AI for Government
Aware · M21 · lesson 21 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Recognizing AI-Generated Threats
📖
now learning

Recognizing AI-Generated Threats

10 min

Learning Objectives

After completing this lecture, you will be able to:

  • Understand the key concepts of recognizing ai-generated threats in a government context
  • Connect recognizing ai-generated threats to your agency's AI initiatives
  • Identify next steps for applying these concepts in your role

Key Topics Covered

  • Identifying AI-generated phishing emails, deepfake audio/video, and synthetic media
  • Practical detection exercises
  • Government context for recognizing ai-generated threats
  • Practical applications and next steps

Why This Matters for Government

Government agencies face unique challenges when it comes to AI adoption. This lecture addresses these challenges head-on by providing all government employees with the knowledge and frameworks needed to navigate AI in the public sector responsibly and effectively.

As part of the L1 (AI Aware) curriculum, this lecture builds on the foundational principle that every AI system in government ultimately serves citizens. Whether you are working with AI tools daily or setting strategy for your agency, understanding recognizing ai-generated threats is essential for responsible, effective government AI adoption.

Lecture URL: https://skill.re/learn/govt/recognizing-ai-generated-threats.php

======================================================================

TRANSCRIPT: Recognizing AI-Generated Threats

======================================================================

What you will learn: Identifying AI-generated phishing emails, deepfake audio/video, and synthetic media. Red flags and indicators.

Now that we understand the threats, let's talk about how to spot them. What are the telltale signs that something is AI-generated or manipulated?

Some are obvious. Some are subtle. The more you understand the indicators, the better you can defend yourself and your agency.

WHY THIS MATTERS FOR GOVERNMENT

Spotting AI-generated threats before you fall for them is critical to security. The first line of defense is human judgment and awareness.

IDENTIFYING AI-GENERATED PHISHING

Subtle Errors:

AI-generated text is often slightly off in ways that are hard to pinpoint.

Look for:

  • Unusual word choices in formal emails
  • Grammar that's technically correct but phrasing is slightly awkward
  • Tone that doesn't quite match what you'd expect from that person
  • Formatting inconsistencies

Over-Formality or Over-Informality:

AI sometimes generates text that's either too formal or too casual for the context.

Genuine colleague: "Hey, can you send me the Q3 report?"

AI-generated: "I am writing to request that you transmit the quarterly report for Q3."

Or: "yo can u send me that report bro?" (tone doesn't fit a work context)

Generic Personalization:

The email uses your name but little else personal. Real phishing often researches specific details about you.

AI might: "Hi Sarah, I'm reaching out about your recent project" (uses your name, but "your recent project" is vague—not researched)

More convincing phishing: "Hi Sarah, Great work on the infrastructure bill analysis you mentioned in the city council briefing last week..."

Awkward Requests:

AI sometimes makes requests that don't quite make sense for the context.

"Please confirm your password and recent transactions." (Why would someone ask this?)

Suspicious Links:

The link might be slightly misspelled or use a URL-shortening service (which hides the real destination).

IDENTIFYING DEEPFAKES (VIDEO/AUDIO)

Video Deepfakes:

Look for:

  • Unnatural eye movement
  • Inconsistent lighting between the face and background
  • Subtle glitches in movement (AI sometimes creates unnatural jittering)
  • Lack of detailed background (AI sometimes simplifies background details)
  • Unnaturally smooth transitions
  • Synchronized lip-sync issues (off by a frame or two)
  • Inconsistent skin texture

Voice Clones:

Look for:

  • Unnatural pacing or rhythm
  • Lack of natural breathing between sentences
  • Slightly robotic quality (improving but still sometimes noticeable)
  • Missing natural verbal fillers ("um," "uh")
  • Unusual emphasis or intonation

What Makes Detection Hard:

Deepfakes are improving rapidly. What was obviously fake 2 years ago is convincing now. In a few years, they might be indistinguishable from real.

For this reason, verification through independent channels is more reliable than trying to spot the fakes yourself.

VERIFICATION STRATEGIES

Instead of trying to spot deepfakes, verify through independent channels:

For Written Communication:

  • If an email asks you to do something unusual, call the person using a phone number you know is correct
  • Ask questions only the real person would know
  • Verify through another method of communication

For Video/Audio:

  • If you receive video of a public official, verify it through official channels or trusted news sources
  • If you receive audio of someone, call them and ask if they made that statement
  • Check official websites or social media for authentic versions

For Claims:

  • If the communication makes a factual claim, verify it independently
  • Check official agency sources
  • Don't rely on the communication itself to verify

ANTI-PATTERNS / MISUSE RISKS

Anti-Pattern 1: Relying on Your Ability to Spot Deepfakes

You think you're good at spotting deepfakes so you accept video evidence without verification.

Risk: Future deepfakes will be too convincing. You'll be fooled.

Anti-Pattern 2: Assuming Deepfakes Will Be Obviously Fake

You assume that if something's important, you'll be able to tell if it's a deepfake.

Risk: Sophisticated deepfakes are not obviously fake. You'll believe them.

Anti-Pattern 3: Trusting Source Without Verification

You receive phishing that appears to come from your agency's IT department, so you trust it.

Risk: Attackers spoof official email addresses and create convincing forgeries.

PRACTICE / REFLECTION PROMPTS

  • Look at recent emails you've received. Are any of them suspicious? Apply the indicators discussed in this lecture.
  • If you received a video of a senior government official making a controversial statement, what would you do to verify it?
  • In your agency, what's the official process for verifying a communication from leadership?

KEY TAKEAWAYS

  • AI-generated phishing often has subtle errors in tone, pacing, or word choice.
  • Deepfakes have telltale indicators (eye movement, lighting, lip-sync), but these indicators are improving.
  • The most reliable defense is verification through independent channels.
  • Don't rely on your ability to spot fakes—future fakes will be too good.
  • When in doubt, verify independently.

TERMS / GLOSSARY ITEMS

Deepfake: AI-generated synthetic media made to appear authentic.

Lip-Sync: Synchronization between audio and lip movement in video.

Synthetic Media: Audio, video, or images created or manipulated by AI.

Spoofing: Forging the source of a communication to appear to come from a legitimate entity.

You receive a video allegedly showing a city council member accepting a bribe. The video is HD quality, looks professional. The member denies it.

What do you do?

  • Don't share it yet. Don't spread potential deepfake content.
  • Check official sources. Has the legitimate media reported on this? Has the council member responded officially?
  • Look for indicators. Watch for the deepfake telltales (eye movement, lighting, lip-sync issues).
  • Verify independently. If this is important, news organizations will investigate and verify.
  • Wait for credible verification. Don't act on or share the video until it's been authenticated by credible sources.

That's responsible handling of potentially AI-generated threats.

10 minutes.

Find an example of a deepfake (YouTube has some educational examples). Watch it carefully. What indicators suggest it's AI-generated? What aspects are convincing?

This trains your eye to spot AI-generated media.

Recognition of AI-generated threats is important, but verification is more important. Don't trust your ability to spot fakes. Instead, develop the habit of verifying important communications and media through independent channels.

Level 1: AI Aware | How AI Changes the Threat Landscape | Lecture 4.2

A GOVT.CLUB initiative.

<- 1.4.1 How AI Changes the Threat Landscape 1.4.3 Data Leakage: When Sensitive Info Enters AI ->

Start Your CLUB Certification

This lecture is part of L1: AI Aware—8 hours of comprehensive government AI training.

L1 1.4.1—How AI Changes the Threat Landscape 10 min - Video

L1 1.4.3—Data Leakage: When Sensitive Info Enters AI 10 min - Video + Scenarios

L1 1.4.4—Approved vs. Shadow AI 10 min - Video + Policy

Frequently Asked Questions

What will I learn in Recognizing AI-Generated Threats?

In this 10 min video + exercises lecture, you will Identifying AI-generated phishing emails, deepfake audio/video, and synthetic media. Practical detection exercises

What level is Recognizing AI-Generated Threats?

This is a Level 1 (AI Aware) lecture, part of Chapter 1.4 \u2014 Safety and Security. It is designed for all government employees.

How long is lecture 1.4.2?

Lecture 1.4.2 (Recognizing AI-Generated Threats) takes 10 min. It is delivered as a video + exercises format.

Do I need prerequisites for Recognizing AI-Generated Threats?

This lecture is part of L1 (AI Aware). Prerequisites: None.

What is the CLUB Certification?

CLUB (Community Leading Unified Benchmarks) is a maturity-based AI certification for government professionals with 5 levels (L1-L5), 215 lectures, and 25 chapters aligned with NIST AI RMF, OMB, and GAO frameworks.