Nearly 40% of govts will build TrustOps units by 2028 to fight deepfakes

Share:
Audio Loading voice…
Nearly 40% of govts will build TrustOps units by 2028 to fight deepfakes

Synopsis

Gartner's latest report projects that nearly 40% of governments worldwide will stand up dedicated TrustOps units by 2028 — a structural shift from reactive fact-checking to proactive trust architecture. The driver: deepfakes that can impersonate heads of state, compromise biometric systems, and go viral faster than any takedown can contain them.

Key Takeaways

Nearly 40% of government organisations globally are projected to establish TrustOps functions by 2028 , according to Gartner, Inc.
Deepfake threats include impersonating leaders for disinformation campaigns and attacking internal systems via voice-cloned social engineering.
Gartner recommends adopting the C2PA protocol to embed tamper-proof cryptographic metadata in all official digital media.
High-risk workflows such as financial disbursements should be audited and secured with multi-approver authentication.
Governments are urged to shift from reactive takedowns to proactive trust architecture, saturating the information space with verified content first.

Nearly 40 percent of government organisations worldwide are projected to establish dedicated TrustOps functions by 2028 to counter deepfake identity impersonation and disinformation-as-a-service (DaaS), according to a report released on Monday, 18 May by business and technology research firm Gartner, Inc. The findings underscore a sharp escalation in synthetic-media threats targeting public institutions globally.

The Scale of the Deepfake Threat

According to the Gartner report, deepfake attacks on government bodies take two primary forms: public-facing disinformation campaigns — including impersonating senior leaders to issue fabricated public statements — and targeted intrusions into internal systems. The report warns that these threats are no longer theoretical; they are actively exploiting the intersection of social media and AI-generated synthetic content.

'These threats manifest as public-facing disinformation campaigns, such as impersonating leaders to issue misleading public statements, and in attacks on internal systems,' the report stated. The convergence of scale and speed means a single viral deepfake can outpace any reactive response.

What TrustOps Means in Practice

Daniel Nieto, Senior Director Analyst at Gartner, stressed that deepfakes carry an existential dimension beyond individual incidents. 'Deepfakes can undermine or even weaponize notions of digital identity, attacking the credibility of the State itself,' he said.

Nieto recommended that governments mandate outbound content grounding by adopting the Coalition for Content Provenance and Authenticity (C2PA) protocol — a standard that embeds tamper-proof cryptographic metadata into all official digital media. In the longer term, he said, C2PA implementation could serve as a systemic defence layer for government communications.

Key Recommendations from the Report

The Gartner report outlines several concrete steps for government Chief Information Officers (CIOs) and security leaders. First, organisations are urged to shift from reactive fact-checking to a proactive trust architecture — a structural change in how institutions manage the credibility of their digital output.

Second, the report calls for identifying and auditing high-risk administrative workflows, particularly financial disbursements, which are vulnerable to voice-cloned executive impersonation. Security measures requiring multiple approvers and application-level authentication are recommended to eliminate single-point-of-failure vulnerabilities.

Third, governments are advised to avoid relying solely on reactive takedowns. 'Organisations must saturate the information space with the truth first,' the report noted, acknowledging that once a deepfake goes viral, corrective action alone cannot contain the damage.

Why This Matters Now

The report's urgency reflects a broader global pattern: as generative AI tools become cheaper and more accessible, the barrier to producing convincing synthetic media has collapsed. Deepfakes now aim to compromise automated biometric authentication — including voice and facial recognition — or use social engineering to manipulate government employees into harmful actions by rapidly establishing false authority and urgency.

This comes amid growing international concern over AI-enabled influence operations, with several democracies reporting deepfake incidents ahead of elections. For India, which operates one of the world's largest digital government infrastructures, the Gartner projections carry particular relevance as the country scales Aadhaar-linked and biometric services.

The Road Ahead

The report calls on organisations to take an orchestrated, enterprise-wide approach to defence, with CIOs leading oversight in consultation with primary stakeholders. The implications of deepfakes at scale, the report concludes, demand rapid institutional action — not incremental adjustments to existing cybersecurity postures.

Point of View

Not a communications one — yet the 2028 timeline means a majority of governments will still be exposed for years. The C2PA recommendation is technically sound, but adoption requires political will and vendor coordination that has stalled in most jurisdictions. For India specifically, the convergence of deepfakes with Aadhaar-linked biometric authentication is an underexamined vulnerability that this report implicitly flags without naming.
NationPress
11 Aug 2026

Frequently Asked Questions

What is TrustOps and why are governments adopting it?
TrustOps refers to a dedicated organisational function focused on proactively managing digital trust — verifying the authenticity of official communications and defending against synthetic-media threats. Governments are moving toward it because reactive fact-checking can no longer keep pace with AI-generated deepfakes that spread virally.
What is the C2PA protocol recommended by Gartner?
The Coalition for Content Provenance and Authenticity (C2PA) protocol is an open standard that embeds tamper-proof cryptographic metadata into digital media files, allowing recipients to verify the origin and integrity of content. Gartner recommends governments mandate its use for all outbound official digital communications.
How do deepfakes specifically threaten government organisations?
According to the Gartner report, deepfakes threaten governments in two ways: externally, through disinformation campaigns that impersonate leaders to issue fabricated statements; and internally, by using voice-cloned executives to manipulate employees into harmful actions such as authorising fraudulent financial disbursements.
Why can't governments simply take down deepfakes once they appear?
The Gartner report cautions that reactive takedowns cannot outrun a deepfake once it goes viral. By the time a false video is flagged and removed, it may have already shaped public perception. The recommended approach is to pre-empt the damage by saturating the information space with verified, cryptographically authenticated content.
Which workflows are considered highest risk for deepfake exploitation?
The report specifically identifies financial disbursement workflows as high-risk, where voice-cloned impersonation of senior executives can be used to authorise fraudulent transfers. Multi-approver security protocols and application-level authentication are recommended to close these vulnerabilities.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 week ago
  2. 1 week ago
  3. 2 months ago
  4. 2 months ago
  5. 10 months ago
  6. 10 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google