Security: no generated breach victims
Product UI and captions.
Product UI and captions. Not a crying employee. Not a generated "CISO who learned the hard way." Not a photoreal family whose laptop is on fire because the landing page needed stakes. A breach victim is a private person. Inventing one is not empathy. It is a likeness problem in a red grade.
A deepfake of a private person is not a style. TikTok's private-figure line is permission, not labelling. A labelled synthetic victim is still a replica — or nobody presented as somebody, which is a different lie. The fake-review rule is the adjacent door: a constructed person speaking as if they were harmed or saved is fabricated proof.
This is general information, not legal advice. Do not generate the victim.
A breach victim is a private person
Private means not a public figure. Your customer's staff. A made-up "Sarah in finance" who is still a face. A lookalike of a real incident responder you pulled off LinkedIn "for realism." If a reasonable person who knows them would say "that is them," you have a replica. If nobody knows them because they do not exist, you still cannot put words in their mouth as testimony.
Fear-led ads already bounce the practitioner who builds the shortlist. AI video for cybersecurity companies is the audience page for that: buyers are saturated with threat marketing; the clip that moves an evaluation teaches a path, not a panic. A generated victim is the panic, with a rights problem on top.
Do not prompt "an exhausted SOC analyst at 3am." Do not upload a staff Slack photo as a style reference — that is how you get their head. If you ever need a real person in generation, the release has to cover it. Most security brands should not be generating people at all.
Ship the product, not a face
The honest object is the product. Capture a real screen: detection firing, a timeline that is true, a control the buyer will actually click. That screenshot is the still. Lock it before you spend on motion. If the graph is dramatised, the clip is a false dashboard. Practitioners notice.
Image-to-video can add a slow push or a cursor move on that still. Prompt only the motion. Do not re-describe a "dark operations floor" around it. The UI is the set.
Copy is type, not a generate. Status, CVE names, the one sentence the product is allowed to claim — burn them as a text overlay or time several lines with timed text overlays. Do not ask a video model to typeset a CVE. It will invent a number. Auto-captions are for speech you already recorded from a cleared human. They are not a way to put a victim's confession on screen.
Public-incident mechanics belong as diagrams, not as a reconstructed face of someone who got hit. Demonstrate the concept and the defence. Do not cast a stranger as the casualty.
What you are allowed to show
- The product, as it is. A real screen, a real alert. If you must motion it, I2V the screenshot.
- A named human you actually employ, on camera, with lines they will stand behind.
- A diagram, arrows and boxes, no photoreal body.
- Captions you wrote, over the product, not over a generated mouth.
Not allowed: a generated employee, customer, or "typical victim"; a synthetic testimonial; a CISO lookalike; a minor. Minors are a hard stop. If the brief is "make them feel the breach," the feeling you want is competence — a true UI and a sentence a practitioner would sign — not a stranger crying in 9:16.
FAQ
If we label the video AI-generated, can we still show a fictional victim?
A label tells viewers the media is synthetic. It does not create a grant from a private person, and it does not turn fabricated testimony into a case study. Leave the victim out. Show the product.
Can we generate a hooded attacker instead of a victim?
A photoreal private figure is the same class of mistake on the other side of the keyboard. Stick to diagrams, screens, and people you filmed. The hooded-hacker cliché is also how security buyers discount the ad.
Should we I2V a screenshot or rebuild the UI in a video model?
I2V the screenshot you can defend. Text-to-video will restage the product. Wrong chrome, wrong counts, a red banner that is not yours — that is a false dashboard, not a metaphor.
Who can talk in the clip?
A real, named person whose copy is cleared, or no one. Overlay the claim. Do not hire a generated analyst to explain the blast radius.