Digital Doppelgängers in the Workplace: Emerging Employment Law Risks

By Ivie A. Serioux and Jerry Zhang

September 16, 2026

Digital Doppelgängers in the Workplace: Emerging Employment Law Risks

9.16.2026

By Ivie A. Serioux and Jerry Zhang

A dark, artistic image showing multiple overlapping profiles of human faces in shadow, facing each other and fading into the darkness on both sides of the image.

White text on a red background invites readers to preview the Labor and Employment Law Journal and encourages non-members to join the Labor & Employment Law Section for more articles.An employee opens her work email and finds a message, apparently from her supervisor, directing her to wire $100,000 to an unfamiliar account. The request is unusual as her supervisor has never asked her to wire money before. She clicks to expand the sender’s address and immediately sees that the domain does not match. She reports the attempt to IT and wires nothing. The scheme she foiled is known as a business email compromise scam, a form of spoofing in which fraudsters impersonate authority figures to trigger unauthorized financial transfers.[1] Most employers are aware of this type of scam and have policies designed to prevent it. Employers are generally prepared to address routine spoofing, however, artificial intelligence has significantly raised the stakes and introduced new risks.

House Ad

Consider what happened in February 2024. A finance employee at a non-U.S.-based multinational engineering firm also received what appeared to be a suspicious email.[2] This time, however, the employee was persuaded to join a video conference call that appeared to include the company’s chief financial officer and other senior executives. The employee agreed to wire $25.6 million. Every participant on that call, except the victim, was an AI-generated deepfake. The faces and voices of real corporate officers, including the CFO, had been manufactured while on the video call. The deception was difficult to detect because the deepfakes on the video call looked and sounded real. According to the FBI’s Internet Crime Complaint Center, in 2025 American businesses reported losses over $30 million to business email compromise scams involving AI alone.[3] This figure is solely based on American businesses that reported losses, acknowledging that many businesses may not report being subjected to a scam.

AI is reshaping not only how fraud is committed, but also key aspects of the employment relationship, including the rise of deepfakes in the workplace. Deepfakes are synthetic media, that is, content created or manipulated using machine learning, particularly deep learning models trained on large datasets of images, voices or videos, in an effort to create false (and typically malicious) information.[4] With minimal effort, bad actors can now impersonate coworkers, executives or clients – making deepfakes a potent tool for fraud, impersonation and harassment.

Courts are already grappling with the use of AI-enabled tools being deployed to harass, retaliate, humiliate and impersonate within the workplace. In Carranza v. City of Los Angeles, a California appellate court affirmed a $4 million jury verdict for a police captain whose workplace was permeated with sexually explicit, fabricated images purporting to depict her, holding that the circulation of false sexual imagery could constitute unlawful harassment under California law. Although the court did not address AI-generated deepfakes specifically, the decision underscores that employers may face liability where synthetic or falsified sexual content creates a hostile work environment, regardless of the method used to generate the imagery.[5] A Washington State Patrol trooper is alleging claims of discrimination, retaliation and invasion of privacy against his employer. Specifically, he is alleging that his supervisor generated and disseminated a deepfake video showing the officer kissing a coworker.[6] Separately, a Nashville television meteorologist sued after she alleged her employer failed to address synthetic sexually explicit images circulating among staff.[7] These cases share a common thread: a human actor using AI tools to generate synthetic content aimed at harassing a coworker.

However, given the rise of agentic AI in the workplace, there is now a threat that misconduct may originate from an external actor or an AI system impersonating a workplace authority figure. Agentic AI refers to AI systems designed not merely to generate content or respond to prompts, but to independently pursue goals and take actions with limited human supervision.[8] Unlike traditional generative AI tools that wait for user input, agentic AI systems can plan, reason and execute multi‑step tasks – often by interacting with other software systems, calling tools or APIs, and adjusting their behavior based on feedback and results.

These developments raise difficult questions for employers. Unlike traditional harassment cases, the alleged misconduct may not always be traceable to a human coworker or supervisor. This evolution tests the contours of liability under Title VII, the New York State Human Rights Law and the New York City Human Rights Law, each of which was drafted with human misconduct in mind.

This article examines how AI‑enabled impersonation challenges existing employment‑law frameworks and outlines practical considerations for New York employers navigating this emerging risk.

From Fake Content to Fake Actors: Recent Data on AI Impersonation by the Numbers

Recent data confirms that AI‑enabled impersonation is no longer a speculative risk. Deloitte reports that the proliferation of generative AI has dramatically reduced the technical barriers to identity replication, accelerating the spread of “digital doppelgängers” across workplace and social contexts.[9] Independent industry tracking shows a sharp rise in reported deepfake incidents in 2024 and early 2025, with first‑quarter 2025 incidents exceeding all of 2024, indicating sustained growth rather than a temporary spike.[10]

The trend is especially pronounced for voice‑based impersonation, which has direct implications for employment law risk. Industry reporting indicates that AI voice‑cloning and voice‑based fraud increased by more than 600% year over year in 2024, reflecting a shift away from static deepfakes toward real‑time audio impersonation, including live phone calls and voice messages.[11] These tools often require only seconds of source audio, making them particularly effective in workplace settings where employees are accustomed to receiving verbal instructions from supervisors or human resources personnel. According to McAfee security researchers, voice cloning can now be generated from as little as three seconds of recorded audio, producing an 85% voice match to the original speaker.[12]

As discussed above, these technological trends are already manifesting in employment litigation. Furthermore, the Equal Employment Opportunity Commission’s 2024-28 Strategic Enforcement Plan emphasizes scrutiny of technology-driven discrimination and digital harassment.[13]

Deepfake Harassment: The Hostile Work Environment Framework

When deepfake or synthetic content overwhelmingly targets women with the foreseeable effect of altering working conditions, humiliating employees, chilling leadership participation or undermining professional credibility, the conduct can translate into a hostile work environment claim under Title VII and its New York analogues. The operative question is not whether the content is synthetic, but whether it is severe or pervasive enough to affect the terms and conditions of employment. Synthetic origin does not insulate deepfakes from existing harassment law; it is simply the delivery mechanism for conduct those frameworks already prohibit.

Voice cloning further compounds this harm. A fabricated audio recording can be weaponized not only to harass but to manufacture apparent proof of something an employee never said, authorized or approved. In workplace investigations and disciplinary proceedings, that manufactured proof functions as a credibility issue. These incidents cause severe reputational and psychological harm to victims and place employers in difficult credibility determinations, particularly when relying on outdated policies and investigative procedures.[14]

Employers should also recognize that the gendered nature of many deepfake incidents does not define the outer limits of this risk. AI‑generated content can just as easily be used to target other protected characteristics, such as race, disability, religion, or national origin. For example, a deepfake can be used to alter a colleague’s appearance or identity in ways intended to demean or ridicule. Title VII and its New York analogues prohibit harassment based on any protected class, regardless of the medium used. Deepfakes therefore fall squarely within these prohibitions when they target protected characteristics and contribute to a hostile work environment.

Agentic AI and the Absence of a Human Harasser

Agentic AI challenges a foundational assumption in workplace harassment law that misconduct can always be traced to a single human actor, but the absence of a human creator does not eliminate liability where human conduct amplifies the harm. Even if responsibility for the creation of AI‑generated or synthetic content is unclear, human dissemination, commentary and tolerance of such material in the workplace remain squarely within existing harassment frameworks. As illustrated by Carranza v. City of Los Angeles, courts focus less on how falsified sexual imagery originates and more on how employees circulate, discuss and react to it, and on whether employers take prompt corrective action, underscoring that workplace liability may arise from human responses to AI‑generated content regardless of the technology involved.[15]

In this setting, the threshold question is not simply whether an employer can be held liable when AI generates harassing or discriminatory outputs; instead, it is which theory of liability is applicable. Section 8-107(13) of the New York City Human Rights Law establishes three routes to employer liability for discriminatory conduct by an employee or agent: strict liability where the wrongdoer exercised managerial or supervisory responsibility; actual knowledge plus acquiescence or failure to take immediate corrective action; and constructive knowledge plus failure to exercise reasonable diligence. Separately, Section 8-107(1) imposes direct liability on employers for their own discriminatory conduct.

Which theory applies to agentic AI depends on a question courts have not yet resolved: whether the functional authority conferred on an AI system – delivering disciplinary communications, directing employee conduct, operating with the apparent authority of HR – equates to managerial or supervisory status under Section 8-107(13). If it does, strict liability attaches without any showing of notice. An AI system authorized to act with supervisory authority is not meaningfully distinguishable, in functional terms, from a supervisor acting within that same authority. Courts construing the city’s human rights law broadly in favor of its remedial purposes may well adopt that analysis. However, the recommended practices for AI use in the workplace always include keeping a human in the loop. Accordingly, some may argue that an AI agent is never acting with supervisory authority.

If the agentic AI is viewed not as supervisory but instead as a third-party agent, the relevant inquiry may become whether the employer exercised reasonable care in selecting, configuring, supervising and constraining AI systems, and whether it acted promptly once harmful or discriminatory outputs became foreseeable. That framework mirrors longstanding principles governing third‑party harassment, under which employers may be held accountable for misconduct by customers, vendors or other non‑employees when they knew or should have known of the conduct and failed to take appropriate corrective action.[16]

Agentic AI fits uncomfortably but plausibly within both doctrines. The unresolved issue, therefore, is not whether liability is theoretically possible, but whether an employer deploys AI in a way that permits it to act with supervisory authority, real or perceived, and where the line of foreseeability should be drawn when an autonomous system is capable of impersonation, decision‑making and unsupervised communication. At what point does an employer’s decision to deploy an autonomous system, capable of impersonation, decision‑making and unsupervised communication, carry with it a duty to anticipate and prevent the risk that the system itself may generate conduct contributing to a hostile work environment? There is currently no bright-line rule answering this question. Courts will have to grapple with how to classify agentic AI systems under the law.

Additional Implications for New York Employers: Liability, Investigations and Risk Management

These issues are especially salient under New York law since the New York City Human Rights Law is construed broadly in favor of its remedial and deterrent purposes and imposes a more expansive conception of employer responsibility than its federal counterpart. The three-route structure of Section 8-107(13) means that the scope of authority an employer confers on an AI system at deployment, not what the employer learns afterward, may be the decisive liability question. Where an agentic system is authorized to exercise supervisory or managerial functions, the strict liability track may apply, and actual or constructive notice of discriminatory conduct is irrelevant. Where the system functions as a non-supervisory agent, liability turns on what the employer knew or should have known and whether it responded with reasonable diligence.[17] In either scenario, the employer’s deployment decision may independently give rise to direct liability under Section8-107(1) for its own discriminatory conduct.

Accordingly, the liability analysis should focus on the AI system’s authorized scope of function at deployment, the foreseeability of harmful outputs, and the adequacy of safeguards and response mechanisms. Where employers can demonstrate that AI systems were implemented for legitimate business purposes, subject to defined constraints and monitored for misuse, those facts will bear on, though not necessarily eliminate, employer exposure.

AI impersonation also complicates internal investigations in ways that directly affect employer liability. Traditional investigations assume identifiable senders, authentic communications and reliable documentary evidence. AI‑generated content disrupts each of these assumptions. Employers may encounter spoofed phone numbers, fabricated audio recordings or conflicting employee accounts where individuals genuinely believed they were interacting with supervisors or HR personnel. Effective investigations therefore require early coordination among human resources, legal and information‑technology teams, including careful assessment of authentication, metadata and system access.[18] Failure to adapt investigative protocols may support claims that employers did not take reasonable steps to address known harassment risks, particularly after complaints are raised.[19]

While courts continue to grapple with these issues, employers can adopt a proactive, multidimensional approach to mitigate risk:

  • Update policies to address AI‑enabled misconduct. Anti‑harassment, misconduct and acceptable‑use policies should expressly cover AI generated impersonation, deepfakes and digital harassment, making clear that fabricated communications may constitute actionable misconduct regardless of whether a human actor is involved.
  • Document and limit the functional authority of AI systems. Because New York City Human Rights Law liability may attach without notice where a system exercises managerial or supervisory functions, employers should clearly document what each AI system is capable of doing and authorized to do, at what level of authority it operates and how its scope is constrained. Systems authorized to communicate disciplinary decisions, direct employee conduct or represent human resources should be treated as presumptively subject to strict liability analysis.
  • Prohibit unsanctioned impersonation of supervisors or HR personnel. Employers should design and deploy AI systems with technical and policy‑based constraints that prevent autonomous agents from impersonating supervisors, human resources personnel or other individuals, or from communicating in ways that reasonably create a false impression of human or managerial authority. Where AI systems are deployed in HR‑facing roles, employers should implement safeguards limiting which employer files or networks the system can access, limiting the system’s communicative scope, and provide clear disclosure that employees are interacting with an automated system rather than a human decision‑
  • Strengthen authentication and access controls. Sensitive communications, particularly those involving discipline, payroll, benefit, or investigations – should be subject to enhanced verification, logging and auditability to reduce the risk of spoofing or AI‑generated deception.
  • Train managers and HR to identify impersonation red flags. Targeted training should focus on recognizing signs of voice cloning or AI misuse, such as unusual communication patterns, urgency that bypasses standard procedures or requests inconsistent with established protocols.
  • Adapt investigation protocols for AI‑generated evidence. Complaint response frameworks should include early escalation to IT and cybersecurity teams and incorporate procedures for assessing authenticity, metadata, system logs and access credentials when AI‑enabled impersonation is suspected.
  • Reassess controls once risks become known. Employers should periodically evaluate foreseeable misuse risks tied to agentic AI and update safeguards, training and investigative practices – particularly after incidents or complaints – to demonstrate reasonable care and prompt remediation.

These measures addressing deepfakes and digital harassment remain critical as the technology evolves, and recent cases emphasize that employer investigation and intervention are central to assessing liability. Accordingly, employers should implement clear reporting mechanisms, conduct prompt and well‑documented investigations into suspected synthetic or falsified content, and take immediate corrective action to halt dissemination and address employee conduct, even where the origin of the content is uncertain.

Conclusion

The employee who agreed to wire $25.6 million was not careless. He saw familiar faces and heard familiar voices. He did what anyone would do; he trusted them. That trust was the vulnerability, and the technology exploited it perfectly.

Agentic AI doesn’t just replicate that threat. Instead, it embeds it in every employer’s workflow that chooses to deploy agentic AI. When the system handling your HR calls, generating your performance records, and responding to employee complaints is also capable of impersonating the people who run those functions, the question of who is responsible for when things go wrong is no longer clear cut.

Existing employment law frameworks are flexible enough to adapt, but employers who rely on outdated assumptions about misconduct risk being unprepared. For New York employers operating under expansive human rights laws, AI‑enabled impersonation should be understood not merely as a technological issue, but as an emerging employment law risk. Proactive policy development, training and cross‑disciplinary response mechanisms will be essential for employers to create clear boundaries that uphold trust, minimize liability and protect employees as courts and agencies confront the next phase of workplace misconduct.


This article appears in the Labor and Employment Law Journal, a publication of the Labor and Employment Law Section. For more information, please visit nysba.org/labor.


Ivie A. Serioux is a shareholder in the New York office of Littler Mendelson, P.C. She counsels employers, executives and HR leaders on complex workplace matters including discrimination, retaliation, compliance and risk management. She also advises organizations on the legal and ethical implications of AI, helping develop compliant, transparent and effective AI strategies. A frequent speaker on AI, employment law and the future of work, she is co-chair of the New York City Bar Association’s Presidential Task Force Subcommittee on Artificial Intelligence in Labor and Employment.

Jerry (Gongyu) Zhang is an associate at Littler Mendelson, P.C. His practice encompasses a broad range of employment law matters, with experience in both litigation and international employment compliance. He represents employers in cases involving discrimination, harassment, and retaliation, and advises international clients on cross-border labor and employment issues.

Endnotes:

[1] Federal Bureau of Investigation, Business Email Compromise, https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/business-email-compromise (last visited Apr. 29, 2026).

[2] Heather Chen & Kathleen Magramo, Finance Worker Pays Out $25 Million After Video Call with Deepfake “Chief Financial Officer,” CNN (Feb. 4, 2024), https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk.

[3] Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 Internet Crime Report (2026), https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf.

[4] Ivie Serioux & Jerry Zhang, Deepfakes and Digital Harassment: What Employers Need to Know, Littler ASAP (2025), https://www.littler.com/news-analysis/asap/deepfakes-and-digital-harassment-what-employers-need-know-2025.

[5] Carranza v. City of Los Angeles, 111 Cal. App. 5th 388 (2025).

[6] Id.

[7] Khorri Atkinson, AI Deepfakes Spawn New Breed of Workplace Harassment Lawsuits, Bloomberg L. (Daily Lab. Rep.) (Feb. 24, 2026), https://news.bloomberglaw.com/daily-labor-report/ai-deepfakes-spawn-new-breed-of-workplace-harassment-lawsuits.

[8] Cole Stryker, What Is Agentic AI?, IBM (May 4, 2026), https://www.ibm.com/think/topics/agentic-ai.

[9] Deloitte, Digital Doppelgängers: The Implications of AI-Driven Identity Replication in the Workplace (Dec. 2022), https://www.deloitte.com/global/en/issues/work/digital-doppelgangers.html.

[10] Keepnet Labs, Deepfake Statistics & Trends 2026: Growth, Risks, and Future Insights (Mar. 12, 2026),
https://keepnetlabs.com/blog/deepfake-statistics-and-trends.

[11] Bright Defense, 150+ Deepfake Statistics (Apr. 2026), https://www.brightdefense.com/resources/deepfake-statistics/.

[12] Scammers Use AI Voice Cloning Tools to Fuel New Scams, McAfee, https://www.mcafee.com/ai/news/ai-voice-scam (last visited May 4, 2026).

[13]  U.S. Equal Emp. Opportunity Comm’n, Strategic Enforcement Plan for Fiscal Years 2024–2028, https://www.eeoc.gov/strategic-enforcement-plan-fiscal-years-2024-2028 (last visited May 4, 2026).

[14] Jesse Dill, AI and Deepfakes Complicate Evidence in Workplace Investigations, Bloomberg L. (Feb. 27, 2024).

[15] See Carranza, supra note 5.

[16] See, e.g. Summa v. Hofstra Univ., 708 F.3d 115, 124–25 (2d Cir. 2013) (“The United States Court of Appeals for the Second Circuit adopts the well-reasoned rules of … in imputing employer liability for harassment by non-employees according to the same standards for non-supervisory co-workers”).

[17] N.Y.C. Admin. Code § 8-107(13).

[18] See Zubulake v. UBS Warburg LLC, 220 F.R.D. 212, 217–18 (S.D.N.Y. 2003) (recognizing employer obligations to preserve and evaluate electronic evidence once litigation risk becomes foreseeable).

[19] See Distasio v. Perkin Elmer Corp., 157 F.3d 55, 65 (2d Cir. 1998) (employer liability turns on reasonableness of response after notice of harassment).

Related Articles

Six diverse people sitting holding signs
gradient circle (purple) gradient circle (green)

Join NYSBA

My NYSBA Account

My NYSBA Account