For most of the digital era, identity verification has rested on a simple premise: if a credential looks authentic and the person presenting it matches the photo, we can reasonably trust them. This worked well enough when forgery required skill, equipment, and time. That premise is now failing.
Generative AI has made it possible to produce synthetic faces, forged documents, and cloned voices at a quality and scale that overwhelms conventional verification.
Earlier this month, a breach at Infutor, a consumer identity data management firm, exposed 676 million identity records in the United States. Not financial records. Identity records — the kind of data that makes impersonation straightforward.
These are not isolated incidents. They represent a structural shift in the threat landscape. And the response from most of the industry has been to invest in better detection: more sophisticated liveness checks, deeper biometric analysis, AI trained to catch AI. That response is understandable. It is also insufficient.
The detection dilemma
Detection-based approaches face a fundamental asymmetry. Every improvement in detection capability trains the next generation of synthetic media to evade it. This is not a temporary gap — it is an inherent property of adversarial systems. The attacker only needs to succeed once. The detector must succeed every time.
Gartner quantified this trajectory in a recent forecast: by the end of 2026, 30% of enterprises will no longer consider face-based identity verification reliable in isolation. That finding does not mean biometrics are useless — it means they are no longer sufficient as a standalone trust signal.




The deeper issue is that most identity verification was never based on cryptographic proof to begin with. It was based on visual resemblance and document inspection — methods designed for in-person interactions, adapted imperfectly for digital environments. AI did not create this vulnerability. It revealed the extent to which digital identity was still running on analog assumptions.
A different verification model
There is an alternative, and it is already in deployment at meaningful scale.
Verifiable credentials are digital documents cryptographically signed by the institution that issued them — a government, a university, an employer. When someone presents a verifiable credential, the verification is a mathematical operation: does this signature match the issuer’s public key? Has the credential been revoked? Is it within its validity period?
These questions have deterministic answers. They do not depend on visual inspection, pattern matching, or probabilistic AI models. A deepfake is irrelevant to a system that never looks at a face.
This model also addresses a second problem that detection cannot: data minimization. Through selective disclosure and zero-knowledge proofs, a holder can prove specific attributes — “I am over 18,” “I hold a valid medical license,” “I am a resident of this jurisdiction” — without revealing the underlying data. This reduces the attack surface not just for fraud but for data breaches. You cannot steal what was never transmitted.
Where this is happening
The European Union’s eIDAS 2.0 regulation requires all 27 member states to offer citizens a digital identity wallet by December 2026. The reference implementation is already in testing, with support for credential issuance, online and offline presentation, and qualified electronic signatures.
In the United States, 18 departments of motor vehicles have deployed standards-based mobile driver’s licenses to over 5 million citizens, built on ISO/IEC 18013-5.
In Latin America, several governments have moved further. The state of Nuevo León in Mexico deployed verifiable digital identity across its public services, achieving an 80% reduction in processing time and a 30% reduction in bureaucratic burden. The province of Salta in Argentina issued verifiable digital credentials to 1.4 million citizens, transforming access to health, education, and administrative services — including for communities where the nearest government office was hours away by road. The municipality of Luján de Cuyo digitized over 100 services in months, reducing requirements by 66% and case resolution time by 45%.
From the team
We study and build identity infrastructure every day. This newsletter is where we share what we’re learning — for anyone working in identity, public services, or trust infrastructure who wants to understand where this is going. If you found this useful, share it with a colleague.
If you’re new here: Start with What Happens After a Verifiable Credential Is Issued? for the technical foundation, or listen to our latest podcast with Pedro Alessandri on QuarkID for a real deployment story.
One link worth reading
Deepfake Financial Fraud: The Global Regulation of AI-Driven Scams — Columbia Institute of Global Politics & Data & Society Research Institute. A thorough policy brief on the scam ecosystem, who enables it, and why liability needs to shift from individuals to institutions. The most complete framing of the problem we’ve seen this year.
The Identity Brief is published by Sovra. We build reusable identity infrastructure for governments and citizens across Latin America.






