Probably not.
AI is making it increasingly difficult to tell the difference between a legitimate document, email or signing request and something created to deceive.
This article is worth reading because many companies still rely on employees being able to spot when something seems wrong. As fake senders, documents and messages become more convincing, gut instinct is no longer enough as a security control. Here, you will get a clear picture of how AI is changing the risks in document and approval processes — and which questions you should be able to answer before an important contract, power of attorney or payment is approved.
A professional appearance is no longer proof
An email with the right logo. A sender who sounds like a colleague. A contract that appears to come from a known supplier. For a long time, many of us have relied on instinct to judge whether digital communication seems trustworthy.
That is becoming increasingly difficult.
In August, the Swedish Financial Supervisory Authority warned that AI-generated content, fake news articles and professionally designed websites are being used to make scams appear legitimate. At that point, the authority had warned about 197 actors suspected of investment fraud during 2026. Although the warning is aimed at consumers, the lesson is just as relevant for businesses: something that looks credible is no longer sufficient protection.
This does not mean that every email, document or signature should be met with suspicion. But businesses need to be more aware of which processes are actually based on controls — and which are based on assumptions.
AI is changing both the attacks and the demands on businesses
AI can be used to write convincing emails, imitate a person’s tone of voice and create material that looks thoroughly prepared in a matter of minutes. At the same time, the technology can be used appropriately to identify vulnerabilities and strengthen protection against cyberattacks.
This is also the starting point for the European Commission’s new action plan on cybersecurity and AI. The plan points to a dual development: AI can make attacks faster and more scalable, but it can also help organisations identify and manage risks earlier.
For Swedish businesses, the important thing is not to follow every new technology trend. The important thing is to recognise where AI amplifies an existing risk.
A fake document can, for example, be used to persuade someone to approve a payment. An email may contain a link to a fake signing process. An executive can be impersonated in an urgent message. As content becomes more credible, the process around it needs to become stronger.
The question is not only whether the document looks right
In many organisations, important agreements, powers of attorney, HR documents and approvals are still sent through workflows where the recipient is expected to assess whether the sender is genuine and whether the document has remained unchanged.
That is a weakness. Not because employees are careless, but because people should not have to be the only security control.
| When something looks credible | When the process can be verified |
|---|---|
| The right logo and professional language | An identified signer |
| An email that appears to come from the right sender | Clear verification of who sends and approves |
| A document that appears unchanged | Traceability of how the document was handled |
| A signature in a document | An audit trail that can be reviewed afterwards |
| The recipient’s gut instinct | Documented controls |
Four questions to ask internally
- Can we verify who approved it?
- Can we see whether the document was changed?
- Can we follow the sequence of events?
- Do employees know what a legitimate signing request looks like?
If you receive a suspicious document or request
The most important thing is not to let urgency dictate your actions. An unusual payment, new bank details or an unexpected signing request should always be verified through a different contact channel from the one you have just received.
- Do not click the link or sign the document. Do not disclose login credentials or other sensitive information either.
- Verify the sender independently. Call the person, company or authority using a phone number you have found yourself — not the number in the email or message.
- Keep the evidence. Save the email, document and any links. They may be needed for an internal investigation or a report.
- Inform the right people internally. Contact IT, the security manager or the function responsible for incident management.
If a payment has already been made or login credentials have been disclosed, you should immediately contact your bank and report the incident to the police. In the event of suspected or confirmed IT and cybersecurity incidents, organisations can also report the incident to CERT-SE.
Security must be part of the workflow
As the threat landscape changes, it is tempting to look for yet another security tool. But improvement often begins by reviewing the processes already in place.
Which documents are sent through regular email? Which decisions are made without clear identity verification? Where are there dependencies on individual people? And which events would be difficult to investigate if something went wrong?
Secure digital signing does not solve every cyber risk. But when designed correctly, it can reduce uncertainty at one of the most sensitive moments: when a document moves from draft to an approved and traceable decision.
Fundamentally, it is about shifting the focus from appearance to evidence. A document should not merely look correct. The company needs to be able to demonstrate how it was handled.
Now is the time to be more attentive
Companies that build clear identification, traceability and control into their most important processes are better prepared — both when something seems wrong and when they later need to show what actually happened.
This is also where Addo Sign can contribute. We cannot determine whether an email or SMS containing a link is legitimate, and when in doubt, the recipient should always verify the contact with the sender through another channel. But we can help companies make the process behind the invitation more secure through authentication and e-signing before a document can be opened, secure delivery channels such as e-Boks in Denmark and Kivra in Sweden, and a documented sequence of events. The goal is for security not to depend on whether an email looks genuine.
Frequently asked questions
No. AI primarily changes the threat landscape around fake emails, senders and documents. This makes it more important to choose processes where identity, document integrity and events can be documented.
Start with identity verification, access controls, audit trails, document integrity, and whether employees can recognise a legitimate signing request.
IT plays a central role, but responsibility should be shared with the teams that handle contracts, HR matters, financial decisions and sensitive documents.
Sources
- Swedish Financial Supervisory Authority: FI warns about 197 actors — fraudsters use AI and fake trading platforms to lure victims
- European Commission: EU Action Plan on Cybersecurity and Artificial Intelligence
- Swedish Police Authority: Increasing number of scam emails targeting businesses
- CERT-SE: Reporting and notification
Mikkel Thiel
I primarily share knowledge and experience on digital signing, automation and digital document processes — and on how platforms, systems and AI can work together to support businesses.
I have more than 10 years of experience in Customer Success, consulting, leadership and service. My focus on great user experiences goes back to my years at Apple, where I worked in customer service and management. This has shaped my approach to technology: it should not only work — it should be easy to use and create value for the people who use it.