Skip to content
Vigil

Live video, 2026

The live call can now be faked.

In June 2026, most people talking to an AI on a video call realised it within 10 seconds. In October, a company-run test reported that about half did not. What that means for the last check most people still trust: seeing a face, live, answering back.

1%

of 200 people never realised they were talking to an AI video agent, in an independent study published in June 2026. Most realised within 10 seconds.1

26 of 54

people believed a new real-time video model was a real person after a one-minute call, in a test by its maker, published in October 2026.2

41%

of genuine videos were wrongly called fake when people were told to look for deepfakes, in a September 2026 study.7

On 1 October 2026, the AI video company Tavus announced Griffin, which it describes as a "Human Interaction Model": a single system that sees and hears the person on a video call and generates its own face, voice and replies in real time, rather than chaining separate speech, language and avatar systems together.2Tavus says a lighter version, Griffin-Lite, is the first model to pass a "video Turing test". It has not released the model to customers, saying "further alignment and safety procedures are required for safe release".

The headline number is 48%: in a blind test, 26 of 54 people who spoke to it for a minute believed they had been talking to another person.

That figure needs careful reading, and we read it carefully below. But even with every caveat applied, it marks a turn. For years, the last line of defence against impersonation has been the live video call: if you can see the person, watch them react and talk back, surely it is them. The research published in 2026 says that line is moving, faster than most security programmes have noticed.

BeforeIn June, people spotted the AI almost every time

The best independent evidence on live, two-way AI video calls comes from a team at UC Berkeley led by Hany Farid. In a preprint published in June 2026, they ran 200 conversations between paid participants and AI video agents built on two commercial platforms, Tavus and HeyGen, with an ethics-approved deception: participants were not told in advance.1 Afterwards they were asked how long it took to realise they had been talking to an AI.

The answer was quickly. 80.5% said within 10 seconds. Only 1% never realised. The researchers also found that people did better than the audio and video deepfake detectors they tested; one text-based detector performed well.

Figure 1

How long it took people to realise they were talking to an AI, June 2026

200 live video conversations with AI agents built on commercial avatar platforms. Share of participants by when they realised.

0%25%50%75%100%Within 10 seconds80.5%10 to 30 seconds13.0%30 to 60 seconds2.0%1 to 2 minutes0.5%More than 5 minutes3.0%Never realised1.0%

Source: Barrington, Bohacek and Farid, "DeepSpeak-Agentic", arXiv preprint, June 2026.1 The question asked how long it took to realise the partner was an AI, so it assumes the participant did; the researchers treat this as a baseline for the systems of the time.

AfterIn October, a company-run test says about half did not

Tavus's test of Griffin-Lite used a similar idea: participants were told they would be matched with another participant for a one-minute call "to discuss what they were looking forward to this year". Their partner was the AI. Only at the end of a survey were they asked whether it had crossed their mind that their partner might not be human.2

26 of 54 participants believed their partner was real. On Tavus's previous system, the same kind of test produced 2.4% (1 of 41). Tavus says "over half of participants said the possibility had not crossed their mind during the call", and those who did suspect "tended to suspect within the first 20 seconds".

Figure 2

Share of people who believed the AI was a real person

Tavus's own tests: its previous system against Griffin-Lite. Whiskers show the plausible range given the small samples.

0%25%50%75%100%Previous system (n = 41)2.4%Griffin-Lite (n = 54)48.1% (35 to 61%)Plausible ranges are 95% Wilson intervals calculated by Vigil from Tavus's counts.

Source: Tavus, "Griffin: The First Human Interaction Model", 1 October 2026.2 Company-run test; no data released.

An independent signal points the same way. NVIDIA's VideoFDB benchmark, which scores how naturally video agents handle the back-and-forth of conversation, rated Griffin-Lite close to its human reference on generating natural responses.3,4 Two caveats apply: the scoring is done by language models rather than people, and it rates outputs the developer submits, though Tavus says NVIDIA ran the scoring independently.

Figure 3

On one benchmark, the AI now scores close to the human reference

NVIDIA VideoFDB scores, 0 to 5, judged by language models. Generation: how natural the agent's own responses are. Perception: how well it reads the other person.

012345GenerationNext best system2.80Griffin-Lite3.83Human reference3.92PerceptionBest baseline3.44Griffin-Lite3.73Human reference4.20

Sources: NVIDIA VideoFDB results page; Mazumdar et al., "VideoFDB", arXiv, May 2026.3,4 Scores were produced by language-model judges on outputs submitted by the developer.

Read it carefullyWhat the 48% does and does not show

The fake you were trained to spot is already gone from voice and text. The same test is now arriving for live video.

A careful reader should hold two thoughts at once.

It is a weak Turing test. Tavus ran the test itself, on 54 people, with one persona, for one minute, and has released no data.2There was no comparison group talking to real people, so we do not know how often a real human would have been judged real under the same conditions. The model tested was the lighter Griffin-Lite, not the full model. With a sample this small, the true figure could plausibly sit anywhere from about 35% to 61%. RuntimeWire summed it up: "a small company-run study, not a broad measure".5

It is a realistic fraud test.In Alan Turing's original game, the judge knows one of two parties is a machine and must pick which. In Tavus's design, nobody was told a machine was involved. That makes it a poor test of machine intelligence, and a good model of a payment fraud call: victims are not expecting a machine either. The jump from 2.4% to about half, under the same conditions, is far larger than the uncertainty in either number.

For your programmeDo not build policy on the exact 48%. Build it on the direction: in its maker's own test, the newest system went from an easy tell (2.4%) to close to a coin toss (48%).

The toolsLive AI video is now a product category

Griffin has the strongest published results, but it is not alone, and it is not the cheapest. Several companies now sell real-time conversational avatars by the minute, with response times they quote in fractions of a second. An open-source tool that swaps a face onto a live webcam feed from a single photo, Deep-Live-Cam, had almost 97,000 stars on GitHub when we checked.10The prices below are vendors' own figures and are not directly comparable, but the direction is clear.

ProductWhat the vendor says, and when
HeyGen LiveAvatarReal-time two-way avatar over WebRTC, sold in credits of $0.10 for 30 seconds to a minute (undated help page).11
Pika real-time video chatAbout 1.5 seconds end to end on a single GPU, able to join Google Meet, April 2026.12
AnamAn average agent response time of 180 milliseconds (page viewed 2 October 2026); about $0.11 to $0.16 a minute in a September 2026 price index.13,14
Tavus Griffin-Lite0.43 seconds from audio to video, October 2026; not available to customers.2
Deep-Live-Cam (open source)Live webcam face swap from a single image; free.10

Criminals are already using real-time video. The FBI warned in July 2026 that scammers "generate videos for real time video chats with alleged company executives, law enforcement, or other authority figures".15Eleven governments warned the same month that North Korean IT workers in video meetings show "video feeds that appear to be manipulated or artificially generated".16 And in March 2025 a finance director in Singapore joined a Zoom call in which the chief executive and other executives were deepfakes, and sent US$499,000.17

The eyeWatching more closely does not help, and suspicion has a cost

The obvious response is to tell staff to watch harder. The 2025 and 2026 research suggests that backfires.

Siwei Lyu, who leads the Media Forensic Lab at the University at Buffalo, wrote in December 2025 that current models produce faces "without the flicker, warping or structural distortions around the eyes and jawline that once served as reliable forensic evidence of deepfakes", and that on low-resolution video calls "their realism is now high enough to reliably fool nonexpert viewers".6Even a heartbeat, once a promising sign of a real face, is no longer a dependable test: a peer-reviewed study in April 2025 found that its own high-quality deepfakes "exhibit valid heart rates".8

A September 2026 study from Ben-Gurion University measured what happens when you ask people to look.7 Participants caught only about two thirds of real-time deepfake videos. When told to look for deepfakes, they called about 41% of genuine videos fake. For about half of the identities tested, the fake was rated more trustworthy than the real person.

Figure 4

People miss fakes, and accuse real colleagues when told to look

Human judgements of real-time deepfake and genuine videos made with four open-source tools.

0%25%50%75%100%Fakes correctly caughtabout 67%Genuine videos called fakeabout 41%The second figure is for participants told to look for deepfakes.

Source: Frankovits, Yasur, Grabovski and Mirsky, "DF-CAPTCHA", Ben-Gurion University, arXiv preprint, September 2026.7

That second number is the one programmes overlook. A culture of "be suspicious of everyone on video" means one genuine colleague in every few gets treated as an impostor. That cost can make people reluctant to challenge at all. Verification has to be routine and impersonal, or it will not happen.

If seeing someone live is no longer proof, the check has to move to something the attacker does not control: a channel, a number, a second person.
Vigil Security

The auditWhich live-call advice still holds

Much of the advice circulating today was written for older tools. Here is where it stands on the 2025 and 2026 evidence.

AdviceStatus in late 2026
Watch for lag, lip-sync errors, odd blinking or lightingUnreliableThe FBI still lists these cues but now says AI content "is often difficult to identify";15,18 real calls lag and compress too.
Check for a pulse or natural skin colourUnreliableHigh-quality deepfakes now show valid heart rates.8
Ask them to turn their head or pass a hand over their faceLimitedStill exposes many open-source tools when software scores the response (Figure 5),7,9 but people shown ordinary deepfake clips missed about a third of them. Passing it proves nothing.
Ask something only the real person would knowUsefulAttacks the impostor's knowledge, not their software; weaker if their email has been compromised.
End the call and ring back on a number you already holdRecommendedThe FBI's lead step; MAS's "separate and trusted communication channel". 18,19
Pre-agreed code words, rotatedRecommendedMAS suggests "code words" and app-based one-time passwords for high-risk requests.19
A second person must approveRecommendedDual control means one convinced person cannot move money alone.19

Figure 5

Asking for a physical challenge makes fakes far easier for software to catch

How well automated detectors separated real people from real-time deepfakes, with and without a challenge. AUC, where 0.5 is guessing and 1.0 is perfect; best of nine detectors for each challenge. The axis starts at 0.5.

0.50.6250.750.8751.0Open mouth0.993Hand over face0.974Smile0.951Puff cheeks0.944Turn head0.941No challenge (passive)0.555 to 0.794

Source: Frankovits et al., "DF-CAPTCHA", arXiv preprint, September 2026, detection results table.7Tested against four open-source real-time tools, not commercial or bespoke criminal systems. The authors warn future systems "may not share all of" today's weaknesses.

The platformsWhat meeting tools can now prove, and what they cannot

Meeting platforms have started to respond. In April 2026, Zoom announced a beta integration with World ID that shows a "Verified Human" badge when the face on the video tile matches a person enrolled through World's iris-scanning device.20 It confirms that a face matches an enrolled person; it does not confirm who that person is in your organisation or what they are authorised to approve.21 In May 2026, iProov launched a meeting product that checks whether video comes from a physical camera rather than software.22In Microsoft's documentation for Teams, we found reporting of suspicious calls and controls over external domains, but no native deepfake detection.23

Each of these signals proves something narrower than it appears to. An "External" label proves which organisation an account belongs to. A camera check proves the video is not injected by software. A biometric badge proves a face matches an enrolled human. None proves that this is your chief financial officer, or that your chief financial officer wants this payment. That still needs a business process.

For your programmeUse platform signals as inputs, never as approval. A verified badge on a call asking for money is a reason to follow the callback rule, not to skip it.

2027Where this is heading

1

Convincing live video will reach anyone who wants it

Tavus is withholding Griffin from customers, but cheaper real-time avatars and free face-swap tools already exist.10,11,12 Plan as if the best capability shown in 2026 will be widely available within a year or two.

2

Disclosure rules will bind the honest, not the criminal

Since 2 August 2026, the EU AI Act has required providers to design such systems so that people are informed they are interacting with an AI, unless that is obvious.24 That will shape legitimate products. A fraudster on a video call will not comply.

3

Verification moves from the face to the channel

Lyu expects that "the meaningful line of defense will shift away from human judgment", towards signed media and provenance.6 Until that exists for every call, the practical version is a callback, a second approver and a code word.

What the evidence does not yet show

  • We found no peer-reviewed study that has yet measured how often unwarned people detect a deepfake in a live, two-way video call. The two 2026 data points come from a preprint and a company test.1,2
  • We found no independent red-team test showing the best commercial real-time systems passing head-turn and hand-over-face challenges. Claims that "these tests are dead" are, so far, opinion.
  • We found no independent accuracy data yet for the new meeting verification and detection products.
  • We found no controlled study measuring how often callbacks or code words prevent losses. The support is official guidance and the logic that a fake on one channel cannot answer a call you place on another.

The modelFour shifts for the live-call era

1
From"If I can see them, it is them"
To"Seeing them is not approval"Griffin-Lite judged human by 26 of 54 people
2
FromSpot-the-glitch tips
ToA callback on a held number, every time money or access is involvedThe FBI leads with this; MAS recommends it
3
From"Be suspicious of everyone"
ToRoutine, no-blame verification that anyone can call, including on the chief executivePrimed viewers called 41% of genuine videos fake
4
FromReading about deepfake calls
ToRehearsing one, live, before the real one arrivesMAS suggests regular video and voice deepfake simulation exercises

The authoritiesWhat regulators and law enforcement say

FBIPublic service announcement, 20 Jul 2026 · United States
Scammers generate videos for real time video chats with alleged company executives, law enforcement, or other authority figuresSource 15
FBIPublic service announcement, 15 May 2025 · United States
independently identify a phone number for the person and call to verify their authenticitySource 18
MASInformation Paper on deepfakes, Sep 2025 · Singapore
if the request is made via video call, it is advisable to confirm the call's legitimacy by contacting the individual through a different mediumSource 19
MASInformation Paper on deepfakes, Sep 2025 · Singapore
Code words are pre-agreed secret phrases or terms that are rotated periodicallySource 19
Singapore Police ForceCase statement, Apr 2025 · Singapore
establish protocols for employees to verify the authenticity of any video calls or messagesSource 17
EU AI ActArticle 50(1), applies from 2 Aug 2026 · European Union
the natural persons concerned are informed that they are interacting with an AI systemSource 24

For the boardFour questions to ask this quarter

QuestionWhy it matters now
Can a video call alone authorise a payment, a new supplier or an access change?The best live AI video was judged human by about half of the people in its maker's test.
Do our people know they may end a call with the chief executive to verify it?Without explicit permission, authority and politeness win. Verification must be routine, not an accusation.
What does a "verified" badge in our meeting tool actually prove?Platform signals prove an account, a camera or an enrolled face, never authority.
Has anyone in finance rehearsed a live deepfake call?MAS suggests regular simulation; reading about it is not practice.

Where Vigil fitsRehearse the live call before it is real

We built Vigil for regulated firms whose people need to follow the verification rule even when the face on the screen is exactly right, and to show that they did.

Shift 4

Rehearse the live call

Live deepfake video calls in the browser and calls in a cloned executive's voice, used only after you record that executive's consent. Zoom meeting tests are available per customer.

Shift 2

Teach the rule, not the glitch

Short, story-driven training films that show the pattern of a real attack and the step that defeats it.

Shift 3

Measure what people did

A dated record for every person of what they were tested on and what they did, and a risk score for each employee with trends across the organisation.

For your regulator

Evidence for your auditors

A one-click compliance report for auditors and cyber insurers, which shows "Not available" rather than a false zero, and a tamper-evident audit trail.

A note on evidence: the research above shows why live video can no longer serve as proof of identity. It does not test any vendor's product, including ours.

Book a 30-minute programme reviewWe read your current programme against your regulator's own words and send you a one-page list of gaps, whether or not you work with us.

Sources

Sources published between January 2025 and October 2026, opened on 2 October 2026. Figures are quoted as published. Secondary reporting and vendor material are marked.

  1. Barrington, Bohacek, Farid. DeepSpeak-Agentic. arXiv preprint, June 2026. arxiv.org/abs/2606.03686
  2. Tavus. Griffin: The First Human Interaction Model, 1 October 2026 (vendor). tavus.io/griffin
  3. NVIDIA Research. VideoFDB results. research.nvidia.com
  4. Mazumdar et al. VideoFDB: Evaluating Full-Duplex Vision-Speech Capabilities in Conversational Agents. arXiv, May 2026. arxiv.org/abs/2605.30256
  5. RuntimeWire, 1 October 2026 (secondary). runtimewire.com
  6. Lyu. Deepfakes leveled up in 2025. The Conversation, 27 December 2025. theconversation.com
  7. Frankovits, Yasur, Grabovski, Mirsky. DF-CAPTCHA. arXiv preprint, September 2026. arxiv.org/abs/2609.11404
  8. Seibold et al. High-quality deepfakes have a heart! Frontiers in Imaging, April 2025. frontiersin.org
  9. Palo Alto Networks Unit 42. North Korean synthetic identity creation, 21 April 2025 (vendor). unit42.paloaltonetworks.com
  10. Deep-Live-Cam repository, GitHub, viewed 2 October 2026. github.com
  11. HeyGen. Introducing LiveAvatar, help centre (vendor). help.heygen.com
  12. Pika. Introducing real-time video chat, 2 April 2026 (vendor). pika.art
  13. Anam. Interactive avatars, September 2026 (vendor). anam.ai
  14. Akapulu Labs. Real-time talking avatar pricing index, 15 September 2026 (vendor). blog.akapulu.com
  15. FBI. I-072026-PSA, 20 July 2026. ic3.gov
  16. US Department of State. Alert regarding North Korean IT workers, 31 July 2026. state.gov
  17. Mothership, April 2025, reporting the Singapore Police Force statement (secondary). mothership.sg
  18. FBI. I-051525-PSA, 15 May 2025. ic3.gov
  19. Monetary Authority of Singapore. Information Paper: Cyber Risks Associated with Deepfakes, September 2025. mas.gov.sg
  20. Zoom. Zoom and Tools for Humanity, 17 April 2026 (vendor). news.zoom.com
  21. TechCrunch, 17 April 2026 (secondary). techcrunch.com
  22. iProov. Verified Meetings announcement, 19 May 2026 (vendor). iproov.com
  23. Microsoft Learn. Microsoft Defender for Office 365 support for Teams, updated September 2026. learn.microsoft.com
  24. EU AI Act, Article 50. artificialintelligenceact.eu