Services I Can Help With
Pick the closest match. If any sound familiar, it's worth a short conversation because the biggest risk is delay, confusion, or poor documentation.
- Someone may have used AI to create harmful or explicit content about a person
- Your organization is unsure how to respond to a deepfake or AI impersonation scam
- You want an AI policy, but need governance and guardrails first
- You're an attorney or advocate defending a victim of AI-generated harm
Service Packages
↓ See Hypothetical ScenariosEvery engagement is scoped to a real problem with defined deliverables. No open-ended retainers with vague outcomes. Choose the package that fits your situation, or reach out and I'll recommend the right starting point.
Deepfake Incident Response & Documentation
Structured, first-response consulting for individuals who have been targeted by deepfake content. I help you preserve evidence correctly, build a legally defensible timeline, and understand your options so you are prepared before you walk into an attorney's office or file a police report.
- Incident intake review
- Evidence preservation checklist
- Platform reporting overview
- Honest scope assessment
- 60-min intake session
- Incident timeline PDF (attorney-ready)
- Evidence log with chain-of-custody notes
- Platform reporting instructions (submitted or guided)
- Resource referral memo (legal, law enforcement, support orgs)
- 30-min follow-up call
- Everything in Documentation Package
- Coordination support for attorney handoff
- Second incident review if new content surfaces
- Deepfake-specific legislative context memo
- Emotional referral resources
- Up to 2 additional check-in calls
AI Impersonation & Business Risk Audits
Small and mid-size organizations are increasingly targeted by deepfake audio, video calls, and AI-cloned voice scams. I assess your actual exposure and produce a prioritized, actionable risk brief not a generic checklist.
- Executive impersonation surface review
- Public-facing AI exposure assessment
- Written risk brief (4–6 pages)
- Top 5 priority recommendations
- Everything in Risk Snapshot
- Deepfake scam preparedness review
- Internal policy gap analysis
- Staff awareness session (90 min, remote)
- Incident response playbook (draft)
- Post-delivery Q&A call (60 min)
- Monthly threat landscape briefing
- Policy update reviews
- Incident triage support (up to 2/month)
- Regulatory monitoring for your sector
- Priority response within 48 hrs
Deepfake Fraud & Incident Readiness for Financial Institutions
Banks, credit unions, broker-dealers, and asset managers face a distinct category of deepfake risk: voice authorization, client deepfake-video calls, KYC bypass attempts, and impersonation-driven account takeover. These incidents carry regulatory exposure on top of direct financial loss. I build specific protocols, scenario-based training, and incident documentation frameworks aligned to how financial institutions actually operate.
- Wire/transaction authorization workflow review
- Client-facing impersonation surface review
- Written risk brief (5–7 pages)
- Top priority recommendations, ranked by exposure
- Everything in FI Exposure Assessment
- Scenario-based protocol covering KYC bypass, market manipulation, client impersonation, loan fraud, governance fraud, and extortion
- Eight-step incident intake framework, tailored to your institution
- Scenario Summary Matrix for staff quick-reference
- Staff awareness session (90 min, remote)
- Regulatory disclaimer language clarifying advisory vs. legal/compliance counsel scope
- Post-delivery Q&A call (60 min)
- Monthly threat landscape briefing (financial sector focused)
- Incident triage support (up to 2/month)
- Regulatory monitoring relevant to your sector
- Protocol/document updates as new scenarios emerge
- Priority response within 24 hrs
College/University Protocol Development
Schools are navigating AI-generated harassment, student impersonation, and synthetic abuse content with almost no institutional framework. I work directly with administrators, counselors, and district policy staff to build the protocols, response procedures, and staff training materials your school actually needs without exposing me or your staff to harmful content directly.
- 90-min scoping session (administrators + counselors)
- Incident response flowchart (PDF)
- Reporting pathway guide for staff
- Basic definition & identification resource sheet
- Everything in Protocol Starter
- Staff training deck (editable)
- Parent communication template
- Policy language recommendations for student handbooks
- Jurisdiction-specific legal context memo (PA law focused)
- Administrator Q&A session (60 min)
- Everything in Full Protocol Package
- Cross-school policy harmonization review
- Tailored content for multiple grade levels (staff-facing)
- Regulatory alignment review (Title IX, FERPA, state law)
- 90-day follow-up support window
Attorney Research & Case Support
Law firms handling harassment, defamation, employment disputes, NCII (non-consensual intimate imagery), and cyber abuse cases increasingly need credible deepfake and AI policy expertise they can hand off to clients or use in filings. I provide organized, cite-ready research and structured intake support built around how legal work actually flows.
- Topic-specific AI/deepfake policy research
- Legislative landscape overview (state + federal)
- Formatted for use in briefings or filings
- Delivered within 5 business days
- Client intake summary (organized for counsel)
- Evidence log with chain-of-custody documentation
- Deepfake-specific research memo (tailored to case facts)
- Platform policy reference sheet
- Attorney briefing call (60 min)
- Revisions based on attorney feedback (1 round)
- Up to 2 research memos/month
- Intake support for new matters
- Legislative monitoring relevant to your practice area
- Priority turnaround (3 business days)
- Monthly check-in call
Hypothetical Scenarios
These are illustrative situations composites drawn from real patterns in deepfake incidents across higher education, finance, and legal practice. They are not case studies or client disclosures. They exist to help you recognize when a situation is more serious than it appears.
"A student's image was on a site she'd never heard of."
A sophomore at a mid-size university discovers that AI-generated explicit images using her likeness have been posted to a content-sharing platform. She doesn't know when it happened, who created them, or whether her school is even equipped to respond. A friend sends her the link. She takes screenshots, then panics and deletes the thread destroying key metadata in the process.
When she finally reaches the student conduct office, they have no protocol. They tell her to "document everything," but she's already lost critical evidence. Her parents want to involve attorneys, but no one has organized the incident into a usable format.
"The CFO authorized the wire. Except it wasn't the CFO."
A regional asset management firm receives a Zoom meeting request from what appears to be a long-standing institutional client. The video call looks normal familiar face, familiar voice, familiar mannerisms. The client requests an expedited wire transfer of $340,000 to a new account, citing a time-sensitive deal closure. Two employees approve it internally.
Three days later, the actual client calls asking about an unrelated matter. No wire was requested. The firm has transferred $340,000 to an account that no longer exists. They had no deepfake detection protocol, no verbal verification requirement, and no written policy governing video-based authorization for wire transfers.
"My client has the evidence. I don't know what I'm looking at."
A civil litigator is representing a woman in a harassment and defamation matter. The opposing party allegedly created AI-generated video and audio content depicting the client in fabricated conversations distributed to her employer and professional network. The attorney has screenshots, a Google Drive folder of files, and a client who is credible but emotionally exhausted.
The attorney knows the case is strong but has no experience with AI-generated evidence. She's unsure how to frame the technology for the court, how to establish a chain of custody for digital files, or whether existing state statutes cover this fact pattern specifically.
"The video call passed identity verification. The account didn't belong to who it said."
A regional credit union's remote onboarding team completes a video-based identity verification call for a new high-balance account. The applicant's face and voice match the submitted ID on file the call goes smoothly, and the account is approved same-day.
Three weeks later, the real identity owner contacts the credit union after noticing unfamiliar activity on their credit report. The account was opened using a synthetic video built from the victim's publicly available driver's license photo and a handful of social media clips. The credit union's KYC process had no protocol for verifying liveness against deepfake video, and no escalation path once the discrepancy surfaced.
How I Handle Client Engagements
My process is designed to produce clear, defensible outputs — not lengthy reports that sit unread. Here's how a typical engagement works.
Initial Scoping Call (30–45 min)
We define the problem precisely. What happened, or what are you trying to prevent? What does harm look like in your specific context legal exposure, reputational risk, operational disruption, compliance liability? I ask direct questions and give honest preliminary framing at this stage.
Proposal & Agreement
I send a written scope of work confirming the package, deliverables, timeline, and payment terms. Nothing starts without a signed agreement. For packages over $500, I require a 50% deposit before work begins.
Risk Assessment & Research
Depending on scope, I conduct policy analysis, review your existing documentation, or analyze an incident. I focus on what actually applies to your situation not a broad survey of AI risk in general. The output is a clear picture of exposure, gaps, and priorities.
Structured Deliverables
I deliver written memos, protocol documents, or briefings prioritized by urgency, written for your audience (legal, executive, administrative, or technical). Every recommendation is tied to a specific risk and a specific action. Not generic checklists.
Follow-Through Support (Optional)
For organizations needing ongoing support policy implementation, regulatory monitoring, or periodic risk reviews I offer monthly retainer advisory. For one-time incidents or flat-fee engagements, the work closes when you have a clear response plan and documentation in hand.
Scope & Boundaries
Being clear about what I will and won't do is part of how I protect clients from wasted time and misplaced expectations.
I Will
- Give you an honest risk assessment, even if the news is good
- Tell you when something is outside my scope
- Refer you to appropriate legal counsel when needed
- Deliver written outputs you can use without me in the room
- Be direct about what's urgent vs. what's noise
- Hold your information in strict confidence
- Work on compressed timelines when a situation is urgent
I Won't
- Provide legal advice or act as your attorney
- Guarantee detection outcomes or forensic authentication
- Produce "cover" without real risk analysis behind it
- Oversell the threat to create dependency
- Take engagements where I can't add meaningful value
- Directly review or handle content depicting minors
- Assist in creating or deploying harmful synthetic media
Not sure if your situation "counts"?
If you're debating whether it's serious enough to escalate, that's exactly the moment to reach out. A short conversation can prevent unnecessary mistakes and give you a clean response plan.