Feb 28, 2025 · 22m · a16z
How to spot an AI Deepfake
gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions
In this episode of the a16z podcast, host Joel de la Garza and Adaptive Security CEO Brian Long explore how open-source AI and deepfakes are accelerating social engineering threats, emphasizing the urgent need to revolutionize workforce security training and protect the human layer.
How this conversation actually went
Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →
speaking balance: gold is the host, purple is the guest (3 minute bins)
Brian directly critiques security industry leaders for their ego in assuming systems can replace securing human vulnerabilities.
Hardest push from the host ▶ 9:50 Exposing the training ROI paradoxJoel challenges standard industry practices by framing compliance-driven training as a 'dirty little secret' that yields high ROI on paper but fails in execution.
Biggest teaching moment ▶ 4:51 Voicemail audio cloning warningBrian educates listeners on how just a few seconds of voicemail greeting audio provides enough training data for threat actors to execute voice clones.
The host holds their own ▶ 12:20 Incident responder chat log evidenceJoel showcases deep domain knowledge as a former incident manager by explaining how scammer group chat logs revealed deliberate grammatical errors to filter targets.
the scores for every segment, with the reasoning behind each
| Chapter | Topic | The host as informed peer | Guest teaching | Guest disagreement | The host pushing back | Why |
|---|---|---|---|---|---|---|
| The Acceleration of AI-Driven Social Engineering Attacks | 5 | 6 | 1 | 1 | Joel provides a relevant real-world story about a virtual kidnapping attempt via voice cloning to frame his question. Brian educates listeners with statistics on social engineering growth and gives immediate practical advice on removing custom voicemail greetings to prevent audio scraping. | |
| Addressing Corporate Vulnerabilities and Legacy Security Training | 4 | 5 | 2 | 1 | Joel cites specific enterprise scam tactics like executive impersonation texts and wire transfer fraud. Brian highlights the hubris of security teams focusing on systems over people and explains how legacy compliance training fails through 'rage clicking'. | |
| Transforming Security Education through AI and OSINT | 6 | 4 | 1 | 2 | Joel demonstrates industry expertise by identifying the security spend vs ROI paradox of awareness training and sharing a personal example of ignoring compliance emails. Brian details why legacy vendor modules fail and how AI and OSINT can personalize corporate education. | |
| Autonomous AI Attack Agents and Critical Infrastructure Risks | 7 | 5 | 1 | 1 | Joel draws directly on his past career as an incident manager, describing insights from scammer chat logs where typos were used deliberately to filter targets. Brian expands on autonomous attack agents and potential critical infrastructure threats like the deepfaked Senate Foreign Relations incident. | |
| Infiltration Risks and Immersive AI Simulation Training | 6 | 4 | 1 | 2 | Joel highlights foreign state-sponsored employment scams infiltrating tech companies and questions the efficacy of point-in-time compliance. Brian agrees and recounts a notable incident where a legacy security training vendor inadvertently hired a North Korean operative. | |
| Defensive AI Agents and Protecting the Human Layer | 6 | 4 | 1 | 0 | Joel details the tactical steps of remote worker onboarding exploitation and asks about defensive AI companions. Brian outlines how AI agents will serve on defense in an ongoing arms race and provides closing resource recommendations. |