The first 24 hours: a clear and consistent message across all channels
The first public statement does not need to be exhaustive. It needs to be precise, calm and consistent across all the channels your organisation uses. A message that appears differently on the website, on social media, and in responses to the media signals disorganisation, which, in itself, damages credibility.
Three elements that every initial statement must always include: what you know (only confirmed facts), what you are doing (concrete next steps, not vague reassurances) and where to find updated information (a single source of truth that your audience can return to).
What it should not include: speculation about who is responsible, technical explanations of how deepfakes work, or language that over-escalates the incident.
The first 7 days: closing the loop and learning publicly
By the seventh day, the immediate crisis may have passed, but the work of rebuilding trust is not over. The transparency obligations of the EU AI Regulation, which comes into force in August 2026, responsibilities. Beyond regulatory compliance, there is a more fundamental reason to close the loop: audiences remember whether organisations explained what happened and what they changed as a result.
A brief public account — not a lengthy post-mortem, but a clear statement of what happened, how the organisation responded and what it has put in place — is the difference between an incident that erodes trust and one that, if well managed, can strengthen it.
How to respond to a deepfake without exacerbating the crisis: the three most costly communication mistakes
Experience in institutional crisis communication (not specific to deepfakes, but directly applicable) reveals three recurring mistakes that systematically amplify the damage rather than containing it.
Over-denial: why repeating false content spreads it further.
The instinct to refute in detail is understandable. In most cases, it is also counterproductive. Repeating the false content, even to deny it, increases its reach. The framing that works is not “this video is fake because of X, Y and Z”, but a clear statement of what is true, backed by credible evidence, without giving the synthetic content any more visibility than it already has.
Changing the spokesperson mid-response
Changing the person speaking on behalf of the organisation during an active incident signals internal disagreement or a loss of control, regardless of the actual reason. Audiences interpret this as instability. If the response plan does not designate a clear spokesperson before an incident occurs, this mistake is almost inevitable.
Treating silence as a neutral stance
In the absence of a clear institutional voice, other voices fill the void: the media, critics, and the synthetic content itself. Silence is not neutral; it is an abdication of the narrative. The question is not whether to communicate, but how to communicate accurately rather than hastily.
What communications teams should prepare before a deepfake incident occurs
Only 32% of executives believe their organisation is prepared to manage a deepfake incident. That figure is consistent with a broader pattern: organisations plan for financial, reputational and operational risk, but treat synthetic media as someone else’s problem: a cybersecurity issue, an IT matter, a question of platform moderation.
It is not. It is a communications issue with institutional consequences.
Three decisions that need to be made before they are needed
Who has the authority to activate the response plan? Not who drafts the statement, but who has the organisational authority to say “we are facing a deepfake incident and this is our response”. That authority needs to be designated in advance, not negotiated under pressure.
What is your pre-approved template for the first statement? Not the final message, but the structure and tone that any initial statement will follow. A template reviewed in calm conditions is more coherent than one drafted in the first ninety minutes of an active incident.
How do you protect your team members who appear in the deepfake? If the deepfake involves a staff member or partner, rather than the organisation as a whole, the response plan must include a clear commitment to that person: what support they receive, how their safety is prioritised, and how the organisation’s public response does not inadvertently increase their exposure. The transparency framework of the EU’s AI Regulation is beginning to set standards here, but organisational commitment must precede regulatory obligation.