Why liveness detection is now a core KYC control

Why liveness detection is now a core KYC control

As generative AI makes biometric spoofing cheaper and faster, identity verification firm Identomat says liveness detection has moved from optional add-on to essential defence, and warns that firms relying on face matching alone are exposed.

In a recent analysis, Identomat explained that liveness detection is the part of a biometric system that confirms a real person is physically present when their image is captured. It exists to stop fraudsters using printed photos, replayed videos, 3D masks or synthetic deepfakes. Without it, even a highly accurate face-matching engine can be defeated by a simple printout or an AI-generated face-swap.

The scale of the problem is growing quickly. Around 500,000 video and voice deepfakes circulated on social media in 2023, and that number is estimated to have reached eight million by 2025. Forgeries that took attackers weeks to produce in 2022 can now be created in minutes.

Regulators are paying attention. On 13 November 2024, the Financial Crimes Enforcement Network (FinCEN) issued alert FIN-2024-Alert004 after a rise in suspicious activity reports linked to deepfake media. The alert named live verification checks, where customers confirm their identity by audio or video, as a key tool against fraudulent identity documents.

Identomat described two main approaches. Active liveness uses a challenge-response model, asking users to perform an action such as “blink your eyes” or “turn your head to the left” and checking whether the response looks like natural human behaviour. Passive liveness runs in the background. It analyses a standard selfie or short clip for signs such as skin texture, eye reflections, depth cues and micro-movements, so the user does not have to do anything.

Many deployments combine the two. Identomat’s Adaptive Liveness switches between passive and active methods depending on risk level, device signals and user behaviour. This keeps the process smooth for genuine customers and adds scrutiny only when something looks suspicious.

The firm also separated two kinds of threat. Presentation attacks involve holding an artefact, such as a photo, a screen replay or a silicone mask, in front of the camera. Injection attacks are more advanced. They include real-time face-swaps that bypass the camera through virtual cameras, device hijacks, or deepfake streams fed through browser or driver shims.

For benchmarking, Identomat pointed to ISO/IEC 30107-3, the global standard for presentation attack detection. It relies on two metrics. APCER measures how often spoofs are wrongly accepted, and BPCER measures how often genuine users are wrongly rejected. Pushing one rate down tends to push the other up, so vendors must strike a balance between security and usability.

Identomat recommended judging vendors on certification and independent testing, attack coverage, architecture, integration and regulatory alignment. It argued that liveness checks deliver limited assurance unless they are tied to document verification and face matching in a single KYC and AML workflow.

For more insights into liveness detection, read the full story here.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.