TL;DR: AI-generated identities, deepfake liveness attacks, romance scams, synthetic profiles, and coordinated fraud networks are making online dating trust harder to establish, while users still expect low-friction experiences, according to SumSub and the ODDA. The central issue is that one-time checks and reactive moderation no longer match the speed, scale, and believability of AI-enabled deception.
At a glance
What this is: This is a white paper on how AI-generated identities are changing trust and safety in online dating, with the key finding that legacy verification and moderation models are no longer sufficient.
Why it matters: It matters because dating platforms now have to balance user safety, fraud resistance, and low-friction onboarding while preventing synthetic identities and scam operations from eroding trust.
Context
Online dating depends on identity trust at the point of profile creation, matching, messaging, and offline meet-up decisions. When synthetic profiles, deepfake liveness attempts, and coordinated romance fraud become easier to produce at scale, the problem is no longer just content moderation. It becomes an identity assurance problem, with verification paths that must work for real users without giving fraud networks easy coverage.
SumSub's white paper with the ODDA frames this as a trust and safety redesign problem rather than a single-check problem. The article argues that platforms need proportionate verification, behavioral analysis, and visible trust features that preserve user experience while reducing the chance that AI-enabled deception passes as a genuine person.
Key questions
Q: What breaks when dating platforms rely on weak identity assurance?
A: Weak assurance increases fake profiles, lowers confidence in user reports, and forces moderation teams to compensate with more manual review. Over time, that creates a degraded trust environment where legitimate users see more abuse and less certainty that the people they meet are real.
Q: Why do AI-generated profiles create more risk than traditional fake accounts?
A: AI-generated profiles can produce realistic photos, text, and behavioural variation at scale, which makes them harder to distinguish from genuine users. They also lower the cost of running large numbers of parallel scams. That combination increases both the volume of deception and the quality of the impersonation.
Q: How should dating platforms reduce fraud without making signup unusable?
A: Use risk-based verification instead of a single hard gate. Keep low-friction onboarding for low-risk users, then apply step-up checks when accounts show suspicious signals such as rapid messaging, repeated profile changes, device inconsistency, or attempts to move conversations off-platform. The goal is to separate access to the platform from access to trust.
Q: What should platforms do when synthetic identities start looking legitimate over time?
A: They should reassess trust as a living signal, not a one-time decision. That means correlating profile quality, message behaviour, device consistency, and escalation patterns to detect when an account is building credibility for abuse. If the trust model cannot change with the account, it will miss the moment the fraud becomes operational.
Technical breakdown
Why one-time identity checks fail against synthetic dating fraud
Traditional dating verification assumes a user proves identity once and then behaves consistently enough for later moderation to catch anomalies. AI-generated profiles and deepfake liveness attacks break that assumption because the deception can be created, tested, and iterated quickly. In practice, the attacker is not just masking identity at sign-up. They are maintaining a believable persona across messages, photos, and video checks. That makes static checkpoints weak when the fraud operation can adapt faster than review cycles.
Practical implication: platforms need verification and risk decisions to follow the session, not just the account.
How behavioural signals change the trust model for dating platforms
Behavioural analysis shifts attention from whether a profile passed a single check to whether its activity pattern fits normal human use. That includes message timing, profile completion patterns, device and network consistency, and anomalies across high-risk interactions. For dating platforms, this matters because romance fraud often succeeds through gradual trust-building rather than obvious malicious bursts. Behavioural signals help surface synthetic identities and fraud networks before the scam reaches the offline meeting or money request stage.
Practical implication: use behavioural analysis as a risk layer, not as a replacement for identity verification.
What reusable identity signals change in cross-platform dating trust
Reusable identity signals aim to reduce repeated friction for legitimate users while giving platforms a more durable assurance signal than a single disposable check. In a dating context, that can help distinguish real users from operators cycling through synthetic accounts and fresh profiles. The technical value is in portability and trust accumulation, but the governance challenge is ensuring those signals are proportionate, transparent, and not so opaque that users cannot understand why access or verification changed.
Practical implication: treat reusable trust signals as governed assurance artefacts, not as a shortcut around due diligence.
Threat narrative
Attacker objective: The objective is to create a believable dating persona that can extract trust, move conversations out of platform controls, and convert that trust into fraud or manipulation.
- Entry begins when a fraud actor creates a synthetic profile or uses AI-generated identity assets to appear real during onboarding and initial contact.
- Escalation occurs as the same actor uses deepfake liveness attempts, scripted conversations, and coordinated scam network support to build credibility over time.
- Impact follows when the target is moved from platform messaging into off-platform manipulation, with trust converted into financial loss, exploitation, or broader user harm.
Breaches seen in the wild
- Arup deepfake fraud 2024: Deepfakes of Arup's CFO and colleagues on a video call led a Hong Kong employee to transfer HK$200 million (about US$25.6m) to fraudsters.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Trust in dating has become an identity assurance problem, not a moderation problem. Platforms used to assume that a verified account was good enough to support matching, messaging, and meet-up decisions. That assumption breaks when synthetic identities can survive initial checks and continue to behave plausibly across sessions. The implication is that trust features now have to be designed as part of the identity layer, not bolted onto content review.
One-time verification creates an identity illusion that fraud operators can exploit. The central weakness is not the absence of a check, but the belief that a check performed once can carry the full burden of trust for a relationship that evolves over days or weeks. AI-generated personas, deepfake liveness attempts, and scam networks all benefit from that gap. Platforms need to treat trust as cumulative and continuously reassessed, because the deception evolves after onboarding.
Visible trust cues are now part of the security control surface. Users will not accept a platform that feels hostile, but they also will not sustain engagement if every interaction feels unverifiable. That creates a design constraint that older trust and safety models did not face: the user experience itself must help communicate assurance without exposing weak points. The consequence is that trust indicators, verification states, and escalation paths have become governance artefacts, not just product features.
Risk-based triage is the only scalable response to asymmetric fraud pressure. The article's DATE framework points in the right direction because it recognises that not every account needs the same level of friction. High-risk behaviour needs stronger scrutiny, while lower-risk users need a smoother path. That is the practical balance the market is moving toward: a governed verification model that protects growth by making fraud more expensive without making genuine dating feel impossible.
From our research library:
- U.S. fraud losses are projected to reach $40 billion by 2027.
What this signals
Trust signaling has become a core product control. Dating platforms are now judged not only on whether they can block bad actors, but on whether real users can see and understand the difference between verified, under-review, and high-risk states. That turns trust cues into an operational part of identity governance rather than a cosmetic layer.
Risk-based friction is the sustainable pattern. A dating platform that applies the same verification pressure to every user will either lose legitimate engagement or leave room for fraud networks to adapt. The more durable model is selective friction, with stronger scrutiny where behavioural signals indicate synthetic identity or scam escalation.
Cross-session trust must replace single-session certainty. Fraud in this category rarely ends at sign-up. Once a profile is accepted, the real test is whether the platform can continue reassessing credibility as messaging, profile changes, and off-platform moves unfold.
For practitioners
- Deploy risk-based verification flows Apply stronger checks only where signals justify them, such as suspicious sign-up patterns, inconsistent device behaviour, or repeated profile regeneration. Keep low-risk onboarding lighter so genuine users are not pushed away by unnecessary friction.
- Add behavioural review to trust scoring Combine liveness, profile, and message behaviour into a single trust view so that accounts are not judged only at registration. Use pattern changes over time to prioritise cases for human review and to spot scam network coordination.
- Introduce visible trust indicators Show users when an account has passed stronger verification, when it is under review, and what the platform means by those states. Clear trust cues reduce ambiguity and make safety controls easier to understand without overpromising certainty.
- Map off-platform escalation points Identify the moments when scammers typically move users from in-app messaging to external channels, payment requests, or other higher-risk interactions. Those handoff points are where detection and deterrence need the most scrutiny.
Key takeaways
- AI-generated identities make dating fraud harder to catch because the deception now survives the first verification step and continues inside the relationship lifecycle.
- The key operational challenge is balancing stronger assurance with user experience, since excessive friction can push genuine users away while still failing to stop sophisticated scams.
- Platforms need cumulative trust models that combine identity checks, behavioural signals, and visible user-facing controls so that fraud becomes harder to sustain over time.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | AI-generated personas and synthetic profiles exploit human trust at the identity layer. |
| NHI-04 — Insecure Authentication | Deepfake liveness attacks target authentication and identity proofing flows. | |
| NHI-02 — Secret Leakage | Fraud operations rely on reusable credentials, tokens, and verification artefacts to scale abuse. | |
| Recommendation — Treat synthetic profile abuse as an identity governance problem and tighten review around human trust signals. Harden identity proofing and liveness checks where account creation depends on remote verification. Reduce reuse of verification artefacts and revoke any exposed trust tokens or session material. | ||
| NIST SP 800-63 | SP 800-63A — Enrollment and Identity Proofing | Dating platforms need stronger proofing at enrollment when synthetic identities are a primary threat. |
| Recommendation — Apply identity proofing rigor proportional to the risk of account abuse and fraud. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Trust state and verification status govern what users are allowed to do and see. |
| Recommendation — Align access decisions and trust states so elevated actions require stronger assurance. | ||
Key terms
- Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
- Deepfake Liveness Attack: A deepfake liveness attack uses manipulated video, audio, or interactive media to defeat systems or reviewers trying to confirm that a user is physically present and genuine. In trust and safety workflows, it turns identity verification into a contest between human review and synthetic realism.
- Risk-Based Verification: A control approach that adjusts assurance strength to the context of the transaction, such as jurisdiction, wallet type, and value at stake. It avoids one-size-fits-all checks and lets firms apply stronger proof where the compliance and fraud risk is higher.
- Behavioural Analysis: Behavioural analysis is the practice of judging an identity by how it acts, not only by the credentials it presents. For AI agents, this means monitoring task paths, tool use, and interaction patterns so deviations from approved behaviour can be detected and investigated.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org