Language

31 Jul 2026 in Identity fraud

Why “AI Detected” Can Be Misleading for Identity Verification

Nikita Dunets

Vice President of Digital Identity Verification

The participation of AI software in the ID verification process is now a reality, and it’s our job as an IDV vendor to understand what exactly that implies.

Sometimes, very little. A customer may use browser translation or accessibility software to complete a form, and a company may never detect it.

But in other cases, AI software changes the evidence: a virtual camera may replace a live face with generated media, while automation can repeat identity attempts at machine speed. 

That’s why identity teams need clear rules for assistance, delegation, evidence integrity, and higher-risk actions. Simply put, a general AI policy is too blunt for the job.

Regula at GITEX AI Europe 2026

This article is based on Regula’s presentation at GITEX AI Europe 2026, where Nikita Dunets (Vice President of Digital Identity Verification) stressed the idea of “AI ≠ fraud”.

quote

If an AI agent translates the instructions or helps someone complete a field, I’m not interested in punishing the tool. Still, we must be sure that the evidence is genuine and the user authorized the action.

Nikita Dunets Vice President of Digital Identity Verification, Regula

Legitimate AI software has its place…

AI automation is becoming part of normal digital behavior, and we can even prove it.

As per Regula’s latest research “The New Shape of Identity Threats”, 87% of companies reported AI-assisted or automated actors attempting to interact with identity processes during the previous year.

69% also said AI-assisted tools were common in identity or authentication work.

The question is: how to manage it?

Take autofill, for example. An AI tool can read the name, date of birth, and document number from an ID the customer has chosen to submit, then place those details into the corresponding form fields. 

The customer then reviews the entries and completes the selfie or liveness check personally. This removes tedious typing and reduces transcription errors without changing the evidence behind the verification. Totally fair.

…until assistance turns into substitution

The real risk begins when AI supplies the face, the evidence, or the authority that should come from the customer.

A virtual camera, for instance, can feed generated or prerecorded media into a selfie check while presenting it as live camera output. In this case, even if face comparison returned a match, it would not matter anymore. The check has only proved resemblance, but not whether someone just uploaded a photo of a person who is not them.

quote

A face match is useful, but it cannot tell the whole story. We still need to know that a live person controlled the capture and approved the action.

Nikita Dunets Vice President of Digital Identity Verification, Regula

What’s more, AI agents are now clever enough to use valid customer data to request account recovery or change payout details without consent. Every field may be correct while the person behind the identity never approved the action.

In both examples, software has replaced something the business expected from the customer: live evidence in one case, authorization in the other.

Blanket blocking is possible, though undesirable

Once AI can replace evidence or act without consent, blocking every automated session may feel like the safest answer. However, a blunt rejection rule can block legitimate applicants, force repeated biometric requests, and create more support work.

What’s interesting is that the commerce sector is already testing a more precise response. Visa created its Trusted Agent Protocol to help merchants distinguish approved shopping agents from hostile bots, since both may reach a website through similar channels. Rather than asking an agent to behave like a human visitor, the protocol gives it a verifiable identity of its own.

When an approved agent sends a request, it attaches a cryptographic signature — tamper-resistant proof that the request came from an agent holding an approved key. The merchant or its bot-protection provider validates that signature against a trusted public key. A timestamp and unique code also help confirm that the request is fresh and has not been copied or reused.

quote

I think that’s a fair rule: if software acts for a customer, it should identify itself, show what it was allowed to do, and leave the person’s evidence untouched.

Nikita Dunets Vice President of Digital Identity Verification, Regula

Now, ID verification vendors cannot copy this payment protocol as is, but the principle travels well: authenticate the software, record its authority, and verify the source of the identity signals.

So how does IDV react?

Applied to an ID verification session, Visa’s general principle can lead to four different responses:

When AI…

The response is to...

Helps the customer understand instructions or complete a form

Continue with the usual identity checks

Acts for the customer within recorded permission

Limit the agent to the agreed task; return to the customer for biometric capture or final approval

Supplies or replaces a document, face or camera feed

Stop the capture; request fresh evidence through a trusted route or send the case to review

Runs many linked attempts

Rate-limit the activity, connect related sessions and investigate the pattern

These responses also depend on the company’s risk appetite. During a low-risk task, an authorized agent may be allowed to prepare or submit information within a recorded scope. But for a high-risk action (e.g., account recovery or payment approval), the company may refuse delegated identity evidence and accept only evidence captured directly by the end user. 

On top of that, biometrics specifically show why such separation is needed: 

  1. Face comparison tells us whether two faces resemble each other. 

  2. Liveness checks tell whether a live person participated. 

  3. Capture-source controls tell how the media reached the system.

Lastly, uncertainty also needs its own route. Another capture, a different verification method or human review may resolve the case without a hard rejection. That’s why teams should track abandonment, complaints and reversed decisions beside confirmed attacks. Otherwise, a strict policy can look effective while legitimate customers disappear from its reports.

How Regula IDV Platform fits

Regula IDV Platform does not claim to see every browser extension, translation product or AI assistant. However, even perfect visibility would only tell a company that software was present; It would not establish whether the software acted with permission or replaced identity evidence.

The solution brings together identity lifecycle management, document and biometric checks with liveness detection and injection attack prevention, automated decisions and external services. 

By doing so, it gives each company control over how the above recommendations can be applied. Teams can configure various checks, thresholds, agent permissions and review routes according to their risk appetite, use case and internal policy. Alternatively, they can start with preconfigured workflows and adapt them to their needs.

This way, a company can:

  • Keep the usual checks for routine onboarding.

  • Request stronger proof before account recovery or payment approval.

  • Send uncertain cases to human review.

  • Keep each decision attached to the evidence and session history behind it.

And that turns AI ≠ fraud from a useful principle into something identity teams can apply session by session.

Have a Use Case? Let’s Explore.

Speak with our experts to see how you can speed up verification, reduce fraud, and stay compliant.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules