The Proof Premium: How Much Proof a Decision Deserves
Share
Key Points
- The Arup deepfake loss of $25M was a verification-pricing failure
- You must adopt an adaptive authentication model
- AI made everyday signals cheap to fake
- Put friction where mistakes are costly and irreversible.
Key Points
- The Arup deepfake loss of $25M was a verification-pricing failure
- You must adopt an adaptive authentication model
- AI made everyday signals cheap to fake
- Put friction where mistakes are costly and irreversible.
Arup, the engineering firm behind the Sydney Opera House, will not approve a routine purchase order without several sign-offs. In January 2024, an employee in its Hong Kong office wired roughly $25 million on the strength of a single video call. His chief financial officer was on that call asking for the transfers, and so were colleagues he recognized, yet every one of them was an AI deepfake stitched together from footage scraped off the public web. The striking part is the mismatch: a company that wraps a small purchase in controls let a $25 million decision through on the say-so of a video call, which is about the cheapest kind of proof there is now that a face and a voice cost almost nothing to fake.

Proof should be priced like insurance, to the value at risk
Every verification step is a premium you pay in friction, delay, and cost, and like any premium it earns its keep only when it is priced to what is at stake. You would not insure a bicycle the way you insure a house, and you would not spend an hour proving your identity to read a news article. Call that discipline the Proof Premium: the amount of proof a decision deserves scales with the loss you take if the proof turns out to be wrong. Price it too low on something that matters and a single event clears you out, which is what happened to Arup, and price it too high on something routine and you bury ordinary work in friction that buys almost nothing. Most organizations manage to do both at once.
Your login screen already prices proof to risk; the rest of the company does not
Security worked this out years ago, and it lives inside the login box under the name risk-based or adaptive authentication. A bank lets you check a balance from your usual phone with a tap, then demands a hardware key or a one-time code the instant you try to move a large sum from a new device in another country, because the assurance it asks for is matched to the money at risk. NIST's identity guidelines and rules like Europe's strong customer authentication assume exactly this graduated approach. The careful pricing simply stops at the edge of the identity system, because the moment a decision passes into human judgment, a wire approved on a video call, a candidate hired off a resume and a remote interview, a vendor trusted because the email looked right, the risk engine is nowhere in sight and the proof required falls back to whatever happens to feel normal.
AI moved the attack to the parts of the business that never got a risk engine
What AI changed is the price of faking the everyday signals those human decisions lean on, because a face on a call, a voice on the phone, and a polished resume each used to carry enough built-in cost to work as a decent proxy, and that cost has collapsed. Hiring shows the repricing in real time, since more than half of applicants now use AI in their materials and Gartner projects that by 2028 one in four candidate profiles worldwide will be fake. Employers, in the words of Gartner's Jamie Kohn, increasingly find it "harder to evaluate candidates' true abilities, and in some cases, their identities," and the revealing fix is that Google, Cisco and others are bringing back in-person interviews, quietly repricing the interview upward to a signal that still costs something to fake. The same collapse is hollowing out web analytics, where a session full of bots and agents no longer proves a human was ever there (Also read: The Proxy Collapse: When Web Traffic Stops Being Human).
How much proof a decision deserves, and how to set it
The useful question is how much you lose if a signal is fake and how easily you could claw it back, because almost any signal can be faked now. Three things set the premium a decision deserves: the size of the loss if the proof is wrong, whether the action can be reversed, and how often that kind of action actually gets attacked. A large, irreversible transfer triggered from outside sits at the top and earns real friction, like a callback to a number nobody on the request could choose or a second approver reached through a separate channel. A reversible, low-value, internal action sits at the bottom and deserves almost none. The point is to spend your friction budget where the losses concentrate and pull it out of everywhere else, which for most companies means less proof on the routine path and far more on the handful of decisions that can actually hurt them.

Pricing proof is becoming a company-wide discipline, not a security setting
This turns verification from a control the security team owns into a pricing decision that runs across finance, hiring, procurement, and product, because the expensive failures now happen in their workflows rather than at the login screen (Also read: Enterprise AI Is an Organizational Design Problem in Disguise). The advantage goes to the company that prices well, because it moves fast on the ninety-odd percent of interactions that carry little risk and concentrates its scrutiny on the few that carry most of it, while a rival that verifies everything to the same degree ends up both slower and less safe. Getting that curve right, rather than buying more verification, is the actual skill.
The next few years reprice the workflows AI just made soft
The adoption figures below are vendor-reported, so read them as directional; my predictions carry their own confidence and invalidation conditions.
| Prediction | Confidence | Timeline | Evidence | Invalidated if |
|---|---|---|---|---|
| High-value approvals (wires, vendor bank-detail changes, payroll edits) adopt mandatory out-of-band confirmation as standard, the way logins adopted MFA | 70% | 2027 | Deepfake CFO frauds like Arup; established step-up patterns in banking | Real-time deepfake detection gets reliable enough to trust a live call again |
| Hiring for sensitive roles standardizes a live in-person or proctored identity step | 75% | 2027 | Google and Cisco reverting to in-person interviews; Gartner projections | Reliable remote identity proofing arrives and removes the need |
| Proof pricing becomes an explicit function spanning security, finance, and HR rather than a setting inside the identity system | 50% | 2028 | Losses migrating into human workflows outside the risk engine | Workflow tools bake calibrated verification in by default |
| Proof-of-personhood or content provenance gets priced into high-stakes flows as an accepted assurance tier | 55% | 2028 | World's AgentKit; C2PA provenance adoption | Privacy backlash or easy stripping keeps them out of serious workflows |
Audit where your proof is mispriced, in both directions
The Arup loss reads as a story about deepfakes, and underneath it is a story about a decision priced for a routine call rather than for twenty-five million dollars. Almost every organization is carrying the same mismatch somewhere, guarding the front door with elaborate checks while a side door with far more behind it swings open on a convincing email or a familiar face. The work now is to find the few decisions where a wrong answer is expensive and hard to undo and make those genuinely costly to fake, rather than adding friction everywhere, which only slows the business and trains people to click through. Proof, priced correctly, stays cheap where it can be and turns expensive only where it must.
Key Takeaways
- Verification is a premium priced to the value at risk: too little on a high-stakes decision and one event wipes you out, too much on routine ones and you drown ordinary work in friction.
- The Arup deepfake loss was a pricing failure rather than a technology failure, because a $25 million decision got the verification of a routine video call.
- Security already prices proof to risk inside the login box through risk-based and adaptive authentication, while the rest of the organization mostly does not.
- AI collapsed the cost of faking the everyday signals behind human decisions, so the underpriced surfaces are now hiring, approvals, and vendor trust rather than the login screen.
- The skill is calibration rather than maximal proof: concentrate friction on the few decisions that are costly and hard to reverse, and strip it from everything routine.
FAQ
What is the Proof Premium? It is the idea that the proof a decision deserves should be priced to the value at risk, the way an insurance premium is priced to the loss it covers. Verification costs friction and time, so spending it evenly wastes it, and the discipline is matching the strength of proof to what you lose if the proof is wrong.
How do I decide how much proof a decision needs? Weigh three things: the size of the loss if the signal is fake, whether the action can be reversed, and how often that kind of action actually gets attacked. High-value, irreversible, externally triggered actions earn strong out-of-band proof, while low-value, reversible, internal ones earn almost none.
Isn't this just risk-based authentication? Risk-based and adaptive authentication apply the same principle, but only inside the login and transaction box. The Proof Premium extends that calibration to the human decisions AI now targets, like approvals made on a video call or candidates hired off a remote interview, which usually sit outside any risk engine.
About the Author
Martin Goetzinger has spent his career in enterprise software sales, helping large organizations such as Apple, Microsoft, and Verizon connect data, insight, and action. His work focuses on transforming how businesses measure success and create customer value through technology.
Outside the enterprise world, he writes about the five forces he believes are reshaping everything: AI, blockchain, energy, personalized health, and robotics. Not from a purely technical lens, but from a human one as to how these technologies will redefine work, wealth, and well-being.
He is based in the U.S. and publishes at www.MartinGoetzinger.com.
Disclaimer
The views expressed in this article are the personal opinions of the author and are provided for informational and educational purposes only. Nothing in this article constitutes investment advice, financial advice, legal advice, or any other form of professional advice. Do not make investment or financial decisions based on the content of this article. Always consult a qualified professional before making decisions that affect your finances, business, or livelihood.
