When my daughter watches a video, she almost immediately knows if it’s AI. “Look, it’s made of really short scenes, and all the words are perfectly pronounced,” she explains, like it’s the most obvious thing there is. “There are a lot of signs; you just have to look at them as a whole”.
But what about where it really matters, like in KYC? How can we make sure our systems detect AI-generated material there?
AI Breaks the Iron Triangle
The problem is especially severe because AI is a disruptor also of the “fraud market”.
The classic “iron triangle” of project management says you can have fast and cheap but not good, good and fast but not cheap, or cheap and good but not fast. When it comes to “fraud projects”, however, AI has broken the triangle: fraud can now be fast, cheap and disturbingly convincing.
Take passport forging, for example. This used to require a professional forger, who needed to source specialised tools and materials from others. It was a “proper” criminal conspiracy.
Now all one needs (to create a digital passport, anyhow) is a prompt. The AI model can produce a better-quality fake passport, faster and at a fraction of the cost. Not only that, but the model can also throw in, for free, a synthetic identity combining real and fabricated information, convincing utility bills, a couple of deepfake selfies and a liveness video to match.
🚨 CRYPTO SECURITY ALERT: THE END OF FACIAL VERIFICATION (KYC) 🚨
— VECERT Analyzer (@VECERTRadar) April 5, 2026
🌐 The launch of JINKUSU CAM—a cybercriminal tool—has been detected. It is a powerful AI suite designed specifically to BREACH the security protocols of the world's largest exchanges (Binance, Coinbase, Kraken,… pic.twitter.com/qZgVYkDxn9
Asymmetric Economy
This “market disruption” already has real-life impact. FinCEN has long observed an increase in suspicious activity reports filed by financial institutions describing the suspected use of deepfake media, particularly fraudulent identity documents used to circumvent identity verification and authentication methods.
In 2024, Deloitte’s Center for Financial Services projected that generative AI could enable fraud losses in the United States alone to rise from $12.3 billion in 2023 to $40 billion by 2027.
But it is not simply that the fakes have become better and more frequent. The economics have changed. The attacker’s cost per attempt has collapsed, while the defender’s cost per check has barely moved. This asymmetry means that if the answer to every new threat is simply to add another manual review or verification layer, we answer the fraudster’s cost reduction with our own cost increase. That is not a contest we can win in the long run.
Do Not Publish the Exam Paper
This is not an argument for weaker gates. Quite the opposite.
Forensic document analysis, genuine liveness detection (not one that boasts “high pass rates”) and verification against independent sources, rather than only against information uploaded by the client, should be the minimum. Firms should be far more demanding about these controls than many currently are.
However, if these controls are wrongly deployed, they will lose the economic battle.
Not only that – deployed at scale, any new layer is studied by attackers, triggering adjustments and new attempts.
This is amplified by the fact that many onboarding processes are still static in nature. Every applicant follows the same route, receives the same questions in the same order and is asked for the same documents, regardless of who they are, where they are based or what they want to do.
That is the equivalent of publishing the exam paper. It doesn’t matter what or how many questions you put forth in an exam, if the students already have the exam paper.
In Fact, Don’t Write an Exam Paper At All
Don’t just keep the exam paper secret; better not write one at all.
An exam paper is a form. A form is easy to lie to. It’s much harder to lie to a lawyer who remembers your previous answers in a cross-examination, and can confront you with the protocol.
In a KYC journey, each individual check (“exam question”) may be fully justified and of good quality, yet the journey as a whole is predictable and therefore easier to defeat. A fraudster can rehearse against a fixed and known process. They fail on Monday, adjust the synthetic identity, and pass on Wednesday.
- Are KYC and AML Protocols Enough to Curb Fraud?
- Data Privacy and Ethics in Fintech: Balancing Innovation with Consumer Protection
- Mainstream Crypto Integration Brings Trade Offs around KYC
The solution, therefore, is not to ask everyone more questions and request more documentation. It is to ask each applicant the right questions and request the right documentation, given the answers and documentation they have already supplied – just like one would do, for example, in a cross-examination.
When the journey adapts to the client type, jurisdiction, requested product and risks emerging as the file develops, coherence becomes a test of its own. The documents must match the type of person or entity. The answers must fit the regulatory profile. The profile must make sense for the jurisdiction, ownership structure, intended activity and products requested.
A deepfake may beat a face check. It is considerably harder for a synthetic identity to remain convincing across an entire connected rule set. The fraudster is no longer trying to defeat one detector; they must sustain the same lie across every relevant fact, document, rule and decision.
Or, as my daughter put it, “there are a lot of signs; you just have to look at them as a whole”.
Doing so also does something funny – it creates a better journey for genuine clients. A legitimate applicant should be asked only relevant questions and required to provide only information that cannot be obtained reliably in the background. Honest clients encounter less friction; incoherent profiles encounter more. A single rigid corridor for everyone achieves the opposite: unnecessary friction for real clients and a rehearsable script for fraudsters.
INTERPOL’s new African Cyberthreat Assessment Report 2026 cites Sumsub’s Identity Fraud Report 2025–2026, drawing on our research to highlight several important shifts in Africa’s fraud landscape.
— Sumsub (@sumsub) August 19, 2026
Among the findings referenced:
🔹 AI is reshaping identity fraud. Our research…
Three Final Notes
Before I sign off, there are three final points worth making.
First, onboarding ends, but KYC does not. Information collected at the outset is only a snapshot. Identity verification, classification, risk assessment and monitoring must remain connected throughout the client lifecycle, triggering review whenever the client’s activity no longer fits their stated profile. This means onboarding data needs to continue operating as a “living” data layer throughout the client lifecycle, not sealed-off in a silo somewhere.
Second, none of the above-described can operate as a black box. A firm must be able to see and change its rules, identify the evidence behind each trigger and explain why a question was asked or a decision made. Automation supports judgment; it does not transfer responsibility for it. And if you have a responsibility you cannot explain – or control – you’re at real risk.
And finally, my daughter was right. Spotting AI is rarely about finding one definitive flaw. It is about recognising when the details, viewed together, fail to tell a coherent story. Therefore, in an age of near-perfect fakes, the most important question may no longer be “does this look real?” but rather “does the whole journey make regulatory sense?”