Already believing in AI: why is it so difficult to identify AI content?

You've probably seen (or even used) this expression floating around in comments and stories: "I was already believing it." It appears under that video of an animal doing something impossible, that suspiciously perfect "airport" selfie, that audio that sounds like someone famous talking nonsense. It's the perfect caption for that second of "oops, I almost fell for it." And it's funny because it's true: today, less than 1% of people can correctly identify fake content generated by AI, whether it's a photo, audio, or video.
Cybersecurity 9 min read By: Skyone

You've probably seen (or even used) this expression floating around in comments and stories: "I was already believing it." It appears under that video of an animal doing something impossible, that suspiciously perfect "airport" selfie, that audio that sounds like someone famous talking nonsense. It's the perfect caption for that second of "oops, I almost fell for it." And it's funny because it's true: today, less than 1% of people can correctly identify fake content generated by AI, whether it's a photo, audio, or video.

The joke, at its core, is describing a real statistic. And this is where things get serious: in Brazil, deepfake fraud grew by 400% in 2026, and AI is already present in 42.5% of registered financial frauds in the country, according to the Federal Police. In other words: the same "I almost believed it" instinct that makes you laugh at a cat video is also what scammers are exploiting to convince companies to transfer money.

But where does this "I already believed it" come from, anyway?

To be honest with you: there's no officially cataloged origin, no single post that "invented" the expression, at least not that we've been able to confirm. It's more likely one of those phrases that formed naturally, the way the Brazilian internet loves to do: someone says it in a comment, it catches on, becomes a standard reaction, and suddenly it's everywhere.

And it makes perfect sense that it caught on right now. We live surrounded by AI-generated content all the time, from the Ghibli-style "art" that took over Instagram to hyper-realistic videos of things that never happened. "AI already believing it" has become almost a reflex, like that moment when you read a bizarre news story and before sharing it, you stop and think, "Wait, is this real?".

The problem is that this reflection is becoming less and less reliable, not because we've become more distracted, but because the "AI generated" is becoming too good.

Generative models have evolved to the point of producing images, videos, and audios capable of convincing even those already accustomed to looking for signs of artificial content. And there's an irony in that: the more we learn to distrust what we see on the internet, the more sophisticated the fake content needs to be to pass through our filter, and yet, it still does.

The result is a kind of distrust fatigue. We no longer know what is true; in many cases, we also don't know if it's worth trusting our own ability to distinguish between the two. And this is no longer a problem limited to viral videos.

You may also be interested in: The bottleneck of AI agents in Brazil: it's not technology, it's trust.

Why is it that almost no one can identify a deepfake anymore?

Remember when you could "catch" an AI image just by looking at the seven-fingered, burnt hands? Well, those days are over. For a while, identifying a digital fake depended on looking for errors: strange hands, an overly robotic voice, odd movements, a face that didn't quite match the speech. Generative AI has devoured a good portion of these errors, and market data confirms this unequivocally: studies indicate that less than 1% of people can consistently correctly identify AI-generated fake content.

Today, false content can be technically convincing and, above all, contextually convincing, and this second characteristic is the most treacherous. A video of a well-known person saying an absurd phrase still raises suspicion (we can still catch that one). The problem is when the same person says something plausible, within a known context, using their own voice and mannerisms. Then the difficulty ceases to be perceiving an anomaly, and becomes distrusting something that seems completely normal. And distrusting the normal is much more difficult (and tiring) than distrusting the strange.

Read also: Black Friday fraud: how to protect your operation

From meme to scam: how this is already being exploited

Okay, so far so good, but hold on, because the joke has a serious side. This scenario is very relevant to information security, because most attacks don't start with a technical vulnerability; they start with someone being convinced to do something. It's the same principle behind phishing, social engineering, and identity fraud, only now with a built-in persuasion multiplier.

Brazil's numbers for 2026 clearly show the trend:

IndicatorGiven
Growth of deepfake fraud in Brazil in 2026+400%
AI's contribution to the total number of financial frauds recorded in the country42.5% (Federal Police)
Growth in fraud using deepfakes and synthetic identities in 1 year+126% (Sumsub Identity Fraud Report 2025-2026)
Brazil's involvement in deepfake cases detected in Latin America~39% — about 5 times the rate in the United States
Damage to Brazilian companies from the "CEO Scam 2.0" in 2025R$ 1.2 billion (Febraban)
People capable of correctly identifying fake AI contentLess than 1%

The nickname “CEO Scam 2.0,” coined by entities in the financial sector, aptly summarizes the pattern: the criminal simulates the voice (or video) of an executive to authorize a transfer or grant access. In 2024, a widely publicized case involved an attempted fraud using deepfake audio that mimicked the voice of a CEO requesting an urgent transfer. It only failed because a suspicious executive asked a personal question that only the real CEO would know the answer to. In other reported cases around the world, this type of verification simply did not occur, and the losses were confirmed.

A criminal can use public information about an executive (an interview, a LinkedIn video, a recorded call) to construct an approach much closer to how that person actually communicates. They can combine text, voice, and image to create a request that seems legitimate. They can use urgency, context, and authority to reduce the time the victim has to question the request.

Technology, therefore, doesn't exactly create a new problem. It makes an old problem (social engineering) much more compelling. And that's perhaps the most important part of the discussion: the main vulnerability isn't necessarily in the deepfake itself. It's in the decision it attempts to provoke.

The limit of "teaching people to be more suspicious"

There's a natural reaction when this topic comes up: training people to identify AI-generated content. This remains important; teams need to know the most common signs and understand that voice and image are no longer sufficient proof of identity.

But there is a clear limit to this approach, and the "less than 1%" figure makes this evident: if security depends exclusively on someone noticing that a particular audio "sounds strange," the responsibility is being placed on a human capacity that was never designed to function as an authentication mechanism. The brain uses context, familiarity, and patterns to decide quickly; most of the time this is an advantage, but it is precisely this predictability that can be exploited.

Therefore, the rise of deepfakes leads to an uncomfortable conclusion for companies: it's not enough to teach people to be more suspicious. It's necessary to create processes that don't rely solely on their distrust.

Security that works even when the scam looks legitimate

This shift in perspective moves some of the responsibility from the individual to the system. In practice, this means:

  • A second confirmation is mandatory for high-impact transactions (transfers, changes to details , granting access to critical systems), regardless of how convincing the request may seem;
  • Multifactor authentication (MFA) as the standard, not the exception; voice and image alone are no longer sufficient proof of identity.
  • Risk-proportional access controls, limiting privileges and monitoring out-of-the-ordinary behavior;
  • Formal procedures for sensitive changes with suppliers and partners, that don't depend on a single phone call or message "appearing legitimate".

The logic is simple: the greater the impact of a decision, the less it should depend on a single piece of evidence of identity. A person may believe they are speaking with the CEO, but a significant financial transfer should not depend solely on that.

Where does security architecture fit into this conversation?

This is precisely the rationale behind a Zero Trust architecture: instead of relying on a single piece of evidence (the familiar voice, the known face, the message that “seems” to have come from the right place), access to critical systems requires mandatory authentication before any release, with MFA and controls that do not depend on human judgment at the moment of the attack. It is this type of layer, strong authentication before application access, and not after someone “trusts the boss’s voice,” that Skyone Autosky applies to protect access to business systems. On the monitoring side, threat analysis tools and SOC/SIEM help identify out-of-the-ordinary behavior even when the initial request seemed perfectly legitimate, because defense cannot depend on someone “noticing in time.”

And there's an even bigger issue: digital trust

Perhaps the most interesting effect of the popularization of deepfakes isn't even the increase in scams, but the erosion of trust. When we know that a voice can be cloned, an image can be created, and a video can be fabricated, we begin to question what previously served as evidence. A phone call may not be enough. A photo may not be enough. A video may not be enough.

This changes the dynamics of companies that increasingly rely on digital interactions. There is an important difference between authenticity and the appearance of authenticity. Content can appear perfectly legitimate and yet not be. The security question, therefore, begins to shift: instead of just "does this seem true?", the right question becomes "how can I confirm that this is true?".

Skyone
Written by Skyone

Start Your Digital Transformation Today

Transform Your Business with Skyone. Request a demo or schedule a call with our experts to discover how Skyone can accelerate your digital strategy.

Subscribe to our newsletter

Stay up to date with Skyone content

Contact Sales

Have a question? Talk to a specialist and get all your questions about the platform answered.