Synthetic Identities Are Passing Your Onboarding Checks
Generated faces, consistent document sets and live video that responds to challenges. KYC flows built for photocopy-era fraud are not holding, and the fix is behavioural rather than visual.

Onboarding fraud used to be caught on inconsistency: a face that did not match the document, a document that did not match the template, a selfie that did not blink. Generative tooling removed all three failure modes at once, and it did so at a cost per identity low enough for volume attacks.

What a 2026 synthetic identity looks like
- A face that exists nowhere else, so reverse image search returns nothing — which most systems score as a positive signal.
- A coherent document set: ID, proof of address and a bank statement that agree on name, address and dates.
- Liveness that responds. Turn your head, read this number, blink twice — all handled in real time by a driven avatar.
- A thin but plausible digital history: an email domain with age, a phone number with carrier history, a device that is not obviously fresh.
Why visual detection is the wrong hill
Every detector trained on generation artefacts is training on a moving target that improves faster than the detector ships. Vendors who sell only artefact detection are selling a subscription to a race they cannot finish. Detection still has a place, but it belongs low in the stack, not at the decision point.
What actually separates real from synthetic
1. History that cannot be generated
Cross-checks against sources that require years of real-world existence — credit-bureau depth, mobile-carrier tenure, address continuity — remain expensive to fake because they need time, not compute.
2. Behaviour during the session
Real applicants hesitate, correct typos, tab in human patterns and read. Automated flows are fast, precise and identical across sessions. Session behavioural telemetry catches farms far more reliably than face analysis.
3. Cross-application correlation
Individual synthetic applications look clean. A hundred of them share something: device fingerprints, timing distributions, address ranges, phrasing in free-text fields. Fraud detection has to run at the population level, not per application.
4. Risk-tiered outcomes
Not every account needs the same assurance on day one. Approve with limits, escalate verification when behaviour crosses a threshold, and reserve heavyweight checks for the accounts that reach for real value.
The organisational part
Fraud, security and product all own a slice of this and usually report separately. The teams that improved their numbers in 2026 did one boring structural thing first: they put onboarding fraud rates, verification cost and conversion in a single review with a single owner.
Stop asking whether the face is real. Start asking whether the history, the behaviour and the population pattern are.

