AI is making digital identity harder to trust.
Deepfakes can imitate a person’s face and voice. Stolen personal information can be combined with generative AI to support more convincing identity theft. Biometric systems can also be targeted with manipulated images, synthetic video, replay attacks, and other techniques designed to make a fake identity appear real.
As a result, digital identity verification can no longer rely on a single signal such as a face match, voice, password, security question, or video call. Organizations increasingly need to verify not only who someone claims to be, but also whether that person is real, whether the biometric data is genuine, whether the device and communication channel can be trusted, and whether an AI agent has actually been authorized to act on someone’s behalf.
In this episode of Edly Spotlight, we discuss these challenges with Burak Sahin, an independent advisor and global biometric expert with more than 25 years of experience in identity verification. Sahin explains how AI is changing identity theft, biometric authentication, deepfake detection, liveness detection, remote identity verification, and the emerging problem of AI agents acting for humans.
His central argument is that identity verification is becoming a layered trust problem. Biometrics still matter, but they increasingly need to work alongside liveness detection, device security, provenance, transaction risk, and stronger authentication.
This article explains what digital identity and identity theft mean in the age of AI, the biggest risks organizations now face, and what Sahin believes businesses should do to build more trustworthy identity systems.
What Is Digital Identity?
Digital identity is the collection of information, credentials, attributes, and digital signals used to establish who a person is online. It can include basic personal information such as a name or date of birth, but modern identity systems increasingly rely on stronger signals such as passwords, devices, identity documents, facial biometrics, fingerprints, behavioral patterns, and authentication credentials.
For businesses, digital identity is what allows a system to answer a basic question: Is this person really who they claim to be?
AI is making that question significantly harder to answer.
What Is Identity Theft?
Identity theft occurs when someone obtains and uses another person’s personal or identifying information without authorization, typically to impersonate them, access accounts, commit fraud, or obtain services or financial benefits.
Traditionally, identity theft might involve stolen passwords, payment information, government-issued identifiers, or personal data obtained through phishing or data breaches.
AI expands the problem because attackers can now potentially reproduce more than information. They can imitate characteristics that people and systems associate with identity, including a person’s face, voice, writing style, or appearance on a video call.
That means organizations increasingly need to protect not only identity data, but also the signals they use to determine whether an identity claim is genuine.
Why Is Digital Identity at Greater Risk in the Age of AI?
Generative AI has lowered the barrier to creating convincing impersonations.
A fraudulent identity attempt may combine stolen personal data with an AI-generated face, cloned voice, manipulated video, or synthetic identity document. Attackers may also attempt to inject manipulated media directly into identity-verification systems rather than presenting a fake physically in front of a camera.
As a result, several signals that once created confidence are becoming less reliable on their own:
- Knowing someone’s personal information does not necessarily prove identity.
- Recognizing someone’s face does not necessarily prove they are present.
- Hearing someone’s voice does not necessarily prove they are speaking.
- Seeing someone on a video call does not necessarily prove the video feed is authentic.
- An AI agent knowing information about a person does not necessarily mean it has permission to act on that person’s behalf.
This changes the challenge from simply matching an identity to establishing whether the person, biometric sample, device, communication channel, and authorization behind an interaction can all be trusted.
What Burak Sahin Says About Identity Verification in the AI Era
This is where Burak Sahin’s perspective becomes particularly important.
Across our conversation, Sahin argues that businesses can no longer treat identity verification as a single biometric match or authentication check. As AI makes individual identity signals easier to reproduce, organizations need multiple independent layers of trust.
In his view, that means looking beyond whether a face matches a stored record and asking additional questions: Is the person genuinely present? Is the biometric sample authentic? Where did the image or video come from? Can the device and capture process be trusted? And if software is acting on someone’s behalf, has that action actually been authorized?
The result is a broader approach to digital identity built around biometrics, liveness detection, device security, provenance, contextual risk, and stronger authentication.
That shift from simply recognizing someone to establishing trust across the entire identity interaction — is one of the central themes of our conversation.
AI Has Changed What It Means to Verify Someone’s Identity
Biometric verification was once associated primarily with government, law enforcement, and high-security environments. Today, it is part of everyday digital life. We unlock phones with our faces. Banks verify customers remotely. Companies onboard employees digitally. Airports compare travelers against identity documents. Financial institutions authenticate transactions without requiring people to visit a physical branch.
That convenience has created enormous value But it has also created a much larger attack surface.
As Sahin explains, identity systems no longer need to answer only:
“Does this face match the person we have on record?”
They increasingly have to answer:
“Is this even a real person in front of the camera?”
“Detecting whether what we’re seeing is actually a human, as opposed to a spoof or mimicking some other human’s characteristics, has become also part of the equation.”
That distinction matters because AI has made it dramatically easier to reproduce the signals organizations traditionally relied on for trust. The implication for businesses is important: matching identity is no longer enough. You also need to verify authenticity.
Better AI Improved Biometrics And Made Attacks More Powerful
One of the most interesting parts of Sahin’s perspective is that the same technological progress responsible for stronger biometric systems also helped create their newest threats.
Between roughly 2014 and 2018, advances in deep learning dramatically improved facial recognition. Face recognition moved closer to biometric modalities that had historically been considered more accurate, including fingerprints and iris recognition.
That made facial verification far more practical for consumer products because practically every smartphone already had the necessary sensor: a camera.
But there was a tradeoff. The machine learning techniques improving facial recognition were also making synthetic images, cloned voices, and manipulated video more convincing.
As Sahin puts it:
“The same technological underlying frameworks that pretty much propelled this advancement is, on the other side of the coin, also helping fraudsters pretty much produce viable material as easily.”
That creates an uncomfortable reality for security teams.
AI is improving both sides of the identity arms race.
Organizations benefit from better recognition models, but attackers benefit from better generative models.
The competitive advantage therefore no longer comes simply from having an accurate face-matching algorithm. It comes from building a broader identity architecture around it.
Live Deepfakes Turn Video Calls Into an Identity Theft
For many people, “deepfake” still means a manipulated video uploaded to social media.
That mental model is already outdated. One of the biggest risks Sahin highlights is the ability to manipulate identity during a live interaction.
A person can join a video call while software alters their appearance to resemble somebody else. Their voice can also be modified or cloned. The person on the other side may therefore believe they are speaking with a colleague, executive, customer, or authorized individual when they are actually communicating with someone entirely different.
Sahin explains:
“I can talk to you, but you would think I’m somebody else.”
For businesses, this means video itself can no longer automatically be treated as proof.
That matters for situations such as:
-
approving financial transactions,
-
confirming sensitive business instructions,
-
remote employee onboarding,
-
executive communications,
-
customer support,
-
account recovery,
-
remote KYC,
-
and high-value purchases.
The lesson is not that businesses should stop using video.
It is that visual familiarity is no longer an authentication method.
A recognizable face and voice may create confidence, but they should not create authorization.
The Bigger Threat Is Not Always the Deepfake Itself
Another useful distinction Sahin makes is between a deepfake and the mechanism used to deliver it. Attackers do not necessarily have to fool a camera by physically presenting something fake in front of it.
They can attack the technology stack itself. One example is an injection attack.
Instead of allowing a phone or computer camera to provide the genuine live feed, an attacker can attempt to hijack the capture process and inject a different video stream. That changes how organizations need to think about identity security.
It is not enough to ask:
“Does this image look real?”
Security teams also need to ask:
“Where did this image come from?”
That includes signals such as device integrity, capture method, source provenance, metadata, application permissions, and the path the media took before reaching the verification system.
Sahin summarizes the idea well:
“Identity is a big composite picture. We can’t be good at just one part of it. We have to be good at all parts of it.”
For organizations designing identity systems, this may be the most actionable lesson from the conversation. Trust should come from multiple independent signals not one highly accurate algorithm.
How Deepfake Detection Actually Works
If generative AI can create increasingly convincing fake media, how can organizations detect it? One approach he describes is surprisingly intuitive.
To identify deepfakes, detection systems can be trained on both authentic content and artificially generated content. Organizations do not have to wait for attackers to produce examples. They can generate deepfakes themselves, analyze the artifacts they create, and continuously improve their detection models. The goal is similar to biometric recognition: teach the system to distinguish between categories with increasing reliability.
But visual analysis is only one part of the process.
A stronger system can combine:
-
characteristics inside the video,
-
signs of manipulation,
-
device-level security information,
-
media provenance,
-
capture metadata,
-
application behavior,
-
and other contextual signals.
This means businesses should think beyond deepfake detection software as a standalone tool.
The better question is: How many independent reasons does our system have to trust this interaction?
The more trustworthy signals agree with each other, the harder it becomes for an attacker to successfully fake the entire identity chain.
Liveness Detection Is Becoming Essential for Remote Identity Verification
Deepfake detection sits within a broader challenge: determining whether the person interacting with a system is genuinely present.
This is where liveness detection, also known in standards terminology as presentation attack detection, becomes important. A biometric system may correctly determine that an image resembles a customer but organizations increasingly need another layer that asks whether the biometric sample was captured from a real, present person rather than from manipulated or replayed media.
That distinction is particularly important for non-proctored digital experiences.
Think about remote banking. There may be no employee physically watching the customer. The entire identity decision may happen through a phone.
If the system is going to approve an account, transaction, application, or identity claim automatically, it needs greater confidence that the biometric data it receives is genuine.
For product and security teams, the benefit of strong liveness detection is therefore not simply “better fraud prevention.” It enables organizations to safely move more identity processes online without requiring expensive manual verification.
The Next Identity Challenge Is Not Human; It Is AI Agents
The most forward-looking part of the conversation comes when Sahin turns from humans pretending to be other humans to AI agents acting on behalf of humans.
AI agents are increasingly capable of performing tasks such as:
-
booking flights,
-
scheduling appointments,
-
making purchases,
-
interacting with customer service,
-
comparing financial products,
-
and completing multi-step workflows.
That creates a new kind of identity problem. An AI agent can know plenty about you. It may know your name, address, birthday, travel preferences, payment information, calendar, or account details. But knowing information about you does not prove it has permission to act for you.
As he explains, identity has traditionally been built around three categories:
What you know. What you have. What you are.
An AI agent may have access to the first two. The difficult part is establishing a trustworthy connection to the third. That means the future of AI-agent security may depend heavily on delegated authorization.
An organization needs confidence not only that an agent knows who you are, but that you explicitly authorized that agent to perform a particular action.
Risk-Based Authentication Could Make AI Agents Safer
Not every action performed by an AI agent requires the same level of verification. That gives organizations an opportunity to apply risk-based authentication rather than making every interaction equally difficult.
He gives a useful example.
If an AI agent books a free event ticket, additional identity verification may provide little value. But imagine that same agent is about to purchase a $5,000 non-refundable airline ticket. That transaction carries far greater risk. Before completing it, the system could send a notification to the user asking for biometric confirmation.
The AI agent handles the workflow. The human authorizes the consequential action. That model could become increasingly important as businesses deploy autonomous agents. The goal is not to force humans back into every step.
It is to put human verification at the moments where mistakes or unauthorized actions would be costly. For companies building agentic AI products, this creates a useful design principle:
Automate the workflow. Authenticate the risk.
Why Security Questions Are Becoming Less Useful
AI is not the only reason identity systems need stronger authentication. Traditional knowledge-based authentication has been weakening for years.
Security questions such as your birth date, former address, family information, or other personal details rely on the assumption that those facts are secret.
Increasingly, they are not. Large data breaches, social media, public databases, and stolen identity records have made personal information far easier to obtain.
He notes that standards organizations have been cautioning against excessive reliance on knowledge-based authentication for years. That matters even more in the AI era. An AI-powered attacker can potentially aggregate publicly available and leaked information far faster than a human attacker manually researching a target.
So if an organization’s identity strategy still depends heavily on “something only the real person should know,” it may be relying on an assumption that no longer holds.
What National Digital Identity Systems Teach Us About Scale
Sahin’s perspective is shaped by work on identity systems that operate at an unusually large scale. He has been involved with biometric identity initiatives connected to countries including Mexico, India, and Indonesia.
These systems illustrate why digital identity is not simply a cybersecurity feature. It can also become infrastructure. A robust identity system can help governments deliver services to citizens who previously struggled to prove who they were.
Biometrics can reduce duplication, simplify access to benefits, and help services reach people living far from physical government offices. The same principles are increasingly relevant to private companies.
Whether an identity platform needs to support ten thousand users or hundreds of millions, organizations eventually confront similar questions:
- How accurate must the system be?
- How should false matches be handled?
- How much friction will users tolerate?
- Which biometric modalities make sense?
- What happens when verification happens remotely?
- How should liveness be incorporated?
- And how does the system respond as fraud techniques evolve?
There is rarely one universally correct answer. The architecture has to reflect the risk of the transaction and the consequences of getting identity wrong.
What Businesses Should Take Away
AI is not making digital identity irrelevant. It is making strong digital identity more valuable.
For organizations building AI products, financial platforms, authentication systems, marketplaces, government services, or digital onboarding experiences, several lessons stand out:
-
Do not rely on a face or voice alone. Generative AI makes both increasingly reproducible.
-
Treat identity as a collection of signals. Biometrics, liveness, device integrity, provenance, behavioral signals, and transaction context work better together.
-
Design authentication around risk. A low-value action should not require the same friction as a high-value, irreversible transaction.
-
Prepare for AI agents as identity actors. Organizations will increasingly need to verify not only who a customer is, but whether software has permission to act for them.
-
Move beyond knowledge-based authentication. Personal information is becoming easier for both human attackers and AI systems to obtain.
-
Build security that can evolve. Deepfake techniques will improve, so identity architecture needs to accommodate new detection and authentication layers rather than depend on one permanent defense.
The bigger lesson is that the question is changing.
For years, digital identity systems asked:
“Are you the person you claim to be?”
Now they increasingly need to ask:
“Are you real, are you authorized, can we trust the channel you are using and if an AI agent is acting for you, did you actually give it permission?”
That is a much harder problem. But it is also an opportunity.
Organizations that build strong identity infrastructure now will be better positioned to automate more processes, deploy AI agents more confidently, reduce fraud, and create digital experiences that customers can actually trust.
Watch the Full Interview
Watch the full conversation with Burak Sahin to explore how deepfakes, biometric authentication, digital identity verification, liveness detection, and AI-agent security are converging and what organizations need to do to prepare.
Frequently Asked Questions
What is digital identity?
Digital identity is the collection of information, credentials, biometric data, devices, and other signals used to establish who a person is online. It can include personal information, passwords, identity documents, facial biometrics, fingerprints, device information, and authentication credentials.
In the age of AI, digital identity systems increasingly need to verify not only who someone claims to be, but also whether the person, biometric sample, device, and communication channel can be trusted.
What is identity theft?
Identity theft happens when someone uses another person’s personal or identifying information without authorization to impersonate them, access accounts, commit fraud, or obtain services or financial benefits.
AI can make identity theft more sophisticated by helping attackers combine stolen personal information with cloned voices, synthetic images, manipulated video, or other forms of impersonation.
How is AI increasing the risk of identity theft?
AI can make it easier to create convincing impersonations using deepfakes, voice cloning, synthetic media, and automated analysis of stolen or publicly available personal information.
This means attackers may be able to imitate both what a person knows and how they look or sound, making traditional identity verification methods less reliable when used on their own.
How do deepfakes threaten digital identity?
Deepfakes can imitate a person’s face, voice, or appearance in video, making it harder to determine whether a digital interaction is authentic.
The risk is particularly significant in remote identity verification, video calls, account recovery, financial approvals, employee onboarding, and other situations where organizations may rely heavily on visual or voice-based confirmation.
Can biometric authentication be fooled by AI?
Biometric authentication can be targeted using synthetic images, manipulated video, replay attacks, spoofing, or other techniques designed to imitate a legitimate user.
This is why biometric matching alone may not be enough. Organizations increasingly need additional safeguards such as liveness detection, device integrity checks, media provenance, and contextual risk analysis.
What is liveness detection in biometric verification?
Liveness detection is the process of determining whether biometric data is being captured from a real, physically present person rather than from a photo, video replay, mask, synthetic image, or other spoofing method.
It is especially important in remote identity verification, where there may be no human employee physically present to confirm that the person interacting with the system is genuine.
What is the difference between biometric matching and identity verification?
Biometric matching determines whether a biometric sample, such as a face or fingerprint, matches a stored reference.
Identity verification is broader. It may include biometric matching, liveness detection, identity documents, device security, provenance, transaction context, and authentication signals to determine whether an identity claim can be trusted.
Why is a face match no longer enough for identity verification?
A face match can show that an image resembles the person on record, but it does not necessarily prove that the person is physically present or that the image itself is authentic.
AI-generated faces, manipulated video, replay attacks, and injection attacks can make a matching face appear legitimate even when the interaction is fraudulent.
What is a deepfake injection attack?
A deepfake injection attack occurs when manipulated or synthetic media is inserted directly into an identity verification process instead of being captured from a genuine camera feed.
Rather than trying to fool the camera physically, an attacker may attempt to interfere with the capture process and provide a fake video or image stream to the verification system.
How can businesses protect digital identity from AI-powered fraud?
Businesses can reduce risk by using multiple independent identity signals rather than relying on a single verification method.
A stronger identity architecture can combine biometrics, liveness detection, device integrity, media provenance, stronger authentication, behavioral signals, and transaction risk. The goal is to create several reasons to trust an interaction rather than depending on one highly accurate algorithm.
Are passwords and security questions still reliable for identity verification?
Passwords and security questions can still play a role in authentication, but they are becoming less reliable when used as the main proof of identity.
Personal information such as birth dates, former addresses, and family details may already be available through social media, public records, or data breaches. AI can also make it easier for attackers to gather and organize this information at scale.
How should companies verify users in the age of AI?
Companies should treat identity verification as a layered trust process.
Instead of asking only whether a user matches a stored identity, organizations should also consider whether the person is genuinely present, whether the biometric sample is authentic, whether the device can be trusted, where the media came from, and whether the action being requested is appropriate for the level of risk involved.
What role will AI agents play in digital identity?
AI agents create a new identity challenge because software may act on behalf of a real person.
An AI agent may know a user’s personal information, preferences, payment details, or account data, but that does not automatically prove that the user authorized the agent to perform a specific action.
Future identity systems may therefore need to verify both the human identity and the agent’s delegated authority.
How can businesses verify that an AI agent is authorized to act for a user?
Businesses may need systems that link an AI agent’s actions to explicit user authorization.
For low-risk tasks, minimal additional verification may be appropriate. For higher-risk actions, such as large financial transactions or non-refundable purchases, the system could require the user to provide stronger authentication or biometric confirmation before the action is completed.
What is risk-based authentication?
Risk-based authentication adjusts the level of identity verification according to the potential consequences of an action.
A low-risk activity may require little additional verification, while a high-value or irreversible transaction may trigger stronger authentication. This helps organizations balance security with user experience.
Will AI make biometric authentication obsolete?
AI is unlikely to make biometrics irrelevant, but it is changing how biometrics should be used.
Biometric verification can remain an important identity signal, but it is increasingly effective when combined with liveness detection, device security, provenance, contextual risk, and additional authentication methods.
What is the biggest digital identity risk created by AI?
One of the biggest risks is that individual identity signals are becoming easier to reproduce.
A face can be generated, a voice can be cloned, personal information can be stolen, and a video feed can be manipulated. As a result, organizations increasingly need to establish trust across the entire identity interaction rather than relying on one signal alone.
How is AI changing identity verification?
AI is changing identity verification in two directions. It can improve biometric recognition and fraud detection, but it can also help attackers produce more convincing synthetic identities, deepfakes, cloned voices, and manipulated media.
This creates an ongoing identity security challenge in which both defensive systems and fraud techniques continue to improve.
What is the future of digital identity verification?
The future of digital identity verification is likely to rely on layered authentication and multiple trust signals.
Biometrics, liveness detection, device integrity, media provenance, contextual risk, and delegated authorization for AI agents are becoming increasingly important as organizations try to distinguish genuine users from synthetic or manipulated identities.