GoFirm
Back to Blog
Threat Landscape·2 min read

The National Academies reports that AI-driven impersonation has no defensive equivalent. Their answer isn't detection, it's provenance.

By GoFirm

The National Academies of Sciences, Engineering, and Medicine does not publish casually.

When it convenes a rapid expert consultation, sponsored through its Rapid Response to Emerging Science, Engineering, and Medicine Challenges Initiative, the resulting document is read by exactly the people who write policy and exactly the people who brief the people who write policy. On 26 June 2026, three authors with credentials spanning Arizona State University, the National Academy of Engineering, and UC Santa Barbara published one such consultation: Implications of AI for Cybersecurity.

Read it closely and a pattern emerges. Almost every AI-driven cyber capability the report describes has a defensive mirror. Vulnerability discovery has automated patching. Exploitation has continuous, agent-based red teaming. Reconnaissance and threat correlation have AI-assisted threat intelligence. The report calls this dual use: the same technique that lets an attacker find a flaw lets a defender close it first.

Then the authors reach AI-powered impersonation, synthetic identity, and deepfake-driven social engineering, and the pattern breaks. They state it plainly: unlike vulnerability analysis or threat intelligence, there is no direct defensive analog that mirrors this capability. Attacks have moved beyond email and voice scams into fully interactive impersonation in live videoconferences, where an adversary convincingly mimics a trusted colleague in real time. There is no AI tool that detects this with reliability. There is no automated equivalent to patching a deepfake.

The report's verdict on the obvious fix, labelling or watermarking AI-generated content, is blunt. Current techniques are easily circumvented by a motivated adversary, and the authors consider it plausible that AI-generated and human-produced content become indistinguishable in practice. Detection, in other words, is a losing race.

Their one proposed mitigation is a change of question entirely. Instead of asking whether content is real, the report argues organisations should ask whether the action came from a verified source. Cryptographic signatures and strong account authentication can associate a digital action with a confirmed individual regardless of whether AI tools produced the content around it. The report extends this logic to high-risk actions directly, recommending that financial transfers, credential resets, and access approvals be revised to include verification steps resilient to impersonation, naming multi-party authentication by name.

Critically, a federally convened body looked at the fastest-growing category of AI-enabled attack, found that detection cannot keep pace with generation, and concluded that the only durable answer is confirming who is really behind the action before it executes.

That’s what GoFirm does.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

National Academies of Sciences, Engineering, and Medicine. 2026. Implications of AI for Cybersecurity: A Rapid Expert Consultation. Washington, DC: The National Academies Press. https://doi.org/10.17226/29493.

Share this article