The EUDI & Wallet Playground: test real wallet flows in your browser for free. Try it now
Jarek Sygitowicz
Jarek Sygitowicz

Beyond deepfakes | What actually stops AI-generated identity fraud

Last updated: 23 August 2026

Deepfake detection is a race against a model that improves faster than the detector. The way out is not a better detector but a different kind of evidence: attributes read from a government credential, where there is no image to manipulate.

This Authologic briefing covers what changed in the attack, what the numbers show, and what the alternative looks like.

Deepfakes and identity fraud threat briefing title card

Key takeaways

  • The FBI tracked AI as a complaint descriptor for the first time in its nearly 25-year history of the report: 22,364 complaints and $893 million in adjusted losses.
  • Injection attacks, where video is fed straight into the verification stream and never passes a camera, rose 741% against iOS devices across 2025 according to iProov's 2026 threat report.
  • Detection improves, generation improves faster, and the defender is always one model behind. Gartner reached the same conclusion in June 2026, placing deepfakes among four threats where attackers hold the advantage and stating that no single control defends against them.
  • A government credential is not an image. It is a signed statement from an issuing authority, so there is nothing to forge at the presentation layer.
  • eIDAS 2.0 sets two dates: wallets available by 24 December 2026, acceptance obligatory from 24 December 2027 for the sectors listed in Article 5f, and only at the user's request.

How do deepfakes bypass identity verification?

They do not bypass it. They satisfy it.

A remote identity check asks the user to present an image of a document and, usually, an image of their face. The system then decides whether the document looks authentic and whether the face matches and belongs to a living person. Every one of those decisions is an inference drawn from pixels.

Generative models produce pixels. A synthetic document image that carries the right fonts, the right security features and consistent wear will pass a check designed to spot a photocopy. A generated face that blinks and turns will pass a liveness test designed to spot a photograph held up to a camera. Neither is a break-in. The system is asked a question about an image, and it is given an image engineered to produce the answer the attacker wants.

There is a second route that skips the camera entirely. In an injection attack the attacker feeds video directly into the verification stream through a virtual camera or a modified client, so no physical capture ever happens. Presentation attack detection is designed to catch something held in front of a lens. There is nothing in front of the lens.

What do the current numbers actually show?

Five figures from 2025 and 2026 reporting, each traceable to a named source, and one correction.


Figure

What it measures

Source

22,364 complaints, $893m in adjusted losses

Cybercrime reported to the FBI under a newly created AI-related descriptor, out of $20.877bn in total reported losses

FBI 2025 Internet Crime Report, April 2026

741% annual rise, 1,151% in H2 2025

Injection attacks against iOS devices

iProov Threat Intelligence Report 2026, via Biometric Update

720% spike in Q3 2025

Attacks in Southeast Asia, identified as a testing ground for emerging fraud techniques

iProov Threat Intelligence Report 2026

62% of organisations

Faced at least one deepfake attack in the previous 12 months, whether social engineering or an attack on automated verification

Gartner survey of 302 cybersecurity leaders, September 2025

37% on video, 43% on audio

Security leaders who encountered at least one deepfake incident during a call

Gartner, September 2025

Two of these deserve a second look. The FBI figure was recorded under a descriptor that had not existed in the report's history until this edition, and it depends on victims recognising and describing AI involvement, which the FBI itself notes makes it a floor rather than a ceiling. The injection attack figure matters because Apple devices had been treated as comparatively resistant to injected media used against biometric KYC checks; that assumption no longer holds. The most recent source in this piece is not a number at all: in June 2026 Gartner placed deepfakes among four threats where attackers hold the advantage, which is the subject of the next section.

A note on a number you will see everywhere. The figure of $40 billion appears in most coverage of AI-enabled fraud. It is a Deloitte Center for Financial Services projection of generative-AI-enabled fraud losses in the United States by 2027, against $12.3 billion recorded in 2023. It is a forecast, not a measurement, and it covers one market. Quoted without that framing it says more than the source does.

Two things to keep in mind when reading any of this. Vendor threat reports draw on the traffic those vendors see, so they describe the attacks reaching one set of defences rather than the whole market. And the FBI figures cover reported crime in the United States, which is a subset of a global problem.

Why is detection alone a losing position?

Because the attacker gets to iterate against your detector, and you do not get to iterate against theirs.

Detection models are trained on artefacts left by the generators that existed when the training data was assembled. Each new generation of generative models removes some of those artefacts. The defender responds by retraining on examples of the new generation, which by then is no longer the newest. The gap is structural, not a matter of effort or budget.

The economics point the same way. Producing a convincing forgery used to require skill, equipment and time, which limited the number of attempts. That constraint is gone. When the cost of an attempt falls towards zero, volume rises until it meets the accuracy limit of the defence, and a false accept rate that looked acceptable at a thousand attempts a month behaves differently at a hundred thousand.

Gartner reached the same conclusion in June 2026, placing deepfakes among four threats where attackers hold the advantage and stating plainly that no single control will protect an organisation against them.

None of which makes liveness detection useless. It makes it a layer rather than an answer, and it means the strength of a verification flow is set by what it can fall back on when the image-based layer is the only thing standing.

What is the alternative to checking an image?

Not checking an image.

A national eID, a bank-based identity or a government wallet does not hand you a picture to assess. It hands you attributes signed by the party that issued them, with a cryptographic path back to that issuer. There is no forgery surface at the presentation layer, because nothing is being presented for visual judgment. The question changes from "does this look real" to "who signed this, has it been altered, and is it still valid".

That difference is why the regulation points the same way. Article 22(6) of the AMLR names electronic identification means at substantial or high assurance, and relevant qualified trust services, as a route to verifying customer identity alongside identity documents. How the EUDI Wallet changes KYC sets out what that means for customer due diligence in practice, and what the Wallet does not do.


Document and selfie check

Credential-based check

What the user presents

An image of a document and of their face

Attributes released from a credential

What is verified

Whether the image looks authentic and live

Who signed the data, whether it was altered, whether it is still valid

Attack surface

The image itself, and the channel it travels through

The issuer's signature

Fails when

A generator produces a better image than the detector expects

The issuer's data is wrong, or the credential is revoked

Available

Almost everywhere

Only where a scheme exists and the platform can reach it

The same applies to injection attacks. There is no media stream to inject into, because the check is not looking at media; a forged or replayed credential fails the signature check regardless of how it reached the server.

The limit is coverage. A credential can only be read where one exists and where the platform can reach it, and reach varies by an order of magnitude between platforms: some cover a handful of national schemes, others most of the markets where a scheme exists at all. In markets a platform cannot reach, every check falls back to a document image and the whole argument above applies again.

Authologic exists to close that gap: it reads credentials wherever a scheme exists and falls back to document verification only where one does not.

What does eIDAS 2.0 actually require, and when?

Two dates, and they are often conflated.

Every Member State must make an EUDI Wallet available by 24 December 2026. From 24 December 2027, private relying parties in the sectors listed in Article 5f must accept it wherever the law requires strong user authentication, and only at the voluntary request of the user. Microenterprises and small enterprises are excluded as a rule.

The obligation attaches to the Wallet, not to electronic identification in general. An eID is a national electronic identification means; the Wallet is a user-controlled container that can hold identity data and other attestations. Who issues, who provides, who guarantees defines the roles behind both, and how eIDAS 2.0 affects private relying parties and SCA covers the obligation in detail.

Alongside it, the Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) applies from 10 July 2027 and harmonises customer due diligence across the EU without national transposition.

What should a verification stack look like in 2026?

Credential first where one exists, document second everywhere else, and one record of which was used.

That order is a routing decision, and it has to be made per user and per market rather than once at integration time. A user in a market with a mature national eID should never be sent through a document flow because the platform has no other option there. A user without a credential should not be turned away because the platform only speaks eID.

Three things follow for anyone specifying a stack.

Coverage decides your exposure. The share of your users who can be verified against an authoritative source is the share of your traffic that is out of reach of image-based attacks. That is a platform question before it is a security question, and how the main platforms compare on it is a separate exercise.

Fallback has to be automatic. A fallback that requires an engineering change when a method fails is not a fallback.

Evidence has to survive. Which method verified which customer, at which assurance level, retrievable years later. A document check leaves you an image and a confidence score; a credential check leaves you a named issuer, a method and an assurance level. That difference is what an audit will look at first.

Authologic is an orchestration platform: it routes each user to the strongest method available in their market, across 100+ eID methods and 240 countries and territories as of August 2026, holds document and biometric verification as the fallback rather than the default, and keeps one record of what was used. The vocabulary behind that - routing, fallback, method coverage - is defined in the Identity Orchestration Glossary.

FAQ

How do deepfakes bypass identity verification?

They satisfy the check rather than breaking it. Document and selfie verification draws conclusions from images, and generative models produce images engineered to support the conclusion the attacker wants. Injection attacks go further and feed video straight into the verification stream, so no physical capture happens at all.

Can liveness detection stop deepfakes?

It raises the cost of an attack, but it cannot settle the question on its own. Detection models are trained on artefacts left by the generators that existed when the training data was assembled, and each new generation removes some of them. Liveness is a layer, not an answer.

What is an injection attack?

Feeding prepared video or images directly into the verification stream through a virtual camera or a modified client, rather than presenting them to a real camera. Presentation attack detection looks for something held in front of a lens, and in an injection attack there is nothing in front of the lens. iProov recorded a 741% annual rise in injection attacks against iOS devices across 2025, reported by Biometric Update.

How much fraud is AI-enabled?

Nobody knows precisely, and any source claiming otherwise is estimating. The clearest data point is the FBI's 2025 Internet Crime Report, which logged 22,364 complaints under a newly created AI-related descriptor with $893 million in adjusted losses. It covers cybercrime reported in the United States across all categories, not identity fraud alone, and the count depends on victims recognising AI involvement in the first place.

Does credential-first verification work outside Europe?

Where a scheme exists and the platform can reach it, yes. Government-backed identity is not a European phenomenon: bank-based identity, national eID and government wallet apps operate across Latin America, the Gulf and parts of Asia, and mobile driving licences are appearing in the United States. The constraint is not the region but whether a given platform has integrated the local method, which is why coverage is the first question to ask a vendor.

Why are government credentials harder to forge than documents?

Because there is nothing to forge at the presentation layer. A credential is a set of attributes signed by the issuing authority, verified against that signature rather than assessed visually. A document check asks whether an image looks authentic; a credential check asks who signed the data and whether it has been altered.

Does the EUDI Wallet make document verification obsolete?

No. For the next few years most customers in most markets will hold neither a wallet nor a national eID, and document checks remain the fallback that keeps them onboardable. What changes is the order: credential first where one exists, document second.

When does EUDI Wallet acceptance become mandatory?

From 24 December 2027, for private relying parties in the sectors listed in Article 5f of eIDAS 2.0, wherever the law requires strong user authentication and only at the user's request. Member States must make wallets available a year earlier, by 24 December 2026.

Sources


Changelog

  • 23 August 2026 - Rewritten and expanded by Jarek Sygitowicz. Corrected the eIDAS 2.0 dates and the scope of the acceptance obligation, refreshed all statistics with 2025 and 2026 sources, added an FAQ and internal links.
  • 7 May 2025 - Initial publication by Pamela Oldfield.

Share article

Text of this article
Media in this article

Press Contacts