- Perception no longer carries evidentiary weight. Any verification program still leaning on visual or auditory review by staff is already failing and probably does not know it.
- Detection buys time. It does not buy certainty. Durable trust comes from cryptographic provenance, privacy-preserving personhood credentials, and scoped, auditable machine authority.
- The next decade is about proving origin, transformation, authorization, and accountability at machine speed. Institutions that get this early will spend the decade verifying. The rest will spend it apologizing.
For most of the history of identity security, the field ran on an assumption nobody bothered to write down. A person, paying attention, could spot a fake. Machines got fooled by printed photographs and replayed audio, sure. But the human in the loop was the backstop. Between the two of us we have spent close to four decades on this problem, across identity security, applied cryptography, and now AI governance, and we think that assumption is dead. The industry has not caught up to what its death costs.
The Evidence Is Not Subtle
Start with iProov's 2025 study. Participants were warned in advance that some of what they were about to see was fake. They were primed. They still failed, and badly. One in a thousand got every item right. Voice is worse. Research in Scientific Reports found listeners mistook a cloned voice for the real person roughly four times out of five.
Enterprises have noticed. Gartner predicted that by 2026, roughly a third of them would stop treating standalone identity verification as reliable. Then there is Arup, where an employee in Hong Kong sat through a video call with colleagues who did not exist and wired out about 25 million dollars. That case stopped being a curiosity a while ago. It is the reference. Deloitte expects generative fraud losses in the United States to more than triple between 2023 and 2027.
Fraud Became Software
The volume is not the interesting part. The shape is. Shufti's Identity Fraud Index puts the sharpest growth not in face swaps or manipulated live video but in paperwork. Passports. Utility bills. Payslips, corporate records, whatever the onboarding flow asks for, generated wholesale and submitted as genuine, with document deepfakes projected to grow nearly 40-fold this year. Attackers stopped bothering with the camera. Injection attacks feed synthetic media straight into the verification pipeline and skip the sensor.
The economics explain the rest. Old trust models assumed convincing forgeries were expensive and hard. Generative systems inverted that. An impersonation attempt now costs about what an API call costs, while verification keeps getting more expensive for the defender. That gap only widens.
Detection Cannot Carry This
Deepfake detection research follows a pattern that anyone who has watched the field for a decade will recognize. Train a discriminator on the artifacts today's generators leave behind. Publish good benchmark numbers. Watch performance rot as the frontier moves. Generator and discriminator are the same optimization problem seen from opposite ends, and one side has more compute, more data, and more money.
Detection still earns its place in a layered defense. It raises cost per attempt, and that matters. But raising an attacker's costs is not the same as restoring certainty, and the field keeps confusing the two. The real work is not spotting artifacts. It is manufacturing evidence worth trusting.
Three Things Worth Building
1. Provenance: The C2PA standard changes the question from whether something looks real to whether it can prove its own history. Cryptographic attestation bound to capture hardware does not decay as generators improve, which is exactly what detection cannot claim. Its problems are practical. Metadata gets stripped. The analog hole is still there. And provenance only bites once adoption is thick enough that missing credentials look suspicious on their own. Getting there is a coordination problem, which makes it a governance problem.
2. Personhood: A 2024 multi-institution paper sketched credentials, ideally built on zero-knowledge proofs, that let someone prove they are a unique human without revealing which one. The cryptography is close to ready. The hard part is everything around it. Enrollment. Recovery. Interoperability. Who gets left out, and who decides. Populations without stable documents or addresses do not disappear because the math works. If proving personhood becomes the price of participating online, identity infrastructure turns into governance whether anyone designed it that way or not.
3. Machine Authority: Agentic systems authenticate, hold delegated power, and act for humans at speeds our authorization models never contemplated. A human grants an agent, that agent spawns sub-agents, those call tools. That chain is now a primary attack surface and the literature on constraining it is thin. Non-human actors need short-lived, task-scoped, cryptographically verifiable authority, plus audit trails that can reconstruct intent afterward. Regulators are moving. The EU AI Act's high-risk obligations, live for Annex III systems since August 2026, treat biometric and identity systems as regulated infrastructure rather than product features.
The Part That Keeps Us Up
Chesney and Citron named it the liar's dividend. Once everyone knows synthetic media exists, real evidence becomes deniable. The threat runs both directions. It fabricates proof and it dissolves proof, and the second effect may do more damage to institutions than the first. Building systems that can affirmatively establish that something did happen, rather than flagging what did not, is the harder question and the more consequential one.
These arguments started with practitioners in the room at our RSAC 2026 session, AI, Identity, and Ethical Governance: Building Trust in High Stakes Systems. The questions we got there shaped most of what is above.
The path forward is not to make humans better at spotting increasingly convincing fakes. It is to build systems that do not require them to. Provenance, personhood, and constrained machine authority will not eliminate deception, but together they can restore something detection alone cannot: evidence that remains trustworthy even when perception does not. Human verification may be dying. Verifiable trust can thrive in its place, enabled by systems that make proof automatic, accountability auditable, and trustworthiness a property of the architecture itself