5 questions directors should ask CEOs about AI fraud and deepfakes

Thursday, 16 July 2026

Jane Nicholls photo
Jane Nicholls
Journalist
    Current

    As cyber risks – including AI deepfakes – evolve rapidly, boards must actively engage with their leadership teams to continuously evaluate their cybersecurity posture. 


    The next wave of cyber threats is harder to detect, easier to deploy and makes old-fashioned phishing scams look positively quaint. Regulators warn that the rise of deepfake technology puts the threat to corporate governance at a “minute to midnight”. Cloned voices and video calls, AI-generated emails and synthetic identities have upped the ante for fraud targeting executives, directors and governance processes. 

    “ASIC’s message is straightforward: Do not wait for perfect clarity to address the threat posed by new AI models,” said ASIC commissioner Simone Constant in an open letter to licensees and directors in May. “Instead, act now, and act with discipline, to strengthen the cyber resilience fundamentals that underpin your business.”

    The Australian Signals Directorate (ASD) and the AICD collaborated to produce director-specific guidance, Cyber security priorities for boards 2025-26. To keep their organisations safe, directors must educate themselves and move away from accepting generic updates and instead ask CEOs for specific responses about cybersecurity measures. Here are five key questions.

    1. Are we eliminating out-of-band communication for financial approvals?

    Humans are famously the weakest link in any cybersecurity scenario, especially now AI has joined the deception squad. 

    “AI-enabled deepfakes can look incredibly polished and indistinguishable to how you know your CEO might talk or how they may craft an email,” says Emma Maley GAICD, who spent more than 15 years in senior cybersecurity and resilience roles at CommBank and the RBA before becoming a board adviser and NED. 

    Maley says technology eliminates excuses for bypassing secure platforms. “There is no longer the excuse that secure workflow patterns aren’t accessible when out of the office or travelling – all of the authorisation processes can be done from your phone if you’ve got the platforms in place to enforce identity, logging and the approval process.” Directors must ensure the CEO strictly mandates platform-based authorisations and forbids “out-of-band” (OOO) actions via a separate channel. 

    SMEs lack the cybersecurity budgets of big corporates, which potentially makes them even more at risk. The AICD worked with the Australian Cyber Security Centre to produce this governance principles checklist to help SME and NFP directors assess the maturity of their organisation. 

    2. Have we established a culture where verification is expected at every level?

    A resilient corporate posture relies heavily on a fundamental cultural shift regarding verification protocols. Particularly in SMEs, employees are hesitant to question an urgent demand that appears to originate from an executive or board member, a psychological vulnerability that deepfakes exploit. Which is why there can be no exceptions to the OOO mandate. 

    “You can’t be allowed to go out-of-band just because you’re the CEO or the chair,” says Maley. Boards must ensure staff are receiving targeted education, particularly in a hybrid working world. “Voice cloning has become so much more common, and we can no longer just trust what we’re seeing,” says Valeska Bloch, partner and head of cyber at international commercial law firm Allens. 

    “Additional controls need to be applied to verify the people we think we’re talking to, whether that’s on the phone or video conferencing.” 

    3. What’s our cyber incident simulation program?

    For listed organisations, the operational complexity of a cyber crisis demands coordinated, rapid responses that cannot be developed through simple paperwork reviews. Yet, boards frequently fail to practice these scenarios. 

    “There are still a lot of boards that have never participated in a cyber simulation, or do it once every few years,” says Bloch, adding that boards need to appreciate that cyber risks are different to the risks of a natural disaster or a cultural incident. 

    “The pace of change in the threat environment, the technology infrastructure and how that impacts various stakeholders internally and externally is so different from year to year – sometimes even within six months.”

    It’s critical to develop muscle memory to cope with a cyber incident and to do so, large organisations must implement diverse, recurring simulation programs. “One might be for the incident response team, another might be more focused on the key decisions the board will need to make in that context,” says Bloch. “The idea is that there is broad familiarity with the processes and the playbooks, and an opportunity to identify in a simulation where there are gaps or where there are decisions that actually could be made in advance of an incident.” 

    4. Do our risk frameworks account for the speed, scale and vulnerability chaining of frontier AI?

    Directors must challenge the CEO around whether traditional audit and risk frameworks can withstand the automated cyber threats of cutting-edge attacks, known as frontier AI, such as Anthropic’s Claude Mythos. 

    “In the wrong hands, frontier AI can autonomously find and exploit previously unknown security vulnerabilities,” says Bloch. Reporting must shift toward “ensuring that boards are getting meaningful reporting, not just on activity, but also on the end-to-end control effectiveness,” she adds.

    “Sometimes assessments are undertaken to check whether a control works or not, but it doesn’t necessarily check whether it’s protecting the right thing. The capability of these frontier AI technologies to chain together vulnerabilities to create a clear path of attack in a way that hasn’t been possible previously means that boards need to have a broad perspective over these issues across the organisation.”

    Frontier AI is top of mind for ASIC. In the wake of the finding against FIIG Securities Limited for cybersecurity failures, the regulator reminded companies that it “reinforced the legal case for cyber risk management controls to be demonstrably effective and proportionate to the size, nature and complexity of a business”. 

    5. What is our playbook if a fake announcement or statement is made in our name?

    When an advanced deepfake targets a major public corporation, the reputational fallout can be instant. 

    “Deepfakes are being used to put out statements that appear to come from a CEO or a board chair, but it’s fabricated,” says Maley. “It can lead to market movements and community and customer backlash, and erode confidence very quickly.” Deepfakes are also used in investment scams, with fabricated endorsements from prominent businesspeople, such as Andrew Forrest, who recently criticised Meta for allowing the publication of a deepfake video of him spruiking a fake cryptocurrency scheme. 

    Because social media platforms often fail to remove such “synthetic media” quickly, says Maley, management must have a playbook in place to counter reputational and even legal exposure. 

    “The board must ask how our organisation will respond quickly when these things happen. What is our process to take down that media, are our legal teams across how to request removal, and do we have a public statement pretty much ready to go to correct anything fake that’s put out there?” 

    Latest news

    This is of of your complimentary pieces of content

    This is exclusive content.

    You have reached your limit for guest contents. The content you are trying to access is exclusive for AICD members. Please become a member for unlimited access.