← All posts

August 20, 2026

·Video Strategy·Chuck Brooks

How to Tell If a Video Call Is Real, Not a Deepfake

Chuck Brooks spent 10 years on Capitol Hill, worked at the Department of Homeland Security, and now teaches cybersecurity at Georgetown. He says the fakes...

Chuck Brooks spent 10 years on Capitol Hill, worked at the Department of Homeland Security, and now teaches cybersecurity at Georgetown. He says the fakes are getting good, but they still have tells.

Key Takeaways

  • AI-generated people still look stiff, and their voices run flat instead of rising and falling.
  • Chuck Brooks says trust is an economic asset, tied directly to whether you can do business.
  • Watermarking and paid verification tools exist, but no tool gives a 100% guarantee.
  • Before a risky interaction, check who a LinkedIn profile is connected to and ask those people first.
  • Gateway quantum computers are still five to 10 years out, so today's fight is AI versus AI.

This fits inside a bigger picture. If you want the full view first, here's the bigger picture.

How do you know the person on your video call is real?

Watch the mannerisms and listen to the voice. That is Chuck's short answer, and he gave it live on camera when Dane asked him to prove they were both real.

"Still some of the mannerisms look a little stiff and a little fake." — Chuck Brooks

The voice is the other giveaway. Synthetic speech tends to run linear. It does not have the up and down of a person reacting to something in real time.

Chuck's checklist for a live call:

  • Are they looking you in the eyes?
  • Do they use their hands the way a real person does?
  • Does the voice have real excitement and real hesitation in it?
  • Do they react to something unexpected, or only to the script?

He was clear that this window is closing. AI is improving at mimicry, and in a year or two the cues get much harder to read.

Why trust became an economic asset

Trust used to sound like a soft word. Chuck frames it as a business input, because AI is now built into everything and a lot of the personas you meet online may be synthetic.

That changes the basic question from "do I like this person" to "can I verify this person." Deepfakes are cheap to produce. Phishing is now automated at a scale that reaches millions of people at once instead of a few at a time.

His practical floor for any digital relationship:

  • Verify who you are dealing with and why
  • Get the encryption parameters right
  • Know the threats in your supply chain
  • Cover the basics: strong passwords, multi-factor authentication, segmented data, backups

Skip those and the odds are not in your favor. As Chuck put it, there is a good chance you are going to be breached if you have not been ready.

Do deepfake detection tools actually work?

They help, but they are not a guarantee. Chuck pointed to watermarking, checking whether a file was sent encrypted from a known sender, and commercial programs you can buy to test whether a video is real.

The problem is volume. We are flooded with video on LinkedIn, Instagram, and everywhere else, which makes it hard to sort real from fake at speed. There is also steganography, where something gets embedded into a pixel of an image and turns into downloaded malware.

New verification technology is coming, and Chuck expects better answers soon. Until then his rule is the same one he uses on email.

"I will not open anything from a sender I don't know." — Chuck Brooks

How to vet someone on LinkedIn before you trust them

Look at the relationship, not the profile photo. Fake profiles have been used for espionage, and Chuck says the same fakery shows up anywhere people connect, including dating sites.

What he actually does:

  • Watch the account over time and read what they post
  • Look at how many people are connected to them
  • Validate where they say they worked
  • Find a mutual connection you already know and reach out to that person first, before you do anything risky

Chuck gives LinkedIn credit for improving. There were a lot of fake signups before, and Microsoft, Google, and Meta have all built capability against it. Fakes still get through, so there is no 100% guarantee.

Why video still beats text for building trust

Video sits in the middle between meeting someone in person and reading their writing. Chuck called it an insurance factor, and he traced the shift to COVID, when Teams, Zoom, and Google calls became routine.

Two things make it work. People read less than they used to, because attention spans are short and smartphones trained that. And a face carries information text cannot.

"Having the expressions you have, knowing your sincerity and your voice, means something." — Chuck Brooks

He is a fan of video and thinks it is here to stay, even with deepfakes in the mix. That is the tension worth sitting with. The format that builds trust fastest is also the one under attack.

Zero trust, applied to video

The guardrail Chuck recommends is the oldest one in cybersecurity: trust but verify. Identify that the person is real first, the same way you would confirm a device on your network is real.

Then add a second layer before anything transactional happens. Have several interactions, not one. And bring up something that might catch an impostor off guard, a detail you never actually discussed.

On quantum, he is not sounding an alarm yet. Quantum algorithms, photonics, and quantum technologies exist, but the gateway capabilities are probably five to 10 years away because of stability and error problems in the physics. In the meantime, defenders get to use AI too, and spotting AI-generated content with AI is the most practical tool we have right now.

"Trust but verify is really essential for everything you do these days." — Chuck Brooks

Doing the thing is the easy part. The hard part is knowing where you're already winning and where you're invisible. That's exactly what our free AI Visibility Snapshot shows you, before you spend a dollar.

Frequently Asked Questions

How can you tell if someone on a video call is AI generated?

Look for stiff mannerisms and a flat voice. Chuck Brooks says AI-generated people still move a little unnaturally, and synthetic voices run linear without the natural up and down of real excitement. Also watch whether they make eye contact and use their hands the way a real person does.

Are there tools that verify whether a video is real?

Yes. Chuck Brooks points to watermarking, encrypted delivery from a known sender, and commercial programs you can buy to check authenticity. None of them offer a 100% guarantee, so he pairs the tools with knowing who you are dealing with in the first place.

How do you spot a fake LinkedIn profile?

Watch the account over time, read what it posts, check how many connections it has, and validate where the person says they worked. Chuck Brooks adds one fail-safe: find a mutual connection you already know and ask them first before doing anything risky.

Is video still a good way for cybersecurity companies to build trust?

Chuck Brooks says yes, and calls it an insurance factor. After COVID made video calls routine, seeing someone's expressions and hearing their voice became a normal part of verifying who you are talking to, and it carries more than text does.

Does quantum computing break trust online?

Not yet. Chuck Brooks says quantum algorithms, photonics, and quantum technologies exist today, but the gateway quantum capabilities are probably five to 10 years away because of stability and error problems. He expects defensive capability to develop before then.

Most teams don't get this right on the first try. Here's how we approached it for a real team. Curious what it'd look like for you? Let's talk it through.

Full Interview Transcript

Dane: I'm here today with Chuck Brooks, who is a tech and cybersecurity expert around the world and a professor at Georgetown University. Among other things, what else should we need to know about you?

Chuck: Well, I have an extensive background both in government, where I was at the Department of Homeland Security in the Science and Technology Directorate, also 10 years on Capitol Hill. And I was in executive management at some large firms like Xerox, General Dynamics Mission Systems, Rapiscan, SRA International, and Sutherland. So I've had a long career both in the private and public space, and I'm also an author of Inside Cyber. So it's exciting to be here.

Dane: Yeah, me too. It's nice to have someone with your deep experience and, I would expect, the sort of bird's eye view and the whole tech and cybersecurity landscape. So I wanna kind of kick it off talking about the theme of trust in cybersecurity, in particular, an industry that the whole trust is sort of the whole point of the industry, right? And you wrote an article the other day about the new stakes for business viability in the digital era. And you talked a lot about trust and why that's important. And so I wanted to kind of just get your high level take, what do we need to know about that issue in these industries?

Chuck: Yeah, well, there's so many variables now. And I think if you're gonna talk about trust, you have to look at the fact that now AI is really integral to everything we're doing and more specifically, agentic AI. So you're creating a lot of personas out there that may be synthetic. So the question is, how do you verify and know what's real and what's not real? The capacity to make deep fakes is fairly easy. Phishing attacks are just now becoming routine with the technology, being embedded to, basically reach millions of people at once rather than do it a few at a time. So everything is sort of up for grabs in the digital world. So you have to establish, you know, verify basically who you're dealing with, why you're dealing with them, and whether you have a relationship that's trusting. And this relationship could be enhanced by having the right parameters of encryption, by having the right relationships in the supply chain. By understanding the threats out there is probably the most important thing. And also by having protocols in a framework for people that are involved in the relationship or doing work on digital to have all the basic cyber hygiene, you know, of knowing what they're doing, having strong passwords, multi-factor authentication, having their data segmented, knowing, you know, knowing the threats, keeping abreast of them and making sure they have backups and everything. Because there's a good chance that you're gonna be breached if you haven't been ready.

Dane: Yeah, it sounds like it's almost inevitable for everybody. The idea in your article about trust being an economic asset that really resonated with me is like, you know, we could talk about trust and why it's important, but like, it's sort of amorphous until you really think about like, that's directly tied to your ability to do business and make money, right? And so within the context of video, which is really what I'm most interested in is like using video as a tool to build and maintain trust. In the context of like deep fakes, how do we navigate like what's real, what's not? I mean, I'm sure there's technical ways of verifying, but there's also like a sniff test. Like, does this feel real to me? How do those sort of ideas kind of come together for you?

Chuck: You know, that's a good point. I mean, there's a lot of similarity with a phishing attack, right? You don't, do I open that document? Does the document look real? It's same with videos, but with videos that there's other technologies out there that could ensure their authenticity, like watermarking, knowing whether they're sent encrypted from a sender, there's things you can do, plus there are programs out there you could buy to verify the fact that it's real. But it is a real problem because we're so inundated now with so many videos and whether it's being Instagram or LinkedIn or social media, you know, it's very difficult to find what's real. And I think there's new technologies coming our way, which hopefully will be brought soon, that will be able to provide global verification, to see if anything's been done, because you can do what is called steganography and actually input something and embed it into a pixel of the picture. So, you know, that could be downloaded malware. So there's a lot of difficulties in that. But the best thing to do is know who you're dealing with, just like we're dealing with in business. There's no difference from, if you know who the people are, know what time they're gonna contact, you know what they're sending and verify it, because I will not open anything from a sender I don't know. And that's just a good rule to keep. Make sure that you're expecting it. And if you're on social media, there are gaps there too, because a lot of stuff gets now embedded in websites and you could basically open something that even if you get by the cloud or whoever your provider is. So it's a very volatile situation, but hopefully, and I'm sorry, hopefully, I've seen some of the emerging technologies out there that are dealing with this, we'll have some pretty good solutions soon.

Dane: Yeah. So I wanna get your take on part of that. I imagine that some of the tools require some integration, like you have to input a video to test it to see if it's real, or you'd have to have some watermarking or something in place, but if you didn't have those things, you're just on social media, you're looking at stuff. My take has been, you can trick me once, right? Like you can get me for a few seconds, but my take has been building trust with an audience over time. If you're spending a lot of time with you, like on podcasts, they're spending hours with you, over time, they're gonna be able to tell and trust you. And I guess AI may be there quickly to be able to like even fake that, but I think are we still at that point where like, if you're building a relationship with people on social media like LinkedIn or YouTube or something like that or a podcast, do you still feel like that's trustworthy enough? Is that a viable avenue for cybersecurity people to like build a trusting relationship?

Chuck: I think that, well, there's a lot of people faking identities. I mean, they're pretty good now at LinkedIn at discovering them has been used for espionage and other things with a lot of fake profiles. But, you know, I think what you need to do is sort of develop those relationships and sort of watch them over time, watch what they're posting, watch the number of people that connected to them, maybe validate where they work, you know, if they said they did work somewhere. You know, I think it's, there's a lot of people, and I think it goes true with anything. If you're on a dating site too, a lot of fake stuff, lot of fake profiles. So you have to really know, develop a relationship like you said, with understanding who you're connected to and why you're connected to them. And also, one fail-safe way to do it is if you know someone's they're connected to when you go to say LinkedIn, you look to see where their connections are, and you know those people, you reach out to them first if before you do anything that might be risky in a cybersecurity sense. And I think those platforms have gotten better, some are better than others and some aren't. I think LinkedIn has made a lot of improvements because there was a lot of fake signups before, but they've developed some capabilities because they're big companies like Microsoft and Google too has done stuff in meta. So I think they're trying to move in those directions, but they still get by. There's no 100% guarantee that it's real.

Dane: Yeah. So understanding, of course, that I spend all day, everyday thinking about video stuff, and that's not necessarily where you spend all of your time thinking, what's your take on video as a strategy for communicating the trust that cybersecurity companies need to communicate? Because I was thinking about this, you can meet someone in person and that's pretty great for trust, especially over time. And then you can write articles and have text over here, but video is like that middle ground where you can kind of have a somewhat in-person experience at scale. And if you do it, like I was mentioning over time, that seems like maybe the best of both worlds. And I'm just kind of curious what you think about that.

Chuck: Oh, I think with COVID, we all sort of adapted to teams and to Zoom and to Google, all those places, and it became routine to see who was on the other side. And I think now that we're accustomed to it, I think it's a really smart thing to do, to, and a lot of the conferences and people reach out to me, let's do a call or a video call or whatever. And I think it really is an insurance factor for you. So I think I 100% think that's a better way of going. Plus, I think in terms of communicating too, I mean, people read, but their attention spans are short nowadays. I think the smartphones have created that. So having a visual before you and having the expressions you have, knowing your sincerity and your voice, means something. So I think a lot of that psychologically picks up on building some relationships. So I think I'm a big fan of video and I think it's here to stay, even if it's being deep faked a lot.

Dane: Yeah. So you kind of transitioned perfectly to, I wanted to have a little fun with something and I don't mean to put you on the spot, but the irony is we're talking about trust in video. So like, let's play a game. How do I know you're real? How do you know that I'm real right now on this video call, right? Like people may be wondering this. This is like a situation people are gonna be in a lot. What's the thing we should be looking for?

Chuck: Well, you know, there are ways to look at someone's image and see that it's AI generated. Now they're a lot better than they used to be and they're getting close. But still some of the mannerisms look a little stiff and a little fake. You know, you can see them in the AI generation, and the voices too. The voices are, you know, they're sort of basically linear. They don't have up and down excitement, you know, and just like a person reacting to certain things. But also look at, you know, whether they're looking you in the eyes, adaptations, you know, using your hands, all these things that people do, you gotta pick up on those cues to understand what's real. And for the time being, I think we're okay. You know, I think you're real. But, you know, I think in a year or two, it's gonna be even more difficult because I think AI is actually improving in the ability to mimic. And more technology enhances that and more the experiment with it. It's gonna be much more difficult to discern what is and what isn't real.

Dane: Yeah, well, once again, you transitioned perfectly to my next question. This is something you said in your article. Leaders should be asking, how do we ensure that we remain trustworthy? And so within the context of video, as AI is getting better, what can we do, do you think, to remain, keep this video thing sacred and trustworthy? Is there anything we can sort of put guardrails on?

Chuck: Well, you know, it sort of goes to the cybersecurity theme of zero trust: trust but verify. So you have to identify whoever you're dealing with is real first, you know, just like you would identify if a person on your network is real or a device is real. So I think that guardrail is one that works for everything. And the other thing is, you know, before you do anything, in terms of actually doing transactional work, is to make sure you have several interactions to verify it. You know, so the first thing, and then maybe bring back something that might catch them off guard. No, we didn't talk about that kind of thing. So I think you can check with the realities now of, you know, using your own logic to determine whether something's real or not.

Dane: Yeah. So as sort of like a parting thought, I wanted to kind of put a cherry on top here. What does trust look like in the age of quantum computing?

Chuck: Well, that's a tough one right now, because, you know, quantum is going to basically be a catalyst for everything. It will be for AI. So you're talking about really the, you know, the generation of capabilities combined between AI and quantum will really be off the charts. And so what it does is it immediately brings in the power of, you know, like a million classical computers. So you're going to really have a difficulty, you know, with all these aspects right now. But the problem, I think, and it's not a problem, it's actually a benefit, is that right now, first of all, there's quantum algorithms and there's quantum technologies and photonics, which are quantum capabilities. But the real big, what we call gateway quantum capabilities have not arrived yet. And they're probably five to 10 years away. And a lot of variables are, because of the physics of it keeping them down and stable, there's a lot of, you know, errors involved in stability and stuff. So I don't think we're there yet. And I think we'll develop capabilities before that to adjust to this. So, you know, I think, when I think about cybersecurity, it's not a static thing. You always have to be, you know, increasing your knowledge capabilities. You know, what worked five years ago, even five days ago, may not work now. So I think with everything with digital, we have the advantages of using AI against the threats too. So they can determine what's real and what's not too. Using AI to see what's AI-generated is probably the easiest way to do that. Certainly with the written form. But it could also be done with video. So that's what we have right now in our quiver. So I think we're gonna be okay. But, you know, again, with trust, you know, trust but verify is really essential for everything you do these days, because, you know, it really goes more to what, you know, cybersecurity with fraud, identity theft, everything is so prevailing now, because what has happened is that bricks-and-mortar crime has moved to digital. And the benefit for the criminals is it's difficult to catch them, and they get paid, and, you know, cryptocurrencies and prepaid cards. And no one really prosecutes them. It's very difficult to do. So for these big organized gangs, plus there's also states involved with this too. So nation states, you know, states like Russia, China, and Iran and North Korea. So I think you have to basically also look at cloud and see what, you know, your carrier's bringing you to cloud, what kind of security, what kind of encryption, what kind of verifications, who has access to it. So there's a lot of things that are changing. So I think the best advice I can say is keep reading and keep learning.

Dane: Yeah, yeah, that's great. Well, thanks so much for sharing your insights today. Great stuff, and it's nice getting to know you a little bit. And good luck out there.

Chuck: You too. Appreciate it.