**Daniel Faggella** (0:12)
Welcome everyone to the Emerge AI in Business Podcast. Today's guest is Jon-Rav Shende, Global CTO for Data and AI at Thales Group. As AI-generated voice tools make synthetic fraud increasingly accessible, enterprise contact centers face a risk that has less to do with technology and more to do with the workflows agents use to make trust decisions under pressure. Jon examines where the live voice channel is most exposed, why the convergence of identity, urgency and business action in a single call represents the highest risk point for regulated organizations, and how senior leaders can build a practical response framework that satisfies internal auditors, cyber insurers and regulatory requirements simultaneously. The conversation delivers a clear four-step order of operations, from mapping high-risk voice journeys to defining the evidence chain required before any AI risk signal layer is deployed. Today's episode is sponsored by Modulate. A quick note for our audience, that the views and opinions expressed by Jon-Rav Shende on today's program are his own and do not reflect those of Thales Group or its leadership. Emerge works with a selected group of AI vendors to reach Fortune 500 decision makers through research, media and direct access. If you want to be considered, download our media kit at go.emerge.com/partner. That's go.emerj.com/p-a-r-t-n-e-r.
Now the conversation with Jon.
Jon, it's great to have you in our Emerge AI in Business Studio today.
**Jon-Rav Shende** (2:00)
Thank you. And it's a pleasure being here, Jolande.
**Daniel Faggella** (2:03)
I'm looking forward to a conversation that our leaders will definitely resonate with. And to give them some practical guidance, I think we would want them to, at the end of this conversation, be able to look at their own voice channel today and answer one question. If a deepfake or a manipulated caller hit their agent today or in the next 10 minutes, would anyone know before the call ended?
If the answer is no to that, then they should be listening to what they should be doing or thinking about or asking. And I think a good place to start is, I think it's pin drops 2025 Voice Intelligence and Security Report that had deepfake fraud attempts up with 1,300 percent in 2024, going from about one a month to seven a day, which is absolutely crazy. So I want to know from your CISO seat, where is the live voice channel actually most exposed right now?
**Jon-Rav Shende** (2:57)
That's a really good question. And it's based on several factors. So a couple of things, when we think about this, the highest risk areas that we would look at would be for from a CISO perspective and the C-suite perspective. You're looking at things like your customer support, call centers, your help desk, individuals that handles claims, payments, password resets, account recovery, and executive facing workflows. The next logical flow would be well why? And that's because teams are basically trained to help quickly. They're measured on speed, they're measured on customer satisfaction and resolution. And most people within customer service, within these type of organizations, they're trained to be service oriented, to focus on resolution, focus on customer satisfaction. And those are all wonderful things to think about. Those are all wonderful things that we are measured on. And we expect, you know, CSAT, customer metrics, satisfaction surveys to come on and say, yes, you did great. And that's typically why at the end of a call, typically a service rep would say, hey, can you answer this feedback, or you will get a link to a survey, can you please rate me, and so on. And with that in mind, because folks are trained to help so quickly, attackers know this. And because attackers know this, they don't just attack technology per se, they attack the process. So a deep fake does not need to fool the entire company.
Basically, it needs to fool one individual, one weak point.
And fool is not necessarily the right word. I would say it's take advantage of the good nature and the expectations of good customer service from the agent. To take advantage of that and in Vigil, change to an email, reset a password, approve a transaction, or access a policy which may lead to bypassing a specific control.
So when we think about this, the exposure is not only in the voice per se, it's basically in the journey. And we think about things like who's calling, what are they asking for? Is the device, is the number trusted? Is this a normal request that we are looking at? When we think about that, we have to think about risks to the environment. So we want to know if, hey, is this action high risk?
And with all of that, then it falls back to the agent. Does the agent have a clear escalation path? And then afterwards, can the company prove why the call was allowed? And obviously, if you have a clear escalation path, you should have flags. You should have process controls. You should have risk measurements that will say, hey, this seems suspicious. This seems fraudulent. Let's stop it. So basically, for an executive perspective, the practical takeaway is simple. Your voice channel is most exposed at the point where identity, urgency and business actions come together. And that's where deepfake risk becomes an actual business risk.
17 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000768868604