Deepfake detection is a losing strategy

Detection is measured by what it catches. Security is measured by what gets through. As long as attacks stayed crude, the two metrics overlapped: what got through, you eventually caught. Since 2024 they have diverged, and most corporate security stacks now optimise the wrong one.
The inverted-metric trap
A deepfake detector sells you a number: “94% detection rate.” The number is true. It is also irrelevant to your actual exposure, because those 94% are computed on a sample that blends amateurs and professionals. The fraud that drains a treasury never comes from an amateur.
Ask it differently: against attacks capable of fooling an experienced finance director, what is the detection rate? The answer is documented, and it is brutal.
The CSIRO study: anatomy of a collapse
In March 2025, researchers from CSIRO, Australia’s national science agency, and Sungkyunkwan University published an analysis of 51 deepfake detectors, sixteen of which were tested under real-world conditions. None of the sixteen reliably identified real-world deepfakes. The paper, SoK: Systematization and Benchmarking of Deepfake Detectors in a Unified Framework, was accepted at the IEEE European Symposium on Security and Privacy 2025.
Their explanation fits in one sentence: detectors collapse as soon as they leave their training corpus. The ICT detector, trained on celebrity faces, becomes markedly less effective on ordinary faces. On your employees’ faces.
A patch will not fix that flaw, because it marks a structural asymmetry: fake generation improves exponentially, detection only linearly. The gap widens every quarter. Building your defence on detection means betting that curve will reverse, and no technical reason suggests it will.

The perverse effect of false statistical comfort
Here is the mechanism that makes detection dangerous rather than merely useless. The same detectors that miss professional deepfakes excel at cheapfakes, the crude forgeries thrown together in an afternoon. They catch the amateur with flair. The dashboard fills with green lights. The buyer reads the detection rate and sleeps well.
But the amateur was never the threat. Catching the one who could not defraud you anyway offers no protection against the professional, who walks through without tripping a single alarm. Every intercepted cheapfake reinforces confidence in a tool that is blind where it counts. You pay to buy your own blind spot, and you present it to the board as a security gain.
What a glaciologist understands better than a cybersecurity vendor
Palaeoclimatology faced exactly this problem, reconstructing a truth no single instrument can establish, and solved it sixty years ago.
To know the temperature 100,000 years ago, no thermometer exists. The first instinct was to find the right indicator, the single reliable signal. It failed: every proxy, ice cores, tree rings, marine sediments, pollen, carries its own bias. The discipline then made a methodological reversal. It abandoned the search for the perfect signal in favour of triangulation: you trust no single substrate, you cross-reference independent sources whose errors do not overlap. Truth emerges from convergence, not from the purity of one sensor.

Payment security is still hunting for the right detector. It could learn something from a glaciologist: an identity is not established by a single corruptible signal, but by cross-referencing sources the attacker cannot forge simultaneously.
Authenticate the real rather than detect the fake
Hence the change of frame. Detection asks: “is what I am seeing fake?”, a question the attacker is free to optimise against you. Authentication asks the opposite: “is this person really who they claim to be?”, a question decidable through multiple sources, on every transaction, without depending on the vigilance of a human under pressure at 5:45 on a Friday.
That shift changes the playing field. You stop chasing the latest generation of fakes and start anchoring proof of the real. The tools you already have, IBAN verification, anti-phishing filters, awareness training, remain useful bricks. None answers the question of the originator’s identity at the moment of decision. That missing piece is not one more layer. How Sealfie works rests on that shift.
What finance leaders are discovering
Until now, this reasoning was intellectual comfort. Three rulings by the French Cour de cassation on 19 November 2025 (no. 24-17.056, 24-17.780, 24-19.776) turned it into personal exposure.
Their lesson: when a fraudulent transfer goes out because the internal authorisation structure allowed it, the bank stops being the automatic safety net. Liability shifts to the company, and through the duty of care, to the executive who did or did not build the adequate control system. Combined with the NIS2 directive, which binds corporate officers personally on cyber governance, the subject has changed in nature. What was yesterday a budget line arbitrated by the CISO today falls under the officer’s personal liability.
The question has therefore changed shape. It now bears on your ability to document the authentication system in place, and on how that system holds against the 2026 state of the art.
Detecting the lie is a prosecutor’s job. Authenticating the truth is an engineer’s
Synthetic-identity fraud will be won neither in the court of the human eye, which has lost, nor in that of detection AI, which is losing faster and faster. It is won by making the question “is it really them?” technically decidable, through multiple sources, on every transfer.
As long as your system answers “is this fake detectable?”, you are playing the game the attacker chose. The day it answers “is this originator authenticated?”, you are playing your own.
Measure your exposure
The BEC risk calculator estimates your company’s annual incident probability and expected loss in six questions, with a published methodology and sourced coefficients. No data leaves your browser.