accounting, legal, communications, privacy, HR, and brand. Response should not live in one silo.
These steps do not require organizations to solve every AI policy question at once. However, they do help move identity misuse into the security risk model.
The Role of Security, Legal, and Communications
Every security leader already has ransomware playbooks. Very few have synthetic identity playbooks.
AI impersonation often sits between security incidents, legal issues, and reputational crises. Security needs to get involved If a fake executive video is used in a scam. Legal and communications need to respond If a synthetic endorsement harms customers, employees, or the brand. With brand reputation and CEO visibility on the top of many priority lists of companies today, this is critical. HR may need to get involved If an employee is impersonated in a recruiting scam too.
The fastest responses will come from organizations that already know how these teams work together. Security teams should help drive the process because the risk can lead directly to fraud, credential theft, data exposure, or operational disruption. The broader shift is that identity security is moving from account protection to presence protection.
Identity Security Must Expand Beyond the Login
For twenty years identity security answered one question: Is this really you? With a bigger priority on credentials. The AI era introduces a second: Is this really authorized?
Generative AI makes likeness portable, reproducible, and exploitable. Some AI-generated uses will be creative, authorized, or valuable. Others will be fraudulent, abusive, or dangerous. The goal is not to stop all AI-generated content. The goal is to create systems for permission, verification, monitoring, and rapid response.
Security teams should treat likeness abuse as part of the broader identity risk landscape. For years, organizations have told people to protect their passwords. In the age of AI, they also need to help protect their presence too.
_____
About Phillip Shoemaker
Phillip Shoemaker is CEO and co-founder of PersonaShield, a company focused on helping individuals, creators, public figures, and brands protect their digital identity in the age of artificial intelligence. A former Apple executive who helped build and oversee the App Store, Phillip has spent decades working at the intersection of technology, trust, and consumer protection. Today, he focuses on combating deepfakes, impersonation, voice cloning, account takeovers, and other emerging threats while advocating for technologies that help people verify authenticity, maintain control of their likeness, and build trust online.











