When Andy Burnham stood before the United Nations General Assembly, he wasn’t just delivering another diplomatic speech. He was delivering a stark warning—one that framed the future of British democracy as a battle for the very information people see, believe, and act upon. As the newly appointed UK Prime Minister, Burnham used his platform to describe an “industrial-scale assault” on the information environment, not just in Britain but across allied nations. He didn’t mince words. He pointed his finger squarely at Russia, accusing its agencies of using every tool at their disposal to spread lies, stoke fear, and exploit the anxieties of ordinary citizens. This wasn’t old-fashioned propaganda in the Cold War sense. It was something more insidious, more personalized, and more technologically advanced: AI-assisted deepfakes, manipulated narratives, and an endless pipeline of digital deception designed to make people feel that their country is falling apart, that their neighbors are enemies, and that their institutions cannot be trusted. In his words, these hostile actors are attacking the “strong, cohesive society” that underpins “everything we hold dear and everything we want to achieve.” It was exactly the kind of existential framing that gets people to sit up and pay attention—not because Burnham is prone to hyperbole, but because the threat he described reaches into people’s homes and twists how they feel about their own country and community.
To answer this challenge, Burnham announced the creation of a new National Centre for Information Defence. The Centre, according to an official release, will bring together intelligence agencies, law enforcement, and social media companies under a single remit: detect, attribute, and disrupt foreign information attacks, while also helping communities build resilience against disinformation. This is not just another bureaucratic acronym in the UK’s national security apparatus. It’s a recognition that the battlefield of modern warfare has shifted from physical territory to the information space—the place where people form their opinions, make their decisions, and eventually cast their votes. The Centre’s name is telling: “defence” implies something more than simply monitoring or reporting. It suggests active protection, proactive disruption, and a coordinated effort to guard the public’s collective sense of reality. Burnham’s announcement was bold, and the political capital he devoted to it suggests that what has been happening behind closed doors is far more serious than most citizens realize. Russia, he implied, has been actively meddling with volatile UK political sentiment on a scale that few outside government fully comprehend. The Prime Minister made clear that the UK will not play Russia’s game of trading escalatory rhetoric, but it will systematically take apart the machinery of disinformation, piece by piece, and create a bulwark against it. The Centre, in this sense, is as much about psychological resilience as it is about cyber defense.
Yet, as with any ambitious government initiative, there are questions about whether the UK has the expertise and the speed to make it work. Andrew Bud, CEO of the identity verification company iProov, voiced a cautious but constructive response. He acknowledged that the Centre will have an important role to play, but warned that its success will depend on how quickly it can move from identifying threats to actually disrupting them. Bud’s point is critical because the nature of the threat is evolving at a pace that traditional government processes often struggle to match. Deepfakes, for example, are no longer the clunky, obviously fake videos of a few years ago. They are now sophisticated, scalable, and increasingly difficult to spot with the naked eye. Bud argued that relying on individuals or platforms to simply spot fake content after the fact is no longer viable. Instead, the Centre should be looking at the infrastructure behind these attacks—how to verify that the people, accounts, and communications we interact with online are genuine. This means shifting the focus from reactive detection to proactive verification. If AI is industrializing deception, then the response must be equally industrial in its ability to distinguish the real from the fabricated. Bud emphasized that this is not just about catching the bad guys after they’ve already done damage; it’s about building a system where trust is the default, where authenticity is baked into the architecture of online life, and where fraud and disinformation are stopped at the door rather than cleaned up after the fact.
Bud’s call for a more comprehensive approach to verification connects directly to the UK’s emerging cyber resilience framework. The Cyber Security and Resilience Bill, which has been making its way through Parliament, recognizes the need to protect the authenticity and integrity of data as part of securing essential services. Bud argued that this same principle should extend to the authenticity of the people and digital interactions that those services rely on. In other words, if the UK is going to secure its banks, energy grids, and healthcare systems, it also has to secure the identities of the individuals accessing them—and the information they are consuming. This is why Bud believes identity verification and deepfake detection should be moved to the center of the UK’s defensive strategy, alongside intelligence sharing and public education. The logic is simple: a cyber defense system that can protect data but can’t tell whether the person behind an account is real is only half a defense. An attacker doesn’t need to hack a server if they can simply impersonate a legitimate user. And an attacker doesn’t need to create a fake news website if they can just as easily generate a convincing video of a government official saying something they never actually said. The integration of identity verification into the broader cybersecurity framework is not a technical detail; it is a fundamental shift in how the country approaches its own digital sovereignty. For the first time, the fight against disinformation is being treated not just as a communications challenge, but as a core cybersecurity issue.
The urgency of this integration is underscored by the rapidly growing scale of the deepfake threat. According to the 2026 Deepfake Fraud Detection Market Report from Biometric Update and Goode Intelligence, the number of deepfake fraud attempts is projected to exceed 334 million annually by 2028. That number is almost too large to wrap one’s head around. It means that within a couple of years, deepfake-enabled fraud could affect hundreds of millions of attempts globally every year—everything from fake identities used to open bank accounts to synthetic voices used to authorize wire transfers. The report’s findings are further corroborated by new data from Gartner, which shows that 41 percent of Chief Information Security Officers reported at least one social engineering incident involving a deepfake over the past year. This is no longer a theoretical risk or a plot point in a science fiction movie. It is happening now, and it is happening on a massive scale. What makes it even more dangerous is the overconfidence of the general public. The Avast 2026 Safe Tech Report found that 56 percent of adults worldwide are “convinced they’d catch an AI fake the moment they saw one.” The reality, however, is that deepfakes have become so sophisticated that even trained experts can be fooled. The gap between perception and reality is enormous, and it is exactly the gap that malicious actors are exploiting. They don’t need to fool everyone; they just need to fool enough people at the right moment to tip an election, tank a stock, or ignite a riot. And because most people believe they are immune, they let down their guard, making them more vulnerable rather than less.
The United States is already taking new action against this growing threat. The Department of Homeland Security has expanded its testing of remote identity verification technology to specifically target AI-generated identity documents and biometric deepfakes. As part of this effort, it has added a dedicated deepfake detection challenge to the 2026 Remote Identity Validation Rally (RIVR). This is a clear sign that governments are beginning to understand the necessity of building defenses not just against traditional cyberattacks, but against the manipulation of identity itself. It also shows that the problem is global in nature and cannot be solved by any single nation acting alone. The UK’s new National Centre for Information Defence, the European Commission’s newly approved cross-border ID framework, and the DHS’s testing initiatives all point toward a shared recognition: the authenticity of digital identity is the foundation of digital trust, and digital trust is the foundation of democratic society. The path forward is not to retreat from technology, but to develop better, faster, and more human-centered ways of verifying what is real. Andrew Bud’s challenge to the Centre is a challenge to all of us. It is easy to talk about fighting disinformation in grand terms, but the actual work is unglamorous: it lies in verification protocols, detection algorithms, data integrity standards, and the painful but necessary process of educating the public to be just a little less confident, a little more curious, and a lot more skeptical. The Centre’s success will not be measured in press releases or political speeches. It will be measured in the quiet moments when a parent receives a suspicious video, when a voter sees a sensational headline, when an employee gets a strange email from their boss—and something inside them says, “Wait, is this real?” In that moment, the National Centre for Information Defence, and all the systems it will help build, will prove whether it truly understood its mission: not just to defend the information space, but to defend the human trust that holds our world together.

