I asked a room of high school students how they would know if a video of themselves was fake. One said she would remember whether it happened. Another said you can always tell.
Both answers were reasonable in 2018 and both are now wrong, and neither student had been told that by anyone. The gap between what they believed about verification and what is actually true had opened up quietly, in about four years, without a single class covering it.
Retiring the argument that no longer works
The standard case for teaching teenagers cybersecurity is the workforce shortage. There are unfilled roles, the field pays well, get in early. I have made that argument myself from stages more than once.
It has weakened, and pretending otherwise costs credibility with exactly the audience you are trying to reach. The tier of work that used to absorb new entrants, alert triage, first-line monitoring, ticket enrichment, is the tier that automation is compressing fastest. A 16-year-old told to enter the field because of a headcount gap is receiving advice built on 2019 conditions, aimed at the rung of the ladder most likely to be missing when they arrive.
Sell it on jobs, and when the jobs move you lose both the student and the argument. There is a stronger case available and it has almost nothing to do with employment.
What the discipline actually teaches
Strip cybersecurity down past the tools and certifications. What remains is a single habit, applied relentlessly.
Treat every assertion as a claim with a provenance, and ask what would establish it.
That is authentication. It is forensics. It is intelligence triage, malware analysis and fraud investigation. Every serious activity in the field is a variation on the same move, which is refusing to accept that something is what it appears to be until you know what makes it hard to fake.
Which reframes the question entirely. Your teenager is not primarily going to be attacked. Statistically, most will not be the target of anything sophisticated. They are going to be asserted about, continuously, by systems, for the rest of their lives. A model will score their loan application. An automated tool will screen their resume. A background check will produce a record. A recording will circulate. In each case an institution presents a machine output as a fact about a person, and the only defence available is knowing that it is a claim.
That habit is now the core habit of citizenship, and cybersecurity is one of the few subjects that teaches it explicitly.
Why "you can tell" stopped being true
The student who said you can always tell was expressing something most adults still believe.
A 2025 study published in Scientific Reports, examining how well people detect AI-generated voice clones, found that participants correctly identified an AI-generated voice only around 60 percent of the time. Against a two-option choice, that is close to guessing.
A separate study published in PLOS One in October 2025 by researchers at Queen Mary University of London went further. Listeners could not reliably distinguish voice clones from genuine recordings, and some synthetic voices were rated as sounding more trustworthy than the real voices they were cloned from.
Sit with that second finding. The instinct we tell young people to rely on, that something will feel off, is not merely unreliable. In some cases it points the wrong way. The forgery is the one that sounds sincere.
No amount of being careful fixes that, because it is not a carefulness problem. It is a provenance problem, and provenance is a technical question with technical answers.
The objection from the curriculum
Educators will have an immediate and fair response. This is media literacy. Schools already teach it, it has been in curricula for a decade, and rebranding it as cybersecurity helps nobody.
The two overlap and they are not the same, and the difference matters more every year.
Media literacy teaches evaluation of sources. Is this outlet reliable, does the author have an agenda, who benefits from me believing this. Those are judgements about reputation, and they are genuinely valuable.
Security teaches evaluation of artifacts. Can this specific thing be forged, what would a forgery look like, what independent evidence exists that does not depend on the artifact itself. That is a judgement about provenance.
Reputation-based evaluation fails at exactly the moment generation becomes cheap, which is the moment we are in. A trustworthy outlet can publish a forged recording in complete good faith, having applied every media literacy check correctly. Reputation was never designed to answer the question of whether an artifact is authentic, and now that artifacts can be manufactured for nothing, it cannot carry the weight.
There is a second thing security teaches that almost nothing else in a curriculum does. It teaches the adversarial frame explicitly. Assume someone is deliberately constructing something to make you believe a false thing, and think from inside their position. History classes rarely say that. Science classes almost never do.
What to actually do
The instinct is to build a cybersecurity pathway, hire a specialist and buy a platform. That is expensive, slow, and reaches the small number of students who were going to be fine anyway.
Do something cheaper and broader. Add one adversarial exercise to subjects that already exist.
In a history class, have students forge a primary source convincingly, then have classmates attempt to detect it and explain what gave it away. In a science class, fabricate a plausible dataset and have others find the tell. In an English class, generate a passage in an author's voice and defend or attack its authenticity.
Every one of those teaches the same move, which is the only move that matters, and none of them requires a new department. The student who has spent an afternoon building a convincing forgery has learned something permanent about what evidence is worth.
Three questions worth asking, whether you are a parent, a superintendent or a technology leader who speaks at schools. Ask a teenager how they would verify that a recording of a person saying something is real, and listen for whether the answer involves any independent source. Ask them what happens if an automated system produces a wrong fact about them, and whether they know an appeal exists. And ask them who they would tell.
The third question is the one that surprises people. In the incidents I have seen involving young people and fabricated media, the damage was rarely done by the artifact itself. It was done in the days when the person believed nobody would take their side.
What this is really for
Some of these students will build careers in security and that would be good. It is not the point and it should not be the pitch.
The point is that a generation which cannot evaluate whether a system's output about a person is true will be governed by systems it does not know how to question. That is not a security problem or an education problem. It is a much older problem about who gets to make claims and who gets to test them, arriving in a form we have not had to handle before.
The cheapest intervention available is teaching a habit that a specialised profession has already worked out, to people who are going to need it in contexts that profession never anticipated.
We spent years teaching young people not to trust strangers on the internet. The harder and more necessary lesson is not to trust artifacts, including the ones that sound exactly like someone they love.