A Deepfake of Western Australia's Premier Ran as a YouTube Investment Scam Ad
What happened
A YouTube pop-up ad showing Western Australia's Premier endorsing an investment scheme had one thing working for it: the Premier never made it. Western Australia's Consumer Protection commissioner issued a public warning in November 2025 about a video circulating on the platform that used a purported AI-generated deepfake of Premier Roger Cook to promote a fraudulent investment opportunity. The ad reached viewers before any intervention.
The video was built from under ten seconds of real footage and real audio from Cook. That sliver of authentic material was enough to reconstruct a likeness, place it in a fabricated context, and attach a script Cook never delivered. The manipulated clip showed him apparently endorsing a "low investment, high return" scheme, the kind of language calibrated to sound credible enough to push past a viewer's skepticism before they could think twice. Cook, once made aware of the ad, described it as "very scary."
The Consumer Protection commissioner's warning named the video as an example of AI-driven fraud and called on platforms to take action against deepfake content used for financial crime. The request came after the ad had already been circulating. The warning was reactive, issued in response to a scheme that had already found an audience through a channel with billions of daily video plays and advertising inventory that moves faster than human reviewers can screen it.
The incident fits a pattern regulators have been describing for several years. Synthetic media capable of deceiving ordinary viewers is now cheap enough and fast enough that scammers can produce it at a volume that outpaces moderation. A state premier's face, his voice, and his institutional credibility were all used without consent to solicit money from viewers who had no reason to suspect the video was fabricated. The harm here is not abstract. Anyone who responded to that ad was being directed toward fraud.
What the incident exposes is how little the platforms are currently required to demonstrate after the fact. When deepfake content runs as a paid ad and causes harm, the accountability trail is thin: a commissioner's warning, a takedown, and no public record of what verification happened before the video was approved for distribution. That is precisely the gap a provable record of what a system did is meant to close. Without an auditable log of how the content entered the ad pipeline and what checks ran against it, regulators are left issuing warnings after the damage is done, with no basis for enforcement and no way to confirm whether the same failure will happen again next week.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.