Faces, voices and behaviour have become powerful tools for proving identity online. Generative AI is making all three increasingly reproducible, forcing identity security to move away from single moments of biometric verification towards layered and continuous evidence of trust.
For years, one of the central ambitions of digital identity has been to replace weak knowledge-based authentication with something more closely connected to the person themselves. Passwords can be stolen, security questions guessed and one-time codes intercepted, while a face, voice or behavioural pattern appears considerably harder to reproduce. Artificial intelligence is beginning to change that assumption.
Synthetic faces can now be created convincingly, voices cloned from relatively small samples and live video manipulated in real time. The problem is no longer confined to crude photographs being presented to a camera. Attackers can increasingly construct an entire interaction that looks and sounds sufficiently like the person a system expects to see.
This does not mean biometrics have suddenly become useless. It means a biometric match can no longer carry quite as much trust on its own. That distinction is becoming increasingly important as identity providers, cybersecurity companies and researchers rethink what authentication needs to look like in an environment where many of the signals traditionally associated with a real human can themselves be synthesised.
When the fake person joins the call
The development is particularly visible in video. Researchers at Germany’s Fraunhofer Institute for Secure Information Technology are working on real-time detection of manipulated videoconferences, reflecting growing concern about fraud in an environment where employees routinely make consequential decisions through Teams, Zoom and similar platforms.
Fraunhofer points to a sharp increase in cases involving AI-generated video and voice impersonation and is developing technology capable of analysing live conferences for signs of manipulation while the conversation is taking place.
The problem is fundamentally different from identifying a manipulated video after it has been uploaded to the internet. Videoconferencing introduces inconsistent lighting, changing network quality, compression and limited image resolution, all of which make reliable detection considerably harder.
It also creates an immediate security decision. If someone who looks and sounds like the CEO requests a payment, access to sensitive information or an urgent change to a business process, identifying the deception tomorrow is not particularly helpful. Authentication increasingly has to work during the interaction.
The attack is moving inside the identity process
The same problem is appearing in digital onboarding and authentication. Traditional biometric defence has concentrated heavily on presentation attacks: photographs, masks, recorded video or other attempts to fool the camera or sensor. Liveness detection developed partly to establish that a real person was physically present rather than simply presenting a representation of one.
Generative AI has expanded the attack surface. A synthetic face or manipulated video can potentially be injected directly into an identity-verification workflow rather than physically presented to the camera. That has driven greater attention towards injection attack detection, which attempts to determine whether the data reaching the biometric system genuinely originated from the expected sensor and session.
CyberLink, for example, added injection attack detection to its FaceMe identity-verification technology in August, placing it alongside facial matching, presentation-attack detection and deepfake detection as separate layers of defence.
The architecture is revealing. Instead of assuming that one sufficiently sophisticated biometric check will establish identity, verification increasingly becomes a combination of signals attempting to answer slightly different questions.
Does the face match? Is a live person present? Has the image been synthetically manipulated? Did it genuinely originate from the device expected to capture it? That is a considerably richer definition of identity assurance than simply asking whether two faces look alike.
The problem with detecting the fake
There is also a more fundamental limitation to relying exclusively on deepfake detection. Generation and detection are engaged in a continuing technical competition. As generation improves, artefacts that detection systems previously relied upon disappear, requiring new methods of identifying manipulation. A detector that performs extremely well against today’s synthetic media therefore cannot automatically be assumed to perform equally well against tomorrow’s.
That is why researchers are increasingly arguing against treating deepfake detection as a single binary security control.
A recent IEEE Biometrics Council discussion on identity security in the age of deepfakes highlighted the complementary roles of biometric matching, liveness, presentation-attack detection and media forensics, arguing for layered, evidence-based and risk-aware authentication rather than a single “real or fake” decision. This is an important evolution in thinking.
If a sufficiently convincing synthetic person can eventually pass any individual test, security has to rely on several independent forms of evidence whose combined manipulation becomes progressively more difficult.
Identity becomes continuous
That logic is beginning to extend beyond the initial authentication event altogether. Most digital services still operate around a familiar model: prove who you are at the beginning, receive access, and remain trusted until the session ends or something obviously goes wrong.
AI-driven fraud makes that increasingly uncomfortable. An identity could be genuine when an account is created but compromised later. A legitimate user could authenticate successfully before an attacker takes control of the session. Behaviour may change during a transaction, or the level of risk may increase dramatically when a user moves from checking an account balance to transferring a large amount of money.
That is pushing identity security towards continuous or adaptive verification, in which the amount of assurance required changes according to what the user is doing.
Unico, for example, introduced a revalidation system this month that can move between background verification, passkeys and server-side facial biometrics depending on transaction risk. Ping Identity has similarly been arguing for what it calls “verified trust”, bringing identity verification, fraud detection and access management together so that trust can be reassessed throughout an interaction rather than established solely at login. Vendor terminology will inevitably vary, but the direction is becoming clear. Authentication is moving from an event towards a process.
Biometrics still matter
There is a temptation in discussing deepfakes to declare that biometrics have been defeated. That would be an overreaction.
A properly implemented biometric system remains capable of providing extremely useful evidence about identity. Liveness detection, sensor integrity, device binding and increasingly sophisticated anti-spoofing techniques make successful attacks considerably more difficult than simply generating a convincing face on a laptop.
But biometrics operate inside a wider trust architecture. A face can establish one form of evidence. A cryptographically protected credential can establish another. Possession of a trusted device, behavioural consistency, transaction context and risk signals can contribute further assurance. The important change is that none necessarily has to carry the entire burden alone.
This becomes particularly relevant as digital identity wallets, passkeys and verifiable credentials develop alongside biometric technologies. Strong digital identity may increasingly depend on combining evidence about who someone is, what they possess, where a credential originated and whether their behaviour remains consistent with the transaction taking place. Biometrics become part of the trust decision rather than the trust decision itself.
From proof of identity to evidence of identity
Generative AI therefore presents identity systems with something deeper than another fraud technique. Digital identity has traditionally attempted to establish reliable anchors in an environment where physical interaction is absent. Documents, faces, voices and behaviour became proxies for the person behind the screen. AI can now reproduce an increasing number of those proxies.
The response cannot simply be to keep inventing a better detector and assume the problem has been solved. Identity systems need to become better at combining independent evidence, recognising changes in risk and reassessing trust as interactions progress.
That does not take us beyond biometrics in the sense of abandoning them. It takes us beyond the idea that one biometric moment is sufficient proof of a continuing identity. As synthetic identity becomes more convincing, the future of authentication may depend less on asking whether a face or voice is real once, and more on continuously establishing whether the person, device, credential and behaviour still make sense together. That is a much harder problem.
It may also be where digital identity is now heading.




Leave a Reply