Feb 28, 2025 · 22m · a16z

How to spot an AI Deepfake

Brian C. Long · 14m spoken Joel de la Garza · 6m spoken Brian Long · 0s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z podcast, host Joel de la Garza and Adaptive Security CEO Brian Long explore how open-source AI and deepfakes are accelerating social engineering threats, emphasizing the urgent need to revolutionize workforce security training and protect the human layer.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 5.7 Guest teaching 4.7 Guest disagreement 1.2 The host pushing back 1.2
05100:0010:0020:002:01–6:12 · The host as informed peer 5/10 The Acceleration of AI-Driven Social Engineering Attacks Joel provides a relevant real-world story about a virtual kidnapping attempt via voice cloning to frame his question. Brian educates listeners with statistics on social engineering growth and gives immediate practical advice on removing custom voicemail greetings to prevent audio scraping.6:12–9:50 · The host as informed peer 4/10 Addressing Corporate Vulnerabilities and Legacy Security Training Joel cites specific enterprise scam tactics like executive impersonation texts and wire transfer fraud. Brian highlights the hubris of security teams focusing on systems over people and explains how legacy compliance training fails through 'rage clicking'.9:50–12:20 · The host as informed peer 6/10 Transforming Security Education through AI and OSINT Joel demonstrates industry expertise by identifying the security spend vs ROI paradox of awareness training and sharing a personal example of ignoring compliance emails. Brian details why legacy vendor modules fail and how AI and OSINT can personalize corporate education.12:20–17:00 · The host as informed peer 7/10 Autonomous AI Attack Agents and Critical Infrastructure Risks Joel draws directly on his past career as an incident manager, describing insights from scammer chat logs where typos were used deliberately to filter targets. Brian expands on autonomous attack agents and potential critical infrastructure threats like the deepfaked Senate Foreign Relations incident.17:00–19:26 · The host as informed peer 6/10 Infiltration Risks and Immersive AI Simulation Training Joel highlights foreign state-sponsored employment scams infiltrating tech companies and questions the efficacy of point-in-time compliance. Brian agrees and recounts a notable incident where a legacy security training vendor inadvertently hired a North Korean operative.19:26–21:32 · The host as informed peer 6/10 Defensive AI Agents and Protecting the Human Layer Joel details the tactical steps of remote worker onboarding exploitation and asks about defensive AI companions. Brian outlines how AI agents will serve on defense in an ongoing arms race and provides closing resource recommendations.2:01–6:12 · Guest teaching 6/10 The Acceleration of AI-Driven Social Engineering Attacks Joel provides a relevant real-world story about a virtual kidnapping attempt via voice cloning to frame his question. Brian educates listeners with statistics on social engineering growth and gives immediate practical advice on removing custom voicemail greetings to prevent audio scraping.6:12–9:50 · Guest teaching 5/10 Addressing Corporate Vulnerabilities and Legacy Security Training Joel cites specific enterprise scam tactics like executive impersonation texts and wire transfer fraud. Brian highlights the hubris of security teams focusing on systems over people and explains how legacy compliance training fails through 'rage clicking'.9:50–12:20 · Guest teaching 4/10 Transforming Security Education through AI and OSINT Joel demonstrates industry expertise by identifying the security spend vs ROI paradox of awareness training and sharing a personal example of ignoring compliance emails. Brian details why legacy vendor modules fail and how AI and OSINT can personalize corporate education.12:20–17:00 · Guest teaching 5/10 Autonomous AI Attack Agents and Critical Infrastructure Risks Joel draws directly on his past career as an incident manager, describing insights from scammer chat logs where typos were used deliberately to filter targets. Brian expands on autonomous attack agents and potential critical infrastructure threats like the deepfaked Senate Foreign Relations incident.17:00–19:26 · Guest teaching 4/10 Infiltration Risks and Immersive AI Simulation Training Joel highlights foreign state-sponsored employment scams infiltrating tech companies and questions the efficacy of point-in-time compliance. Brian agrees and recounts a notable incident where a legacy security training vendor inadvertently hired a North Korean operative.19:26–21:32 · Guest teaching 4/10 Defensive AI Agents and Protecting the Human Layer Joel details the tactical steps of remote worker onboarding exploitation and asks about defensive AI companions. Brian outlines how AI agents will serve on defense in an ongoing arms race and provides closing resource recommendations.2:01–6:12 · Guest disagreement 1/10 The Acceleration of AI-Driven Social Engineering Attacks Joel provides a relevant real-world story about a virtual kidnapping attempt via voice cloning to frame his question. Brian educates listeners with statistics on social engineering growth and gives immediate practical advice on removing custom voicemail greetings to prevent audio scraping.6:12–9:50 · Guest disagreement 2/10 Addressing Corporate Vulnerabilities and Legacy Security Training Joel cites specific enterprise scam tactics like executive impersonation texts and wire transfer fraud. Brian highlights the hubris of security teams focusing on systems over people and explains how legacy compliance training fails through 'rage clicking'.9:50–12:20 · Guest disagreement 1/10 Transforming Security Education through AI and OSINT Joel demonstrates industry expertise by identifying the security spend vs ROI paradox of awareness training and sharing a personal example of ignoring compliance emails. Brian details why legacy vendor modules fail and how AI and OSINT can personalize corporate education.12:20–17:00 · Guest disagreement 1/10 Autonomous AI Attack Agents and Critical Infrastructure Risks Joel draws directly on his past career as an incident manager, describing insights from scammer chat logs where typos were used deliberately to filter targets. Brian expands on autonomous attack agents and potential critical infrastructure threats like the deepfaked Senate Foreign Relations incident.17:00–19:26 · Guest disagreement 1/10 Infiltration Risks and Immersive AI Simulation Training Joel highlights foreign state-sponsored employment scams infiltrating tech companies and questions the efficacy of point-in-time compliance. Brian agrees and recounts a notable incident where a legacy security training vendor inadvertently hired a North Korean operative.19:26–21:32 · Guest disagreement 1/10 Defensive AI Agents and Protecting the Human Layer Joel details the tactical steps of remote worker onboarding exploitation and asks about defensive AI companions. Brian outlines how AI agents will serve on defense in an ongoing arms race and provides closing resource recommendations.2:01–6:12 · The host pushing back 1/10 The Acceleration of AI-Driven Social Engineering Attacks Joel provides a relevant real-world story about a virtual kidnapping attempt via voice cloning to frame his question. Brian educates listeners with statistics on social engineering growth and gives immediate practical advice on removing custom voicemail greetings to prevent audio scraping.6:12–9:50 · The host pushing back 1/10 Addressing Corporate Vulnerabilities and Legacy Security Training Joel cites specific enterprise scam tactics like executive impersonation texts and wire transfer fraud. Brian highlights the hubris of security teams focusing on systems over people and explains how legacy compliance training fails through 'rage clicking'.9:50–12:20 · The host pushing back 2/10 Transforming Security Education through AI and OSINT Joel demonstrates industry expertise by identifying the security spend vs ROI paradox of awareness training and sharing a personal example of ignoring compliance emails. Brian details why legacy vendor modules fail and how AI and OSINT can personalize corporate education.12:20–17:00 · The host pushing back 1/10 Autonomous AI Attack Agents and Critical Infrastructure Risks Joel draws directly on his past career as an incident manager, describing insights from scammer chat logs where typos were used deliberately to filter targets. Brian expands on autonomous attack agents and potential critical infrastructure threats like the deepfaked Senate Foreign Relations incident.17:00–19:26 · The host pushing back 2/10 Infiltration Risks and Immersive AI Simulation Training Joel highlights foreign state-sponsored employment scams infiltrating tech companies and questions the efficacy of point-in-time compliance. Brian agrees and recounts a notable incident where a legacy security training vendor inadvertently hired a North Korean operative.19:26–21:32 · The host pushing back 0/10 Defensive AI Agents and Protecting the Human Layer Joel details the tactical steps of remote worker onboarding exploitation and asks about defensive AI companions. Brian outlines how AI agents will serve on defense in an ongoing arms race and provides closing resource recommendations.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 7:09 Calling out tech industry hubris

Brian directly critiques security industry leaders for their ego in assuming systems can replace securing human vulnerabilities.

Hardest push from the host ▶ 9:50 Exposing the training ROI paradox

Joel challenges standard industry practices by framing compliance-driven training as a 'dirty little secret' that yields high ROI on paper but fails in execution.

Biggest teaching moment ▶ 4:51 Voicemail audio cloning warning

Brian educates listeners on how just a few seconds of voicemail greeting audio provides enough training data for threat actors to execute voice clones.

The host holds their own ▶ 12:20 Incident responder chat log evidence

Joel showcases deep domain knowledge as a former incident manager by explaining how scammer group chat logs revealed deliberate grammatical errors to filter targets.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
The Acceleration of AI-Driven Social Engineering Attacks 5611 Joel provides a relevant real-world story about a virtual kidnapping attempt via voice cloning to frame his question. Brian educates listeners with statistics on social engineering growth and gives immediate practical advice on removing custom voicemail greetings to prevent audio scraping.
Addressing Corporate Vulnerabilities and Legacy Security Training 4521 Joel cites specific enterprise scam tactics like executive impersonation texts and wire transfer fraud. Brian highlights the hubris of security teams focusing on systems over people and explains how legacy compliance training fails through 'rage clicking'.
Transforming Security Education through AI and OSINT 6412 Joel demonstrates industry expertise by identifying the security spend vs ROI paradox of awareness training and sharing a personal example of ignoring compliance emails. Brian details why legacy vendor modules fail and how AI and OSINT can personalize corporate education.
Autonomous AI Attack Agents and Critical Infrastructure Risks 7511 Joel draws directly on his past career as an incident manager, describing insights from scammer chat logs where typos were used deliberately to filter targets. Brian expands on autonomous attack agents and potential critical infrastructure threats like the deepfaked Senate Foreign Relations incident.
Infiltration Risks and Immersive AI Simulation Training 6412 Joel highlights foreign state-sponsored employment scams infiltrating tech companies and questions the efficacy of point-in-time compliance. Brian agrees and recounts a notable incident where a legacy security training vendor inadvertently hired a North Korean operative.
Defensive AI Agents and Protecting the Human Layer 6410 Joel details the tactical steps of remote worker onboarding exploitation and asks about defensive AI companions. Brian outlines how AI agents will serve on defense in an ongoing arms race and provides closing resource recommendations.

Statements from this episode (17)

Assertion Supported
Long: Social engineering attacks rose over 4x since ChatGPT launch
“So since ChatGPT came out a little over two years ago, we've seen over a four X increase in social engineering attacks.”
Brian C. Long Feb 28, 2025 ▶ 2:09
Assertion Not publicly verifiable
Long: US recorded over 100,000 deepfake attacks in 2024
“Where in the United States in 20, 24, we saw over a 100,000 deep fake attacks.”
Brian C. Long Feb 28, 2025 ▶ 2:18
Prediction Not checkable as stated
Long: Everyone will experience a deepfake attack within a year
“And I think that's gonna end up being the, you know, the answer that everyone's gonna experience it in the next year or so.”
Brian C. Long Feb 28, 2025 ▶ 2:43
Assertion Not checkable as stated
Long: New AI models enable scalable attacks across voice, SMS, and video
“So, you know, whether that's voice or SMS or video or chats all of those can now be done at scale where, you know, previously I think it would have been cost prohibitive.”
Brian C. Long Feb 28, 2025 ▶ 3:41
Assertion Supported
Long: Modern AI models only need a voicemail greeting to replicate voices
“Because now with these models, that's all they need in order to do the replication of your voice.”
Brian C. Long Feb 28, 2025 ▶ 5:04
Prediction Not checkable as stated
Long: Avoiding unknown callers to prevent voice cloning will become standard
“And that sounds like a crazy comment now, but I'm betting pretty strong that in five years this will be a very normal thing people think about.”
Brian C. Long Feb 28, 2025 ▶ 6:01
Assertion Partly supported
Long: Nearly 90% of cyberattacks still originate through human vectors
“The reality is that almost 90% of attacks still come through people.”
Brian C. Long Feb 28, 2025 ▶ 7:51
Assertion Not checkable as stated
De la Garza: Security training offers highest ROI in CISO portfolio
“If you actually look at, I spend X dollars and I present Y, prevent Y breaches, training and awareness is by far the best ROI of the entire portfolio that a CISO has.”
Joel de la Garza Feb 28, 2025 ▶ 9:51
Assertion Not checkable as stated
Long: 90% of legacy cybersecurity training content is irrelevant
“90% of the content's not relevant.”
Brian C. Long Feb 28, 2025 ▶ 10:59
Prediction Not checkable as stated
Long: AI will enable cybercriminals to deploy autonomous attack agents at scale
“Now with AI, they can lever themselves up and they can make, you know, infinite numbers of themselves as agents to go out and do these types of attacks autonomously. And it's going to be very, very profitable for them. So they're going to have lots of money to…”
Brian C. Long Feb 28, 2025 ▶ 13:41
Insight
Long: Bad security training signals that company security is unimportant
“When the training is kind of a joke at the company, I think it also sends a signal to all of the employees that the company's security posture is also not very important.”
Brian C. Long Feb 28, 2025 ▶ 14:29
Prediction Open · timeframe Feb 2027
Long: AI cyberattacks will disable critical infrastructure within two years
“I think what I'm really worried about is that when you're going to see this actually transition to people being actively hurt you know, hospitals being taken down, energy systems taken offline, other things like that. Obviously we've had cases of that already …”
Brian C. Long Feb 28, 2025 ▶ 15:41
Assertion Partly supported
Long: Deepfake Russian official targeted the Senate Foreign Relations Chairman
“Example that I brought up in a recent post that I feel like was just kind of overlooked. Maybe you covered at some point. I don't know, but overlooked in the broader media was when someone used to deep fake in order to call up the chairman of the foreign relat…”
Brian C. Long Feb 28, 2025 ▶ 16:25
Assertion Supported
De la Garza: Foreign hackers infiltrate Silicon Valley via remote jobs
“You've got active groups of foreign, probably foreign state sponsored hackers Getting employment at Silicon Valley tech companies showing up for day one and, you know, walking away with all the secrets and then disappearing, right?”
Joel de la Garza Feb 28, 2025 ▶ 17:10
Insight
Long: Security training is ineffective unless it is jarring to users
“One, I think training should be personalized to you and it should really engage and hopefully be jarring to you. If it's not jarring in some way, then it's not really working.”
Brian C. Long Feb 28, 2025 ▶ 17:46
Assertion Supported
Long: A legacy security training company unwittingly hired a North Korean operative
“One of the legacy training companies actually came out a few months ago and said that they actually had someone from North Korea that I think they may have employed or that got into their systems or something.”
Brian C. Long Feb 28, 2025 ▶ 19:08
Prediction Not checkable as stated
Long: Protective AI will beat malicious attack agents over next decade
“So yes, I do think that you're going to see a lot of that AI being used for very good to protect. And you know, we're going to be fighting each other over the next decade plus, and I'm confident that we're going to went over it”
Brian C. Long Feb 28, 2025 ▶ 21:07
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.