• 4 min read
Proof of personhood challenges document-based ID checks
Synthetic identities are defeating document checks. A multi-signal approach uses digital footprints, devices and behavior to verify real people.

Image: TechRadar
A valid government ID and a matching selfie no longer prove that a customer is a real person. Synthetic identities assembled with generative AI can pass those checks, remain dormant long enough to establish behavioral credibility, and then be used to defraud a platform.
Deepfake-enabled fraud caused more than $200 million in losses in the first quarter of last year, according to the source. The threat is no longer a theoretical stress test: synthetic identity fraud is becoming a routine operating condition for businesses that onboard customers digitally.
Why document-first verification falls short
Traditional identity verification focuses on whether a document is genuine, whether a selfie matches it and whether the name appears in a database. That process treats identity verification as a one-time event, leaving intent, behavior and the coherence of a user’s digital history outside the assessment.

Recommended reading
OpenAI’s rogue agent compromised four more accounts
The financial impact is growing. GenAI-enabled fraud losses in the U.S. are projected to reach $40 billion by 2027, up from $12.3 billion in 2023, representing a compound annual growth rate of 32%. On the dark web, scam kits capable of generating deepfake videos and synthetic documents sell for as little as $20.
Synthetic identities—fabricated profiles combining real and invented information—already account for 10% to 15% of charge-offs in a typical unsecured lending portfolio. The source argues that this makes the fraud a built-in cost of credit rather than an unusual edge case.
From KYC to proof of personhood
The proposed shift is from asking whether an ID is real to determining whether a real, unique human is behind the transaction. That assessment should continue across the customer lifecycle instead of ending at onboarding.
A convincing synthetic identity may pass optical character recognition, document authentication and liveness detection. What it struggles to reproduce is the accumulated context of a genuine person’s digital existence: email accounts registered with real services, phone numbers tied to consistent carriers, devices with histories across sessions and networks, and behavioral patterns shaped by normal product use.
None of these indicators is decisive by itself. Their combined presence—or absence—can reveal whether an identity has a credible history or was assembled recently.
How multi-signal assessment works
The source divides the approach into explicit and implicit signals:
- Explicit signals: eKYC and eID database checks compare user information with authoritative government records; document authentication validates submitted IDs; biometric liveness checks confirm that a person is present in real time.
- Implicit signals: Digital-footprint analysis examines email history, social activity and phone-number patterns. Device intelligence identifies anomalies in hardware and software environments, while behavioral signals flag interactions that differ from normal human behavior.
The benefit is cumulative. A fraudster can create one convincing document, but simultaneously manufacturing a years-old email address, a coherent social presence, a clean device fingerprint and natural behavioral rhythms is substantially more difficult. Layering signals raises the cost and complexity of fabricating the entire identity.
Cross-border identity verification
Multinational businesses also face fragmented identity systems and changing regulation. The European Union’s Digital Identity Wallet must be supported by all member states by December 2026. National eID programs are expanding across Asia, Africa and Latin America on different timelines and technical standards.
The World Bank estimates that 850 million people still lack official government identification. That makes broad digital coverage and inclusion central requirements, not just compliance concerns. eKYC and eID checks across national and regional schemes provide the baseline; the source says digital-footprint, device and behavioral signals are what help distinguish a genuine applicant from a synthetic one across jurisdictions.
Moving risk assessment before the ID check
The recommended architecture begins assessing risk before a customer presents a document. Early use of digital-footprint, device and behavioral data can filter synthetic identities before they reach expensive verification steps, while legitimate users may clear faster because the system already has context.
That requires fraud, identity verification and anti-money-laundering functions to share a unified data environment rather than operate in parallel. The source does not provide a release date, product announcement or independently verified benchmark for this approach; it presents proof of personhood as an operational model for organizations responding to synthetic identity fraud.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


