Perry Carpenter on Deepfakes, Digital Identity and AI Agent Security | KB4-CON 2026
Perry Carpenter, Chief Deception Strategist at KnowBe4, joins Techstrong TV at KB4-CON 2026 to discuss deepfakes, digital identity risk and the need to secure both human employees and autonomous AI agents.
Recorded at KB4-CON 2026, this conversation explores how deception is evolving as modern work becomes an ecosystem of people, identities and AI-driven agents.
Topics include AI deepfakes and deception, digital identity risk, human risk management, securing AI agents, the evolving digital workforce and security awareness in an agentic AI environment.
Transcript
Hey everyone. Welcome back here to our coverage from Orlando for KB4CON 2026. We're having a great time up here today, speaking with new friends, old friends.
Let me introduce you to an old friend, acquaintance, Perry Carpenter. Perry is the chief deception strategist here at KnowBe4. Perry, welcome to Techstrong TV.
It's great to have you on here. So happy to be here. Absolutely.
So Perry, though you and I were talking because the name was familiar to you- Yeah ... my name was familiar to you, your name was familiar to me. We kind of crossed paths over the years.
Give people a little bit of your background and how we kind of crossed paths. Yeah. So the first time I heard your name was probably 2003-ish.
Right? There was a little blog ecosystem- Yeah ... of folks, and you and Mitch Ashley had a podcast.
Had a blog. Sure. We were blog- And you were blogging.
I think podcasts came maybe a year or two after. Okay. First it was just the writing.
Yeah. Right? And I had always wanted to get into writing, so I decided to go ahead and hang out a shingle, and I had a website called Security Renaissance because I wanted to reflect the idea of being very multidisciplinary and bringing in all these really traditional ways, and not traditional in the negative sense, but traditional in the ways of, hey, this is how humanity works.
This is how we think. And bring a more liberal arts view into something that is obviously very tech-focused. Tech-focused.
Yeah. I loved it. I love it, and I remembered it from back then.
Now, look, the world's changed a lot since then- Yeah ... but we're still writing, we're still videoing. Yeah.
We're still talking about security. Perry, I mentioned your... Well, let me do this.
Yes. Yeah. Take us from then to now in terms of your career arc.
What have you been doing? Yeah. So, the through line from then to now is kind of early 2000s, I was really started out as a programmer doing deep level tech work.
The 2003, 2004 timeframe when I started doing the blogging and the writing and trying to bring all these threads together was when I really wanted to focus on the fact that we spend a lot of money on technology, hundreds of thousands, millions of dollars per organization out there trying to solve complex risk management problems. And at the same time we spend all that money, somebody that's motivated enough or somebody that's just negligent accidentally breaks all of that, or intentionally breaks all of that. So I really wanted to focus on why people think the things that they think and do the things that they do, and how that affects security and risk management.
And so that's been the past 23 years since then. It's been a minute. Yeah.
And then, of course, deception is a through line through all of that. And so, I grew up as somebody very fascinated in deception and why people are tricked. It's taken me in some really weird places.
I grew up as a budding magician- Uh-huh ... " And so I got more into the psychological side. But along the way, I've done things like street hypnosis and sticking people's hands to tables and making them forget their names.
I've done theatrical pickpocketing. Really? I've done psychological Derren Brown type illusions from the stage.
And all of that is exploiting fundamental parts of human nature, from attention management to memory reframes, things like that. It's social engineering at some point. It is social engineering.
Yeah. In a very visceral way. You can change somebody's reality within seconds to minutes.
And if I can show that from stage, well, then people have that dotted line into, oh, here's how a cyber criminal can do it with a phishing email. I love it. Perry, the whole issue of deception, look, I remember, I guess it was, maybe it was right around COVID or right after, the whole kind of deception as a product- Yeah ...
deception as a company product- Right ... " It was novel. Right.
Even though it really wasn't. It was a reframe of honey pots. It's something that's been around.
Yeah. Right. Yeah.
That's all it kind of was at some level. But I don't know what happened, but it kind of passed, and this is very common in tech and security, it passed from a product to a feature. Yeah.
Yeah. Is that the case here? Or talk about your role here at KnowBe4 with that.
So this is a new title for me, kind of really focusing on work that I've been doing over the past... Well, a continuation of a lot of work that I had done in the past, but really focused on a lot of the deep fake work that I've been doing recently. So KnowBe4, really well known for simulated phishing, which that's the type of deception that we've done, is deception.
We want to trick people so that they can fail safely and that they can learn and build repeatable patterns with it. Deep fakes and other types of deception fit into that. And back when Kevin Mitnick and I used to work together too, we really liked to focus on the fundamentals of, again, why people are susceptible.
The technology is always going to change. It's going to ebb and flow, and there's going to be these peaks of really interesting new things, but they are just the new tool that then gets added to the deceptive framework. Love it.
Now, when we first started talking about deception, when you started blogging in 2003- Yeah ... AI, agentic AI, all these things kind of really weren't- Right ... on the agenda.
Yeah. But I've got to imagine that, well, look, deep fakes will never be the same- Right ... with AI, right?
Yeah. I mean, it's exploded. What effect has this had on the whole deception kind of-community and market?
Yeah. So I love that question because there's two sides to it. One is there's a video that they showed right before our CEO, Brian Palma, came on today, and it's a very fun theatrical trailer type of thing, which has him acting like an action movie hero.
I created that with one image of him, one picture. Really? I didn't have to get 20 hours or 200 hours of video and train a model.
I had to get one good picture of him, and then we did some incredible things. I also did videos yesterday that were framed as surveillance footage of him giving money to other people. And all that's super believable.
That's where we've got. At the same time, so the technology is way up here in capability and way up here in believability. At the same time, it is just the new tool, and the only thing that gives that technology and that sophistication power is the narrative that it unlocks, the emotion that it triggers, the people that are involved.
Because I can have a really good deepfake of person A handing money to person B. That's really interesting to look at, but it only matters when you know who person A and person B are, and where they fit into the contextual ecosystem of your reality. Is that two political figures?
Is it a celebrity? Is it a CFO and maybe a personal assistant that works for them? What does that mean?
And so the deepfake is an artifact that fits within a deceptive framework. So, I've got some thoughts on this- Yeah ... as one way to imagine.
I'm almost of the belief that trying to teach people to spot a deepfake is going to be harder and harder and less and less fruitful. Yeah. I agree.
That the more important thing is whether it's a deepfake or not, if they're asking you to do something that is wrong, dangerous- Yeah ... risky, whatever, that's where we have to concentrate the training. You've just hit the conclusion of all my presentations.
Oh, really? Okay. Yep.
You jumped to the end, which is counterintuitive to most tech people, right? I think it is. Is we want sophisticated deepfake detection systems.
Right. And what I have to take people through is the fact that every deepfake detection system I've personally tested, I've been able to break. Break through.
And I'm not even being sophisticated about it. It is the fact that it's an arms race. Yep.
And so when it comes down to it, the thing that matters less to me is whether something is fake or real, because we're also inviting AI to touch up our appearance, to replace our backgrounds, to do all that kind of stuff. So with the fingerprints of AI slathered over even the real, quote-unquote, "real people," what's a deepfake detector to do? The bigger question is exactly what you said.
What is the reality that it's trying to convey? What's the narrative? What are the emotional triggers?
And what does it want me to do or believe? Also, things like what's the distribution method? How did it get to me?
And all those things factor in. But ultimately, that crux, what does it want me to do or believe? I love it.
I think I'm in agreement with you. Violently in agreement. Yeah.
Now, that's the theory, that's the idea. How does that translate into the KnowBe4 product line? It translates really well because it goes back to our roots, right?
So we've always been well known as a phishing simulation vendor. Mm-hmm. And a vendor that's focused on helping people work with, rather than against human nature in the way that we set up our best practices and our frameworks for doing things.
When we get to the current state of reality and technology, we're now in this agentic AI era that also is focused on deepfakes and deception, but also empowering the modern workforce. And in the same way that humans can be tricked and fooled and go astray, AI agents can be tricked and fooled and go astray as well. And so, an interesting thing that KnowBe4 recently has been doing is trying to deal with that whole workforce understanding of humans plus AI agents, and to build for that current reality.
Absolutely. Now, I was talking to a couple of our guests earlier. As humans, we tend to always think that the moment we're in right now is the apex.
Yeah. But this wave hasn't crested. No.
Right? If I ask you to sit here and say, "Perry, project 12 months. We're at KB4 Con 2027.
What's changed? What have we done better? " So, I think what we see in 2027 is a continued acceleration curve, and I think that we've also hit the point where anybody that has thought that they can't be tricked by a deepfake will have experienced a deeply deceptive moment within the past year that they realize is deeply deceptive.
For a lot of people over this past year, it's been things like Sora 2 videos or Veo 3 videos, or surveillance footage of cats jumping on trampolines or things like that, but it's going to be much more insidious. Yeah. We also have, us in the US, we're headed up to a political midterm, and I think we're going to see the stress points for a lot of deepfakes.
And I don't want to get into the politics of it all, but that is where we see really the tip of the spear for these- Yeah ... types of technologies being used, frankly, because when we see it happen in organizations, people don't share the artifact for that. But when it's public, it's- But when it's public, it gets out there, and we see it all the time I know.
I worry about this becauseWithout getting into the politics of it. Yeah. Look, we haven't quite figured out how social media is herding us like sheep.
Putting deepfakes into- Yeah ... social media, to me, is just absolute insanity poison. And they're getting baked in at the root right now, right?
Because Sora 2 went away. Right. But TikTok now allows you to do the same thing.
Meta AI is allowing you to do the same thing. They're not quite as sophisticated- No ... but they'll get there.
I was talking to my video people just last week. We loved Sora 2. It was fun.
It was fun. We were using it for certain things, like for- Yeah ... a little intro video- Yeah ...
or something like that. It was quick, down, dirty, and easy. CDAM 2 is good.
CDAM. Yeah. S-D- Take a note of that, Alan.
However, it's a Chinese model, and there's... But- There is something to be said about that. Assume that what you're putting in there- Yeah ...
may be going out the back door. But if you're not putting in intellectual property, you're not putting- No ... anything that you're concerned about reuse, then it's good.
The Chinese models for video generation are incredibly sophisticated. Are they? Yeah.
So anything that ByteDance is doing, anything that Alibaba Group is doing, they're worth paying attention to, even if you don't plan on using them. Great advice. Yeah.
Great advice. Perry, I think that's about time here. Okay.
But I'm going to ask you to close- Yeah, sure ... with one thing. CISOs, security leaders, not even security people, just IT leaders- Yeah ...
out there. In this era of deepfakes and deception, give them the top three things they should be doing. Okay.
It may not be a top three, but I want to go back to what you said. Go ahead. This fake versus real conversation, I think, is a red herring.
Red herring. Yeah. I think we have to focus on, is this deceptive or not?
What is the reality that it's trying to project? How did it get to me? Why did it land in front of me specifically?
What emotion is it poking? What narrative is it unlocking? What does it want me to do or believe?
So that's number one. Second one is we all need to learn how to slow the F down. Yeah.
Whether that's hitting a Like button, an angry face button, whether that's replying to an email, whether that's transferring money. The ability to just go, "Oh, wait, I've been triggered by this emotion. I feel fear, I feel urgency, I feel authority, I feel hope," or something like that.
Because I feel that, I should take that as a trigger to actually slow down, take a breath, and get curious. And so I think if we were to do those two things, get rid of fake versus real, as I think that's a false binary, and then learn to slow down. I love them both.
Perry, for people who want to stay up on what you're writing- Yeah ... and talking and doing, what's the best place? Best place to find me is LinkedIn.
It's pretty much the only thing I stay current on. com that I update periodically. I have a YouTube channel called The Faik Files.
That's F-A-I-K Files. And I've got a couple podcasts that I'm intermittently doing right now as well. One is The Faik Files.
Another one is 8th Layer Insights. And then a third one that I hope to get back to is called Digital Folklore, and it's all about urban legends, conspiracy theories, and the things that we convince ourselves to believe. Love it.
Perry, it's great to see you- Thank you ... in person. Appreciate it.
Perry Carpenter, one of the OGs of security blogging back when. We're here. We're going to have a lot more coming at you from KB4Con here in Orlando.
I'm Alan Shimel.