The deepfake confidence gap is wider than it looks
Vericode · 15 December 2025
CommBank ran the numbers last week and published the statistic everybody in fraud has been suspicious of for two years. Eighty-nine percent of Australians say they can spot an AI scam. Forty-two percent actually can. That gap between confidence and capability is where every romance scam, every fake-CEO transfer and every voice-cloned family call lives.
You can’t fix that with a poster.
None of this is a swipe at education. Awareness work matters. People should know deepfake audio exists, that celebrity investment ads can be fakes, that an urgent payment request deserves a second channel and that a familiar-sounding caller can still be false. A better-informed public helps.
The problem is that confidence rises faster than capability. Once people have heard about a threat, a lot of them decide they’re now equipped to spot it. That’s the trapdoor. Knowing deepfakes exist isn’t the same as catching one under pressure.
The loss numbers are big, but the confidence gap is the cleaner signal. Australians are still losing billions to scams across the year. ASIC keeps taking down phishing and investment-scam sites at scale. Banks are pouring money into fraud prevention and reporting real reductions in some categories. Those are important facts, but they sit behind a simpler human one.. people trust their own judgement at exactly the moment attackers are working to bend it.
Voice scams make this especially uncomfortable. The August lesson was that voice is no longer evidence of identity. The December lesson is that even when people know the trick exists, plenty still believe they’ll recognise it in the moment. They picture a fake that sounds fake. It often won’t.
This is where “just train the users” runs out of road. Nobody’s making the call in a clean classroom. They’re tired, distracted, embarrassed, rushed, worried, helpful or under authority pressure. The finance manager hears the CEO, the parent hears their kid, the customer hears their bank — or someone who knows enough account detail to pass for it.
The attacker isn’t asking for an abstract judgement about AI. They’re asking for an action.
That’s why bank-side controls matter so much. Payment warnings, scam intelligence, payee checks, transaction monitoring and customer-support escalation all take pressure off the individual. The best controls don’t just tell people to be smarter. They change the moment the decision gets made.
But the call itself is still a hard place. The person on the phone may have true facts, a familiar tone and a plausible reason. If the only live check is the listener’s gut, the 89 percent number is dangerous. It says people feel ready. The 42 percent number says many aren’t.
The answer isn’t to shame people for being fooled — shame does nothing against a professionalised fraud market. It’s to stop building systems that leave ordinary people as the last authentication layer. Awareness can make someone hesitate. What happens in that hesitation shouldn’t be left to them.
Those are two different gaps. Awareness campaigns close the awareness one. The confidence gap is something else, and it only closes when high-risk actions carry verification steps that don’t lean on a person’s ear for the difference between real and synthetic trust.
Verification has to live somewhere that isn’t the user’s gut.