top of page

The Face That Isn't There

Maria Khan
Sep 2
4 min read

Deepfakes are now beating the tests that banks use to prove whether you are actually you, and this is already happening on a large scale. Who is liable when a deepfake defeats bank verification: the fraudster, the bank, or no one? How are regulators are responding to this new threat?


By Maria Khan




For eight months, a 34-year-old in Amsterdam opened more than 40 accounts in other people's names. He simply face-swapped his image onto stolen passports and took selfies to get through the bank's KYC processes. Each time, the bank's automated system confirmed he was who he claimed to be. The fraud came to light when one application used a woman's photo ID but the accompanying selfie showed the face of a man. When border police stopped him carrying a stack of debit cards and found his phone full of AI searches on how to bypass bank security, the scheme unravelled. CCTV footage showed him depositing large amounts of cash into several of the fraudulent accounts. In June 2026, the Amsterdam court sentenced him to 30 months in prison and ordered €13,000 in restitution to the bank.


While deepfakes are getting more sophisticated, onboarding mechanisms remain largely unchanged. Traditional KYC checks that use selfie-to-document matching answer one question: does this face match that ID? That is a test of consistency. It does not touch the tougher question of whether this is a real, living person present right now. That is a test of presence. Much of global mobile onboarding is strong on the first and thin on the second. The moment someone manufactures a face bridging his own appearance and someone else's document, the check waves it through.


From a legal and policy lens, deepfake-enabled onboarding creates three distinct problems for three distinct stakeholders, and the law has not yet caught up to all of them.


// The offender


Though the specific charges vary by jurisdiction, criminal liability already exists in most jurisdictions. For example, the Amsterdam defendant was prosecuted for fraud, forgery, and using stolen personal details. These are established offences. As a comparator, in the UAE, similar offences would be covered under Article 451 (fraud/swindling) or Article 251 (forgery of official documents), punishable under Article 252 of Federal Decree-Law No. 31 of 2021. Across jurisdictions, what these offences do not do is address the technique of deepfake deployment directly. And for good reason. A rule written around deepfakes will be obsolete the moment the technology shifts. A rule written around manipulated biometric data or synthetic media in verification survives longer. Yet, durable rules are built by regulatory regimes that are mindful of the threat landscape of today and tomorrow, but careful not to prescribe the technical solution to achieving those principles. Typically, that is where industry standards and best practices come in.


// The people whose photographs were harvested


They suffer two simultaneous harms: identity theft at the outset (that is, data breach), and then the risk that their stolen documents are weaponized for downstream fraud. In the Amsterdam case, victims' IDs were obtained through a fake rental listing and social media harvesting. The accounts were possibly used for laundering money.


Deepfake generated accounts can also potentially be used to access accounts in someone's name and move their funds, causing direct financial harm to the victim. The legal question is unresolved: what recourse do identity theft victims have? Who is liable, the fraudster alone, or the institution that failed to detect the fraud? Can victims recover directly from the bank? The answer differs by jurisdiction, and in most places, it is ambiguous.


//The bank


As an intermediary, the bank faces two questions: first, what recourse does the bank have when it is a victim of fraud committed against it? For example, in the Amsterdam case, the bank received an EUR 13,000 compensation, which covered the bank's investigation costs and some restitution. Second, what is the positive obligation of the bank, and what happens if it fails in its duty? Do regulatory regimes envisage any action against banks for their inability to distinguish between authentic applicants and manipulated media. In the Amsterdam case, the accounts were used for money laundering via cash deposits - a crime prohibited under the Act on the Prevention of Money Laundering and Terrorist Financing in the Netherlands. The UAE comparator is Federal Decree-Law No. 20 of 2018 in the UAE which prohibits money laundering. Generally, regulators can impose fines and revoke operating licenses through their financial sector regulatory regimes.


The EUR 13,000 award does not however reach the second circle of harm: people whose photographs opened the accounts. The question of whether the bank's KYC failure should trigger customer compensation to identity victims remains jurisdictionally dependent and unsettled.


// Regulatory response: principle over technique


Globally, regulatory regimes are trying to keep pace, but are more recommendatory than prescriptive, given the newness of the technology. In September 2025, the Monetary Authority of Singapore published an information paper on Cyber Risks Associated with Deepfakes, precisely specific because it isn’t law. It says that financial institutions should conduct comprehensive checks to detect tampering and verify the authenticity of identification documents during onboarding; implement liveness detection techniques in biometric authentication solutions; conduct regular vulnerability assessments simulating deepfake attacks; implement endpoint-level protection; use strong encryption for biometric data; and implement cancellable biometrics. Notably, these are recommendations, not mandates.


In February 2026, the Central Bank of the UAE issued a guidance note on the consumer protection, and responsible adoption and use of artificial intelligence and machine learning by licensed financial institutions, non-binding for the same reason Singapore’s was. The CBUAE's stance is explicitly tech-agnostic and principles-based. The framework emphasizes governance, fairness, transparency, human oversight, and data privacy, but does not prescribe specific technical solutions or name deepfakes by name.


From a policy lens, it is equally important to hold offenders accountable and to ensure that institutions and identity victims have clear, proportionate recovery pathways. What is needed is technology-literate but technology-neutral law, accompanied by technology-specific regulatory guidance to set benchmarks and guide the sector.

bottom of page