Spam and Impersonation in the AI Era: A Proposal to Attach a “Trust Deposit” to Emails and Calls
Considering spam and impersonation in the AI era through data leaks, I propose attaching refundable trust deposits to emails and calls.
Open table of contents
Whenever I see news about personal data leaks or phishing emails, I find myself wondering.
What will we rely on to trust the person behind an email or a phone call?
Generative AI can produce natural, polite emails in a short time. It can also create plausible messages tailored to someone's work or interests. Voice synthesis technology exists, too.
These technologies are useful, but people trying to deceive us can use them as well.
Spam emails, suspicious calls, and messages impersonating a business contact or a family member. If these become more convincing and easier to produce in large numbers, how much can we rely on judgments such as “the writing sounds natural” or “the voice sounds right”?
That led me to consider a system that attaches a refundable “trust deposit” to emails and phone calls.
What the deposit demonstrates, however, is that someone has attached financial responsibility to the communication. Whether they really are the person they claim to be still needs to be checked separately. Here, I want to consider a way to make mass spam and impersonation harder by adding another layer to existing authentication.
If AI makes deceptive messages more convincing, I want more grounds for judging trust
Looking at recent data leaks, I wondered whether the ability to generate convincing emails at scale with AI might also be helping attackers.
Of course, emails are not the only cause of data leaks. Software vulnerabilities, stolen credentials, and other causes also exist. We cannot attribute every recent incident to AI-generated emails.
Microsoft has reported that attackers are using AI to increase the efficiency of their activities, including speeding up research and improving the wording used to lure people. Microsoft Security Blog
I think there will be more situations in which spotting unnatural writing alone will not be enough.
The sender knows about your circumstances. The message is polite. Even the voice on the phone sounds normal. That still does not necessarily make the person trustworthy.
So, alongside the content of a message, I would like to be able to check how much responsibility its sender is taking on.
Attach a refundable deposit to emails and calls
For example, when someone sends an email to an unfamiliar recipient for the first time, the sender temporarily puts down a deposit of 100 yen.
If the recipient accepts it as ordinary communication, the 100 yen is returned. If there is no reply, it is also returned after a specified period. If abuse is confirmed, some or all of it is forfeited under rules established in advance.
The deposit could be waived for people already in contact or contacts registered by the recipient.
The same idea could apply to phone calls.
When a call arrives from an unfamiliar number, the screen might say, “This caller has deposited 100 yen for this call.” If the call is treated as ordinary communication, the deposit is returned. If abuse is confirmed, a penalty applies.
The deposit here is not insurance that compensates the victim for the full amount lost to fraud. It is collateral that attaches the sender's financial responsibility to that communication.
A deposit does not mean that the caller should automatically be trusted, but it provides a signal separate from the writing or the voice.
A small burden for ordinary users, a heavy one for mass senders
What I find particularly interesting about this system is the asymmetry of the burden.
At 100 yen per email, contacting three unfamiliar people requires a deposit of 300 yen. For ordinary communication, that money comes back.
But if someone wants to send messages to one million people at once:
100 yen × 1 million emails = 100 million yen.
If a separate 100 yen is secured for each email and none of the one million deposits has yet been returned, 100 million yen is temporarily tied up.
The required funds are determined by “the deposit per email × the number of emails whose deposits have not yet been returned.” If messages are sent gradually and returned funds are reused, sending one million emails does not always require 100 million yen. If deposits are returned immediately upon acceptance, the funds can also circulate quickly.
The longer a refund takes, the harder it becomes to reuse those funds for the next batch. If forfeiture for abuse is added, actual losses accumulate as well. However, if no abuse is identified and every deposit is returned, the burden consists mainly of tied-up funds and operating costs. The holding period and the way abuse is determined will affect the system's effectiveness.
That is the part I want to target as a spam countermeasure.
Sending a small number of necessary messages would require only a small deposit, while indiscriminate mass sending would require funds in proportion to its volume.
Of course, this might not sufficiently deter well-funded attackers. Even so, it could impose an economic constraint on the strategy of sending huge numbers of messages at very low cost and profiting from a small number of responses.
The idea goes back to trading weapons in an old game
While thinking about this proposal, I remembered Sword × Sword, a social game I used to play on GREE. It was provided by Drecom. Drecom's official company history
It was a game in which players collected cards and fought battles, except that the items corresponding to those cards were weapons.
When I played it, players could not send weapons directly to each other. There was, however, an auction market where weapons could be bought and sold.
So, when I wanted to exchange weapons with someone, we would agree to list both weapons at prices far above their market value and buy each other's listings.
For illustration, suppose each of us listed a weapon worth around 100 units of in-game currency for 10,000. An ordinary buyer would be unlikely to pay that price.
I would buy the other person's weapon for 10,000, and they would buy mine for 10,000. If we both followed through, the currency transfers would cancel each other out and we would have exchanged weapons.
There was still a possibility that one person would make the purchase and the other would break the agreement. The market did not guarantee the exchange.
This experience did not involve the same mechanism as my current proposal, in which a third party holds collateral to support fulfillment of an agreement. The connection that inspired me was attaching something of value that could be lost to an interaction requiring trust.
That method therefore required trust. And that trust had something of value behind it that could actually be lost.
Attach an economic risk to a promise.
When I was thinking about recent data leaks and convincing AI-generated emails, that experience connected with the current problem.
I would like to call this Proof of Commitment
I would like to call this way of thinking Proof of Commitment—a demonstration of taking responsibility.
Instead of merely saying “I am trustworthy,” attach something of value that could be lost to those words.
What is demonstrated is not the sender's good intentions themselves. It is the fact that funds are tied up under specified conditions and that the sender accepts a loss if the rules are violated.
With this approach, we do not have to focus solely on whether a message was written by a human or AI.
I want to receive necessary emails even if an AI assistant sent them. I want to limit indiscriminate nuisance calls even if a human made them.
Alongside who created the writing or the voice, we would be checking who takes responsibility for the communication.
Emails, phone calls, social media DMs, sales outreach, and recruiting messages. The same idea might apply in situations where AI makes it easier to increase the number of contacts.
A deposit cannot completely prevent impersonation
There are still details to work out before this could become a functioning system.
First, if recipients could claim a deposit for themselves simply by saying a message was unwanted, they would have an incentive to label ordinary communication as abuse and make money from it.
A design that does not give forfeited funds directly to the recipient is one possibility, but that alone would not eliminate mistaken judgments or harassment. Conditions for forfeiture and a process for appeals would be necessary.
First-time contacts can also include urgent requests for advice or help. Even a small deposit may be a burden for some people, so I would want an alternative way to make contact in exceptional cases.
And having a deposit is different from proving someone's identity. Attackers might be willing to lose a small deposit if they can steal more than that.
If registered contacts are exempt, someone who takes over one of those contacts' accounts could communicate without the constraint of a deposit. If the account used to fund deposits is compromised as well, a victim's money could be used. We would also need conditions for keeping exemptions and mechanisms to stop suspicious use.
That is why deposits would need to be used alongside sender authentication and existing spam countermeasures.
One could also consider depositing funds on a blockchain and processing the refund conditions there. But what matters more than the name of the technology is that the collateral really exists, the same funds cannot be counted toward multiple communications at once, and the conditions for return or forfeiture can be checked.
Similar systems have existed before
Researching the idea while talking with AI, I found that attempts to link financial collateral to trust in email have existed before.
In 2004, Microsoft announced that it was using IronPort's Bonded Sender Program for MSN and Hotmail. It was a system for identifying legitimate senders through compliance with standards and a financial bond. Microsoft's announcement at the time
However, that example combined sender certification with a bond. It was not exactly the same as the proposal here, which would attach a refundable deposit to each individual communication.
I did not invent this principle for the first time. I am also using the name “Proof of Commitment” here to explain my own thinking.
Still, now that AI can generate emails and phone calls at scale, I think this direction for spam prevention may deserve renewed attention.
As the effort required to create a message becomes smaller, we face the question of how to protect the time and attention of the person receiving it.
It would be useful to have a system that lets us check, alongside what a sender says, how much responsibility they attach to those words.
I think a refundable trust deposit could be one way to do that.
How I used AI
The idea and the experience in the game are my own. I used ChatGPT to organize the article and check sources, and asked Claude to review its logic and wording that might cause misunderstandings. I decided which of Claude's suggestions to adopt and revised the text; Claude did not conduct the external research itself.
The conversation between me and AI that led to this article
The following has been edited for readability while preserving the substance of the actual conversation.
Me:
Personal data leaks have been in the news a lot recently. I wonder whether the ability to generate convincing emails at scale with AI is part of it. If AI starts generating both emails and phone calls, how will we know whom to trust?
AI:
We cannot attribute data leaks solely to AI-generated emails. However, there is a basis for concern that AI reduces the effort needed to create deceptive communications and increases the scale and speed of attacks. We may need another basis for judging trust alongside how plausible the writing or voice sounds.
Me:
In an old game, we could not trade items directly, so we would list them at unnaturally high prices in an auction and buy each other's listings. If you are going to trust someone, put something of economic value behind it. I wondered whether we could use the same idea.
AI:
That experience suggests attaching temporary collateral to communications too: return it for ordinary messages and impose a loss for abuse. However, even the game transaction did not completely remove the risk that someone would break the agreement.
Me:
It would not be much of a burden for ordinary users, but it could be extremely difficult for spammers. I think that kind of asymmetric system suits the era we are entering.
AI:
Even if the deposit per message is small, the funds required for mass sending add up. Having those funds tied up until refunds are made is another burden. At the same time, the system needs to account for unfair forfeiture by recipients and people who have difficulty providing collateral.
Me:
If it becomes harder to trust the words in an email or a call alone, attach financial responsibility to those words. I think this kind of system may attract attention in the years ahead.
AI:
Similar collateral-based approaches have historical precedents. This proposal connects them to the problem of mass communication in the AI era. If the limits of what the collateral demonstrates are made clear, it can be considered as one mechanism for supporting trust.
About this article
This article is based on the author’s experiences and reflections. AI assisted with organizing and reviewing the text, and the author confirmed the published content. Sources and references are linked in the article where applicable.
Revision history
- Initial publication
REFERENCE
Quotations and links are welcome. Full republication is not licensed.
Read the usage policy →
Reader comments
Comments are submitted through Google Forms and appear here only after the author reviews and approves them.
Submit a comment →No published comments yet.
Comment policy