Most people believe they can spot deepfakes. The numbers, however, tell a different story. And anyone who relies on their own eyes is defending a position that was lost long ago.
When Propaganda Still Had a Sender
On 9 November 1989, I was sitting in a flight school, preparing for my private pilot licence exam. Suddenly, the flight instructor called us over to the television. We could hardly believe what we saw: crowds of people and little East German Trabant cars streaming across the border into West Berlin.
Back then, what I knew about propaganda was very simple: it had a sender. Aktuelle Kamera, the East German state news programme, lied, and everyone knew it lied. Anyone who could receive West German television only had to switch channels to see the difference. In many parts of East Germany, however, that was impossible, and anyone caught watching faced harsh punishment.
Since reunification, Germany has enjoyed around 36 years of knowing whom to believe. Today, that luxury is over. Because the fake no longer comes from a recognisable broadcaster. Instead, it now greets you by your first name.
Can People Spot Deepfakes? What Germans Believe About Themselves
In spring, Bitkom, Germany’s digital industry association, surveyed 1,006 people in Germany. According to the results, 91 percent have already encountered fake news. Among German internet users, only 2 percent say they have never come across it, whereas in 2023 that figure was still 21 percent.
Two other figures from the same survey are even more revealing. 89 percent consider deepfakes dangerous. At the same time, only 34 percent believe they could recognise one.
Placing these two numbers side by side paints a clear picture. More than half of the respondents consider the danger real while knowing that they would not notice a fake themselves. That is not ignorance, but rather a remarkably honest self-assessment.
In my seminars, however, things look different. When I ask who would recognise a deepfake, almost everyone raises their hand. People point to the eyes, the hands, the tone of voice. Apparently, everyone in the room considers themselves part of the 34 percent.
When did you last see a deepfake so convincing that you did not notice it? You do not know. That is precisely the point.
87 to 33: The Gap in German Organisations
In August, Bitkom also surveyed 1,003 German companies with ten or more employees about hybrid attacks, meaning cyberattacks, sabotage, drones and disinformation. 87 percent consider a serious crisis likely. Only 33 percent believe Germany is well prepared for it.
That ratio sums up the problem.
So far, companies have filled the gap almost entirely with technology: firewalls, monitoring, training platforms. All of that is right, yet it misses the core. The real attack surface lies elsewhere, namely in people’s habits.
What this looks like in practice is shown by the case of a finance employee in Hong Kong who, in early 2024, transferred around 25 million US dollars after a fake video conference. In my own office, too, a deceptively genuine payment instruction arrived in my name. My accountant stopped it only because the round sum of 5,000 euros struck her as odd. Had it been 2,375 euros, she told me later, she would have made the transfer. I describe both cases in detail in my article on CEO fraud.

Deepfakes are becoming increasingly difficult to detect—which is why clear processes and follow-up questions are crucial. Photo: ChatGPT
I Am Not Outside This Problem
To be honest, there is something else I need to add: I work with this technology myself. My own AI avatar cost 300 euros as a lifetime licence. I can produce a news report from Tagesschau, Germany’s leading public news programme, that never actually aired in roughly forty-five minutes. So anyone who believes such fakes require a large budget or special expertise is mistaken.
Instead of Trying to Spot Deepfakes: What Leaders Must Really Do
You will lose the race to recognise fakes. After all, the technology improves every year, whereas your eyes do not. What matters, therefore, is something else: a fake must not be able to trigger anything in your organisation. That requires four things:
- Clear authority and channels. Who may trigger payments, approvals and press statements, and through which route? Put it in writing rather than relying on “that goes without saying”.
- A second channel for everything that moves money or reputation. A callback to the known number is often enough. There are no exceptions for urgent cases, because the supposed emergency is the typical attack pattern.
- Asking questions must cost nothing. If checking with the boss is seen as mistrust in your organisation, you do not have a security gap. You have a leadership gap.
- Prepared routes for the case that you yourself are faked. Who issues the denial, on which channel and how quickly? In a real incident, speed matters more than perfect wording.
No Reason for Alarmism
To avoid any false impression: I have little time for scaremongering. The technology has many positive sides, for example in dubbing, accessibility or training videos in eight languages for the price of one. I use it myself every day.
Moreover, not every fake turns into a crisis. Most come to nothing because someone asks a question. That is precisely why so much depends on whether questions get asked in your organisation.
The next time you see something that confirms your views, outrages you or puts you under pressure, ask yourself one simple question: who benefits if I believe this?
For your organisation, there is also a second one: who in our company would trigger a transfer without calling back even once?
If you do not know the answer, someone else may already know it.

Dr. Nikolai A. Behr CSP® ist Keynote Speaker, Kommunikationsexperte und Medientrainer für Führung, Vertrauen und empathische Kommunikation in Zeiten von Wandel und KI.

