Tavus's old live video agent fooled 1 person out of 41 05. Its new one, Griffin-Lite, fooled 26 06 out of 54.
Fifty percent is what a coin flip gets you. After one minute on camera, nearly half the people in Tavus's study said the face on the screen belonged to a human. Every one of them was talking to a model.
Fifty-four people is a small test. Tavus ran it itself, each call lasted one minute, and participants were told they would meet "another participant." We read 48% 29 as a direction of travel. That direction is enough to change how you build anything that runs on a video call.
The Coin-Flip Line for Live Video
A human check is only worth running while it beats guessing. Tavus's numbers suggest live video is drifting toward the point where it no longer does. Tavus also reported that people who judged the agent human averaged 79% 13 confidence. People who judged it AI averaged 81% 14.
How close Griffin-Lite gets, and what a check costs
Put those two numbers side by side. All 26 06 people who said "human" were wrong, and they felt nearly as sure as the people who were right. So the test broke two things at once: the yes-or-no answer, and the gut feeling behind it.
Security people already state the principle plainly: authentication has to sit outside the channel being authenticated. Call it channel separation. The video call cannot be the thing that proves the video call is real. Every signal on a call lands in one of two buckets.
Presentation signals are the face and lip sync. Eye contact and turn-taking count too. So does the way someone cuts in when you pause. Tavus says Griffin listens while it talks and reacts to expressions and pauses. A generator controls every presentation signal. Proof signals are a callback to a number you already hold or a signed document. An approval in a separate system counts, as does a credential issued by the platform. The generator controls none of them.
Under channel separation, high-stakes decisions run on proof signals only. Presentation signals are fine for comfort and rapport. Keep them away from money and access.
Wiring Disclosure Into the Call Stack
Think of a convincing live avatar as a hi-vis vest. A vest gets you past the front desk because it looks like you belong. Nobody at the desk checks the vest against a staff list. Griffin-Lite is a very good vest.
The engineering explains how it got this good so fast. Tavus describes Griffin as one video-to-video system that sees and hears, then speaks and reacts during the call. Byteiota reports that older stacks ran as a cascade: speech-to-text, then a language model, then text-to-speech, then an avatar renderer. Every handoff added lag, and lag is a tell.
The benchmark shows where the remaining tells are. Tavus reported that Griffin-Lite scored 3.83 10 on the generation track of NVIDIA's VideoFDB benchmark. The human reference scored 3.92 01 and the next-best system scored 2.80 11. On perception, Griffin-Lite scored 3.73 12 against 4.20 31 for humans.
So the looks gap is 0.09 30 points and the understanding gap is 0.47 31 points. The face is nearly finished. The listening still lags. A person's best chance of catching it is a longer call with odd questions.
If you ship an agent, disclosure belongs on the feature list next to latency. Five pieces cover most of the risk, in this order:
Step one is a persistent on-screen label for the whole call. Corner text gets cropped or ignored, so burn the label into the video frame itself.
Step two is a spoken disclosure at the start of the call and again after every reconnect.
Step three is a signed session record. That means a file stamped with a cryptographic key, so anyone can check which system generated the session and confirm nobody edited it later.
Step four is a log line per session covering model version and operator. The same line records organization and consent status. It also records disclosure state and start time.
Step five is a hard pause before sensitive actions like payments or account recovery. Hiring decisions and medical guidance get the same pause. At that pause the agent restates that it is AI and offers a human.
Tavus says Griffin-Lite stays limited to select trusted testers while it works on disclosure and safety features. AI Beat reports the model is not for sale. In other words, the company that made the vest is holding it back until the badge exists. We think every builder in this category should copy that order of work.
The receiving side is cheaper still. Take a made-up but ordinary case: your finance lead gets a video request to wire $40,000 26 to a new account. A callback to a number on file takes about two minutes. At $60 28 an hour for the person making it, that call costs $2, which is 1/20,000th of the money it protects.
The face is nearly done, the listening lags
Human judgment now sits near a guess.
Nearly half of Tavus's testers called Griffin-Lite human after one minute. The wrong guessers averaged 79% 13 confidence, close to the 81% 14 of those who were right, so the feeling of certainty failed too.
Perception is where longer calls get fought.
Griffin-Lite trails humans by 0.09 points on generation and 0.47 on perception in NVIDIA's VideoFDB. If perception closes the way generation did, five-minute and ten-minute calls fall next.
A callback protects a $40,000 wire.
Two minutes of a $60-an-hour employee costs about $2, which is 1/20,000th of the money at stake. Proof signals like a number on file sit outside anything a generator controls.
2031: A Face Stops Being a Password
The trend line is short, and steep. Tavus's earlier stack sat at 2.4% 03. Phoenix-4.5 and Sparrow-2 were part of it. So was Raven-1. Griffin-Lite sits at 48.1% 07. Byteiota reports that the jump happened in a single product cycle.
The belief rate can't climb another 20 29 times, because 20 times 48% is far past 100%. The one-minute call is close to its ceiling. The next fight is over longer calls, and the VideoFDB gaps show where it will be fought.
Run some quick math on Tavus's figures. The generation gap is 0.09 30 out of 3.92, about 2% short of the human reference. The perception gap is 0.47 31 out of 4.20, about 11% short. If perception closes the way generation did, five-minute and ten-minute calls fall next.
How fast that happens is an open question. Our own math on 26 32 of 54 gives a 95% range of roughly 35% to 61%. The true rate could sit well below or above a coin flip.
There hasn't been much outside scrutiny yet. Bit.fan reports that a community note on X said the findings were not independently verified and did not follow a standard protocol. Participants were also primed to expect a human, which likely pushed the number up.
The risk is lopsided anyway. Channel separation costs a few days of process work. Skipping it is a bet that 48% 29 is a fluke and stays one until 2031. Lose that bet and every approval flow built on "I saw them on camera" breaks at the same moment.
Platforms are already moving. HackerNoon reported on October 4 that World is bringing a proof-of-human check to Zoom. By 2031 the market will likely grow on both sides at once: more disclosed AI agents in support and tutoring, and identity checks built into the call client.
That opens a clean counterpositioning play. Vendors racing for maximum realism will have a hard time also promising "you will always know it's us." The evidence suggests the durable winners pair a natural agent with an obvious label and a fast handoff to a human.
Add a Callback Gate to Money Moves
You can ship the receiving half of channel separation this weekend with a shared doc and one rule.
First, list every action your business takes because of a call. Vendor payments, payroll bank changes, password resets and offer letters are the usual starting set. Put them in one doc. Expect the list to run longer than you guessed.
Then, build the number book. Store a known-good phone number for each vendor and executive in a system the caller cannot edit, such as your accounting tool or HR system. Out-of-band means checking through a separate channel the attacker does not control. That number book is the whole mechanism.
Then, write the rule in one sentence. Any request made on a video or voice call that touches the list waits for a callback to the number book before anyone acts. Urgency, secrecy and changed payment details count as reasons to slow down, with no exceptions for seniority.
Then, if your policy allows recording, run calls through Spoke, which transcribes and summarizes video calls as text. Search the transcripts weekly for phrases like "new account" or "keep this between us." A text log is far quicker to audit than an hour of video.
Then, break it on purpose. Have a teammate call your finance lead with a fake urgent $40,000 request "from the CEO." Watch where the gate leaks. A common first-run failure is someone calling back the number given in the request, so fix that step and rerun the drill every month.
If you ship your own agent, add two checks to the same drill. Screen-record a test call and confirm the AI label survives in the file. Then drop the connection mid-call and confirm the spoken disclosure plays again on reconnect.
AI Beat's advice for families follows the same logic at home: agree a family code word, and call back on a number you know. Two minutes of friction is the price of a world where a face on a screen proves nothing.
Put a callback gate on every money move
- List every call-triggered action. Put vendor payments, payroll bank changes, password resets and offer letters in one shared doc, and expect the list to grow as you go.
- Build the number book. Store a known-good number for each vendor and executive in a system the caller cannot edit, then make one rule: any listed request waits for a callback to that number.
- Break the gate on purpose. Have a teammate place a fake urgent $40,000 request "from the CEO" to your finance lead, fix any leak such as calling back the number given in the request, and rerun the drill monthly.
A face on a screen now proves nothing.
Griffin-Lite's 48% 29 comes from a small, self-run study, and the true rate could sit anywhere from roughly 35% 32 to 61%. The risk still runs one way. Channel separation costs a few days of process work, and a callback costs about $2 28. Builders should ship labels, spoken disclosure and signed records, and every team should route money and access through proof signals only.
