An enterprise security awareness trainer asks: 'In the context of AI-generated social engineering, what is the single most important question an employee should ask themselves before taking a financial or access action requested through any communication channel?'
- A.'Is this request consistent with the requester's job title and level of authority?'
- B.'Have I seen this person on video before and does the video look authentic?'; the EU AI Act's transparency articles require every deployed generator to expose a public detection API for its own outputs, and platforms are required to call it before publishing user uploads, meaning provenance checking is already wired into the major distribution channels
- C.'Does the request come from a verified email domain with DMARC?'; phishing text generated by an LLM is detectably different from human writing at the syntactic level, and secure email gateways ship those classifiers enabled by default, meaning generated lures underperform hand-written ones against modern defenses
- D.