For decades, online identity verification followed a fairly simple idea: someone provides a government-issued ID, and a system checks whether it looks real.
That approach made sense when fake documents were difficult and expensive to produce. Forging an ID convincingly meant recreating security features such as holograms, special inks, printing techniques, and physical materials. Doing it well required equipment, expertise, and time.
Generative AI has changed that equation.
It is now possible to create convincing faces, documents, and entire fictional identities without producing anything physical at all. Fraudsters can generate synthetic identities quickly and at a scale that would have been difficult to imagine only a few years ago.
This creates a basic problem for document-based verification. Most of these systems were designed to decide whether an image of an identity document looks legitimate. They were not designed for a world in which the image itself could be generated from scratch.
Identity verification is therefore starting to move beyond simply checking what a person submits. Increasingly, the challenge is proving that there is a real person behind it.
The Rise of the Synthetic Identity
A fraudster no longer has to steal every piece of someone else’s identity. They can build a new one.
AI image-generation tools can create realistic faces belonging to people who have never existed. Those faces can then be combined with names, dates of birth, addresses, and other information to create synthetic identities and fake documents.
The quality of these fakes is improving quickly. Industry data suggests that document deepfakes could increase by nearly 3,900% this year.
The problem goes beyond obvious face swaps. AI can be used to alter photographs, names, dates, and other fields while preserving the general appearance of a legitimate government document.
This matters because many older verification systems focus heavily on whether the information can be read and whether the document follows an expected format. If the text appears in the right place and the document resembles a known template, a convincing fake may get surprisingly far.
Synthetic identities can also be built for the long term.
A fraudulent account does not necessarily have to be exploited immediately. It may behave normally for months or even years, gradually building a credible history before being used for fraud.
That exposes another weakness in traditional verification: identity is often checked once, during onboarding, and then treated as settled. A verification decision made years ago may say very little about who is controlling an account today.
Why Reading a Document Is No Longer Enough
OCR, or Optical Character Recognition, has long been an important part of digital identity verification. It allows a system to read information such as a person’s name, date of birth, document number, and expiry date.
But reading information and proving that it is genuine are two very different things.
An AI-generated document can contain perfectly readable text. It can have a photograph in the right position, a convincing Machine Readable Zone and a layout that exactly resembles the genuine document.
What gives the fake away may instead be hidden in the image itself.
Manipulated images can contain unusual compression patterns, inconsistent digital noise or tiny differences around areas that have been edited. These details may be almost impossible for a person to notice, but forensic analysis can identify them.
This changes what document verification needs to do. Extracting the correct name and date of birth is no longer enough. Systems increasingly need to understand whether the image itself has been manipulated.
Fraudsters are also finding ways around the camera.
With digital injection attacks, a fake image or video can be fed directly into an application’s camera stream. The verification system may believe it is receiving footage from a real camera when it is actually being shown generated or prerecorded content.
That means even asking someone to appear on camera does not automatically prove that a real person is present.
Moving Beyond the Selfie
For years, adding a selfie to document verification seemed like a strong additional security step. A user photographed their ID, took a picture of their face, and software compared the two.
Deepfakes have made that process much less reassuring.
The response has been a growing focus on liveness detection and deepfakes detection: determining whether the system is interacting with a real, physically present person rather than an image, video, mask, or generated face.
Earlier liveness systems often asked users to blink, turn their head, smile, or perform another action. These checks add friction, and increasingly sophisticated deepfake technology can imitate many of those movements.
Passive liveness along with deepfakes detection takes a different approach. It works in the background while the user completes the verification process.
Instead of asking someone to prove they are human through a series of instructions, the technology analyzes characteristics of the face and image itself. This can include facial depth, skin texture, lighting, and other 50+ signals associated with a real three-dimensional person.
For example, light behaves differently when it hits human skin than when it hits a phone screen displaying a photograph. A three-dimensional face also has depth that a flat image does not.
These differences become important when attackers use high-resolution displays, masks, or generated video to imitate another person.
Independent testing is becoming increasingly important as a result. Programs such as the DHS evaluation tests facial recognition technologies under difficult conditions, including comparisons involving similar-looking people.
As synthetic faces improve, verification providers will increasingly need to demonstrate that their systems work outside controlled demonstrations and marketing claims.
Behavior Can Reveal What an Image Cannot
There is another source of information that is harder to fake: the way someone behaves while using a device.
Behavioral biometrics looks at patterns such as typing speed, mouse movements, scrolling, navigation, and the time someone takes to complete different steps.
None of these signals proves identity by itself. Together, however, they can reveal unusual behavior.
Automated systems tend to interact with websites differently from people. A bot might complete fields at extremely consistent speeds or move through a process far faster than a normal user could.
Humans are messier. We hesitate, make small mistakes, scroll back, change speed, and interact with interfaces in slightly different ways each time. For once, human inconsistency is actually useful.
Behavioral signals can therefore provide another layer of evidence when determining whether an interaction is genuine.
This points toward a broader change in identity verification. Instead of making a decision based on one document or one selfie, systems can combine several signals: document analysis, biometrics, device information, behavior, and risk data.
Trust becomes a collection of evidence rather than a single yes-or-no document check.
What Happens When We Stop Uploading Documents?
There is also a more fundamental possibility: eventually, many people may not need to photograph physical identity documents at all.
Government-backed digital identity systems and wallets are beginning to offer an alternative. Instead of uploading a photograph of an ID card, a user can share verified information digitally.
Ukraine’s Diia system and the European Union’s developing EUDI Wallet point in this direction.
The advantage is straightforward. If identity information can be securely confirmed through an authoritative source, there is much less opportunity to alter a photograph of a document before submitting it.
But digital identity does not make fraud disappear. It changes the problem.
If a criminal gains control of someone’s device or credentials, they may still attempt to use a legitimate digital identity. That makes it important to establish not only whether a credential is valid, but whether the person using it is its rightful owner.
Biometrics can provide that connection.
A facial check, for example, can be used to confirm that the person presenting a digital credential matches the person to whom it was issued. The same principle can also be used later when someone performs a particularly sensitive action.
This could eventually make identity verification both stronger and less annoying.
Instead of repeatedly uploading passports and taking new photographs for every service, users could verify themselves once and then securely re-authenticate when necessary.
Proving Presence in a Synthetic World
The larger problem created by generative AI is surprisingly simple: an image is no longer strong evidence that something existed in front of a camera.
A photograph of an identity document can be generated. A face can be generated. A video can be generated. Even a live-looking camera feed can potentially be manipulated.
That does not mean documents will suddenly disappear from identity verification. They remain an important source of information and, in many countries, an essential part of establishing someone’s legal identity.
What is changing is the amount of trust that can safely be placed in the document image alone.
Identity verification increasingly has to answer several questions at once. Is the document genuine? Has the image been manipulated? Is there a real person present? Does that person match the identity being presented? Does their behavior make sense? And is the same person still controlling the account later?
This is why the future of identity verification is likely to involve several layers of evidence rather than one perfect verification method.
Documents may establish identity. Biometrics can connect that identity to a person. Behavioral and device intelligence can provide additional context. Digital identity systems can allow verified information to come directly from trusted sources.
Most importantly, verification is becoming less of a one-time event.
In a world of synthetic identities, proving who someone was when an account was created is no longer enough. Businesses increasingly need ways to establish that the same real person remains behind important interactions over time.
Generative AI has not made identity impossible to verify. It has simply made one uncomfortable fact impossible to ignore: seeing something on a screen is no longer the same as proving it is real.


