TL;DR: A consumer study of 2,000 people in the UK and US found that 74% would switch banks for guaranteed deepfake protection, while 48% now question almost everything they see online, according to iProov. The shift turns human identity assurance into a business continuity issue, not just a fraud control.
At a glance
What this is: iProov’s consumer study says deepfakes are eroding digital trust, with 74% of respondents willing to switch banks for guaranteed protection and 48% questioning almost everything they see online.
Why it matters: This matters because human identity programmes now have to address trust collapse, not just authentication friction, across banking, public services and fraud prevention.
Context
Deepfake-enabled impersonation is no longer just a content authenticity problem. It is now a human identity assurance problem, because people are making trust decisions about institutions based on whether digital interactions feel verifiable.
For identity teams, the issue sits across biometrics, MFA, customer verification and fraud response. When consumers no longer trust what they see or hear, the assurance layer around human identity becomes part of business continuity, not just security architecture.
Key questions
Q: How should organisations protect human identity journeys from deepfake-enabled fraud?
A: Use layered assurance rather than relying on any single signal. Biometric verification, liveness detection, device binding, and risk-based step-up checks should all support one another, especially for onboarding, recovery, and high-value transactions. The goal is to prove that a live person is present and authorised, not just that a facial or vocal pattern matches.
Q: Why do facial deepfakes create risk for biometric authentication programmes?
A: Because they undermine the assumption that a face capture is strong evidence of a real person present in the session. When synthetic faces, face swaps, and face animation are cheap and realistic, biometric programmes need stronger assurance than image appearance alone.
Q: What are the signs that human identity controls are not keeping up with deepfakes?
A: Common signals include rising manual review, more account recovery disputes, increased customer complaints about verification, and growing use of fallback channels for high-risk actions. If users trust the institution less over time, the identity programme is failing to restore confidence, even if login success rates look healthy.
Q: Who should own deepfake-related identity failures in an organisation?
A: Ownership should be shared across IAM, fraud, customer operations and legal or compliance teams, because the impact spans authentication, financial loss, service quality and accountability. If only one team owns the issue, the organisation usually treats a trust failure as a narrow technical event instead of a broader governance problem.
Technical breakdown
Why deepfakes weaken human identity assurance
Deepfakes break the assumption that visible or audible cues are reliable evidence of presence. Human identity systems have long depended on signals such as a face, voice, document image, or familiar interaction pattern to establish trust. AI-generated impersonation makes those signals cheap to mimic, so the control problem moves from recognising a person to proving that the interaction is genuine. That changes the security model for remote onboarding, high-risk transactions, and help-desk recovery, where the adversary can now simulate legitimacy at scale.
Practical implication: treat presentation-layer trust as untrusted unless it is backed by stronger proof-of-presence controls.
Biometric login and identity proofing under deepfake pressure
Biometric login and identity proofing are still useful, but only when they are designed as layered controls rather than standalone trust decisions. A biometric factor can confirm a user session, but it does not by itself prove intent, context, or fraud resistance if the surrounding process accepts synthetic media too easily. Identity proofing becomes more resilient when it combines liveness, device context, behavioural signals, and step-up checks for higher-risk actions. The challenge is less about whether biometrics work and more about whether the whole verification workflow resists AI-generated imitation.
Practical implication: review onboarding and account recovery flows as a chain, not as isolated authentication steps.
Why trust recovery is now part of identity security
The article’s strongest signal is not technical, it is behavioural: consumers are changing where they will do business based on whether institutions can defend against deepfakes. That makes trust recovery a governance issue, because the business impact extends beyond fraud losses into customer attrition and public confidence. Identity teams therefore need to think about assurance communications, challenge escalation paths, and who owns verification failures when synthetic media drives a false decision. In practice, trust is now a measurable outcome of identity architecture, not an abstract brand attribute.
Practical implication: assign ownership for deepfake-related trust failures to both IAM and fraud operations, not one team alone.
Breaches seen in the wild
- Entra ID actor token flaw (CVE-2025-55241): Hidden Actor tokens plus an Azure AD Graph validation flaw could have let attackers become Global Admin in any Entra ID tenant (CVE-2025-55241).
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Deepfakes have turned human identity assurance into a trust infrastructure problem. The article shows that consumers are no longer treating verification as a back-office control; they are using it as a proxy for whether an institution deserves their business. That shifts the centre of gravity from authentication UX to trust continuity. For identity practitioners, the implication is that assurance failures now have commercial consequences that are broader than fraud.
Presentation evidence is no longer a sufficient basis for identity confidence. Face, voice and document cues were never absolute proof, but synthetic media has made them far easier to counterfeit at the moment of interaction. That means human identity programmes need to stop assuming that the visible artefact is the truth source. The practitioner conclusion is simple: the verification chain must prove liveness, context and resilience against manipulation, not just match a template.
Deepfake protection is becoming a customer expectation, not a niche security feature. When 74% of respondents say they would switch banks for guaranteed protection, the market is signalling that weak assurance will be punished quickly. That elevates identity fraud controls into retention, reputation and regulatory accountability discussions. Security leaders should expect deepfake resistance to be judged as part of service quality, not only control maturity.
Human identity governance now sits at the intersection of fraud, biometrics and institutional trust. The study’s government-services findings reinforce that digital access is increasingly conditioned on perceived authenticity. This is where NIST SP 800-63 and biometric assurance thinking become operationally relevant: not as compliance checkboxes, but as design constraints for high-risk journeys. Practitioners need governance that spans verification, recovery and customer communication.
The named concept here is trust erosion at the identity edge. Once consumers begin to doubt almost every digital signal, the identity system inherits the burden of restoring certainty before any business transaction can proceed. That is a governance shift, not a tooling tweak. The practical conclusion is that institutions must measure whether their identity journeys restore confidence fast enough to sustain usage.
From our research library:
- Gartner predicts that by 2026, 30% of enterprises will consider identity verification solutions unreliable in isolation because of AI-driven attacks.
What this signals
Trust erosion at the identity edge: when people can no longer tell whether a digital interaction is real, identity programmes inherit a trust restoration function as well as an authentication function. That pushes assurance, recovery and customer communication into the same governance discussion.
Biometric and proofing controls remain useful, but only if they are evaluated against synthetic-media resistance rather than isolated match accuracy. The control question is no longer whether a face scan works, but whether the full journey still holds up when the presentation layer can be faked.
The practical signal for teams is that deepfake resistance now affects adoption, retention and incident handling together. Organisations that separate fraud response from identity design will struggle to close the loop when customers lose confidence in the interaction itself.
For practitioners
- Strengthen proof-of-presence checks Use liveness, device binding and context signals together for onboarding, account recovery and high-value transactions so a single biometric or media cue does not carry the decision alone.
- Redesign recovery flows for synthetic media Treat password resets, call-centre verification and manual overrides as prime deepfake targets, and require step-up verification before any sensitive account change proceeds.
- Separate fraud response from verification design Give fraud, IAM and customer operations a shared escalation path for suspected impersonation so trust failures are handled as operational events, not isolated support cases.
- Review customer-facing trust signals Check whether your login, consent and recovery journeys communicate enough assurance for users to keep transacting when public confidence in digital authenticity is falling.
Key takeaways
- Deepfakes are eroding the basic trust assumptions behind human identity journeys, not just creating another fraud variant.
- The study shows a large confidence shift, with 74% willing to switch banks for guaranteed deepfake protection and 48% questioning almost everything online.
- Identity teams need layered assurance, shared ownership and recovery designs that can withstand synthetic media without breaking customer trust.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | The article focuses on human authentication trust under deepfake pressure. |
| SP 800-63A — Enrollment and Identity Proofing | Consumer trust in onboarding and recovery depends on stronger proofing against synthetic media. | |
| Recommendation — Apply SP 800-63B to strengthen authentication flows with layered assurance and liveness checks. Use SP 800-63A to harden proofing and recovery journeys against impersonation. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about access assurance and who can be believed in identity journeys. |
| Recommendation — Align identity assurance decisions to PR.AA-05 so access is granted only after reliable verification. | ||
| OWASP ASVS | V6 — Authentication | Authentication flows are the main control surface stressed by deepfake-enabled impersonation. |
| Recommendation — Review authentication paths under V6 for weak assumptions that synthetic media can exploit. | ||
Key terms
- Deepfake Protection: Controls and verification practices designed to detect or resist AI-generated impersonation in identity journeys. In human identity programmes, it usually combines liveness, device context, behavioural signals and escalation paths so a synthetic face, voice or video cannot satisfy the control on its own.
- Proof of Presence: A verification approach that aims to establish that a real person is actively participating at the moment of authentication. It goes beyond matching a stored trait and instead looks for live, context-specific evidence that resists replay, cloning, and remote fabrication.
- Identity Assurance: The confidence an organisation has that a person or system is truly who it claims to be before access or action is granted. In modern IAM, assurance depends on evidence quality, channel trust, and the strength of verification around high-risk decisions.
- Trust-Boundary Erosion: The gradual loss of clear separation between legitimate interaction and adversarial impersonation. When attackers can copy tone, timing, and business context convincingly, defenders can no longer rely on visual or linguistic cues alone. The practical problem becomes deciding where trust should be established and verified.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org