Can your current KYC vendor actually catch a deepfake, how would you know, and how do you layer the detectors that can?
Deepfake detection in KYC is the set of techniques that decide whether the face, voice, document, or video in an onboarding check is a genuine live person or AI-generated synthetic media. Because generative AI has made convincing fakes cheap and scalable, no single detector is enough. Strong defence layers document, liveness, injection, and behavioural checks and requires them to agree.
Deepfake detection in KYC is the set of techniques a verification system uses to decide whether the face, voice, document, or video presented during onboarding is a genuine live person or a piece of AI-generated synthetic media. It matters because generative AI has turned the remote selfie-and-document check that underpins modern account opening into an actively contested attack surface.
The controls most banks and fintechs rely on for remote onboarding, document capture, selfie match, and liveness, were designed for an era when the hardest attack was a printed photo or a silicone mask. Generative models changed the economics. Secondary reporting puts the cost of a usable face-swap or synthetic identity in the region of a few dollars to a few hundred, produced in under an hour on a laptop. Regulators now treat deepfakes as a direct threat to customer due diligence, not a fringe concern.
"Deepfake media" in KYC is broader than a swapped face on a video call. FinCEN defines it as synthetic content created with AI or machine learning to produce realistic but inauthentic videos, pictures, audio, and text that circumvent identity verification and authentication. That includes fabricated documents, AI-generated document photos, and fully synthetic faces of people who do not exist.
A face swap maps a real target's face onto a fraudster's live video, so the fraudster can respond to prompts in real time while wearing the victim's face. Face reenactment (puppeteering) drives a still image or short clip of a real person with the fraudster's own expressions and head movements. A fully synthetic face is a photorealistic face of a non-existent person generated by a model, used to build a clean identity with no real victim behind it.
A synthetic identity combines real stolen data, for example a genuine national ID number, with fabricated or AI-generated attributes and imagery. The identity is real enough to pass checks but ties to no real accountable person. This is a different problem from a single deepfake image, and it is the higher-volume KYC threat. See our explainer on synthetic identity fraud.
An AI-edited or AI-generated identity document image can defeat document checks. Entrust and Onfido's 2025 Identity Fraud Report found digital forgeries overtook physical counterfeits, reaching 57% of document fraud cases, with a 244% year-on-year rise.
This is the single most important concept to grasp, because most legacy defences only address the first type. A presentation attack shows the fake to the camera: a screen replaying a video, a printed photo, a 3D mask, or a phone held up to the verification device. An injection attack bypasses the camera entirely, feeding synthetic video directly into the verification data stream using a virtual camera, a manipulated app, an emulator, or an operating-system-level video interception tool. The camera layer never sees the attack, so camera-based liveness alone cannot catch it.
The industry inflection is that injection attacks have moved from niche to primary vector. Gartner noted injection attacks rose 200% in 2023. iProov's 2025 threat intelligence report, published April 2026, found iOS injection attacks up 741% year on year, and up 1,151% in the second half of 2025, with native virtual-camera attacks up 2,665% and now named the primary threat vector, partly through mainstream app-store infiltration. A stack that certified its liveness against presentation attacks years ago may have no defence against the attack that now dominates.
Modern deepfake-resistant KYC runs several independent detectors in parallel and requires them to agree, because no single signal is sufficient. Detection is a consensus problem, not a single yes or no.
Document authentication checks security features, fonts, machine-readable-zone and checksum integrity, and looks for signs of digital manipulation or AI generation. Passive liveness analyses a single image or short capture for biological markers such as natural micro-expressions, skin-texture and reflectance variation, and 3D depth cues that flat replays cannot reproduce. State the limit honestly: current generative models can pass some pixel-level passive checks. Active liveness or challenge-response asks the user to perform real-time actions, such as following a randomised on-screen colour sequence, which pre-recorded footage cannot answer.
Injection attack detection uses device attestation, virtual-camera and emulator detection, SDK integrity, and frame-level metadata analysis to confirm the feed came from a real sensor. Biometric binding cross-validates the face extracted from the document against the live biometric; both must independently pass authenticity checks and then match each other. Forensic artefact analysis examines texture, frequency-domain, and compression artefacts, plus temporal consistency across frames, to spot generation fingerprints.
Behavioural and contextual signals, including device reputation, network and IP signals, velocity, and behavioural biometrics, sit outside the image entirely and catch scaled rings that individually pass the image check. Provenance signals such as C2PA content credentials can record whether media was AI-generated, but note the limit clearly: C2PA records an assertion about provenance, it does not itself detect deepfakes, and it can be stripped.
Demand evidence, not marketing. The relevant standard for presentation attack detection is ISO/IEC 30107-3, tested independently by NIST or NVLAP-accredited labs such as iBeta. The levels describe how well-resourced an attacker the system was tested against.
The teaching point: PAD certification proves resistance to presentation attacks only. It does not, on its own, prove resistance to injection attacks, so a buyer must ask separately about injection coverage. Certification is also scoped and point-in-time, a result against a fast-moving threat rather than a permanent guarantee.
An iBeta pass tells you which level and that it covers presentation attacks. It does not cover injection attacks, and it reflects the threat at the time of testing. Ask for the level, the date, and separate evidence of injection-attack detection before you rely on a single certificate.
The figures below come from named vendor, analyst, and regulatory sources. Where analysts diverge, treat the numbers as directional and attributed, not as consensus fact.
Supervisors have moved from silence to specific expectations. FinCEN issued alert FIN-2024-Alert004 on 13 November 2024 on generative-AI fraud schemes circumventing identity verification, authentication, and due-diligence controls, asking institutions to flag related suspicious activity reports with the key term "FIN-2024-DEEPFAKEFRAUD". FATF published its Horizon Scan on AI and Deepfakes on 22 December 2025, naming deepfakes a direct threat to customer due diligence and identity verification, flagging synthetic and hybrid identities, framing AI as dual-use, and urging firms to review their CDD and ID and verification control frameworks against AI-enabled impersonation.
Gartner predicted that by 2026, 30% of enterprises will no longer consider identity verification and authentication solutions reliable in isolation because of AI-generated deepfakes on face biometrics. Under the EU AI Act, deepfake transparency and labelling obligations apply from 2 August 2026, with content that looks or sounds like a real person requiring a label even without intent to deceive, and penalties up to €15 million or 3% of worldwide turnover.
AI is not only the attacker's tool; it is the core of the defence. FATF explicitly frames AI as dual-use, able to increase efficiency in compliance and detection just as it can be weaponised. Defensive AI genuinely helps here: deep-learning models classify texture, depth, reflectance, and micro-motion to separate live faces from replays and masks (this is what ISO 30107-3 certification measures); machine-learning models learn the statistical fingerprints of virtual cameras and injected streams that a genuine sensor feed does not produce; frequency-domain and temporal-consistency models flag generation artefacts invisible to humans; and behavioural and network models catch scaled synthetic-identity rings. Humans are unreliable graders here: Sumsub cites a 2025 study finding people were 36% less likely to correctly spot a fake video than a fake image, even when warned.
Zenoo does not build a deepfake detector; it orchestrates the vendors that do, and its AI works on the decision and investigation layer, not the pixel layer. Zenoo runs 10 specialised AI agents across research, screening triage, and case work. After a detector returns a signal, Zenoo can pre-classify up to 80% of screening alerts with high confidence and cut per-alert disposition from 20 to 45 minutes down to 2 to 3 minutes, so a spike in deepfake-flagged cases does not overwhelm the team. Every decision is recorded in an immutable audit trail of 32 event types across 8 categories. The actual "is this face a deepfake?" decision is still made by the specialist detector Zenoo routes to.
What needed a studio a few years ago now needs a laptop, a free open-source model, and under an hour. Deepfake-as-a-service turns this into a subscription. Secondary reporting puts synthetic identities at roughly $5 to $15, deepfake images at $10 to $50, human-assisted "verification pass" services at $100 to $500 per successful check, and face-swap software rentals at $1,000 to $10,000; treat these as indicative ranges, not precise figures. Injection attacks then feed these fakes into KYC APIs at scale, and synthetic and hybrid identities built from real stolen data plus AI-generated imagery pass onboarding, which FATF flags specifically.
Real incidents show the scale. Sumsub reports that in early 2025 Hong Kong police disrupted a deepfake ring linked to about $193 million in losses that merged fraudsters' faces with stolen IDs to bypass facial recognition, and a separate case saw a suspect open roughly 46 fraudulent accounts using stolen IDs and deepfakes against a bank's mobile onboarding flow. Executive impersonation, as in the Arup video-call fraud, shows deepfakes weaponised against payment authorisation as well as onboarding.
Attackers iterate against detectors, so a passing certification grade last year is not a defence this year. Sumsub reports a 180% year-on-year rise in sophisticated, multi-step fraud and expects agentic-AI-driven scams to surge in 2026. The defender's advantage is not one clever detector but the ability to layer many, monitor them, and swap them fast, which is exactly an orchestration argument.
Standalone verification loses trust. Gartner's guidance is to choose vendors who monitor, classify, and quantify these attacks and go beyond current standards. Regulation tightens and converges: FATF's December 2025 Horizon Scan signals more supervisory attention to AI-enabled CDD circumvention, FinCEN's SAR flagging builds a data trail, and the EU AI Act's labelling regime lands in August 2026. Expect examiners to ask specifically how firms defend against injection attacks and synthetic identities.
Provenance and digital identity offer a longer-term shift from "detect the fake" to "prove the genuine." C2PA content credentials (v2.3 arrived around December 2025 to January 2026, with the Samsung Galaxy S25 signing at capture) and government digital identity such as the EU Digital Identity Wallet under Regulation (EU) 2024/1183 point that way, though provenance asserts rather than detects and can be stripped. Agentic AI will operate on both sides, and the deepfake-detection market continues to grow quickly, if by definition-dependent estimates (analysts cite roughly 40% to 48% annual growth ranges). More detectors and more differentiation strengthen the case for orchestrating between them rather than betting on one.
Use these questions to separate evidence from marketing when you assess a detector or a stack.
Zenoo is a KYC, KYB, and AML orchestration platform. It does not detect deepfakes itself. It connects the specialist deepfake, liveness, and injection detectors you already trust or want to trial, and gives you routing, failover, one audit trail, and cost control across them, with UI freedom via Zenoo Studio. Because detection is a consensus problem, orchestrating multiple detectors and applying policy across their outputs is stronger than any single vendor. Zenoo's Marketplace exposes 240+ check types on the Enterprise tier and supports parallel execution, and lets you add or reroute to a new detector in under an hour instead of a 4 to 6 month integration, so you are not locked into a detector that has fallen behind the arms race. For continuous coverage after onboarding, pair this with ongoing monitoring and perpetual KYC.
Say this plainly. Zenoo does not make the "is this a deepfake?" decision; that is the specialist detector's job. Zenoo cannot make a weak detector strong, only route to a better one and combine signals. Orchestration does not remove the need for certified PAD and injection-attack detection in your stack. The only Zenoo numbers used here come from the metrics registry, and no detection-accuracy or catch-rate claim is attributed to Zenoo.
Zenoo does not detect deepfakes. It orchestrates the specialist detectors you choose, combines their signals into one decision, keeps a single immutable audit trail, and lets you swap a detector in under an hour as the threat moves. Book a demo: 30 minutes, your data, no slides.