Canva Pty Ltd has tightened Enterprise domain verification and publishing gates for Australian customers after the Australian Securities and Investments Commission warned that generative AI is fuelling deepfake investment scams, according to product notices sent to admins and ASIC’s 26-195MR media release published in August. The Sydney-based design platform is not a financial adviser, but its tools are often used to produce social tiles, fake news layouts, and celebrity-style endorsements that regulators say now pass casual inspection.

What ASIC flagged

ASIC chair Joe Longo’s 26-195MR release said scammers build “vast webs of deception” with AI-generated videos, spoof websites, fake reviews, and news articles that reinforce one another. The regulator removed more than 19,400 scams in the 2026 financial year, including 7,051 fake investment platforms—a 151 percent jump in platform takedowns. Chair Danielle Press, quoted in accompanying materials, warned that a quick online search is no longer enough to verify legitimacy and that consumers must match Australian Financial Services Licence details on ASIC’s professional registers to the exact business promoting an opportunity.

ABC reporting on the release highlighted deepfakes of finance journalists and politicians, with Scamwatch data showing millions lost to impersonated public figures. None of those scams originated inside Canva’s network, but enterprise customers in banking and superannuation told InfoHandle they faced rising volumes of counterfeit creative that mimicked their brand templates.

Canva’s Enterprise verification layer

Canva’s updated Enterprise workflow accelerates mandatory domain verification before admins can view organisation-wide usage reports. Verified domains affiliate work accounts with employers after a 30-day notice period, reducing stray teams that scammers could spin up with look-alike email addresses. Domain reports now surface AI feature adoption and design volumes so security teams can spot sudden spikes in publishing activity.

Publishing controls let administrators restrict who may export designs or publish to the web without approval—aimed at marketing teams that previously allowed broad “brand designer” rights. Canva Shield’s existing input and output moderation for Magic Studio remains, including indemnification for eligible Enterprise customers using generative features; the verification layer addresses identity and distribution rather than model safety alone.

Why Australian enterprises care

Major banks already police social channels for impersonation, but ASIC’s emphasis on fake articles and polished landing pages pushes responsibility upstream to brand tooling. A compromised contractor account that can publish Canva sites resembling a bank’s typography is a compliance incident even if no customer funds move through Canva servers.

Wealth managers and super funds subject to design and disclosure rules said they will map the new gates to internal marketing policies, requiring dual approval on any template containing performance claims or testimonial layouts. Canva’s admin documentation stresses that verification does not stop employees pasting ASIC-regulated text into designs—legal review remains the customer’s job.

Competitive context

Adobe and Figma offer enterprise admin controls as well; Canva’s Australian headcount and ASX-adjacent customer base make ASIC’s warning a local product moment. The company has not claimed to detect deepfakes in uploaded photos automatically for all tiers; instead it pairs Shield moderation with organisational policies that limit who can use Dream Lab and Magic Media on official accounts.

ASIC continues separate takedown operations with social platforms and search providers. Canva’s move is defensive: reduce the chance that verified enterprise tenants become unwitting hosts for scam collateral that cites real AFSL numbers stolen elsewhere.

Implementation details

Admins receive a checklist to verify DNS records, enable single sign-on where possible, and narrow permissions for integrations that export designs to third-party ad networks. Canva said unverified domains still allow personal use but hide cross-team analytics that criminals could mine to copy internal campaigns.

Training modules shipped to Australian Enterprise customers cite ASIC and Moneysmart resources, encouraging marketing staff to report suspicious template requests—such as urgent jobs mimicking newsroom layouts with celebrity headshots. That is culture as much as software, but product managers argued verified domains give chief marketing officers a lever they lacked when freelancers used personal Canva logins.

What regulators want next

ASIC’s release urged consumers to stop, check, and protect before investing, emphasising register lookups over social proof. For Canva, the reputational risk is association: if a high-profile scam page traces to a misconfigured Enterprise tenant, regulators will ask what gates failed. The verification rollout is timed before year-end campaigns when super funds and insurers refresh retail creative.

Sydney’s design unicorns are not on the hook to police investment fraud alone, but after 26-195MR, letting anyone with a company email publish on-brand assets without domain proof is a harder sell to risk committees. Canva is betting verified identity and tightened publishing rights are the minimum viable response—and that enterprise buyers agree before the next deepfake headline names a familiar font.