Manage Employee Deepfake Risks
Artificial intelligence (AI) tools make it easier to create fake or manipulated videos, images, audio, screenshots, and other depictions of your employees. A student may create a fake image of a teacher. An employee may circulate manipulated content about a supervisor. A scammer may impersonate a school leader to redirect payroll or obtain confidential data. A member of the public may post a fake video accusing an employee of misconduct.
For K-12 schools, colleges, and universities, deepfakes can cause workplace safety, harassment, privacy, discipline, fraud, and reputational issues.

Recognize Employee-Related Risks
Deepfake incidents can create employment risk in various ways. The underlying conduct may violate institutional policy or the law if, for example, an employee, student, parent, or third party creates or shares sexualized, threatening, or discriminatory deepfake content involving an employee. The response also may create risk if, before the institution takes reasonable steps to assess authenticity of, for example, a troubling video or image, the institution takes disciplinary action, reports alleged misconduct, or communicates publicly regarding the incident.
For instance, a sexually explicit deepfake depicting a teacher or professor may contribute to a hostile work environment, cause emotional harm, and require quick coordination among human resources (HR), legal counsel, Title IX or civil rights staff, communications, information technology (IT), and campus safety. The same incident also may involve student conduct, employee discipline, or law enforcement issues.
Employment actions based on manipulated content may expose your institution to defamation, due process, contract, discrimination, or retaliation claims. False or manipulated content also can damage employee morale, personal safety, professional reputation, and institutional trust.
Public educational institutions also should consider employee speech, public records, collective bargaining, and constitutional due process obligations. Private institutions should consider employee handbooks, contracts, faculty procedures, tenure protections, and applicable state law.
Beyond these employment risks, deepfakes also can create operational risks by making false information or instructions appear credible. A synthetic voice message could direct payroll changes. HR may receive an altered screenshot to support a workplace complaint. A fake video could pressure administrators to suspend an employee before the institution understands what occurred.
Update Policies and Reporting Channels
Review whether existing policies adequately address employee-related deepfakes. Focus on your policies governing:
- Anti-harassment and nondiscrimination
- Employee conduct and social media
- Acceptable technology use and cybersecurity
- Workplace violence and safety
- Mandatory reporting, records retention, and discipline
Use plain language to define prohibited conduct. Examples may include creating, altering, possessing, threatening to share, or distributing AI-generated or manipulated content that impersonates, harasses, threatens, defrauds, or falsely depicts an employee.
Identify where employees, students, parents, and others can report suspected deepfakes or employee conduct involving deepfakes. Provide more than one option so an employee does not have to report to a supervisor who may be involved in creating, sharing, responding to, or appearing in the content.
Work with IT to identify how your institution will preserve digital evidence, review suspected account compromise, assess authenticity, and involve outside forensic support when needed.
Address deepfakes in broader AI governance policies. The same tools employees or students use for legitimate work can create, store, transmit, or retain harmful content. Apply controls used for other AI tools, including authorized use, legal review, data protection, human review, and records retention.
For higher education, define coordination among HR, faculty affairs, Title IX, student conduct, campus safety, IT, and legal counsel. For K-12 schools, clarify when administrators, HR, district leadership (if applicable), IT, school resource officers, or law enforcement should be notified.
Build Response Avenues
Create clear response pathways for two situations: when your institution receives a report about a suspected employee-related deepfake, and when an employee alleges the institution relied on manipulated content in making an employment decision.
For a suspected deepfake incident, assign responsibility for intake, triage, evidence preservation, employee support, investigation, communications, and escalation. This response should apply when an employee is depicted, impersonated, threatened, harassed, or otherwise affected by suspected AI-generated or manipulated content.
When responding to a suspected deepfake incident:
- Preserve content, links, usernames, timestamps, messages, metadata, and screenshots.
- Limit internal sharing to those with a need to know.
- Ask IT or an outside forensic resource to assess authenticity when needed.
- Determine whether safety, leave, schedule, account access, or payroll controls are necessary.
- Consult legal counsel before taking adverse employment action.
- Document decisions and the information available at the time.
An institution’s response may look different when an employee alleges the institution took adverse action based on altered images, video, audio, screenshots, or other manipulated content. In many cases, existing grievance, appeal, faculty, collective bargaining, discrimination, or employee discipline procedures already may provide the appropriate process.
Review those procedures to confirm they allow the institution to pause, preserve relevant evidence, assess authenticity, correct the record if needed, and document how decision-makers evaluated the employee’s claim.
Consult legal counsel when the allegation involves:
- Termination
- Nonrenewal
- Discipline
- Public statements
- Mandated reporting
- Tenure denial or revocation
- Other significant employment consequences
Train Employees and Supervisors
Train supervisors, HR, campus safety, IT, and communications staff to recognize and escalate deepfake concerns. Consider designating a single office to coordinate follow-up and avoid requiring affected employees to repeat sensitive information to multiple offices.
Training should emphasize that employees must not forward, save, or discuss harmful deepfake content except as required for reporting or investigation. Employees also should know that retaliation against a person who reports harassment, fraud, safety concerns, or other misconduct is prohibited. Provide specific examples of when and how a deepfake may be involved in various scenarios.
Support Employees and Limit Harm
Employees depicted, impersonated, or targeted in deepfakes may need prompt support. Being impersonated or depicted in a deepfake can be deeply distressing, so consider paid administrative leave, schedule changes, counseling referrals, safety planning, help documenting the incident, and support requesting platform removal. For employees who acted in reliance on a deepfake, consider whether they need additional training.
The Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks (TAKE IT DOWN) Act requires covered platforms to create a notice-and-removal process for nonconsensual intimate images. Covered platforms must remove covered content and known identical copies within 48 hours after a valid request. The Federal Trade Commission (FTC) began enforcing this requirement May 19, 2026.
Do not promise removal of a deepfake depicting an employee from all sites or platforms. Instead, identify who can help employees locate platform reporting tools, preserve records before takedown, and contact law enforcement or counsel when appropriate.
Communicate Carefully
Prepare placeholder response statements before an incident occurs. Consult your crisis response plan when crafting statements and determining next steps. Keep your communications accurate, limited, and respectful of employee privacy.
Avoid repeating false details.
State that your institution is:
- Reviewing the concern
- Supporting affected individuals
- Preserving relevant information
- Following applicable policies
Before issuing any statement, coordinate with counsel, especially when employment status, student discipline, law enforcement, or litigation may be involved.
Preparing to respond to employee-related deepfakes can help your institution limit workplace harm, reduce legal exposure, and minimize operational disruption.
More From UE
Technology and Artificial Intelligence (AI) Collection Page
Workplace Harassment Resource Collection
Reducing Harm to Students from Deepfakes
Additional Resources
About the Author
-
Lindsey Dunn
Senior Risk Management Counsel
Lindsey joined UE's Risk Management department in September 2024. Prior to that, she spent about six years as a Resolutions Counsel in the South Region for the Specialty Group. Before UE, Lindsey practiced labor and employment law. She is admitted to practice law in Florida and before the U.S. District Courts in Florida and the U.S. Court of Appeals for the Eleventh Circuit.