
Tim Callan at Sectigo considers the implications of deep fakes for biometric authentication and the need for PKI-based solutions
The rapid advancement of AI deepfake technology, the fabricated depiction of genuine individuals, capable of deceptively emulating credible sources, has raised significant concerns among cybersecurity experts.
As this technology becomes increasingly accessible, bad actors are leveraging it to create highly convincing deep fakes, as can be seen in the sheer volume of high-profile deep fakes of celebrities. For instance, earlier this year, Money Saving Expert, Martin Lewis was deepfaked for a scam investment endorsement, allegedly run by Elon Musk.
However, AI deepfake technology has advanced far beyond what most people realise, as malicious actors can now produce convincing deepfakes that can bypass conventional voice recognition systems.
Biometric authentication, which has emerged as a trusted form of identity verification, faces significant challenges as deepfakes grow in sophistication. This is even more pressing as businesses adopt generative AI capabilities, creating a greater need to address the potential loss of confidentiality and secure sensitive data.
Biometrics, including voice authentication, have gained credibility as a reliable form of identity validation.
However, the increasing prevalence of deepfakes threatens to erode confidence, as sophisticated deep fakes, often built with AI, can replicate an individual’s voice with astonishing accuracy, making it difficult to discern between genuine and fabricated audio.
VICE recently managed to fabricate a voice using AI to gain access to their bank account, demonstrating that AI technology has reached worryingly high levels of sophistication, capable of mimicking the bank account users’ voice to gain access to the account.
These instances and others show that voice and other forms of biometric authentication may no longer be sufficient to ensure security, further exacerbating the increasing problem with digital trust and whether entities can trust that the website or enterprise they’re interacting with is legitimate or not.
The ongoing challenges with ensuring digital trust have led to the wider adoption of Zero-Trust principles, a security approach that requires all digital and human identities to authenticate themselves before gaining access to systems or privileges within those systems. In recent years, as password security has weakened, enterprises have begun to adopt biometric authentication as a method for users to verify their identities.
This is how deepfakes exploit the pre-existing faith ingrained in communication channels, complicating the task of differentiating between authentic and manipulated interactions for recipients. This dynamic threat landscape carries substantial repercussions for enterprises, as recent records attribute a collective loss of $78 billion to the impact of deepfake attacks.
Amid the growing threat of deepfake-assisted phishing, Public Key Infrastructure (PKI) authentication is a robust solution. PKI opuses a proven, cryptographically secure method of verifying identities and ensuring secure communication. Unlike biometric data, which can now be spoofed or faked, PKI offers a higher level of security that is not vulnerable to AI deepfakes.
The strength of PKI lies in its use of cryptographic keys, making it virtually impossible for bad actors to impersonate legitimate users. Any digital actor in the system can encrypt data with the intended recipient’s “public key,” which is intended for widespread sharing with any member of the public. However, only the holder of the associated “private key” (the intended recipient) can decrypt the information.
This dual-key approach establishes a robust authentication process that does not depend on any fakable information or guessable “shared secret”. For businesses grappling with the evolving threat posed by AI deepfakes, PKI-based authentication stands out as a reliable defence mechanism. As such, organisations must recognise the significance of a multi-layered security approach to safeguard their networks and protect sensitive information.
Integrating PKI into authentication processes can effectively fortify identity verification measures, ensuring the integrity of data exchanges in the face of ever-evolving cyber threats.
Organisations that are serious about countering the risks imposed by deepfake attacks to rebuild confidence within the enterprise can take advantage of PKI for Zero Trust and move away from newly vulnerable biometric authentication.
Contemporary systems encapsulate PKI in certificates to manage and authenticate the machine and human identities communicating with one another, protecting environments from fraudulent entities.
As AI technology advances with unparalleled sophistication, and malicious entities continually seek novel attack vectors to attain unauthorised access, organisations have no time to rebuild their network’s trust and establish Zero Trust principles to prevent significant fallout.
Tim Callan is Chief Experience Officer at Sectigo
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543