TL;DR: Identity verification must shift from one-time KYC to continuous, AI-assisted decisioning that adapts to reused faces, devices and fraud patterns across markets, according to Smile Identity. The core implication is that fraud defence now depends on network intelligence, precision and human authorisation for AI-mediated actions, not static gates.
At a glance
What this is: Smile Identity argues that 500 million identity checks demonstrate verification is becoming a continuous, AI-driven control rather than a one-time onboarding step.
Why it matters: For IAM and identity verification teams, the key issue is how to combine stronger fraud detection, continuous trust assessment and human authorisation when customers, devices and AI agents all change the attack surface.
By the numbers:
- Smile Identity says it has passed 500 million identity checks since inception, roughly one in three people on the African continent.
- At scale of 15 - 20 million verifications per month, nearly 100 million datapoints are evaluated by the AI suite to protect more than 500 enterprises every month.
👉 Read Smile Identity's analysis of 500 million identity checks and AI-driven fraud defence
Context
Identity verification fails when it is treated as a single onboarding event instead of an ongoing trust decision. Once fraudsters can reuse stolen identity data, synthetic faces, emulated devices or shared network infrastructure, the control point has to move closer to the moment of risk, not just the moment of registration. That is why this article matters to identity verification and IAM teams as much as it does to fraud practitioners.
The article is also relevant to NHI and agentic AI governance because it anticipates a future where AI agents may act on behalf of humans in financial workflows. In that model, the hard problem is not only proving a person exists, but proving the right person authorised the action and that delegated permissions were constrained. For readers building trust frameworks, that is the same policy problem in a different runtime.
Smile Identity’s starting position is typical of modern identity verification vendors that are moving from static KYC checks to continuous, signal-rich fraud controls.
Key questions
Q: How should organisations move from static KYC checks to continuous verification?
A: Organisations should treat onboarding as one control point in a longer assurance process. Add behavioural signals, device intelligence, and risk scoring to reassess identity confidence after the initial check. That approach reduces reliance on a single document or selfie event and gives fraud teams a way to detect drift, reuse, and coordinated abuse over time.
Q: Why does cross-customer fraud intelligence matter for identity verification?
A: Because many fraud patterns are only visible when signals are pooled across organisations. A face, device or address reused elsewhere may look normal in one tenant but clearly malicious in the network. Cross-customer intelligence shortens detection time, improves precision and helps teams stop attacks that isolated rules would miss.
Q: What happens when AI agents start making identity-sensitive decisions?
A: The problem shifts from simply proving who a user is to proving who authorised the action, what scope was granted and whether the agent stayed within it. That requires stronger delegated access controls, explicit consent handling and transaction-specific limits. Without that governance, agentic workflows can look legitimate while still exceeding human intent.
Q: How do teams know if their identity controls are actually reducing fraud?
A: Look for fewer cross-system handoff failures, lower fraud re-entry rates, and shorter investigation time when the same actor reappears under new signals. If the organisation still needs analysts to manually reconcile device, payment, and account data, the identity layer is not yet doing its job.
Technical breakdown
Why one-time KYC fails against adaptive fraud
Traditional KYC captures identity attributes at a point in time, such as a name, ID number or selfie. That model breaks when attackers reuse the same face, device or network path across different institutions, because each single check sees only a fragment of the threat. Continuous verification instead treats identity as a stream of signals, combining document, device, behavioural and network evidence to detect replays, emulation and synthetic activity. The key technical change is moving from static proofing to repeated, risk-based trust evaluation.
Practical implication: design verification so high-risk actions trigger fresh signal collection, not just the initial onboarding check.
How network fraud intelligence improves identity verification
Network fraud intelligence works by learning from confirmed fraud across many organisations and reusing those patterns when the same face, device or infrastructure reappears elsewhere. In the article’s examples, that means recognising a repeated environment even when the person looks new, and identifying a device that lies about its hardware profile. This is not simple rules-based blocking. It is pattern generalisation across shared signals, where the control gets stronger as more fraud is confirmed and associated with real-world outcomes.
Practical implication: prioritise shared-signal correlation across channels and customers, not isolated fraud rules per product team.
What changes when AI agents become part of verification workflows
The article’s forward-looking point is that an AI agent may soon initiate account activity on a human’s behalf. That creates a new identity governance problem because the system must distinguish the human authorising the action from the software executing it. In practice, that means identity verification, authorisation and delegated access control begin to converge. The verification layer has to understand consent, scope and purpose, not just whether a face or device looks legitimate.
Practical implication: prepare policies for delegated action now so agent-driven transactions can be constrained before they reach production.
Threat narrative
Attacker objective: The attacker aims to bypass identity checks and complete fraudulent account access or financial activity without triggering obvious local fraud controls.
- Entry begins with stolen identity data, synthetic media or emulated devices that can pass weak onboarding checks.
- Escalation occurs when the same fraud actor reuses faces, devices or network paths across institutions and evades isolated controls.
- Impact is account takeover, mule activity or fraudulent transaction execution that appears legitimate to the target organisation.
NHI Mgmt Group analysis
Continuous identity verification is replacing the old KYC gate. Static proofing cannot keep up with reused faces, emulated devices and cross-institution fraud reuse. The article is right to frame identity as a runtime decision, not a one-off onboarding event. For identity teams, the governance question is whether controls can re-evaluate trust at login, transfer and profile change, not only at signup.
Network intelligence is becoming a core identity control, not just a fraud signal. The article’s strongest point is that a fraud pattern seen at one organisation can protect another immediately. That changes the economics of detection and makes ecosystem learning part of identity governance. In a broader sense, this aligns with the need for shared trust signals across verification, IAM and fraud operations, because isolated controls miss distributed abuse.
Delegated AI action creates an identity and authorisation problem, not just an AI problem. When agents begin opening accounts or moving money, the control challenge is proving human intent, bounded delegation and acceptable scope. That intersects directly with IAM, consent management and emerging machine identity governance. The practitioners who solve this early will treat agents as governed actors, not just automated workflows.
Precision is the real performance metric for verification programmes. The article correctly rejects block-rate vanity metrics in favour of stopping fraud without suppressing legitimate users. That is a governance lesson for any identity programme: false positives create operational drag, customer harm and compensating control fatigue. The better model is risk-sensitive enforcement with clear thresholds, measurable exceptions and reviewable policy logic.
Fraud defence now depends on the verification trust gap: the space between what one organisation can see and what the network can already know. That gap is where adaptive criminals operate. For practitioners, the implication is that local optimisation is no longer enough. Verification strategy has to assume adversaries can move faster than a single tenant can learn, which makes ecosystem-level intelligence a material control requirement.
What this signals
Verification programmes are moving toward continuous risk decisions, and that shift matters beyond fraud teams. Once identity becomes a runtime control, IAM, fraud and customer operations need shared policies for when to step up assurance, when to delegate and when to block. That is especially relevant as AI-mediated workflows emerge, because the policy question becomes who can authorise action, not just who can log in.
Network-scale intelligence will increasingly define the quality gap between identity providers. Teams that only optimise local conversion and local fraud rates will miss coordinated abuse that spreads across banks, marketplaces and fintechs. The practical challenge is to align detection logic with ecosystem-level learning while keeping customer friction measurable and bounded. That is where trust and identity governance begin to overlap with operational resilience.
The growth path for identity verification is not more static checks, but better governed decision loops. For practitioners, that means instrumenting the moments where risk actually changes and making those decisions auditable, explainable and policy-bound. It also means preparing for delegated machine action now, because once AI agents enter the workflow, identity assurance has to cover both the human principal and the software delegate.
For practitioners
- Shift high-risk identity events to continuous verification Trigger fresh checks at login, transfer, device change and settings updates instead of relying only on onboarding KYC. Use a layered model that combines document, device, behavioural and network signals so the decision reflects current risk, not stale enrolment data.
- Build shared-signal fraud detection into your operating model Correlate repeated faces, reused devices, suspicious IP ranges and emulator patterns across products and business units. Where possible, connect those signals to confirmed outcomes so the detection logic improves across cases rather than resetting at each team boundary.
- Define policy for delegated AI actions before production use Require explicit human authorisation, scoped permissions and transaction limits for any AI agent that can act on a customer’s behalf. Treat the agent as a governed delegate, and separate proof of identity from proof of intent when the workflow involves money or account control.
- Measure precision, not just block volume Track false positives, legitimate customer friction and recovery effort alongside blocked fraud. A control that blocks more transactions is not better if it harms real users or forces manual review to carry the load.
Key takeaways
- Identity verification is shifting from onboarding control to continuous trust assessment at the moment of risk.
- Cross-customer fraud intelligence improves detection because many abuse patterns are only visible across the wider network.
- AI agents introduce a delegated action problem that IAM and identity verification teams will need to govern explicitly.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | The article centres on repeated authentication and risk-based verification decisions. |
| Recommendation — Apply SP 800-63B to step up assurance at sensitive actions, not just at initial enrolment. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorisations | Identity verification here governs who may proceed with account and transaction actions. |
| Recommendation — Map verification outcomes to PR.AC-4 and enforce context-aware authorisation for risky events. | ||
| GDPR | Art.32 — Security of processing | The article discusses identity processing, device signals and privacy-bound defensive controls. |
| Recommendation — Limit identity data use under Art.32 and document how risk signals are protected and retained. | ||
Key terms
- Continuous identity validation: A governance model that checks identity trust throughout execution rather than only at login or periodic review. For AI and machine identities, this means verifying access, scope, and behaviour in real time so actions can be constrained while they are happening.
- Fraud Intelligence Network: A shared data source that aggregates abuse patterns, customer histories, and risk indicators across multiple merchants or participants. It helps compensate when local session data is sparse by adding broader context about repeat abuse and emerging patterns.
- Delegated AI Action Chain: A delegated AI action chain is the sequence of permissions and tool invocations that an AI system uses to complete a task. For governance, the important unit is not the initial login but the full path from identity through retrieval, model output, and downstream execution.
What's in the full article
Smile Identity's full analysis covers the operational detail this post intentionally leaves for the source:
- The production examples behind the 500 million check milestone and how the detection models were tuned across regions.
- The fraud rule patterns used to catch repeated faces, emulated devices and shared network infrastructure in live traffic.
- How the platform balances false positives against blocking fraud, including the precision trade-offs behind its dynamic rules.
- The article's forward view on AI agents opening accounts and moving money, including the human authorisation challenge.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security and secrets management. It is designed for practitioners who need to connect identity controls to broader security and governance programmes.
Published by the NHIMG editorial team on September 16, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org