Skip to content Skip to footer

By 2026, 30% of companies will consider biometric verification systems unreliable when used in isolation. Deepfake attacks have grown by 200% in one year. How KYC changes when fraudsters use the same AI as defense systems.

KYC -- Know Your Customer -- is one of the most regulated and most expensive processes that companies in the financial, insurance, and digital services sectors must manage. Collecting identity documents, verifying them, matching them to a real face, cross-referencing data against anti-money laundering watchlists: until a few years ago, all of this required hours of manual work for each new customer. AI changed the equation, dramatically reducing time and costs. But it also created a new problem: the same technologies that accelerate verification are being used to forge it.

The thirty percent that changes everything

In February 2024, Gartner published a prediction that redefined the scope of the problem: by 2026, attacks using AI-generated deepfakes against facial recognition systems will lead 30% of companies to consider their biometric-based identity verification and authentication systems unreliable when used in isolation.

Akif Khan, VP Analyst at Gartner, clarified the nature of the risk: organizations will no longer be able to distinguish whether the face presented during verification belongs to a real person or a deepfake. Presentation attack detection systems, designed to verify a person's physical presence, do not cover injection attacks, where a synthetic image is inserted directly into the data stream before it reaches the analysis system. Current standards and testing processes, according to Gartner, were not designed for this type of attack.

Injection attacks have grown 200% in one year

The data point accompanying this prediction is equally significant: Gartner found that injection attacks grew by 200% over the course of 2023. This is not an emerging phenomenon in an experimental phase: it is already an operational threat for any organization that uses facial biometrics as a component of its onboarding or authentication process.

The technical response requires a combination of three layers of defense: presentation attack detection for traditional physical attacks, injection attack detection for digital attacks, and image inspection to identify anomalies in synthetic content. None of the three is sufficient on its own. Gartner explicitly recommends selecting vendors that demonstrate capabilities across all three fronts, with a continuous update plan as attack techniques evolve.

Deepfakes are already inside companies

The problem does not only concern customer onboarding processes. In a survey conducted between March and May 2025 of 302 cybersecurity leaders, Gartner found that 62% of organizations experienced a deepfake attack involving social engineering or the exploitation of automated processes in the past twelve months. 43% reported at least one incident in an audio call, 37% in a video call.

A separate survey conducted in 2024 of 456 CEOs and other senior executives found that 62% believe deepfakes will create at least some operational costs and complications for their organizations over the next three years. Risk awareness at the executive level is already present. Response capability, in many cases, is still being built.

Gartner describes deepfakes as a threat that has reached the mainstream phase for phishing, social engineering, and impersonation. Attacks on GenAI application infrastructure and prompt-based manipulations are still in the emerging phase but growing: 29% of cybersecurity leaders reported that their organization experienced an attack on enterprise GenAI application infrastructure in the past twelve months.

Five areas where KYC creates value beyond compliance

The Magic Quadrant for Identity Verification, published by Gartner in August 2025, identifies five areas where identity verification delivers concrete value for organizations. The first is regulatory compliance, with KYC and AML obligations requiring identity verification before establishing any business relationship, particularly in the financial sector. The second is onboarding, for both customers and employees, including remote workers. The third is account security, with verification used for credential recovery and access management. The fourth is fraud prevention, with the detection of stolen or synthetic identities and the protection of high-risk transactions. The fifth is trust and safety in digital marketplaces, portable identity networks, and the gig economy.

This classification is relevant because it shifts the KYC conversation from pure compliance toward business value. A well-designed identity verification process is not just a regulatory requirement: it is a factor that directly influences onboarding quality, registration abandonment rates, and the ability to detect fraud before it causes damage.

The arms race between offensive and defensive AI

The Gartner Hype Cycle for Fraud and Financial Crime Prevention 2025 describes the current situation as an arms race: fraudsters use GenAI to create fake identities and automate attacks, while banks and defense organizations use advanced machine learning models to detect anomalies, retrain systems, and develop synthetic data for secure training of detection models.

Static identity controls have become insufficient. Organizations are moving toward behavioral biometrics, which analyzes gestures, keystroke patterns, and device usage patterns to identify fraud and support continuous authentication throughout the entire session -- not just at the initial login. Device intelligence, which detects anomalies such as the use of emulators, compromised devices, or geographic discrepancies, is also becoming a standard component of KYC and AML flows.

The result is that modern KYC is no longer a single point-in-time check, but a continuous process that accompanies the entire client relationship. Every transaction, every access, every behavioral change becomes a signal that the system can evaluate to update the risk profile in real time.

What organizations must do today

Gartner outlines three operational directions for security and risk management leaders. The first is to combine presentation attack detection, injection attack detection, and image inspection: none of the three technologies is sufficient on its own against current threats. The second is to add additional risk signals such as device identification and behavioral analysis, to increase detection capability for attacks on verification processes. The third is to select vendors that demonstrate they monitor, classify, and quantify new types of attacks, with an explicit plan to evolve their capabilities beyond current standards, which Gartner considers already inadequate against the threats available today.

Automating KYC with AI remains a valid objective: it reduces onboarding time, lowers operational costs, and improves process consistency. But it requires a level of defense sophistication that many current implementations have not yet achieved.

Close
Close