# SP-048 Offensive AI and Deepfake Defence

Status: draft. Release 26.02. Modified 2026-02-22. Licence: CC BY-SA 4.0.

Scope: Security architecture for defending against AI used as a weapon against the enterprise — deepfake executive impersonation, AI-generated phishing and vishing at scale, synthetic identity fraud, voice cloning, AI-accelerated exploit development, and adversarial AI threat intelligence. Complements SP-027 (Secure LLM Usage) and SP-047 (Secure Agentic AI Frameworks) which address AI you deploy; this pattern addresses AI...
Use when: Organisation handles high-value financial transactions that could be targeted by AI-enhanced BEC (wire transfers, supplier payments, cryptocurrency). Executives have publicly available voice recordings (earnings calls, conference talks, podcast appearances, public video) that could be used for voice cloning.
Not when: Organisation operates in a fully air-gapped environment with no external communications exposure.

## Controls (21, NIST SP 800-53 ids)
- Critical (5): AT-02, AT-03, IA-02, PM-16, SC-23
- Important (16): AU-02, AU-06, CA-07, IA-03, IR-04, IR-06, PS-06, RA-03, RA-05, SA-04, SA-08, SA-11, SI-03, SI-04, SI-05, SI-10

## What each critical control mitigates (5)
- AT-02 Security Awareness: T-OAI-002, T-OAI-003, T-OAI-008, T-OAI-010
- AT-03 Security Training: T-OAI-002
- IA-02 User Identification And Authentication: T-OAI-001, T-OAI-003, T-OAI-004, T-OAI-009
- PM-16 Threat Awareness Program: T-OAI-006, T-OAI-007, T-OAI-008, T-OAI-010
- SC-23 Session Authenticity: T-OAI-001, T-OAI-003

## Threats and the controls that mitigate them (11)
- T-OAI-001 Executive deepfake impersonation — synthetic voice or video used to authorise fraudulent financial transactions: IA-02, IR-04, PS-06, SC-23
- T-OAI-002 AI-generated spear-phishing at scale — personalised, high-quality phishing content without detectable quality signals: AT-02, AT-03, SI-03, SI-04
- T-OAI-003 Voice cloning for vishing — synthetic voice targeting financial authorisers or IT helpdesk for access or payment fraud: IA-02, AT-02, SC-23, IR-04
- T-OAI-004 Synthetic identity fraud — AI-generated identity documents and faces defeating remote onboarding verification: IA-02, SA-04, SA-11, RA-05
- T-OAI-005 AI-generated fraudulent content in business processes — fake claims, filings, applications, or evidence defeating document review: SI-10, SA-11, SA-08, AU-02
- T-OAI-006 AI-accelerated exploit development shortening the vulnerability-to-exploitation window for unpatched systems: RA-05, SI-05, PM-16, RA-03
- T-OAI-007 Adversarial AI capability development by threat actors outpacing organisational threat awareness and defensive controls: PM-16, RA-03, CA-07, SI-05
- T-OAI-008 Brand impersonation using AI-generated content — fake websites, social media profiles, and communications targeting customers: SI-04, CA-07, AT-02, PM-16
- T-OAI-009 Biometric authentication bypass — AI-synthesised faces or voices defeating liveness detection in remote identity verification: IA-02, IA-03, SA-11, SA-04
- T-OAI-010 AI-generated disinformation targeting organisational reputation, customer trust, or market position: AT-02, PM-16, CA-07, IR-04
- T-OAI-011 AI-assisted malware development and polymorphic obfuscation increasing evasion of signature-based detection: SI-03, SI-04, RA-05, CA-07

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-048/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-048/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 34 KB: /api/v1/patterns/SP-048
- Page for people: /patterns/sp-048/
- Related: SP-014 Awareness and Training Pattern; SP-025 Advanced Monitoring and Detection; SP-027 Secure LLM Usage; SP-036 Incident Response

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
