Yesterday we looked at voice cloning. Today's threat is more visually convincing : synthetic video. AI-generated footage that can show someone saying or doing something they never did, sometimes convincingly enough to fool the naked eye in real time.
What used to require a Hollywood special effects budget now takes a laptop, some footage of a real person's face, and freely available software. For schools and trusts, that's no longer a distant threat; it's a new category of risk sitting alongside phishing and ransomware.
What synthetic video looks like in practice
In an education setting, this tends to show up as:
- A fabricated video of a headteacher or trustee "announcing" a policy change, a payment request, or a data release, shared internally or even picked up by local media before anyone can correct it
- A fake video call: live deepfake tools can now puppet someone's face in real time on a video call, not just in pre-recorded footage, meaning a "video meeting" with a senior leader is no longer automatic proof of who's really on the other end
- Manipulated footage used to harass, bully, or falsely implicate a pupil or member of staff, including in safeguarding-sensitive contexts
- Fake "evidence" videos circulated to pressure a school into a particular response, financial or otherwise
Why this risk is growing and where your exposure actually sits
Just as with voice cloning, the raw material comes largely from schools themselves. Open days, assemblies, prize-giving footage, promotional videos, staff interviews, and social media posts all provide exactly the kind of clear, front-facing, well-lit footage that produces the most convincing synthetic video.
This is worth treating as an active risk item, not a hypothetical one, and it starts with knowing what's actually out there. It's worth running a straightforward audit of your school or trust's public-facing video and image content:
- Review what's currently live on your website, YouTube/Vimeo channel, and social media accounts
- Note which content features extended, clear, front-facing footage of the same individuals repeated across multiple videos: headteachers, bursars, and front-of-house or finance staff are typically the highest-value targets, since they're the voices and faces people expect to act on instructions from
- Flag anything outdated, unused, or low-value that could reasonably be archived or removed, reducing the pool of material an attacker could draw on
- Make sure consent and image-use records for anyone appearing in this content (particularly pupils) are up to date. This strengthens your existing obligations under your image-use policy and the ICO's guidance on children's images, rather than creating a new one
This isn't about pulling your marketing videos or going dark on social media, schools need that content. It's about knowing your exposure, the same way you'd audit any other asset before deciding how to protect it.
Building this into training
As with voice cloning, the defence here is mostly behavioural, not technical, and needs to be trained in deliberately and regularly:
- Teach staff that video and live video calls are no longer automatic proof of identity. A video call "from" a senior leader requesting something unusual still warrants the same out-of-band check as a phone call would.
- Agree a verification process for anything high-stakes requested on video. A policy announcement, a payment, a release of personal data, before it's needed, not in the moment.
- Brief anyone who manages the school's public video/social content on why reducing unnecessary exposure matters, so it becomes part of their routine content review rather than a one-off task.
- Make sure safeguarding leads are aware that fabricated video involving pupils or staff is a plausible scenario, so it's recognised quickly and escalated through the right channels rather than taken at face value.
💡Your Daily Cyber Tip: treat video the same as you now treat voice
If a video, live or recorded, carries an unusual, urgent, or high-stakes request, apply the same rule as Day 6: verify through a separate, trusted source before acting. A real colleague, on a real urgent matter, will always wait for a call back.
Where this sits in the DfE Digital & Technology Standards
Synthetic video sits under the same Cyber Security standard as voice cloning, cyber awareness and user vigilance, and reinforces the Digital Leadership & Governance standard's expectation of clear escalation routes. It also touches Filtering & Monitoring, where schools are expected to understand emerging online harms affecting pupils and staff alike.
Further reading from our AI Best Practice Library
- AI Best Practice Area: our central hub for AI guidance, checklists and policy templates
- AI Policy Template: recently updated for 2026
- Is your organisation at risk from Shadow AI?
- AI in Schools: Six Pillars for Getting it Right
- Can you use AI safely in schools?
