Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do synthetic identities and deepfakes force identity…
Identity Beyond IAM

Why do synthetic identities and deepfakes force identity verification to become regulated infrastructure?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Identity Beyond IAM

Synthetic identities and deepfakes undermine the trust assumptions behind onboarding, dispute handling, and marketplace access. When fraud can be generated at scale with convincing media, identity verification becomes part of operational risk management, not just compliance. Organisations need controls that support auditability, consistent decisioning, and regulatory alignment across jurisdictions.

Why synthetic identities and deepfakes change the status of verification

Synthetic identities and deepfakes turn identity verification from a back-office check into a trust boundary that affects access, liability, and customer safety. A synthetic identity can pass superficial checks because it blends real and fabricated attributes, while deepfakes can degrade the reliability of photos, voice, and video used during onboarding or step-up verification. That means the verification layer is now part of the organisation’s security posture, not just a formality for meeting policy.

For regulated sectors, the issue is not only whether a person can be identified once, but whether the organisation can explain how it reached a decision, keep evidence for audit, and apply the same standard across channels and jurisdictions. That is why identity verification increasingly resembles regulated infrastructure: it needs defined rules, reviewability, and oversight rather than ad hoc judgement. For broader context on regulated digital identity, see eIDAS 2.0 — EU Digital Identity Framework. In practice, many security and compliance teams discover the fragility of their verification model only after fraudsters have already tested the weakest onboarding path.

How regulated infrastructure changes verification in practice

Once verification is treated as regulated infrastructure, the question shifts from “did the user pass?” to “can the organisation defend the decision?” That requires consistent evidence capture, versioned decision rules, escalation paths for ambiguous cases, and retention of artefacts that can support dispute resolution or regulatory review. It also changes vendor selection: the critical issue is not just detection accuracy, but whether the workflow preserves auditability and control over exception handling.

Synthetic identities are especially difficult because they often evolve over time. A profile may start with fragments of legitimate data, then accumulate trust through repeated low-friction interactions. Deepfakes introduce a second problem: they can be used to bypass controls that assume a camera, microphone, or live interaction proves presence. The result is that organisations must treat identity proofing as a layered control problem, not a single-point verification event.

  • Use stronger checks where the downstream action carries financial, legal, or access risk.
  • Separate identity proofing from ongoing authentication, because one good enrolment does not guarantee future trust.
  • Preserve the evidence behind decisions so disputes can be reviewed consistently.
  • Apply different thresholds for low-risk access, high-value transactions, and account recovery.

For anti-fraud and customer due diligence context, the FATF Recommendations remain directly relevant because they shape how identity evidence and risk-based controls are expected to work in regulated environments: FATF Recommendations — AML and KYC Framework. Where organisations cannot keep the verification process explainable and reviewable, the control stops behaving like infrastructure and starts behaving like an opinion.

Where the edge cases and trade-offs become material

Tighter identity verification often increases friction, operational cost, and false rejection rates, so organisations have to balance fraud resistance against user abandonment and access delays.

Not every use case needs the same strength of assurance. A low-risk newsletter sign-up does not justify the same scrutiny as a wallet withdrawal, benefits claim, or privileged account recovery. The hard part is that synthetic identities and deepfakes compress the gap between those use cases: attackers often begin in low-friction journeys and later exploit weaker recovery or escalation paths. There is still debate about how much biometric verification should be trusted on its own, and that debate is not settled by technology alone.

Some organisations also assume that automation removes bias or inconsistency. In reality, automated identity decisions can still encode weak assumptions, incomplete data, or brittle exception logic. The most resilient programmes combine risk-based thresholds, human review for edge cases, and governance over how evidence is interpreted. That matters most where the organisation must operate across multiple jurisdictions, because the acceptable proof standard and retention expectations may not align neatly.

For that reason, the right model is usually not “verify everything more aggressively,” but “treat identity assurance as a governed control surface whose standards change with the risk of the transaction.”

Risk and Threat Considerations

Synthetic identities and deepfakes create fraud, account takeover, and onboarding abuse risk because they weaken the trust signals that many identity processes rely on. They also increase governance risk when an organisation cannot show why a person was accepted, rejected, or escalated.

Failure mechanism: attackers combine fabricated or mixed identity attributes with convincing media to defeat liveness checks, bypass manual review shortcuts, or seed an account that later becomes trusted through normal activity. Weak recovery flows and inconsistent exception handling often provide the easiest route to abuse.

Impact: the organisation can admit fraudulent users, misallocate trust, face disputed decisions, and lose evidentiary quality for investigations, audits, or regulatory review. Over time, the verification process becomes less reliable as a control because its outputs are no longer defensible.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the technical controls, while EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyIdentity verification now affects operational and fraud risk decisions.
GV.OV-01 — Cybersecurity Risk Management OversightOrganisations need oversight for identity proofing decisions and exceptions.
Recommendation — Embed identity assurance thresholds into risk decisions for high-impact transactions. Assign oversight for verification exceptions and reviewable decision governance.
NIST SP 800-63IAL — Identity Assurance LevelSynthetic identities directly challenge the strength of identity proofing.
AAL — Authentication Assurance LevelDeepfakes can weaken step-up and recovery flows tied to authentication.
FAL — Federation Assurance LevelFederated identity assertions need trustable and reviewable assurance.
Recommendation — Select an assurance level that matches the risk of the identity event. Set authentication assurance to resist spoofed media and recovery abuse. Require federation assurance that preserves evidence and trust boundaries.
CIS Controls v86.3 — Access Agreements and Policy EnforcementVerification becomes regulated infrastructure when decisions must be consistent and auditable.
6.5 — Least Privilege AccessFraudulent identities become more dangerous when they obtain excessive access.
8.5 — Audit Log ManagementAuditability is central when identity outcomes must withstand disputes and review.
Recommendation — Enforce consistent identity proofing rules and exceptions through policy. Limit access granted after identity proofing to the minimum needed. Retain verification evidence and decision logs for audit and dispute handling.
EU AI ActArticle 26 — Transparency and Human Oversight ObligationsDeepfake-driven verification benefits from explainable decisions and human review.
Article 50 — Transparency Duties for Certain AI SystemsSynthetic media and AI-supported verification both raise transparency expectations.
Recommendation — Provide human oversight where automated identity decisions carry significant impact. Disclose when AI materially influences identity verification outcomes.

Practitioner Guidance

What to prioritise: Focus first on the flows where identity assurance changes legal, financial, or privileged access outcomes. Those are the places where synthetic identities and deepfakes create the highest downstream loss, and they should get stronger evidence requirements than routine sign-up paths.

What to verify: Verify that the process produces a defensible record of the decision, not just a pass or fail. Teams should be able to show what evidence was used, who reviewed exceptions, and how the same case would be handled again under the same rules.

Practitioner takeaway: The central decision is not whether identity verification should be stricter, but whether it is governed well enough to survive fraud, dispute, and regulatory scrutiny at scale.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org