Nearly 40% of govts will build TrustOps units by 2028 to fight deepfakes
Synopsis
Key Takeaways
Nearly 40 percent of government organisations worldwide are projected to establish dedicated TrustOps functions by 2028 to counter deepfake identity impersonation and disinformation-as-a-service (DaaS), according to a report released on Monday, 18 May by business and technology research firm Gartner, Inc. The findings underscore a sharp escalation in synthetic-media threats targeting public institutions globally.
The Scale of the Deepfake Threat
According to the Gartner report, deepfake attacks on government bodies take two primary forms: public-facing disinformation campaigns — including impersonating senior leaders to issue fabricated public statements — and targeted intrusions into internal systems. The report warns that these threats are no longer theoretical; they are actively exploiting the intersection of social media and AI-generated synthetic content.
'These threats manifest as public-facing disinformation campaigns, such as impersonating leaders to issue misleading public statements, and in attacks on internal systems,' the report stated. The convergence of scale and speed means a single viral deepfake can outpace any reactive response.
What TrustOps Means in Practice
Daniel Nieto, Senior Director Analyst at Gartner, stressed that deepfakes carry an existential dimension beyond individual incidents. 'Deepfakes can undermine or even weaponize notions of digital identity, attacking the credibility of the State itself,' he said.
Nieto recommended that governments mandate outbound content grounding by adopting the Coalition for Content Provenance and Authenticity (C2PA) protocol — a standard that embeds tamper-proof cryptographic metadata into all official digital media. In the longer term, he said, C2PA implementation could serve as a systemic defence layer for government communications.
Key Recommendations from the Report
The Gartner report outlines several concrete steps for government Chief Information Officers (CIOs) and security leaders. First, organisations are urged to shift from reactive fact-checking to a proactive trust architecture — a structural change in how institutions manage the credibility of their digital output.
Second, the report calls for identifying and auditing high-risk administrative workflows, particularly financial disbursements, which are vulnerable to voice-cloned executive impersonation. Security measures requiring multiple approvers and application-level authentication are recommended to eliminate single-point-of-failure vulnerabilities.
Third, governments are advised to avoid relying solely on reactive takedowns. 'Organisations must saturate the information space with the truth first,' the report noted, acknowledging that once a deepfake goes viral, corrective action alone cannot contain the damage.
Why This Matters Now
The report's urgency reflects a broader global pattern: as generative AI tools become cheaper and more accessible, the barrier to producing convincing synthetic media has collapsed. Deepfakes now aim to compromise automated biometric authentication — including voice and facial recognition — or use social engineering to manipulate government employees into harmful actions by rapidly establishing false authority and urgency.
This comes amid growing international concern over AI-enabled influence operations, with several democracies reporting deepfake incidents ahead of elections. For India, which operates one of the world's largest digital government infrastructures, the Gartner projections carry particular relevance as the country scales Aadhaar-linked and biometric services.
The Road Ahead
The report calls on organisations to take an orchestrated, enterprise-wide approach to defence, with CIOs leading oversight in consultation with primary stakeholders. The implications of deepfakes at scale, the report concludes, demand rapid institutional action — not incremental adjustments to existing cybersecurity postures.