Skip to content
Vulnerabilities

Why AI-generated identities mean verification can no longer be a one-time check

By Harry Varatharasan, Chief Product Officer, ComplyCube Meta’s Muse Image tool briefly showed just how little it now takes to manufacture a convincing likeness of someone. For a few days in July, tagging a public Instagram handle was enough to generate a new AI image of that person – no consent req...

· Jul 27, 2026 · 8 min read · 👁 0 views
Why AI-generated identities mean verification can no longer be a one-time check

By Harry Varatharasan, Chief Product Officer, ComplyCube

Meta’s Muse Image tool briefly showed just how little it now takes to manufacture a convincing likeness of someone.

For a few days in July, tagging a public Instagram handle was enough to generate a new AI image of that person – no consent required, switched on by default, until Meta pulled the feature amid pressure from talent agencies, unions and privacy groups.

The privacy and consent story was the one that made headlines. But there’s a second story worth sitting with, and it is the one that should worry any business that verifies who its customers are.

Meta’s short-lived tool proved that a single public photo is all it takes to manufacture a believable likeness of someone – and a believable likeness is precisely how you circumvent the question: does this photo match that face?

That question has quietly underpinned a huge amount of digital onboarding for a decade. It no longer holds.

Not because verification itself is broken, but because the assumptions behind how most organisations deploy it are increasingly out of step with how fraud actually works.

The uncomfortable conclusion is that identity can no longer be treated as something you confirm once, at the front door, and then trust indefinitely.

A matched face is not a real person

The first thing worth being precise about is that face-matching and liveness are not the same control, even though they are often bundled together and sold as one.

Face-matching answers a narrow question: do two images appear to be the same person? Two images can pass that test – including a still lifted from a synthetic image, or even a deepfake video – while there is no real human being standing in front of the camera at all.

What closes that gap is presentation attack detection and certified liveness: the controls that establish a genuine, live person is present at the moment of the check, rather than a replayed, printed or generated artefact.

Tools like Muse Image do not undermine face-matching so much as expose how little face-matching was ever meant to carry on its own.

If your verification stops at ‘the faces matchʼ, a good synthetic image walks straight through. The check has to prove liveness, not just likeness.

Watermarking is necessary, but it doesn’t stop downstream fraud

Meta’s response – its Content Seal watermark and detection tooling – reflects a correct instinct: these images need provenance.

But watermarking a synthetic image proves it was AI-generated after the fact. It does not stop the image being created in the first

place, and it does nothing to stop that image being used against a bank, an employer or a family member.

Provenance is only genuinely useful when it works in both directions. Labelling synthetic content is one half.

The half that actually protects people is establishing authentic provenance for real data – and that requires cryptographically secure watermarking implemented at the device and hardware level, not bolted on afterwards.

Only then can you build a trust list: a way of demonstrating that a piece of data came from a genuine, verifiable source rather than simply that some other piece of data was fake.

And even if you achieve that at the point of starting a commercial relationship, the problem does not end there. Fraud doesn’t only attack onboarding.

It intercepts customer interactions further downstream – payments, withdrawals, loan origination, transfers of ownership – and each of those moments needs to demonstrate the same level of assurance as the first one, without grinding legitimate business to a halt.

Provenance at the front door is worth very little if every subsequent high-value interaction is left unprotected.

Why verifying only at onboarding is now a liability

For years, the industry has concentrated its most stringent controls at a single moment: onboarding. That made operational sense when onboarding was the one point of real risk.

It no longer reflects where fraudsters are actually spending their effort.

Account takeovers are rising precisely because fraudsters have understood the shape of these defences. The heaviest scrutiny sits at account opening, and often around obviously high-value activities.

So the attack adapts. AI enables fraud at scale – and scale changes the economics. Low-value fraud, repeated across thousands of accounts, becomes cumulatively worthwhile, especially where the controls thin out after onboarding.

A verification model that assumes the risk was resolved at the front door is, in effect, telling attackers exactly where the soft interior is.

This is the structural point. Digital identity is not static. Devices change, behaviours drift, credentials get compromised, and legitimate accounts get taken over.

Treating identity as a one-off checkpoint – verify once, mark as safe, move on – bakes in a blind spot that adaptive, AI-enabled fraud is built to exploit.

What continuous identity assurance actually looks like

The alternative is not to bombard customers with repeated verification requests. Anyone who has been asked to re-verify mid-transaction knows how quickly that erodes trust and abandons carts.

Continuous assurance done properly is largely invisible – and that is the point.

It means continuously detecting and evaluating ancillary signals across every customer interaction, not only the ones that already look suspicious.

In practice, those signals are wide-ranging: commercial and transactional behaviour, device usage, cellular network characteristics, geolocation consistency, repeat biometrics, mobile and email risk indicators, and connections into data-sharing networks and trusted reference sources. Individually, any one signal is weak.

Layered together and evaluated continuously, they build a live, evolving picture of whether the person acting on an account is really the person who opened it.

Biometric reverification is a good example of a control that is badly undervalued here. A quick face authentication check at the point of a sensitive action – a large transfer, a change of details – confirms that the person enacting the transaction is the same person who onboarded, complete with liveness.

Many banking apps already use this for password resets, yet will wave through a substantial transfer without it. That is exactly the kind of gap continuous assurance is meant to close.

Practical controls that don’t punish legitimate users

The objection to all of this is always friction, and it is a fair one. But most of the highest-value signals can be tracked invisibly. Cross-referencing against trusted reference sources happens in the background.

Analysing behavioural and commercial patterns is seamless to the user. Done well, the legitimate customer notices nothing while the risk picture behind them is continuously refreshed – and the extra scrutiny is reserved for the moments and signals that genuinely warrant it, rather than applied bluntly to everyone.

The practical shift for banks, employers and regulated businesses is to stop thinking of verification as an event and start thinking of it as a property of the whole relationship – mapped end-to-end across the customer lifecycle rather than fragmented across teams and systems that each hold one piece of the picture.

The privacy and proportionality question is real

None of this is free of trade-offs, and it would be dishonest to pretend otherwise. Continuous monitoring raises legitimate questions about privacy, bias and proportionality, and they have to be answered rather than waved away.

Tracking consumer behaviour requires permission and a clear basis. There is also a genuine tension in anonymising behavioural analysis: doing so protects the individual, but it hampers the ability to act on behalf of a specific person at risk.

What it does preserve is the ability to identify trends and trigger organisation-wide protections, which is often where the greatest collective benefit lies.

The right posture is not maximal surveillance. It is proportionate, permissioned, signal-driven assurance – enough to protect people and institutions, designed from the outset to respect the people it is protecting.

Trust is a relationship, not a checkpoint

Muse Image itself didn’t last the week – Meta pulled it almost as fast as it arrived. Tools like Muse Image are still not an aberration; they are a preview.

Mainstream, easy-to-use generative tools that turn a single public photo into a convincing likeness are going to keep arriving, and each one hands fraudsters more free raw material.

The response is not to panic about any individual tool. It is to accept what they collectively make undeniable: a one-off verification at the start of a relationship is no longer a sufficient basis for trusting it throughout.

Whether it is a client, a supplier or a remote employee, the businesses that adapt will be the ones that treat identity assurance as continuous, layered and largely invisible – a live property of the relationship rather than a photo checked once and filed away.

The alternative is to keep guarding the front door while the fraud quietly moves i

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you