Deepfake response plan for communications teams: protecting institutional trust, not just managing the crisis

Communications team responding to a suspected deepfake incident in an institutional office, showing pressure, coordination and the need to protect public trust.

When a deepfake involving your organisation emerges, the instinct is to treat it as a technical emergency: find the fake content, prove it is fake, and move on. That instinct is understandable. However, in most cases, it is also insufficient. A deepfake response plan for communications teams is not primarily a detection tool.

It is a trust management tool.

The synthetic video or audio is the trigger. What determines the actual damage is what your organisation does (and fails to do) in the hours that follow. That is a communications decision, not a cybersecurity one.

This matters particularly for institutions that depend on credibility, such as NGOs, public bodies, international organisations, and advocacy groups. For them, a deepfake is not just a reputational setback. It is a direct attack on the infrastructure that enables their communication.

Why a deepfake is a crisis of institutional trust rather than a technical problem

Most online content about deepfakes focuses on detection: how to identify them, which tools to use, and what visual artefacts to look for. That approach makes sense for IT and security teams. For communications teams, it overlooks the essential.

Research published in Frontiers in Psychology found that exposure to deepfakes depicting institutional failures increases public distrust of government, even after the content has been debunked. The correction comes too late, or not at all, because the emotional impression has already been formed. This is the real risk: not the fake content itself, but the void of trust it creates.

UNESCO put it precisely in October 2025: deepfakes threaten institutional trust at its very foundations, not as isolated incidents but as symptoms of a deeper fragility in how organisations produce, validate, and share knowledge. The implication for communications teams is clear: the response to deepfakes cannot be purely reactive. It must be rooted in something the audience already trusts: the organisation’s track record, transparency, and consistency under pressure.

Why deepfakes are particularly dangerous for organisations with a social mission

For institutions working on sensitive issues — public policy, humanitarian action, advocacy, social change — a deepfake poses a specific risk that commercial organisations face to a lesser extent: it turns the credibility that the organisation itself has built into a weapon. A synthetic video of a corporate CEO is damaging, but a synthetic video of a humanitarian director appearing to contradict the organisation’s stated values, or of a public official seeming to endorse something they did not support, operates on a completely different level.

The damage does not depend on legal liability; it depends on perceived control. Audiences judge organisations primarily on whether they appeared to have the situation under control. That perception is formed in the first few hours, which is precisely why a response plan matters more than a detection tool.

What to do in the first two hours, the first 24 hours and the first seven days following a deepfake incident

The most practical way to build a deepfake response plan is through a timeline (with different decisions belonging to different phases), and confusing them under pressure is where most responses fail.

According to research on organisational preparedness, over 80% of organisations have no formal protocol for managing deepfake incidents. That absence does not mean nothing is done: it means that improvisation fills the void. And improvisation, under the time pressure of synthetic content spreading, tends to produce the three most common mistakes: responding too quickly, saying too much, or saying it through the wrong voice.

The first 2 hours: verify, contain and decide who speaks

The first two hours are not for public communication. They are for internal clarity.

Verify before responding. Confirming that the content is genuinely synthetic before acting is not bureaucratic caution: it is the basis of a credible response. A correction that retracts because the content turned out to be real is more damaging than a delayed initial statement.

Contain the internal narrative. Designate a single point of coordination. Having several people speak internally, each with different interpretations of the situation, is how contradictory messages reach the public.

Decide who speaks and who does not. Not every deepfake requires the organisation’s most senior voice. Sometimes, such escalation can amplify the incident rather than resolve it. The decision of who speaks and at what level is a strategic decision, not a default option.

Communications officer reviewing information in the first hours after a deepfake incident, focusing on verification, internal clarity and deciding who should speak.

The first 24 hours: a clear and consistent message across all channels

The first public statement does not need to be exhaustive. It needs to be precise, calm and consistent across all the channels your organisation uses. A message that appears differently on the website, on social media, and in responses to the media signals disorganisation, which, in itself, damages credibility.

Three elements that every initial statement must always include: what you know (only confirmed facts), what you are doing (concrete next steps, not vague reassurances) and where to find updated information (a single source of truth that your audience can return to).

What it should not include: speculation about who is responsible, technical explanations of how deepfakes work, or language that over-escalates the incident.

The first 7 days: closing the loop and learning publicly

By the seventh day, the immediate crisis may have passed, but the work of rebuilding trust is not over. The transparency obligations of the EU AI Regulation, which comes into force in August 2026, responsibilities. Beyond regulatory compliance, there is a more fundamental reason to close the loop: audiences remember whether organisations explained what happened and what they changed as a result.

A brief public account — not a lengthy post-mortem, but a clear statement of what happened, how the organisation responded and what it has put in place — is the difference between an incident that erodes trust and one that, if well managed, can strengthen it.

How to respond to a deepfake without exacerbating the crisis: the three most costly communication mistakes

Experience in institutional crisis communication (not specific to deepfakes, but directly applicable) reveals three recurring mistakes that systematically amplify the damage rather than containing it.

Over-denial: why repeating false content spreads it further.

The instinct to refute in detail is understandable. In most cases, it is also counterproductive. Repeating the false content, even to deny it, increases its reach. The framing that works is not “this video is fake because of X, Y and Z”, but a clear statement of what is true, backed by credible evidence, without giving the synthetic content any more visibility than it already has.

Changing the spokesperson mid-response

Changing the person speaking on behalf of the organisation during an active incident signals internal disagreement or a loss of control, regardless of the actual reason. Audiences interpret this as instability. If the response plan does not designate a clear spokesperson before an incident occurs, this mistake is almost inevitable.

Treating silence as a neutral stance

In the absence of a clear institutional voice, other voices fill the void: the media, critics, and the synthetic content itself. Silence is not neutral; it is an abdication of the narrative. The question is not whether to communicate, but how to communicate accurately rather than hastily.

What communications teams should prepare before a deepfake incident occurs

Only 32% of executives believe their organisation is prepared to manage a deepfake incident. That figure is consistent with a broader pattern: organisations plan for financial, reputational and operational risk, but treat synthetic media as someone else’s problem: a cybersecurity issue, an IT matter, a question of platform moderation.

It is not. It is a communications issue with institutional consequences.

Three decisions that need to be made before they are needed

Who has the authority to activate the response plan? Not who drafts the statement, but who has the organisational authority to say “we are facing a deepfake incident and this is our response”. That authority needs to be designated in advance, not negotiated under pressure.

What is your pre-approved template for the first statement? Not the final message, but the structure and tone that any initial statement will follow. A template reviewed in calm conditions is more coherent than one drafted in the first ninety minutes of an active incident.

How do you protect your team members who appear in the deepfake? If the deepfake involves a staff member or partner, rather than the organisation as a whole, the response plan must include a clear commitment to that person: what support they receive, how their safety is prioritised, and how the organisation’s public response does not inadvertently increase their exposure. The transparency framework of the EU’s AI Regulation is beginning to set standards here, but organisational commitment must precede regulatory obligation.

Staff member receiving private support after being affected by a deepfake, showing the human side of institutional response and duty of care.

Why this plan needs to be reviewed annually

The technological landscape of deepfakes is not stable. In the first quarter of 2025 alone, 179 deepfake incidents were recorded, exceeding the total for the whole of 2024. Tools that two years ago required technical expertise are now accessible to anyone with a mobile phone. A response plan built for the conditions of 2023 is not fit for the reality of 2026.

An annual review is not bureaucracy. It is the minimum commitment required to keep the plan operational.

Conclusion

A deepfake response plan is not a piece of crisis management documentation that sits in a shared folder until it is needed. It is the visible evidence of an organisation that has thought seriously about how trust works, and what is needed to protect it when it is under deliberate attack.

Organisations that manage these incidents well are not those with the most sophisticated detection tools. They are the ones who have already answered the difficult questions before the pressure mounts: who speaks, what they say, how they treat those involved, and what they learn in public.

If you’re working on any part of this within your organisation — internal coordination, the spokesperson issue, or simply where to start — I’d love to hear where you’re at on LinkedIn. I’ll be reading your updates.

Related entries

Institutional communication in closed messaging platforms
Expert

Institutional communication in closed messaging platforms

Institutions keep designing messages for public feeds while their audiences make decisions in WhatsApp groups no institutional algorithm can reach. The problem is not technical. It is a question about how trust works when public visibility disappears and what remains are relationships.

Read more »