Vilhelm German: Why AI Is Changing Identity Verification and KYC

Bybit
Bitbuy


Artificial intelligence is making identity fraud faster, cheaper and harder to detect, exposing weaknesses in the way businesses verify customers online.

Vilhelm German, the businessman who helped to found an innovative digital identity verification provider GlobalPass, says businesses increasingly need to look at more than whether a document or face appears genuine. They also need to consider whether the identity, interaction and transaction can be trusted.

For years, digital onboarding followed a relatively simple process: verify an identity document, match it to a face, run database checks and make a risk decision. But generative AI, deepfakes and synthetic identities are making those individual checks easier to manipulate.

Sponsored

okex

Crypto Prediction Markets

18+ · Gambling involves risk. Play responsibly.

The question for the Know-Your-Customer (KYC) service providers is becoming more basic: can they trust the whole interaction, not just the individual pieces of information?

AI is Changing the Fraud Equation 

The scale of the problem is growing. Deepfakes now account for roughly 6.5% of fraud attempts globally, according to industry data, with the rate rising more than 2,100% since 2022.

Entrust’s 2026 Identity Fraud Report, based on more than 1 billion identity-verification events across 195 countries and more than 30 industries, found that deepfakes accounted for one in five biometric fraud attempts. Deepfake selfie attempts rose 58% in 2025, while injection attacks increased 40% from a year earlier.

Injection attacks are particularly difficult because they can bypass the camera. Instead of showing a fake face to a camera, attackers can feed manipulated video or other synthetic material directly into a verification system. 

Synthetic identity fraud is changing too. The fraudsters are increasingly creating groups of connected synthetic identities that interact with each other to build artificial credibility across platforms.

And here the common problem is simple: a single piece of information is easier to fake when AI can produce convincing alternatives at scale.

Detection Has Limits

Detecting AI-generated content is not straightforward either.

A detection system may perform well in testing and struggle when it encounters new attack techniques in the real world. Human reviewers face the same problem. Research across multiple studies has found that people are often only slightly better than chance at identifying deepfakes.

For KYC systems, that matters because many still depend on documents, facial recognition and liveness checks.

“The question isn’t really ‘is this document genuine’ anymore,” said German. “What we’re chasing is whether the whole interaction holds up: is there an actual person there, are they present right now rather than replayed from a recording, and is this identity being used the way it’s supposed to be.”

The distinction matters because fraudsters do not always need to create a completely fake identity. They can use a genuine identity document and combine it with manipulated biometric or video data to fool systems that rely on a single verification check.

For German, the implication is that identity verification needs to look beyond the document or face being presented and consider the circumstances surrounding the verification.

Digital Identity Could Add Another Layer

Regulation is also changing the identity landscape.

From August 2026, EU member states are required to make European Digital Identity (EUDI) Wallets available. The wallets are designed to give individuals greater control over how their identity information is shared, allowing them to provide specific credentials to public and private organizations without necessarily disclosing additional personal information.

That could make some forms of digital onboarding easier, but it does not eliminate the need to assess fraud or transaction risk.

“A trusted digital credential can answer an important question — who is this person?” German said. “But businesses will still need to understand the context in which that identity is being used and whether the transaction itself makes sense from a risk perspective.”

That distinction could matter more as digital credentials become easier to use across services while other identity signals become easier to manipulate.

KYC Is Moving Toward Continuous Risk Assessment

The evolution of AI capabilities is also pushing KYC beyond the traditional point-in-time identity check.

Instead of simply confirming who a customer is, due diligence service providers increasingly need to assess whether the identity, interaction and transaction remain legitimate as circumstances change.

The issue could become harder as AI agents begin acting on behalf of people and businesses. Identity systems may need to establish who is behind an AI agent, whether the agent has permission to act and whether the action itself is authorized.

Vilhelm German believes that collecting more information is not necessarily the answer.

“More data isn’t the answer if you can’t trust the pipeline it came through,” he said. “It’s about having enough independent signals that agree with each other to make a decision and knowing which of those signals AI has made easier to fake.”

A document can show that an identity exists. A face match can show that two images look similar. But neither necessarily shows that the person is present, that the interaction is genuine or that the transaction is legitimate.

As AI gets better at manipulating individual signals, those questions are becoming harder to separate.

Dive into DailyCoin’s hottest crypto scoops today:
Corporate Maps Still File XRP & XLM As ‘Special’ Banking
OKX, ICE Plan 24/7 Trading for Tokenized U.S. Stocks



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*