Slovakia and the Deepfake Timed for Silence
Two days before Slovakia's 2023 election, a fake audio of a leading candidate discussing vote rigging spread through social media, inside the legal quiet period when he could not answer and platform rules had a loophole for audio.
The clip landed inside the pre-election moratorium, when rebuttal was legally muted and platform policy on manipulated media did not cover audio. The control absent: defenses designed around the response window, and synthetic-media rules that cover every format an attacker can generate.
Two days before Slovakia’s parliamentary election in September 2023, an audio recording began moving through social media. It appeared to capture Michal Šimečka, leader of the liberal Progressive Slovakia party, talking with Monika Tódová, a well-known journalist at the daily Denník N, about rigging the vote, including buying votes from the country’s Roma minority. The audio was fake, generated with AI. Both people in it denounced it immediately, and fact-checkers found the telltale signs of synthesis.
None of that mattered in time, because of when it arrived. Slovakia’s election law imposes a moratorium in the final 48 hours before polls open: campaigning stops, candidates and media go quiet. The clip was built to live inside that silence. The target could not mount a proper public defense without the response itself becoming a legal question. Newsrooms were constrained. And the platforms had a gap of their own. Manipulated-media policies at the time were written around video, so a synthetic audio clip fell through the definition. It spread from Telegram to Facebook, through personal accounts, reaching tens of thousands of shares while every corrective mechanism idled.
Honesty requires saying what cannot be proven: no one can show the clip changed the result, and careful research since has pushed back on simple stories about deepfakes deciding that election. The entry is not here for the outcome. It is here for the design of the attack.
Where it failed
The synthesis was the probabilistic part, and it did not need to be good, only good enough for a phone speaker and a shocked listener. The deterministic part was the environment it was aimed at. The moratorium silenced the target. The audio loophole kept the clip online while fact-checkers were still working. And by the time the synthesis was confirmed, the 48-hour clock had nearly run out. Whoever built the attack did not defeat the controls. They scheduled around them, using the system’s own rules as the weapon.
That is the failure worth studying: a set of safeguards, each reasonable alone, that combined into a window where a known threat could operate untouched. The moratorium was designed for an era when the loudest voice in the final days was a campaign, not a forgery. The platform policy was designed for the last format of fake, not the next one.
Whoever built the attack did not defeat the safeguards. They scheduled the clip for the two days when every safeguard was switched off.
How it could have been caught
Design the defenses around the window, not just the content. If law or policy creates a period when normal response is suspended, that period needs its own protocol: pre-agreed channels through which a target can rebut a fabrication without violating the quiet, election authorities and platforms on call for exactly this scenario, and fact-checking arranged to run at hours notice rather than days. Close the format gap by writing synthetic-media rules that cover anything generative tools can produce, audio included, and re-reading them every time the tools improve. The next attack will use whatever format the policy has not caught up with, at whatever moment the response is structurally slowest.
What it means for AI
This case is in the Atlas because it generalizes far beyond elections. Every organization has moratorium windows: quiet periods before earnings, code freezes before launches, holiday weekends, the hours after a leadership departure. Those are the moments when an AI-generated fabrication, a fake recording of an executive, a forged customer email, a synthetic incident, does the most damage, because the machinery that would normally catch and answer it is throttled by design.
It leaves every organization a planning question. Map the windows when your response capacity drops, assume adversaries know them too, and decide in advance what runs during them. Generative tools removed the cost and skill barriers from producing a convincing fake. What remains scarce is the attacker’s opening, and the openings are in your calendar, published for anyone to read.
← Back to the Atlas