TL;DR: AI-generated IDs and deepfake injection attacks have made traditional document checks too easy to evade, while 40% of legitimate users abandon document-based flows, according to Incode. The core shift is from identity-only verification to session-aware trust controls that preserve conversion without widening fraud exposure.
NHIMG editorial — based on content published by Incode: When Identity Isn't Enough: Solving Fraud in the Age of Deepfakes and AI
By the numbers:
- Incode data shows that 40% of legitimate users abandon document-based verification flows before completing them.
- GovFaceMatch verifies legitimate users in just 10 seconds, on average.
Questions worth separating out
Q: How should security teams reduce fraud without creating excessive verification friction?
A: Use layered controls that separate identity authenticity from session authenticity, then tune each control to the risk level of the transaction.
Q: Why do deepfakes make traditional authentication weaker?
A: Deepfakes weaken traditional authentication because they imitate the human signals that many approval processes still trust, including voice and video.
Q: Where does document-based verification fail in practice?
A: It fails when the organisation assumes document consistency equals identity authenticity.
Practitioner guidance
- Separate identity and session control decisions Design your verification policy so identity proofing, liveness, and session integrity are evaluated independently.
- Add device integrity checks to live verification Require signals such as device attestation, camera provenance, and anti-replay controls when biometric or video evidence is part of onboarding.
- Minimise retained identity artefacts Keep only the minimum biometric, document, and session data needed for the decision, then delete or tokenise what you do not need for audit or legal retention.
What's in the full article
Incode's full article covers the operational detail this post intentionally leaves for the source:
- How GovFaceMatch uses a driver’s license barcode and DMV record matching in the verification flow
- How Deepsight combines biometric signals, behavioural monitoring, and device integrity checks to detect deepfake injection
- The operational claims behind the reported 20% conversion improvement and 150x accuracy comparison
- The product positioning around privacy-first architecture, data minimisation, and session verification
👉 Read Incode's analysis of identity and session authenticity in AI fraud →
AI fraud, deepfakes and session authenticity: what teams need?
Explore further
Identity verification programmes now face a verification trust gap. The problem is no longer simply whether a claimant can present consistent data. It is whether the organisation can prove that the claimant, the device, and the session are all real at the same moment. That is a governance boundary issue as much as a technical one, and it exposes why legacy document checks underperform against AI-enabled fraud. Practitioners should treat this as a control design problem, not a tuning problem.
A question worth separating out:
Q: Which controls matter most when identity onboarding is exposed to AI fraud?
A: Prioritise authoritative-record matching, anti-injection protections, and clear abandonment monitoring. Those three controls address the main failure modes: fake identity evidence, synthetic session capture, and overly painful user journeys. Together they help reduce both fraud and avoidable drop-off, which is the balance most identity teams now need to manage.
👉 Read our full editorial: AI fraud now needs both identity and session authenticity controls