The Deepfake Gap: Corporate Affairs Teams Are Rehearsing the Wrong Crisis

The Deepfake Gap: Corporate Affairs Teams Are Rehearsing the Wrong Crisis

Just 18 percent of corporate affairs practitioners say their function is prepared to manage a deepfake or AI-driven misinformation incident, and over 43 percent describe their function as poorly prepared. The Oxford-GlobeScan Global Corporate Affairs Survey 2026 collected those answers from 294 senior practitioners across 51 countries.

In the same survey, 44 percent named the impact of AI and technology as one of the biggest risks facing global business over the next two years, up from 17 percent a year earlier. The risk register moved faster than the crisis plan did.

What is a deepfake crisis?

A deepfake crisis is a reputational incident triggered by synthetic audio, video, or imagery that appears to show a company, an executive, a product, or a customer doing something that did not happen. It differs from a conventional crisis in one structural way: the organisation has to disprove an event rather than explain one.

That inversion changes everything downstream. In a conventional crisis, the facts sit inside the organisation and the task is to release them well. In a fabricated one, the claim sits outside the organisation, the evidence for it looks convincing, and the organisation's own denial is the weakest form of proof available, because every accused party denies.

Why did AI risk rise so sharply in one year?

Three changes arrived together. Generation quality passed the point where casual viewers detect a fake. Distribution moved to platforms that reward emotional content before verification. And the cost of producing a convincing clip fell far enough that a single motivated person can do it.

The result is a threat that behaves like a supply chain problem. Corporate affairs functions worldwide report the concern rising in step, with GlobeScan's business risk tracking showing AI and technology impact climbing into the top tier of risks over a single reporting cycle. Academic work on the same shift, including research published in the Journal of Contingencies and Crisis Management, identifies speed of dissemination, realism, and erosion of public trust before verification as the three properties that make these incidents distinct.

Which sectors are most exposed?

Preparedness varies sharply. Information and communications technology and media entertainment teams report the highest confidence. Consumer products and retail records the lowest, with 62 percent saying they are not prepared, as Trellis reported from the survey.

That combination is uncomfortable. Consumer brands carry the shortest distance between a viral clip and a measurable commercial effect. A fabricated video of contamination, mistreatment, or an executive comment travels through the same channels that drive purchase, and it reaches customers who have no reason to seek a correction.

Confidence also splits by region, weakest across Europe and Africa, strongest in Latin America, and clustered around moderate levels in North America. Australian teams sit inside a global picture where the average function has thought about the risk and built nothing for it.

What does a deepfake crisis plan contain?

A conventional crisis plan assumes the organisation knows what happened. A deepfake plan has to work before that is true. Six components carry the weight.

  • A verification path with named owners. Who confirms within 30 minutes whether the executive was in that room on that date, and who has authority to say so publicly.

  • Pre-positioned provenance. Authenticated channels, published speaking calendars, and a known place where the company's real statements appear, so a denial has somewhere credible to land.

  • Platform escalation contacts held in advance. Takedown routes at the major platforms are faster for organisations with an existing relationship and a documented process.

  • A legal position agreed before the incident. Counsel's default preference for certainty before comment is correct in most crises and costly in this one.

  • Monitoring that watches for the company outside its own name. Fabricated content often circulates through clipped, re-captioned, and re-uploaded versions that brand monitoring misses.

  • A rehearsed executive protocol. Leaders need a practised way to confirm their own identity to staff, customers, and journalists at short notice.

Why does the first hour decide the outcome?

The first hour decides the outcome because a fabricated clip's credibility peaks before any correction exists and declines only when a faster, more specific account replaces it. An organisation that responds in six hours is arguing against a version of events that an audience has already accepted, repeated, and acted on.

Detection technology helps at the margins and settles nothing on its own. Forensic tools produce probability scores, the scores arrive after the content has spread, and a probability is a poor thing to publish. What persuades a newsroom is the ordinary evidence of an alibi: a calendar entry, a boarding pass, an event agenda, a room of attendees, and a communications team that answers the phone. Corporate risk commentary through 2026 has converged on the same conclusion, treating synthetic content as an operational risk with a documented response path instead of a technology problem awaiting a technology answer.

Speed alone does not fix it. A denial without specifics reads as a denial. A response that says the executive was addressing a shareholder meeting in Melbourne at the timestamp on the clip, with a published agenda and a room full of witnesses to prove it, ends the story. The difference between those two responses is decided months earlier by whether anyone assembled the material that makes specificity possible in under an hour.

What does a fabricated incident cost before it is corrected?

Cost accrues in three places while the correction is being drafted. Customers act on what they saw, and consumer decisions taken during the uncorrected window rarely reverse when the correction lands. Counterparties pause, because a bank, an insurer, or a procurement officer who sees a viral clip has a compliance reason to seek clarification before proceeding. Staff lose confidence, since employees see the same content as everyone else and receive a slower explanation than the public does.

The third one is underrated. In a conventional crisis, employees usually know what happened because they were there. In a fabricated one, they know exactly as much as a stranger, they are being asked about it at dinner, and an organisation that briefs media before it briefs staff creates a second problem while solving the first.

Insurance and legal remedies operate on timelines that do not help inside the window. Defamation action, platform litigation, and cyber policy claims are all worth pursuing, and none of them changes what a customer believes on the afternoon the clip circulates.

What do employees need in the first hour?

Employees need three things quickly: confirmation that the content is fabricated, a single sentence they are permitted to say if asked, and a named person to send enquiries to. That package takes 20 minutes to write and can be drafted in template form long before any incident.

Frontline teams need it most. Retail staff, call centre operators, and field technicians are the people a customer confronts, and they are usually the last to be told. An organisation that reaches them in the first hour converts several thousand potential improvisers into a consistent response.

What should an Australian board ask this quarter?

Five questions surface the gap quickly.

  1. If a fabricated video of our chief executive circulated this afternoon, who confirms it is fake, and how long does that take?

  2. Which platform contacts do we hold today, and when did we last test them?

  3. Has our crisis plan been rehearsed against a synthetic-content scenario, or only against a breach and a product recall?

  4. Does our legal position allow a rapid factual denial before a full investigation concludes?

  5. Who has authority to publish a response outside business hours?

Boards that ask the first question usually discover the answer sits with a single person who may be on a flight. That finding alone justifies the exercise.

Where a communications partner fits

Third Hemisphere is an Australian communications agency, and its crisis management work covers preparation as well as response: building the verification path, rehearsing the scenario with the leadership team, and holding the media relationships that let a denial reach the audience that saw the clip. The relationships are the part that cannot be built during the incident. A journalist who has dealt with an organisation for two years will make a call to check. A journalist who has never heard of it will run the clip.

Preparation also solves the problem the survey exposes. Most functions know the risk exists. The 18 percent that report readiness are separated from the rest by documented decisions, and the documents are cheap.

The takeaway

A deepfake crisis is won or lost by how fast an organisation can prove where its executives actually were, and preparation sets that speed long before the response begins. Any board can test its own position in one meeting by asking who confirms a fabricated clip is fake and how long that takes. Organisations that want the plan built and rehearsed before the test arrives can book a consultation, or read the rest of the Third Hemisphere insights on preparing for reputational risk.