Visual KYC Is Dead: Synthetic Identities and the End of Selfie Verification
A synthetic German identity card, photorealistic and consistent down to the typography, can be generated in about five seconds. The analysis starts from that fact and follows it to its conclusion: identity verification that relies on what a document or a face looks like no longer proves anything.
The article dissects the visual verification stack piece by piece. Document checks fail against AI-generated IDs that contain no copy-paste artefacts because nothing was copied. Selfie comparison fails against faces that never existed. Video identification and liveness detection, built to confirm that a living person sits in front of the camera, are increasingly defeated by real-time deepfakes that blink, turn and answer questions. What remains is a ritual that satisfies the letter of the process while the perpetrator opens the account: compliance theatre.
The constructive part maps what still works because it does not depend on appearance: chip-based verification against cryptographically signed government data (eID), bank-account-anchored identification, behavioural and device signals, and cross-checks that attack the synthetic identity's weakest point, its lack of history. The argument is directed at compliance teams still procuring visual verification in 2026, and at the supervisors still accepting it.