Reputation Arbitrage and the Crisis of Institutional Trust: Defending Organisations When Genuine Identities Perform Fraudulent Actions
Abstract
The proliferation of generative artificial intelligence has restructured the threat landscape for institutional security, shifting the locus of attack from technical infrastructure compromise to the instrumentalisation of legitimate insiders. This paper, the second in a three-part series, introduces the Action Authentication Model to describe how reputation arbitrage, the systematic exploitation of borrowed credibility signals, operates at the institutional level. Drawing on principal-agent theory, normal accidents theory, highreliability organisation theory, and sociotechnical systems analysis, the paper argues that identity-centric security architectures are insufficient when adversaries can manipulate genuine employees into authorising fraudulent transactions. Through analysis of four independently documented institutional failures, the 2016 Bangladesh Bank heist, the 2020 Twitter bitcoin scam, the 2024 Hong Kong deepfake video-conference fraud, and the 2025 Hong Kong voice-cloning cryptocurrency fraud, the paper proposes a three-layer defence architecture: Identity, Context, and Consequence, each operationalised through enumerated controls including consequence-weighted authentication, intelligent friction, trust-path forensics, and distributed security authority. The analysis extends calibrated trust, the individual disposition proposed in Part I of this series, into structured trust, its organisational analogue: the property that emerges when consequence-weighted verification is built into process design rather than left to individual judgement. The answer to reputation arbitrage, the paper argues, is not “better authentication” but “better trust architecture.”
// Source
Authors: Praveen Singh