The AI-Era Fakeness Glossary
From deepfakes to shadow AI to the psychological biases that make it all work, this is the field reference for understanding fakeness in the age of generative AI. Built for security professionals. Useful for everyone.
Want something you can hand your team that won't scare them?
Download the plain-language, share-ready infographic.
Basics for beginners — brief, non-technical grounding for readers unfamiliar with the underlying AI concepts referenced throughout this glossary.
Artificial intelligence (AI)
Computer systems designed to perform tasks that typically require human intelligence, such as understanding language, recognizing patterns, or making decisions, without being explicitly programmed for each individual task.
Machine learning
A branch of AI in which systems learn patterns from data rather than following fixed, hand-written rules, improving their performance as they're exposed to more examples.
Generative AI
AI systems specifically designed to create new content, text, images, audio, or video, rather than just analyzing or classifying existing data. The branch of AI behind deepfakes, synthetic media, and automated text generation.
Large language model (LLM)
A type of generative AI trained on vast amounts of text to understand and produce human-like language. The technology behind tools like ChatGPT and Claude, and the foundation for both automated text generation and AI slop.
Neural network
A computing structure loosely inspired by the human brain, made of interconnected layers that process information. The underlying architecture behind most modern AI, including the models used for deepfakes and voice cloning.
Training data
The dataset an AI model learns from before it's put into use. The quality and content of this data directly shapes what the model can do, and what it can be manipulated into doing through data poisoning.
Foundation model
A large, general-purpose AI model trained on broad data, then adapted or fine-tuned for many different downstream uses rather than built for a single task. Increasingly common vocabulary in vendor evaluations and AI governance conversations.
The synthetic content itself: deepfakes, cloned voices, and fabricated media built to look and sound real.
Deepfake
AI-generated audio, video, or images that convincingly depict a real person saying or doing something they never actually said or did, typically created using deep learning models trained on existing footage of the target.
Synthetic media
Any audio, image, video, or text created or substantially altered by AI rather than captured from reality, encompassing deepfakes but also AI art, voice clones, and generated text.
Cheapfake
Manipulated or misleading media created using simple, low-cost editing techniques (cropping, mislabeling, slowing footage) rather than AI, often just as convincing and harder to detect through technical means alone.
Voice cloning
The use of AI to replicate a specific person's voice, including tone, cadence, and accent, from a short audio sample, enabling synthetic speech that's audibly indistinguishable from the original speaker.
Automated text generation
The use of AI language models to produce written content at scale, from emails and articles to social posts, without direct human authorship of each individual piece.
Face swap
A technique using AI to replace one person's face with another's in an image or video while preserving expressions and movement, commonly used in both entertainment and fraudulent deepfakes.
Synthetic identity
A fabricated identity built by combining real and fake personal information, sometimes reinforced with AI-generated photos or documents, used to open accounts or pass verification checks for a person who doesn't exist.
AI-generated image/video
Visual content created entirely by generative AI models from a text prompt or reference input, rather than captured by a camera, ranging from harmless creative work to convincing fabricated evidence.
The tactics and infrastructure that get fake content in front of people at scale.
Fake news
Fabricated or grossly distorted news content presented as legitimate journalism, designed to mislead readers rather than inform them.
Disinformation
False information deliberately created and spread with intent to deceive, distinct from misinformation (false but unintentional) and malinformation (true information shared with intent to harm).
Misinformation
False information shared without intent to deceive, often spread by people who genuinely believe it's true.
Malinformation
Genuine, factual information shared out of context or with malicious intent to cause harm, such as leaking private details to embarrass someone.
Media manipulation
The deliberate alteration or selective framing of real media, through editing, captioning, or context removal, to change how an audience interprets it.
Fake account
A social media profile created under a false identity. The umbrella term for several distinct types: a fully automated bot account, a human-operated sockpuppet posing as an unrelated party, or an account built specifically to inflate numbers as part of astroturfing.
Coordinated inauthentic behavior
A pattern of accounts working together in a centrally coordinated way to manipulate public discourse, while masking who's actually behind the activity. The term platforms like Meta and X use to describe manufactured engagement campaigns, covering bot networks, sockpuppet accounts, and astroturfing under one enforcement category.
Platform manipulation
The broad practice of exploiting a social media or online platform's features, algorithms, or policies to distort visibility, engagement, or discourse, carried out through tactics like coordinated inauthentic behavior, bot networks, and astroturfing.
Feedback loop
A cycle in which algorithmic recommendation systems amplify content based on engagement, which then generates more of the same content, reinforcing whatever narrative is already gaining traction, true or not.
Astroturfing
The practice of manufacturing apparent grassroots support, using fake accounts, coordinated posts, or artificial engagement, to simulate organic public opinion that doesn't actually exist.
Echo chamber
An environment, often algorithmically reinforced, where a person is repeatedly exposed to opinions and information that confirm their existing beliefs, with little exposure to opposing views.
Bot network
A coordinated group of automated accounts, often AI-driven, used to amplify content, manipulate trends, or simulate engagement at a scale no individual could achieve manually.
Sockpuppet account
A fake online identity created and operated by someone (or something) posing as an independent, unrelated party, typically to support their own arguments or attack critics without disclosing the connection.
The human psychology attackers exploit: the biases and instincts that make fake content effective.
Confirmation bias
The tendency to seek out, interpret, and remember information in ways that confirm existing beliefs, making people more likely to accept fake content that aligns with what they already think is true.
Gaslighting
A manipulation tactic that causes someone to doubt their own perception, memory, or judgment, increasingly enabled by AI-fabricated "evidence" that contradicts what a person knows to be true.
Information silo
A closed environment, personal, organizational, or algorithmic, in which certain information circulates freely while other perspectives are excluded, limiting a person's ability to cross-check what they encounter.
Authority bias
The tendency to trust and comply with information or instructions that appear to come from a figure of authority, a trait attackers exploit through CXO impersonation and fake official communications.
Social proof
The tendency to view an action or belief as more valid because other people appear to be doing or believing it, exploitable through inflated follower counts, fake reviews, or manufactured engagement.
Urgency manipulation
A social engineering tactic that pressures targets to act quickly, such as claiming an account will be locked in minutes, to bypass careful judgment and trigger impulsive compliance.
Where deception tactics, AI-native and AI-supercharged alike, turn into real attacks on companies and their people.
Threat actor
An individual, group, or organization responsible for carrying out a malicious attack or campaign. A generic term used across security contexts regardless of the specific method (phishing, ransomware, impersonation) or motive (financial, political, espionage) involved.
Bad actor
An informal, non-technical term for a person or group engaging in malicious or deceptive online behavior. Used interchangeably with threat actor in everyday conversation, without the same formal precision the security industry attaches to that term.
Insider threat
A security risk originating from someone with legitimate access to an organization's systems or data, whether a disgruntled employee, a careless contractor, or a fraudulent hire such as a deepfake job candidate who gained that access under false pretenses.
Social engineering
The manipulation of human psychology, rather than technical systems, to gain unauthorized access, information, or action, typically through tactics like phishing, vishing, pretexting, or impersonation.
Phishing
Fraudulent messages, typically email, designed to trick recipients into revealing sensitive information or clicking malicious links, now often written or personalized by AI to eliminate the grammatical tells that once made them easy to spot.
Vishing
Voice phishing, a scam conducted over phone calls, increasingly using AI voice cloning to impersonate a trusted person and pressure the target into an action.
Smishing
Phishing conducted via SMS text message, often impersonating delivery services, banks, or coworkers to prompt a quick, unthinking click.
Quishing
Phishing conducted via malicious QR codes, which redirect scanners to fraudulent websites or trigger unwanted downloads, effective partly because QR codes obscure the destination URL until it's too late.
Pretexting
A social engineering technique in which an attacker fabricates a believable scenario or false identity to manipulate a target into sharing information or granting access.
Whaling
A phishing attack specifically targeting senior executives, exploiting their authority and access to sensitive systems or high-value financial approvals.
Impersonation
The act of assuming a false identity, human or synthetic, to deceive a target into trust, action, or disclosure, seen in specific forms like CXO impersonation, vendor impersonation, and deepfake job candidates.
CXO impersonation
An attack in which a threat actor uses AI-generated voice, video, or written communication to impersonate a company executive, typically to authorize fraudulent payments or extract sensitive data from employees.
Vendor impersonation
An attack in which a threat actor poses as a trusted supplier or partner, often using AI-generated communications matching the vendor's real style, to redirect payments or extract information.
Business email compromise (BEC)
A scam in which an attacker gains access to or convincingly spoofs a legitimate business email account to trick employees into making fraudulent payments or disclosing sensitive information.
Omnichannel attack
A coordinated attack that spans multiple communication channels, such as email, phone, text, and social media, using consistent fabricated details across each to make the deception more convincing than any single message would be alone.
Deepfake job candidate
A fraudulent job applicant who uses AI-generated video, voice, or identity documents to pass remote interviews, often to gain insider access to a company's systems or data.
Scamming
A broad term for deceptive schemes designed to defraud victims of money, data, or access, a category now amplified by AI's ability to make fabricated pretexts more convincing at greater scale.
Automated ransomware
Ransomware attacks that use AI or automation to identify targets, craft tailored extortion messages, or accelerate the encryption and deployment process, reducing the time and skill required to execute an attack.
Cyberwarfare
State-sponsored or politically motivated cyberattacks intended to damage, disrupt, or gain intelligence advantage over another nation or organization, increasingly incorporating AI-generated disinformation as a tactic alongside traditional intrusion methods.
Shadow AI
The use of AI tools within an organization without formal approval, visibility, or oversight from IT or security teams, creating unmanaged exposure of company data.
Workslop
AI-generated work output that appears polished and complete but lacks real substance, accuracy, or value, shifting the burden of catching errors onto colleagues or clients who assume it was done properly.
The ways AI systems themselves fail or mislead, separate from deliberate human deception.
Hallucination
An AI model generating false or fabricated information, facts, citations, quotes, and presenting it with the same confidence as accurate output, without any signal to the user that it's wrong.
Prompt injection
An attack that manipulates an AI system by embedding hidden instructions in its input, such as a document, email, or webpage the AI processes, causing it to act on the attacker's commands instead of the user's.
AI slop
Low-quality, mass-produced AI-generated content flooding online platforms, prioritizing volume over accuracy or value. Named 2025's Word of the Year by multiple dictionaries for how thoroughly it entered public vocabulary.
Model drift
The gradual degradation or change in an AI model's performance or behavior over time, as real-world data shifts away from what the model was originally trained on.
Data poisoning
An attack in which corrupted or malicious data is deliberately introduced into an AI model's training set to manipulate its future outputs or behavior.
Sycophancy
An AI model's tendency to tell users what they want to hear rather than what's accurate, agreeing with incorrect statements or softening honest feedback to maximize user satisfaction.
AI washing
The practice of companies overstating or fabricating their use of AI in products or marketing to appear more innovative than they actually are.