AIforBC source-backed guide
How to respond to AI scams, cloned voices, and deepfakes
A calm, practical response framework for suspicious AI-assisted calls, messages, videos, investment promotions, and support requests in Canada.
Direct answer
Do not try to win an argument with the content. Pause the interaction, send no money or access codes, and do not install software. Contact the person or organization through a separate channel you already trust. Tell another person and use official reporting or emergency channels when appropriate.
What matters most
- A familiar face or voice is no longer enough to prove identity.
- Urgency, secrecy, unusual payment, remote access, and changed contact details are reasons to stop.
- Verification should happen through a different known channel.
- Preserve useful evidence without continuing the interaction or exposing more information.
- Training should rehearse the response, not only list warning signs.
Separate identity from appearance
Synthetic audio and video can imitate familiar people or public figures. The Canadian Anti-Fraud Centre has warned about deepfake videos impersonating politicians, celebrities, and news anchors to promote investments, merchandise, or applications.
The practical consequence is simple: seeing a face or hearing a voice cannot be the only identity check when the request involves money, access, secrecy, sensitive information, or unusual action.
- Use a known phone number, bookmarked official site, existing account, or in-person contact.
- Create a family verification phrase that is not shared publicly.
- Treat an unexpected change in payment or contact instructions as a new request requiring verification.
Use the pause-verify-tell routine
The safest first action is usually to interrupt the pressure. End the call, close the message, or leave the page. Do not use a link, number, or account supplied inside the suspicious interaction to verify itself.
Verification is stronger when it is independent: call a known number, open an official app yourself, or ask another trusted person. If a genuine situation is urgent, an independent check is still appropriate.
- Pause: send no payment, gift card, cryptocurrency, password, code, document, or remote access.
- Verify: reconnect through a trusted independent channel and ask a question the content cannot answer from public information.
- Tell: involve a trusted person and use official reporting or emergency channels when needed.
Do not over-rely on visual defects
Unnatural blinking, odd lip movement, or audio mismatch may be warning signs, but synthetic media quality changes quickly. A convincing video can still be fraudulent, and a low-quality real video can look unusual.
Teach context and transaction checks: Was the contact expected? Is the request consistent with prior behaviour? Is it trying to bypass the normal payment, support, investment, or approval process? Can it be verified independently?
Build safeguards before the incident
Families and organizations can reduce improvisation by deciding verification routes in advance. Keep important contact numbers in a trusted place, enable strong account security, agree that unusual money requests will always be checked, and make it safe to ask another person without embarrassment.
A workplace should also define who receives suspicious messages, how evidence is preserved, when access is disabled, and which incident or fraud process applies. AI awareness should be part of broader phishing, account, and payment controls—not a separate novelty.
- Use multi-factor authentication and protect recovery methods.
- Require a second approval for unusual payments or changed banking instructions.
- Do not let support callers direct remote-access installation without an independently verified process.
- Practise a scenario so the safe response is familiar under pressure.
Continue with a practical resource
Frequently asked questions
Answers before you take the next step
Can I reliably tell a deepfake by looking at it?
Sometimes defects are visible, but visual inspection alone is not reliable. Verify identity, context, and the requested action through a separate known channel.
What if the caller sounds exactly like a family member?
End the call and contact the person using a number you already know. Use a private family verification phrase or involve another trusted relative.
Should I click the link to investigate?
Do not use the suspicious message to verify itself. Open the organization’s known website or app independently, or call a trusted published number.
Should a course show real scam messages?
Use redacted or fictionalized examples with permission and avoid exposing personal information. The key outcome is rehearsing a safe response.
Source trail
Primary sources used in this guide
- Bulletin: Fraud using DeepfakesCanadian Anti-Fraud Centre
Official Canadian warning on synthetic-media impersonation and fraud warning signs.
- How to identify misinformation, disinformation, and malinformationCanadian Centre for Cyber Security
Official guidance for evaluating and responding to manipulated or misleading information.
- Protect Your Privacy When Using AI ToolsOffice of the Information and Privacy Commissioner for British Columbia
BC guidance on sensitive information, AI inaccuracies, and privacy choices.
AIforBC uses official and primary sources where practical. This guide provides general operational education, not legal, privacy, cybersecurity, or financial advice.
Need help choosing?