MODULE 4 · LESSON 4

Free — no login required

Sign in to track progress, save quiz attempts and enrol in the full course.

Sign in to track progress / enrol

Adverse Uses of AI

Every general-purpose technology gets used badly. What is worth understanding is the specific way AI changes the picture: it does not usually invent new harms, it removes the cost and skill barriers that used to limit them.

The categories

Synthetic media. Convincing fake images, audio and video of real people. Voice cloning in particular now needs only a short sample. This turns a resource-intensive attack into a cheap one.

Misinformation at scale. Generating unlimited plausible text makes it economic to flood a channel with fabricated reviews, comments or news. The constraint on such campaigns used to be human writing capacity.

Surveillance. Facial recognition and behaviour analysis applied to whole populations. The technology is neutral; the governance around it is not, and it varies enormously by jurisdiction.

Targeted manipulation. Using behavioural data to identify who is persuadable on what, and reaching them with tailored messages.

Autonomous weapons. Outside most organisations' concerns, but a live subject of international debate.

The economics is the story

Consider fraud where a finance employee is deceived into transferring money.

Traditionally this needed an email that looked convincing. Staff were trained to be suspicious of unusual email requests, and to verify by phone.

Voice cloning changes the arithmetic. The verification step — call the person and check — is now attackable with a short sample of their voice, which for any executive who has spoken publicly is freely available. There have been reported cases internationally of voice-cloned executive fraud, and the pattern is well enough established that it belongs in ordinary finance controls.

Nothing about the fraud is conceptually new. What changed is that a control which used to work no longer does.

The organisational response is not detection. Do not train staff to spot fake audio; that is a losing race. Change the control so it does not depend on recognising a voice:

  • Payment changes above a threshold require verification through a separately initiated channel — you call a number from your own records, never one supplied in the request.
  • Two-person authorisation for transfers above a limit, with no exception for urgency.
  • An explicit policy that urgency and secrecy are themselves red flags, because every one of these attacks uses both.

That third point is the most valuable. Attacks of this kind universally apply time pressure and instruct the target not to discuss it. Naming that as the signal is more durable than any technical detection.

Erosion of trust

There is a second-order effect that is easy to miss and arguably more consequential than any individual fake.

Once convincing fakes are known to be possible, genuine evidence becomes deniable. A real recording can be dismissed as synthetic. This is sometimes called the liar's dividend: the mere existence of the technology gives cover to anyone caught on record.

The practical consequence for organisations is that provenance becomes more valuable than content. Where it matters that a communication is genuine, the answer is not better fake-detection but verifiable channels: signed documents, authenticated systems, recorded approvals in a system of record rather than a message.

Most AI capability is dual-use, and the uncomfortable cases are not the obviously malicious ones — they are the ones with a legitimate purpose and a harmful adjacent use. It is worth having this conversation before you are in it.

Emotion recognition in customer calls. Legitimate: routing distressed customers to senior staff faster. Adjacent: scoring employees on emotional performance, or inferring health and personal circumstances they never disclosed.

Productivity monitoring. Legitimate: identifying where a process is causing delay. Adjacent: surveillance that damages trust more than the efficiency is worth, and that will be experienced as such regardless of intent.

Customer segmentation. Legitimate: relevant offers. Adjacent: differential pricing that correlates with protected characteristics — which may be unlawful and will certainly be reported that way if discovered.

Predictive scoring of people. Legitimate: prioritising support outreach to those likely to struggle. Adjacent: quietly limiting opportunity for people a model has labelled, without them knowing a label exists.

Three questions make this practical rather than abstract:

  1. Would we be comfortable if the affected people knew exactly how this works? Discomfort here is the most reliable early signal you will get.
  2. What is the adjacent use? If we built this, what is the next request that arrives, and would we refuse it? Systems get repurposed; capability that exists gets used.
  3. Who decides? If the answer is "whoever asks for it", you do not have a policy. Name the person or forum.

None of this requires an ethics committee or a policy document nobody reads. It requires the questions being asked out loud, early, by someone with standing to stop the project.

Knowledge Check

What is the most effective organisational defence against voice-cloned executive fraud?

📚 Flashcards1 / 6
Term

What AI changes about harm

Click to flip
Definition

It rarely invents new harms. It removes the cost and skill barriers that used to limit them, turning resource-intensive attacks into cheap ones.

Click to flip back
💡Key Takeaway

AI mostly makes existing harms cheap rather than inventing new ones, and the clearest example is voice cloning turning phone verification from a control into a vulnerability. Respond by redesigning controls rather than training people to spot fakes. Expect the second-order effect too: once fakes are credible, real evidence becomes deniable, which makes verifiable provenance more valuable than any detection tool.