Identity Verification: When Generative AI Passes Identity Checks

Synacktiv, a cybersecurity consultancy specializing in offensive security, has dealt a hard blow to the credibility of “proof of life” measures used online.

In a recent study, researchers Kevin Tellier and Léo Desmonts demonstrate that it is possible to fool automated checks designed to ensure that a user meets the age criteria required to access certain content, using generative video AI models that are openly accessible to the public.

To illustrate the flaw, the researchers chose a sensitive use case: age verification on an adult video site. This category has, since France’s law of May 21, 2024, become subject to an obligation to verify visitors’ ages or face blocking by ARCOM.

Read also: Stolen data: a new fuel for an underground economy

The site under test relied on the British service AgeGo, which itself delegates biometric analysis to AWS Rekognition, the hyperscale provider’s facial-recognition component widely used for its liveness-detection capabilities.

The verification principle looks simple on the surface: the user must film their face with a webcam and follow a “challenge” (for example, moving the head back and forth) to prove that they are a real person and not a photo or pre-recorded video.

That is precisely the lock that the Synacktiv researchers managed to bypass. By leveraging a Linux driver (v4l2loopback) that can create a fake virtual webcam, they substituted their own face with an AI-generated video, produced from a single identity photo and artificially aged by an AI model to appear adult.

The whole setup, combined with a generative video model capable of animating this reference image, faithfully reproducing the head movements required by the challenge. Result: the verification was accepted by the algorithm, granting access to the site.

Highly Effective Video AI Tools

What stands out in the demonstration is the accessibility of the means used.

The researchers used open-source models such as Wan2.2 Animate (developed by Alibaba) or cloud solutions like Kling, operated via the ComfyUI interface. A simple server equipped with a consumer-grade graphics card sufficed to generate, in minutes, videos realistic enough to bypass the checks.

Unlike the traditional deepfakes that swap faces (face-swapping) and require lengthy training and often leave visible artifacts (edges, distortions), these new generative models animate directly a reference image from a motion mask extracted from a source video. No prior training step and a rendering that is much more convincing.

Admittedly, everything is not perfect. The researchers note that eye and mouth movements remain occasionally imperfect. But in the tested scenario, the purely algorithmic verification did not hold up.

For obvious legal reasons, the demonstration focused on an adult site.

Nevertheless, these video-based biometric verification technologies today underpin digital identity, the opening of online banking accounts, electronic signatures, and anti-fraud and anti-money-laundering (AML-CFT) measures.

A Challenge That Reaches Beyond Adult Sites

In France, the PVID (Remote Identity Verification Provider) framework from ANSSI governs these sensitive uses, aligning with the European eIDAS regulation.

This framework distinguishes a “substantial” level, already applied by four certified operators (Docaposte IOT, IDnow, NjF Vision, Namirial), and an “elevated” level reserved for the most binding acts, such as qualified electronic signatures.

The researchers also emphasize that human verification, intended as a final safeguard in case of doubt, is not foolproof either.

Operator fatigue, cognitive biases, and high processing throughput in verification centers… all of these factors can allow a spoofed video to slip through. Even more so, the realism of recent deepfakes can deceive a non-expert eye, especially when image quality is degraded.

Synacktiv calls for a rapid adaptation of detection methods.

Frameworks like PVID are regularly updated, with ANSSI incorporating new threats identified during audits.

But the study suggests that the remedy could, paradoxically, come from AI itself. The researchers mention the possibility of detection systems based on generative models capable of spotting artefacts invisible to the human eye. Or increased use of third-party digital identity services like Yoti.

In the meantime, Synacktiv’s demonstration highlights an uncomfortable reality for all digital actors. As generative AI grows more realistic, the trust placed in a video—a cornerstone of many security measures—becomes a vulnerability in itself.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.