TL;DR: AI-assisted fraud sessions on its platform rose from 2% in Q1 2023 to 32% in early 2026, while the cost of producing a convincing deepfake fell to US$1 and 18 seconds, making older detection economics inadequate according to Incode. The shift matters because identity verification now has to defeat synthetic media, bot behaviour, and device tampering at the same time, not one control failure in isolation.
NHIMG editorial — based on content published by Incode: Incode Deepsight wins the 2026 Award for Best AI-Driven Innovation in the Datos Impact Awards in Fraud & AML
By the numbers:
- AI-assisted fraud sessions on Incode's platform grew from 2% in Q1 2023 to 32% in early 2026.
- The cost of producing a convincing deepfake collapsed from roughly US$1,000 in 2020 to US$1 today.
- Deepsight reports a 0.4% false positive rate and a 0.5% false negative rate across the full module.
Questions worth separating out
Q: How should security teams handle deepfake risk in identity workflows?
A: Security teams should treat deepfakes as a trust and verification problem inside identity workflows.
Q: Why does cheaper deepfake generation increase fraud risk so quickly?
A: Because attacker economics have shifted.
Q: What are the signs that fraud controls are failing to catch synthetic identity attacks?
A: Common warning signs include accounts that clear initial verification but later show unusual device patterns, inconsistent behavior, or rapid takeover activity.
Practitioner guidance
- Separate capture integrity from identity confidence Treat device tampering, emulator use, and virtual camera injection as distinct failure modes with separate detection and escalation paths.
- Add behavioural signals to fraud scoring Use session timing, interaction patterns, and farm-like automation indicators alongside biometric and document checks before granting trust.
- Instrument document review for multimodal evidence Require document checks to evaluate layout, text, metadata, and visual artefacts together so one weak signal does not dominate the decision.
What's in the full article
Incode's full article covers the operational detail this post intentionally leaves for the source:
- Independent benchmark results across real deepfake incidents and commercial tools
- The three-layer Deepsight decision flow and how each layer contributes to fraud screening
- Details of the spoof bounty program and how retraining is fed by adversarial attempts
- Deployment outcomes across banking, fintech, gaming, telecommunications, and social media
👉 Read Incode's analysis of AI-driven deepfake fraud and multimodal detection →
Deepfake fraud in identity verification: are controls keeping up?
Explore further
Deepfake fraud has become an identity governance problem, not just a fraud problem. The article shows that the attack surface now spans capture, verification, and decisioning, which means identity teams cannot treat liveness as a single gate. Once synthetic media and manipulated devices enter the flow, the quality of the identity proof becomes a control issue for the whole access lifecycle. Teams should govern verification as a layered assurance process, not a binary pass or fail.
A question worth separating out:
Q: Should organisations prioritise liveness checks or document verification first?
A: Neither should be treated as sufficient on its own. Liveness helps when the attacker uses a fake human presence, while document verification helps when the attacker starts with forged credentials or identity evidence. The better decision is to sequence both inside one risk-based flow, then add behaviour and device checks where fraud pressure is highest.
👉 Read our full editorial: AI deepfake fraud is outpacing identity verification controls