By: Joe Ferrigno, Director of Global Safety and Security at Identy.io
A border agent goes about their day, inspecting travel documents and cargo, enforcing customs and immigration laws, identifying prohibited goods and responding to security concerns. A traveller approaches with a legitimate-looking passport, along with a digital identity verification completed pre-arrival that also appears authentic.
As part of the pre-arrival identity verification process, the traveller was required to take a photo or record a selfie video showing them turning their head and blinking. What the agent can’t see is that a fraudster used stolen biographic information, an AI-generated face and manipulated a camera feed to create a convincing but entirely fabricated interaction to spoof the digital identity verification process. Seeing no reason to doubt what’s been presented, the agent could allow this person to cross a border without actually knowing who they are.
This exact scenario is why traditional identity verification methods are no longer sufficient on their own. Ultimately, trusted identity verification depends on the individual presenting their own live biometrics in real time. AI can generate convincing evidence, but it can’t replace the person themselves. In an environment where almost anything digital can be fabricated, trust starts with the individual. No document, photograph or transmitted video can replace the person it claims to represent – you are the only real key to your own identity.
Traditional Means of Verification are Becoming Rapidly Outdated
Historically, border inspection depended heavily on an officer’s ability to evaluate physical evidence: Does the passport contain the correct security features? Has the photograph or biographic page been altered? Does the traveller resemble the person pictured? Are the traveller’s answers consistent with the document and stated purpose of travel?
Originally, security features such as watermarks, specialised printing, laminates, holograms and machine-readable zones were one of the first steps that made physical documents more difficult to alter. In the 1980s, the International Civil Aviation Organisation’s (ICAO) Doc 9303 established international specifications for machine-readable travel documents, helping standardise how passports and other travel documents could be securely issued and inspected worldwide.
In the 2000s, agencies started using modern biometrics to support border operations. ICAO designated facial images as the primary global biometric for travel documents, and the US-VISIT program began collecting fingerprints and photographs from international travellers at designated air and seaports. It wasn’t until the mid-2010s that U.S. Customs and Border Protection (CBP) began testing facial recognition for departing flights before gradually deploying it across air, land and sea environments.
These methods continue to evolve as technology enables new ways for bad actors to commit fraud. Traditional fraud leaves physical or digital inconsistencies that officers and authentication systems are trained to detect, but generative AI changes the equation by creating highly convincing facial images and videos that may contain few obvious signs of manipulation.
Rather than merely forging documents, criminals can now manufacture the person presenting them.
Deepfakes Change the Border Identity Threat
In the modern environment, border agencies increasingly rely on digital visa applications, automated gates, mobile inspection systems and facial comparison to process travellers efficiently. While traditional methods have proven effective for verifying someone’s identity, they were largely designed to determine whether two pieces of evidence match, such as a live image and a passport photograph.
Modern deepfakes and injection attacks challenge that model by allowing criminals to manipulate evidence before it reaches the verification system. Europol recognises this threat and has warned that deepfakes could become a common tool for organised crime and has identified document fraud as a potential application of synthetic media.
Likewise, NIST’s updated Digital Identity Guidelines explicitly address injection attacks and forged media reflecting the growing importance of verifying the integrity of the capture process and the identity evidence itself. NIST’s Face Recognition Technology Evaluations (FRTE) have demonstrated that leading facial recognition algorithms can achieve near-zero false non-match rates in certain verification scenarios, making it increasingly important to ensure the biometric presented to those systems is authentic.
Injection attacks are particularly dangerous because the attacker doesn’t need to bypass a physical sensor. With these attacks, manipulated content is added into the data stream between the camera and the application. If a traveller presents a selfie during the visa application process, a virtual camera could replace the live feed with a deepfake constructed from a stolen passport photograph. The facial matcher receives a technically clean image that closely resembles the passport holder.
In this scenario, conventional liveness checks may fail because they examine the supplied video without verifying its origin.
Recent government testing also shows how identity verification defences are evolving. The U.S. Department of Homeland Security’s Remote Identity Verification Rally (DHS RIVR) evaluates technologies against presentation and injection attacks. Identy.io’s recent results included zero attack acceptance while also demonstrating strong transaction speed and user satisfaction, showing that security does not have to come at the expense of usability. The results reinforce the need for multiple, coordinated controls that establish trust in the document, biometric, device and the connection between them. As AI and other emerging technologies reshape the threat landscape, agencies need to protect the entire identity lifecycle, from enrolment to arrival, inspection and re-verification.
Layered Identity Assurance for the AI Era
The first layer of a modern identity verification process should authenticate the travel document and the person presenting it. This includes examining physical and digital security features, validating the electronic passport chip, verifying the issuing authority’s digital signature and comparing biographic information across authoritative sources.
Agencies need to confirm that the traveller is the rightful holder of the document rather than treating document authenticity as proof. A passport can establish an identity claim, but the individual is ultimately the key to providing it. Only the individual can validate that identity through a live biometric captured in real time.
Even when an electronic passport passes every chip and signature check, the system still has to compare the traveller with the enrolled biometric, confirm that the new biometric capture came from a live person and determine whether the individual appears elsewhere under another identity. The biometric should serve as a trusted link between the person, their document and the digital identity they use throughout the entire journey.
Beyond that, agencies need injection-attack detection and device-level protections that can operate alongside presentation-attack detection. Presentation-attack detection determines whether a real person is in front of the camera, whereas injection-attack detection determines whether the system is actually receiving information from that camera.
Let’s say a criminal network obtains the name, date of birth and passport details of a real person. With that information, it can create a new facial identity and manipulated video that can be used during remote enrolment. If each piece is examined independently, agencies can miss crucial context.
Instead, agencies should evaluate the document, biometric, device and enrolment session together. This is where liveness detection comes into play.
Passive liveness detection can evaluate characteristics that distinguish a live subject from a photograph, screen replay, mask or generated video without requiring the traveller to complete lengthy movements or challenges. Combined with touchless, mobile-first biometric capture, these passive checks can help agencies verify any person, in any environment without slowing traveler processing.
At Identy.io, this layered approach is built into what we call HumanKey ID — a single touchless journey from capture to trusted digital ID. It begins with multimodal, contactless capture of face, fingerprint or palm from any device; moves through real-time verification against watchlists and trusted sources; and results in a reusable, user-controlled digital identity that can be bound and re-verified at every subsequent interaction. For border agencies, this means a traveller’s identity isn’t re-established from scratch at every checkpoint – it is captured once, verified continuously, and carried forward as a trusted credential throughout the journey – where the only key is you.
Protecting the Entire Identity Lifecycle
The most effective way to combat modern verification challenges is through an integrated chain of trust that connects the physical asset, the live traveller, the capture device and the biometric record.
Deepfakes make it easier to fake identities, but by using document checks, liveness detection, biometric matching and touchless, mobile-first identity verification, border agencies can ensure trust begins with the real person behind the identity. AI can imitate the evidence of identity but it can’t replace the individual. Even as border identity becomes more digital, the person is the key to establishing trust – you are the key.














