Fraud Article
The enterprise defense: Why fighting AI fraud takes AI, not a better lock
By 2026, sophisticated fraud had evolved beyond identity itself, forcing organizations to confront a more fundamental challenge: Is there a real human behind this interaction at all?
Every fraud team eventually hits the same wall. You tighten the lock, the attacker upgrades the key. You add a liveness check, someone finds a way to stream a recorded face past it. You block emulators, the next batch of traffic comes from real devices with real, coached humans behind them.
That wall is the reason most identity defenses feel like they’re always one step behind: they were built to answer one question, and fraud has moved on to a different one.
The question changed
Identity verification has spent two decades answering three questions well: Who are you? Can you be trusted? Are you still the same person who enrolled? Document checks, biometric authentication, and KYC (Know Your Customer) screening were all built to answer those three.
In 2026, a new question forced its way into the conversation: is this a real, live person, or synthetic media, an automated agent, or a device that shouldn’t be trusted in the first place?
That question exists because the old assumptions about liveness broke down from two directions at once.
Synthetic media has caught up to plausible. AI-generated profile photos and stolen images can pass a casual glance without ever having been a live human in the first place. And a growing category of automated agents, bots and LLM-driven “buy-for-me” tools, now complete real transactions on real, authenticated user sessions. The account is legitimate. The action attached to it isn’t.
Device farms and emulated environments can also produce a “live” face without a live, trustworthy session behind it: coordinated fraud rings routinely spin up hardware and network signatures that look clean in isolation but tell a very different story once cross-referenced.
Two different failure modes. One shared root cause: they’re all invisible to a system tuned to detect a single signal.
AI-generated content is more convincing than ever. Test yourself with our free Deepfakes Quiz.
Why single-signal defenses keep losing
Most liveness and deepfake-detection vendors were built to win one comparison: is the face in front of the camera a real, live human, right now? That’s a hard problem, and plenty of vendors solve it well.
It’s also no longer the right problem to solve in isolation.
A single-signal check has no way to notice that the “live” face belongs to a device farm, or that the same session shows impossible location jumps, or that the media stream has the fingerprint of injection rather than a live camera feed. Each of those signals, alone, can look clean. Together, they tell a completely different story, and a defense architecture built around one signal structurally cannot see the other signals.
This is the core design problem with treating identity assurance as a checklist of discrete point solutions bolted together after the fact. Stacking separate tools for liveness, device fingerprinting, and behavioral analysis creates seams, and seams are exactly where coordinated fraud operations look for an opening. Fraud rings don’t attack the strongest layer. They attack the gap between layers.
The human eye was never a security control
There’s a version of this problem that fraud teams have historically leaned on without saying it out loud: if automated detection misses something, a human reviewer, or the end user themselves, will probably catch it on a second look.
Veriff partnered with Kantar on a large-scale survey across the US, UK, and Brazil in February 2026 to test that assumption directly, rather than debate it. The results should end the debate. Across markets, people scored an average of just 0.07 on a detection-accuracy scale where 0 represents a coin flip and 1 represents perfect accuracy, meaning the average person asked to tell a real visual from an AI-generated one is, in practical terms, guessing. Video was the hardest format to judge correctly: for one video pair in the study, 70% of respondents misidentified the fake as real.
It gets more concerning from there. Roughly half of US respondents said they’re confident in their ability to spot a deepfake, and confidence doesn’t reliably track with accuracy. Across markets, Veriff and Kantar identified a “high-risk” segment (people who detect fakes poorly, feel confident they wouldn’t be fooled, and rarely bother verifying suspicious content) at roughly 7% of users. That’s not a rounding error; at any meaningful volume, it’s a standing population of soft targets that fraud rings will keep finding.
As Ira Bondar-Mucci, Veriff’s Fraud Platform Lead, put it in the report: any organization still leaning on manual review or customer self-attestation is inheriting this vulnerability directly, because human judgment has become an unreliable safeguard on its own. The instinct many fraud teams have, that a second set of eyes on a flagged case adds a meaningful layer of protection, doesn’t hold when the eyes in question perform barely better than chance, and believe they’re doing much better than that.
Any organization still leaning on manual review is inheriting this vulnerability directly. Human judgment has become an unreliable safeguard on its own.
This isn’t an argument for removing people from the process. It’s an argument for putting them in the right place in it. The report’s own conclusion is that the strongest posture keeps humans in the loop at the decisions where judgment genuinely adds value, while automated detection carries the load of catching what the eye structurally cannot: exactly the design principle behind a layered, machine-evaluated architecture rather than a checklist a reviewer works through manually.
What a real multi-layered defense looks like
The alternative isn’t a better version of liveness. It’s collapsing detection into a single decision that considers everything the session has to offer at once. Veriff’s approach to this fuses multiple capability layers into one evaluation, running in a matter of seconds and requiring no document upload:
- Device and network integrity: fingerprinting the hardware and network path a session actually travels through, so emulators, jailbroken devices, and inconsistent hardware signals surface before biometrics are even evaluated.
- Injection-attack detection and action-based behavioral signals: action-based device, browser, and network analytics that catch pre-recorded or replayed media, and flag interaction patterns that don’t match a live, unscripted human.
- Video and image quality analysis: forensic-level scrutiny of the capture itself, built to catch the artifacts that AI-generated and manipulated media leave behind.
- Advanced passive liveness: confirming there’s a live human being in front of the camera at all, without adding friction to the capture flow.
- Crosslinking and velocity analysis: checking a session against patterns across the wider network, including whether this device, this document, or this behavioral fingerprint has shown up attempting to onboard under a different identity elsewhere.
None of these layers is sufficient alone. Together, they’re evaluated as one decision, not a set of separate pass/fail gates a fraud ring can probe individually.
If your team is currently stitching together separate vendors for these layers, talk to our fraud specialists about what a single-decision architecture would replace in your stack.
What a point solution can’t match, in concrete terms
The layered stack is the visible part. The harder part to replicate is what sits underneath it: cross-customer fraud signals and an identity graph built from a global base of verification sessions, accumulated over years, not quarters.
That’s what crosslinking actually depends on. A device or document pattern flagged in one customer’s session becomes a signal available across the network, not by sharing raw data between customers, but through data crosslinking that surfaces risk without exposing who else saw it. A point solution evaluating a single session in isolation has no equivalent. It can be excellent at its one job and still miss what a networked view would catch in seconds.
This is also why a defense built this way holds up as fraud patterns shift. Coordinated attacks evolve constantly: new tooling, new distribution channels, new ways of routing around a specific check. A system built around one signal has to be rebuilt every time attackers find the seam. A system built around a network of signals gets stronger with every session it processes, because each new pattern strengthens the graph the next detection runs against.
Where this actually shows up for a technical buyer comparing options:

None of this is a knock on liveness vendors doing liveness well. It’s the point: a buyer comparing Veriff to a point solution on liveness depth alone is comparing the wrong thing. The comparison that matters is one signal versus a decision built from several, running on a network a single-purpose tool has no access to.
Built for compliance, not just detection
A layered decision is only useful to an enterprise buyer if it’s also auditable. Every session evaluated through this architecture produces one documented decision, not several separate logs from several separate tools that a compliance team has to reconcile after the fact.
That matters concretely: Veriff’s infrastructure is built on ISO 27001 certification (via Schellman) and SOC 2, with configurable data retention by jurisdiction and privacy-by-design handling of the biometric data these checks depend on. For a Compliance Officer or DPO sitting in the same buying committee as a Head of Fraud, that’s the difference between adopting a new detection capability and adopting a new audit liability. The layered approach is designed to be the former.
What this looks like for your fraud team
Concretely, this shows up at the moments where risk actually concentrates in a product flow:
- Profile creation and periodic re-verification, where synthetic or stolen imagery needs to be caught before it ever reaches a live user.
- Sensitive transaction and authorization moments, where the question isn’t just “is this the right user” but “is this a device or network we’ve flagged before, or an agent completing an action a human should be completing themselves.”
- Account reactivation flows, where device and behavioral signals, not just a passing liveness check, determine whether the session belongs to the person it claims to.
For a Head of Fraud, the value isn’t a new dashboard. It’s fewer false positives arriving with lower confidence, because the underlying decision already synthesized device, behavioral, media, and network signals before a human ever needs to look at it. For an engineering team, it’s one integration and one decision object, not several vendor relationships to stitch together and maintain. For compliance, it’s a single audit trail instead of several.
Bringing the right tool to the fight
Legacy identity checks were built for a threat model where the hardest problem was confirming a face matched a document. That threat model is gone. The fraud you’re facing now is coordinated, AI-assisted, and built specifically to pass any single test you throw at it, because a single test is exactly what it was built to beat.
Matching that requires a defense that doesn’t ask one question. It asks several, at once, against a network that’s seen the pattern before, in a decision that lands in seconds and integrates in under a week.
If your current stack is still evaluating liveness, device signals, and behavior as separate problems, run a live traffic test against it. Book a demo to see the full layered architecture evaluate your actual sessions, or talk to our fraud team about migrating from a point-solution stack without a gap in coverage.