Deepfakes, Disinformation, and AI Content are Taking over the Internet

2026-08-0128 min read

Most discussions of generative AI risk stay abstract. Shuman Ghosemajumder's argument is concrete and uncomfortable: generative AI is not primarily a disinformation problem or a copyright problem, it is an automation problem. Cybercriminals have been industrialising attacks for two decades, and the one step they could never automate — convincingly impersonating a human in audio or video — is now a commodity API call. His central thesis is that this collapses the economics of fraud, invalidates a generation of defences built around telling humans apart from bots, and forces defenders to adopt zero-trust and combined fraud/security operations.

Ghosemajumder founded the Trust & Safety product group at Google and helped launch Gmail. He was later CTO of Shape Security, acquired by F5 for $1B, where he became Global Head of AI, and is currently co-founder and CEO of Reken, an AI cybersecurity startup. This 49-minute talk was recorded at QCon AI, which he references from the stage; InfoQ published the recording and transcript on April 24, 2026.

These notes report what he presented, with a small amount of clearly labelled supplementary explanation where an intermediate engineer needs background the talk assumed.

What You Will Learn

  • The Disinformation Automation framework: how any content medium moves from "hard to fake" to "one actor can flood the internet with it", and where video and audio sit on that curve today.
  • Why AI-generated content is already a large fraction of what you consume, why "low quality" is the wrong mental model for it, and why formulaic human work is the most exposed to displacement.
  • How model collapse produces citation-backed misinformation that looks more trustworthy than an uncited answer.
  • How credential stuffing actually works at scale, what its traffic signature looks like, and why a low single-digit success rate is enough to sustain a criminal business.
  • Why CAPTCHA, phishing training, and deepfake detection do not solve the problem, and what the measured numbers behind that claim are.
  • What does work: multi-factor authentication, behavioural know-your-customer, zero-trust post-authentication monitoring, and cyber fusion centres.
  • The three organisational surfaces AI changes — infrastructure, business model, and communication channels — and why the third is the hardest.

The Framing Problem: Nobody Agrees What "AI" Means

Ghosemajumder opens with the observation that "AI" has become a marketing suffix. He had his teams photograph security conference show floors and produced a collage of vendors describing products as AI-enabled, AI-boosted, or "AI-infused". He bought a toothbrush with artificial intelligence in it and still does not know where the intelligence is. His favourite illustration of the resulting absurdity is a cartoon about everyone generating content with AI and then deciding to summarise it with AI to save time. He also flags that the infrastructure narrative has holes: AI datacentre buildout now exceeds plans for buildings humans will occupy, but he cautions that we may be seeing patterns where AI use drops precipitously when students are not using it for their primary application. He presents that as a possible pattern rather than a measured finding.

Asking rhetorically where all this is leading, he offers a deliberately useless answer from a Financial Times analysis: AI will either be our salvation, or destroy civilisation, or land somewhere in between — definitely one of those three things and nothing else. The joke is the setup for his real complaint, that the term is too broad to reason about. Alan Turing could publish Computing Machinery and Intelligence — a title he compares to Isaac Newton publishing a paper called "math" — only because the field did not exist yet. Turing proposed the imitation game, now the Turing Test: could a machine imitate a human convincingly enough to fool a human observer? The Economist later dismissed the idea, writing that there is "no practical reason to create machine intelligences indistinguishable from human ones" because "people are in plentiful supply" and "should a shortage arise, there are proven and popular methods for creating more of them." Ghosemajumder's point is not to mock the prediction — he quotes Yogi Berra, "making predictions is hard, especially about the future" — but that we are now living inside a large-scale adversarial deployment of exactly the capability that was dismissed as pointless.

The practical consequence for engineers is that most people's model of AI comes from science fiction rather than any technical source, so machine learning, deep learning, and artificial general intelligence get conflated. Invoking Arthur C. Clarke, he notes that whatever technology seems sufficiently advanced today fools us into thinking we are looking at the magic of AGI.

The Gell-Mann Amnesia Effect

Ghosemajumder illustrates the resulting blind spot with a cognitive bias. The Gell-Mann amnesia effect, named after Nobel laureate Murray Gell-Mann, describes reading a newspaper article in your own field, noticing it is riddled with errors, then turning the page and assuming the article on finance or politics is accurate. His application of it is that we see through hallucinations and errors when a model generates content in our own field, and lose that ability the moment the question falls outside our expertise.

Supplementary observation: this is worth holding onto through the rest of the notes, because the attacks described later all target people who cannot independently verify what they are being told.

How Convincing Synthetic Media Got, and How Fast

The progression Ghosemajumder traces starts with generative adversarial networks producing Nicolas Cage face swaps — amusing, not especially convincing, so nobody was alarmed. The next step combined a skilled human impersonator with generative AI: Miles Fisher's Tom Cruise deepfakes worked because a human already nailed the voice and mannerisms and the model only had to supply the face. That dependency has now been removed. OpenAI's Sora lets anyone generate highly realistic video from a prompt, and Mark Cuban gave all Sora users permission to use his likeness and voice, so anyone can, in Ghosemajumder's phrasing, puppeteer him. Sora users immediately generated video using copyrighted characters, against which there were no guardrails at the time.

Supplementary context: a generative adversarial network trains two models against each other — a generator producing candidate images and a discriminator trying to distinguish them from real ones — so the generator improves by repeatedly defeating a detector. That adversarial dynamic is the same structural reason deepfake detection struggles later in the talk.

Ghosemajumder makes a point engineers evaluating models should internalise. Ask Midjourney, which historically had few guardrails around copyrighted content, for "Chewbacca Reading" and you get a highly realistic rendering of the character. Ask Adobe Firefly, explicitly trained without copyrighted content, and you get what he charitably calls "homemade Chewbacca". This is the general trade-off across generative models: training data licensing directly constrains output quality on anything culturally specific.

The commercial pressure this creates is visible in the market. He notes Disney announced a billion-dollar deal with OpenAI while simultaneously suing Google — effectively, for not having a deal.

The Labour Argument: Tilly Norwood and the Hallmark Channel

Ghosemajumder addresses the backlash against Tilly Norwood, an AI-generated actress that actors, directors, and filmmakers worldwide objected to on the grounds that an automaton cannot supply the humanity, creativity, and imagination that human performers bring to screen. His counterargument is deliberately deflating: look at the level of creativity and imagination humans have been producing on the Hallmark Channel for years.

The serious version of the point is an engineering one. A great deal of human-produced content is formulaic, which means it sits inside the distribution a model can interpolate and extrapolate from. His conclusion is that the displacement risk is probably not concentrated on a Tom Hanks or a Julia Roberts, but on the large population of working actors, directors, and screenwriters producing competent, conventional work that AI can plausibly run with. The same reasoning explains the volume problem in the next section: formulaic content is exactly what generative models produce cheaply and well.

Why "Slop" Is a Misleading Word

Merriam-Webster declared "slop" word of the year, defining it as low-quality AI-produced content. Ghosemajumder objects specifically to "low quality", because it implies the content is easy to identify and not competing with human work. His evidence:

  • A YouTube Shorts video of a gorilla wrestling a python amazed him before he realised it never happened. An entire channel is dedicated to primates fighting animals, with millions of views, and thousands of such channels exist across YouTube and TikTok.
  • In tests his team ran, roughly 20–30% of the default feed on YouTube Shorts and TikTok is already AI-generated. He presents this as his organisation's own measurement, not an industry statistic.
  • Real footage from films and TV is being run through filters that make it look AI-generated, which further erodes any visual heuristic for telling them apart.
  • AI-generated ads featuring Oprah, Ben Carson, and other celebrities are running on YouTube, endorsing pharmaceutical products and home remedies. Oprah had to publicly disclaim them. Out of context, most viewers simply consume them.
  • Searching for "Tiananmen Square Tank Man selfie" returns hundreds of copies of a viral AI-generated image, at the top of Google results. No such photo could exist — there were no selfie cameras at the time — yet future searchers will reasonably assume it is real.

He also ran an exercise with university presidents, reasoning that anyone engaged with AI in any form is probably an AI enthusiast and therefore using other AI tools. He searched Nature — one of the most prestigious academic journals in the world — for "artificial intelligence", pulled a paper on cervical cancer, and ran it through an AI-text detector he calls GPT-0 (the tool generally known as GPTZero). The abstract and first paragraph came back flagged as 100% AI-generated. The question he raises is scoped and specific: how much AI-generated content is already in peer-reviewed journals without anyone realising, and what does that actually mean? He is careful that it does not necessarily indicate wholesale generation — it could be a grammar cleanup, or an AI first draft that humans then fact-checked. His point is that we cannot tell, and that the uncertainty combined with the visible breadth of AI tool use is itself the problem.

Supplementary caution not stated in the talk: AI-text detectors are known to produce false positives, particularly on non-native-English writing and on formulaic academic prose. Treat a single detector score as a weak signal rather than proof, which is consistent with the speaker's own refusal to draw a strong conclusion from it.

Falsehoods Travel Faster by Design

Ghosemajumder quotes Winston Churchill — "a lie gets halfway around the world before the truth has a chance to get its pants on" — and immediately notes Churchill never said it, which is the joke and the demonstration. He cites MIT professor Sinan Aral's study finding that lies spread roughly six times as fast as truth on social media.

His explanation of the mechanism is the useful part. If you originate a lie, you propagate it as aggressively as possible. If you spot the lie, outrage makes you share it too, framed as "look at this lie". Both sides optimise for reach, which is why he characterises social media as having largely become a rage circus. For a defender, this means debunking amplifies, and any containment strategy that relies on public correction is fighting the distribution mechanics.

Disinformation Automation: The Core Framework

This is a framework Ghosemajumder created to describe how misinformation and fraud progress for any type of content. He describes the endpoints explicitly. In the first stage, creating a convincing fake requires a great deal of effort, talent, and resources. In the third stage, a single individual or entity can produce vast amounts of content. His worked example of the middle is the Nicolas Cage face swaps: an automation of something that previously needed Hollywood special effects, but still requiring many days of computing power at the time, so not something anyone could do.

The table below is my reconstruction of that progression, not a slide from the talk. The stage 1 and stage 3 definitions are his and the Nicolas Cage example is his; the middle row, the cost and producer columns, and the placement of each medium are my inference from what he described.

Stage Cost of a convincing fake Who can produce it Where media sits
Stage 1 Great effort, talent, and resources Specialists only Where video sat before deepfakes
Stage 2 Automated but still compute- and skill-intensive Motivated technical individuals Nicolas Cage face swaps, days of compute
Stage 3 Effectively unbounded output One individual or entity floods the internet Text, and now video and audio

Text reached stage 3 long ago. Ghosemajumder points to low-quality sites built to monetise AdSense traffic, something he saw at Google twenty years ago, which generative AI has only made more sophisticated.

Video and audio have now arrived. Sora generates a video in roughly 60 to 120 seconds. Grok can take a single video frame or still image and produce video from it in under 60 seconds in many cases. The consequence is that one actor's output volume is no longer bounded by their production capacity, which is the assumption almost every existing content-moderation and trust system was built on.

Model Collapse Produces Confident, Cited Falsehoods

Two examples in the talk show how synthetic content contaminates the information supply and then re-enters models.

The first is subtle laundering. Within an hour of Ghosemajumder publishing a column in Inc., the article appeared on an Argentinian site in Spanish — the original translated, with extra keywords added to the prompt to generate what reads as independent coverage. That publication is a Google News source. A Spanish-language reader has no way to know they are reading generated derivative content.

The second is the sharper one. A venture capitalist told Ghosemajumder they had a good idea of what Reken does — while Reken was in stealth and had published nothing. The VC had asked a chatbot. Ghosemajumder repeated the query and got plausible-but-wrong answers, so he traced the citation. He points to citation-bearing assistants such as Perplexity as the innovation that makes this dangerous: showing a source generates trust, because how could the content be wrong if it cites something on the web? In this case there genuinely was a source — and the cited source was itself an AI-generated website.

This is model collapse visible in the wild: models train on and cite synthetic content, which then gets treated as ground truth. It is most dangerous exactly where the reader has least ability to detect it — asking about something they know nothing about — which is the Gell-Mann effect operating through the retrieval layer.

Do Not Use a Language Model as a Calculator

Ghosemajumder's single explicit "if you take one thing away" instruction. He asked ChatGPT how many "j"s are in the surname Ghosemajumder — a query he assumes nobody has ever asked on the internet. It answered confidently, showed its work, and while miscounting was pointing at the spaces between the letters rather than the letters. He notes that high scores on International Math Olympiad problems reflect the model simulating those behaviours, not performing computation, and that the same applies to detailed diagrams that look impressive until you notice specific misunderstandings.

His framing of the stakes, delivered at the New York Academy of Medicine: would you want an AI system performing "vibe surgery"? Some details have real consequences when they are wrong.

He also notes where models get their facts. Wikipedia holds high-quality information alongside hoaxes that have survived for years before discovery, and Reddit — full of misinformation — appears to be one of the top training sources for generative models.

Generative AI as the Ultimate Cybercriminal Tool

The pivot in the talk is that AI at its core is just automation — the ultimate form of it — and cybercriminals are constantly automating. Ghosemajumder's illustration covers the last ten years of criminal automation, a period he says most people have had little visibility into. He adds that the picture of a hacker in a hoodie in their parents' basement has been wrong for two decades: cybercrime is highly commoditised and federated, with organised groups building tooling for each other to achieve high levels of automation.

Credential Stuffing, Concretely

When a breach is announced, most people change their password on the breached site and consider it handled. That is only the start. Leaked username/password pairs enter a corpus used to attack completely unrelated sites, because users reuse credentials. This is a credential stuffing attack.

Ghosemajumder shows Sentry MBA, a tool his team found on the dark web. It looks like an ordinary Windows application, but it is purpose-built for criminals to plug commandeered botnets into a target's login form at scale.

The traffic evidence is the memorable part. Normal web traffic, especially retail, shows diurnal periodicity — usage rises when people are awake and falls when they sleep. At one of the largest retailers in the world, that pattern was absent. Once his team separated automated from human traffic, the human diurnal curve was there, but the vast majority of total traffic was automated, hitting the login form 24/7. With password reuse producing a typical 1–2% success rate, attackers took over thousands of accounts en masse. He states this pattern appears in essentially every industry.

The economic lesson matters more than the number. At near-zero marginal cost per attempt, a low single-digit hit rate is not a failed attack — it is enough to sustain a multibillion-dollar business.

CAPTCHA Is Now a Tax on Your Real Users

CAPTCHA stands for Completely Automated Public Turing Test to Tell Computers and Humans Apart — literally an automated Turing test. Ghosemajumder cites a Google study of how it has fared:

Solver Solve rate on distorted-text CAPTCHA
Humans 33%
Machine-learning based OCR 99.8%

The gap has only widened since. There are cybercriminal services specialising in solving CAPTCHAs for other criminals, complete with group discounts and customer support, because they want to be good businesses to their customers. Run a modern CAPTCHA through a generative AI system and it poses no barrier at all.

His conclusion is blunt: if you are using CAPTCHA today you are doing the exact opposite of what you should be doing — adding friction for real users while presenting no obstacle to attackers.

The Last Mile Was the Only Thing Protecting Us

The IRS phone scams affected more than 400,000 people in the United States over a few years. In the vast majority of cases the victim had to speak to a human in the criminals' call centre, because that was the only way to be persuasive. Call centres are expensive to run and risky to operate — that cost was an implicit defence.

Ghosemajumder connects this to a Stanford study from the past year which, across a range of generative AI applications, found customer support to be the most promising one — productivity improved across the board, and the gains were greatest for the least experienced support staff. Enterprises adopting this must manage hallucinations and errors. For criminals, he argues, those hallucinations are features rather than bugs, because the goal is to tell a gullible victim a believable story rather than an accurate one.

Generative AI is therefore usable out of the box to automate the criminals' last mile: realistic audio and video to close the con. Ghosemajumder traces the maturation — voice cloning appeared a few years ago in a fairly simplistic form and has only grown more sophisticated since — and the Arup case is where it lands. An employee of the Hong Kong engineering firm joined a Zoom call with several colleagues, agreed to transfer $25 million at their CFO's request, and later discovered every other participant was a real-time deepfake. His warning is that this technology is only going to get more advanced.

Ghosemajumder cites two reactions to this trajectory. Geoffrey Hinton left Google partly to spread the word about how dangerous AI-enabled scams are. Warren Buffett, asked at his annual meeting about the greatest possible growth industry, answered that AI-enabled scams are likely the greatest growth industry he has ever seen — and that unfortunately he cannot invest in it.

You Do Not Need Frontier AI to Run This

The final piece of the economic argument is the democratisation of capability. The prevailing assumption has been that effective AI requires billions — or by some hyperscaler claims hundreds of billions or trillions — of dollars. DeepSeek's launch contradicted that. Inexpensive systems, including models trained by cybercriminals, can be highly effective and in some cases more effective than models produced expensively.

The operational takeaway: do not model your adversary's capability as bounded by their compute budget. People are fooled at scale by unsophisticated technology all the time.

Architecture And Data Flow

The pipeline below assembles the components as Ghosemajumder described them. Nodes A through H describe automation criminals already had; nodes I onward are what generative AI newly unlocked.

flowchart TD
    A[Public data breaches] --> B[Credential corpus assembled
across unrelated sites] B --> C[Sentry MBA style tooling] C --> D[Commandeered botnets
distribute requests] D --> E[Credential stuffing
against target login form] E -->|CAPTCHA no longer a barrier| E E --> F[Small fraction of credentials valid
thousands of accounts] F --> G{Needs human persuasion
to monetise?} G -->|Historically| H[Human call centre
expensive, risky, rate-limited] G -->|Now| I[GenAI last mile] I --> J[Cloned voice] I --> K[Real-time deepfake video calls] I --> L[Contextually targeted
phishing and support scripts] J --> M[Funds transfer / account takeover] K --> M L --> M

Supplementary reading of the diagram, not stated by the speaker: nodes E and G were the historical choke points and both have now been removed — CAPTCHA no longer constrains E, and generative AI removed the cost ceiling at G. That leaves F and M as the places a control can still bite: detecting anomalous post-authentication behaviour, and gating the irreversible action. This is consistent with the controls he endorses later, though he does not frame them this way.

What Does Not Work Well

Ghosemajumder is careful to say these are all worth doing; the failure mode is treating them as solutions.

Family secret passwords. Agreeing a codeword with relatives is a genuinely useful exercise, mostly because it forces the conversation about what you would do if a call sounded exactly like a loved one. But in the real scenario the fraudster knows which buttons to push — a simulated voice saying "I can't remember the password, I'm panicking" will convince many people. And attackers do not need to succeed every time.

Phishing and security training. Universal practice, and worth doing, but Ghosemajumder cites academic research alongside anecdotal and quantitative evidence that it does not actually stop people clicking phishing links or engaging with social engineering — particularly when lures are realistic and contextually targeted, which generative AI now makes cheap to customise per recipient across an entire organisation.

CAPTCHA. Covered above: negative value.

Deepfake detection. He gives this the most detailed treatment because it attracts the most enthusiasm, and identifies two independent failures:

  1. The benign/malicious boundary does not exist technically. Every Apple phone launch advertises multiple layers of AI processing applied to every image and video, and Google's Nano Banana actively encourages everyone to modify photos with generative AI. Very little media reaches the internet without AI processing, so "was AI involved" no longer separates attacks from ordinary content.
  2. Coverage is unattainable and the output is not actionable. You cannot enumerate every model a criminal might use. And if analysis returns "50% chance that 40% of this content is AI generated", there is no sensible way to operationalise that into a decision.

What Does Work

Multi-factor authentication. He calls this very effective, without qualification.

Behavioural know-your-customer. Study the behaviour of an account, a device, and an individual over time, and flag anomalies and patterns. This is signal that does not depend on distinguishing synthetic media from real media, which is why it survives the collapse of detection-based approaches.

Zero trust. The idea that passing an authentication gate should not grant full trust for subsequent actions. If a password is stolen, the authentication step itself has been commandeered, so you must monitor everything that happens post-authentication to discover abuse. Ghosemajumder's wry observation is that the security industry treated this as an epiphany, while the fraud industry has always worked this way — never trusting any account or device, continuously examining behavioural data.

Cyber fusion centres. The convergence he considers a genuinely good trend: fraud teams and InfoSec teams collaborating, pooling all data available to a web application, mobile application, or enterprise, and using it jointly to spot patterns, anomalies, and abuse.

Good AI against bad AI. Defenders need scale to match the attacker's scale. He cites MIT professor Tom Malone's research on AI in work processes, which found that humans and AI combined outperform humans alone — variously called co-intelligence or human augmentation. His prediction is products and services that combine humans and AI to help humans make better decisions, with generative AI used deliberately as a brainstorming and refinement partner rather than as a replacement for thinking.

The Three Surfaces AI Changes in Your Organisation

Surface How AI changes it Ghosemajumder's note
Infrastructure security Attackers use AI to discover and exploit vulnerabilities at scale AI is excellent at completeness problems — it produces a far more complete list of things to probe
Business model / trust & safety Account abuse and automation of user actions the product never anticipated Gartner recently advised organisations to block all AI-enabled browsers, given the launches from OpenAI, Perplexity and others
Communication channels Social engineering of employees, customers, executives, and the supply chain, at previously impossible scale The hardest, because these doors must stay open by definition

The completeness observation is worth dwelling on. Ghosemajumder's position is that models are not doing real thinking, but they are very good at aggregating everything that exists — including Reddit and Wikipedia — and surfacing what you had not considered. That is exactly the capability an attacker enumerating your attack surface needs, and it is also the capability a defender enumerating their own gaps needs.

The Scale Intuition Gap

His analogy for why we consistently underestimate this: when securing a house we ask how to become less attractive as a target than our neighbours. Attackers on the internet are not targeting you specifically. Nothing needs to be special about you, your organisation, or your website — they can attack everyone simultaneously. Imagine a robber breaking into every house in a community at once, or robbing every bank in a city at once. That is what automation permits, and our real-world intuitions do not model it.

Trade-offs And Limitations

  • Several headline figures are the speaker's own measurements or estimates. The 20–30% AI-generated share of YouTube Shorts and TikTok default feeds comes from tests his team ran, not a published study. The 1–2% credential stuffing success rate is described as typical from his Shape Security experience. Treat both as informed practitioner estimates for prioritisation, not citable industry statistics.
  • He does not claim the ineffective techniques are worthless. Security training, family codewords, and deepfake detection are all described as helpful but insufficient. The failure is treating them as a solution and stopping there. CAPTCHA is the one exception, where he argues the cost now exceeds the benefit.
  • Behavioural KYC and zero trust carry costs he does not enumerate. Continuous post-authentication behavioural monitoring implies collecting and retaining detailed behavioural telemetry on users, which has privacy, regulatory, and storage implications, and false positives translate directly into blocked legitimate customers. This trade-off is supplementary context; the talk presents these controls without discussing their downsides.
  • Blocking AI-enabled browsers is a directional recommendation, not a settled one. He reports Gartner's position and the reasoning behind it rather than fully endorsing it, and the same automation risk sits in tension with genuine productivity uses.
  • Detection asymmetry is structural, not temporary. Because benign AI processing is now applied to nearly all media by default, the signal deepfake detectors depend on is being destroyed by the ordinary consumer-device pipeline, independent of any adversarial effort.
  • The "AI is just simulating" claim is a framing, not a proof. Ghosemajumder uses the letter-counting failure and Olympiad performance to argue models are not doing real computation. The practical instruction — do not use a language model where you need arithmetic guarantees — is sound regardless of where one lands on the deeper claim.

Practical Takeaways

  1. Remove CAPTCHA from your critical flows. The one control he says is actively negative-value today.
  2. Use multi-factor authentication, behavioural know-your-customer, and zero-trust post-authentication monitoring as the core control set, for the reasons set out above.
  3. Connect your fraud and InfoSec teams into a cyber fusion capability so the behavioural data from both sides is pooled.
  4. Stop using generative AI as a calculator. His single explicit take-one-thing-away instruction; high benchmark scores reflect simulated behaviour, not computation.
  5. Have the family codeword conversation — its value is rehearsing the scenario, while accepting that a determined fraudster knows which emotional buttons to push.
  6. Adopt AI where it demonstrably improves the outcome, not because it is AI. His closing instruction to his own teams: monitor every advance so you can recognise what helps, but do not fall in love with the technology or use it for its own sake.

Engineering actions these imply

These follow from the talk's evidence but were not stated as instructions by the speaker.

  1. Plot your login traffic and look for the missing diurnal curve. Absence of the expected day/night shape is the tell that automation dominates your volume, which is exactly how his team spotted the retailer's problem.
  2. Add out-of-band verification before irreversible financial actions, independent of voice and video. The Arup case establishes that a live video call with recognisable colleagues no longer authenticates anyone.
  3. Budget deepfake detection as telemetry rather than as a control. Given his point about unoperationalisable probability outputs, no gating decision should depend on one.
  4. Give models a calculator or code-execution tool and validate the output wherever arithmetic or counting correctness matters.
  5. Click through citations before trusting a cited answer. The Reken example shows a cited source can itself be AI-generated, so the citation raises apparent credibility without raising accuracy.
  6. Model attacker capability by access to commodity models, not by budget. DeepSeek-class economics mean a cheap or self-trained model is sufficient to fool people at scale.

Key Terms

  • Deepfake — Synthetic audio, image, or video generated or manipulated by machine learning to depict a real person saying or doing something they did not.
  • Generative adversarial network (GAN) — An architecture training a generator against a discriminator, so the generator improves specifically at defeating detection.
  • Disinformation Automation — Ghosemajumder's framework describing a content medium's progression from requiring specialist effort to fake, through partial automation, to a stage where a single entity can produce unlimited convincing content.
  • AI slop — Mass-produced AI-generated content; Merriam-Webster's word of the year, though Ghosemajumder rejects the "low quality" part of the definition because much of it is indistinguishable from human work.
  • Model collapse — Degradation that occurs as models train on and cite AI-generated content, propagating and reinforcing synthetic errors as fact.
  • Gell-Mann amnesia effect — The bias of noticing errors in reporting on your own field, then trusting reporting on fields you do not know.
  • Credential stuffing — Replaying username/password pairs leaked from one breach against unrelated sites, exploiting password reuse.
  • Diurnal periodicity — The day/night rhythm of genuine human web traffic; its absence indicates automation dominates the volume.
  • CAPTCHA — Completely Automated Public Turing Test to Tell Computers and Humans Apart; a challenge intended to separate humans from bots, now solved by machines at 99.8% against a 33% human rate.
  • Zero trust — A model in which passing authentication grants no standing trust, and post-authentication behaviour is continuously evaluated.
  • Behavioural know-your-customer — Building behavioural baselines for accounts, devices, and individuals, and flagging anomalies, rather than relying on a single identity check.
  • Cyber fusion centre — A combined operation where fraud and information security teams share data and detection to spot abuse neither would catch alone.
  • Co-intelligence / human augmentation — Combining human and AI decision making so the pair outperforms either alone.

Ghosemajumder closes with William Gibson: "The future is already here — it's just not evenly distributed." His reading of it is that the most dangerous uses of AI already exist, including uses more dangerous than anything in the talk, and the reason society is not panicking is that they are not affecting everyone yet. That gap is the opportunity — to see where the risks are emerging, to find the genuinely beneficial applications in security and operations, and to work out how those scale across an organisation. He frames the payoff in competitive terms: the only way to improve your organisation or your product faster than your competitors is to recognise those opportunities before everyone else does, which is the reason to keep monitoring every advance without falling in love with any of them.


Reference: Deepfakes, Disinformation, and AI Content are Taking over the Internet