Deepfakes in customer onboarding: When the camera lies

Is this person real? And are they who they claim to be? These questions mark the start of every digital customer relationship. Without modern deepfake detection, generative AI makes answering the questions above harder than ever. What businesses need now is reliable verification, not mere detection. As if identity is incorrectly verified during onboarding, everything that follows is worthless. 

 

The new threat landscape

AI can mimic faces, voices and even behavioural patterns with astonishing realism. The necessary tools are freely available and scalable, ranging from face swaps and fully synthetic faces to forged identity documents. There are two distinct types of attack:

  • Presentation attack: The camera is shown something fake – a photograph, a mask, or a pre-recorded deepfake video.
  • Injection attack: The camera is bypassed, feeding a synthetic video signal directly into the data stream. The verification system 'sees' a person who never sat in front of a device.

In its Guidance 02/2026, FINMA made it clear that AI-powered deepfakes pose a real threat to digital identification. Visual inspection alone is no longer enough: defending against deepfakes has become a clear supervisory expectation in regulated environments.

"We are seeing a rise in deepfake fraud attempts across our customer base. Compared to 2025, volumes in 2026 are nearly three times higher." Michael Born, CEO PXL Vision

 

From detection to verification

Any process that relies on an image looking genuine checks a characteristic that attackers can replicate at will. Modern identity verification therefore combines several independent layers of verification:

  • Document verification: verifies the security features of the identity document and reads the data automatically.
  • Passive liveness detection: ensures a real person is present in real time — without requiring any additional tasks from the user.
  • Biometric matching: connects the person present with their document.
  • NFC chip verification: provides government-signed biometric data — a proof that can be mathematically verified rather than relying on what a camera sees.
  • Injection, screen, and deepfake detection, along with anomaly and device analysis: uncovers injected or AI-generated content and identifies suspicious patterns.

No single method is infallible; the strength lies in combining them. As attackers continue to evolve, verification is not a product you buy once, but a process that requires continuous adaptation.

 

The PXL Deepfake Detector

A key layer of verification is the PXL Deepfake Detector. PXL Vision developed it in collaboration with the Idiap Research Institute as part of a research project funded by Innosuisse, the Swiss Innovation Agency. This AI-powered solution is integrated directly into the PXL Ident identity verification platform and is already live in production.

  • Detects core attack vectors: identifies face swapping, face re-enactment, and fully synthetic identities.
  • Utilises current AI research: including vision-language models that detect manipulations which escape traditional detectors.
  • Trained on balanced data: synthetic datasets ensure balanced coverage across gender, age, and skin tone for reliable results across all demographics.
  • Zero added friction: the verification process runs seamlessly in the background of automated onboarding without impacting the user experience.


Secure enough to pass - simple enough to convert

Every additional verification step risks drop-off. Conversely, an unusually high conversion rate is a red flag if security criteria are loose enough to let fraudsters slip through. Striking the right balance is essential: as much verification as necessary, as little friction as possible – depending on the risk of the transaction.

In future, the E-ID and the EUDI Wallet will complement this balance: anyone holding a state-issued wallet can verify their identity cryptographically in seconds. Since not everyone can or will have one from day one, a hybrid solution is needed: wallet where available, otherwise automated verification with a physical ID. Both paths lead to the same result: substantiated trust.

"We are fully prepared for first movers, supporting both the Swiss E-ID and the EUDI Wallet as document types from day one. Nevertheless, companies should adopt a hybrid strategy and continue to offer identification via traditional methods." Elmar Reif, CPO PXL Vision

 

Discover how secure verification builds true trust between humans and machines in the 'Identity First' whitepaper by our partner Airlock. Download for free now.

Want to know more about our digital identity verification solutions?

image