Faryam Asif, Chief Technology Officer at Shufti: “In the AI era, knowing who you’re dealing with is becoming just as important as protecting your systems from attack.”

Artificial intelligence is transforming cybersecurity at a pace few organisations anticipated. As attackers use AI to identify vulnerabilities, generate convincing deepfakes and create increasingly sophisticated synthetic identities, businesses are being forced to rethink not only how they secure their systems, but also how they establish trust online. Apple’s recent decision to accelerate the release of security updates is just one example of how the AI arms race is reshaping digital security.

Yet while much of the conversation has focused on protecting infrastructure, another challenge is rapidly emerging: verifying that the people, or increasingly the machines, interacting with digital services are genuinely who they claim to be. Traditional identity checks, often performed only during customer onboarding, are struggling to keep pace with a threat landscape where AI can generate realistic identities in a matter of minutes.

As Chief Technology Officer at Shufti, Faryam Asif leads the engineering teams behind the company’s AI-powered identity verification and compliance platform, giving him a front-row seat to the rapidly evolving world of digital identity and fraud prevention.

In this interview with TechFinitive, Asif discusses how generative AI is changing the nature of identity fraud, why businesses should move beyond one-time verification towards continuous identity assurance, how organisations can balance stronger security with a seamless customer experience, and why digital trust could become one of the defining competitive advantages of the AI era.

Apple recently announced it will accelerate the release of security updates because AI is helping attackers exploit vulnerabilities more quickly than ever. Do you think businesses have fully grasped how AI is changing not just cybersecurity, but the challenge of verifying digital identity?

Apple’s decision to accelerate security updates reflects how quickly AI is changing the threat landscape, but many businesses still think of AI as primarily a cybersecurity issue. In reality, it’s also an identity problem. AI can now generate convincing faces, voices and documents at a scale that makes it much harder to know whether you’re interacting with a real person. That means trust can no longer be based on a single document or one verification event. Businesses need to rethink identity as an ongoing process rather than a one-time compliance requirement. In the AI era, knowing who you’re dealing with is becoming just as important as protecting your systems from attack.

Your research suggests AI is dramatically shortening the gap between creating an identity and using it for fraud. How has generative AI changed the sophistication of identity fraud over the past 12 to 18 months, and what developments concern you most?

Our 2026 Deepfake Identity Fraud Index found that generative AI has gone far beyond creating fake images or text. Criminals can now use it to create realistic synthetic identities, known as synthetic identities, that look almost identical to real people. With AI-generated faces and forged documents, these fake identities can often pass traditional identity checks that weren’t designed to detect them.

The bigger problem is that many companies focused on making customer onboarding as fast as possible, which means some of these fake accounts may have already been approved. In other words, the fraud isn’t just trying to get into the system anymore. It may already be there, hidden among legitimate customers. That’s why checking someone’s identity only once during sign-up is no longer enough. Businesses need continuous identity verification, because AI is changing the rules of digital trust faster than many organisations can keep up.

Many organisations still treat identity verification as a one-time event during customer onboarding. Why is that approach becoming increasingly outdated, and what does continuous identity assurance look like in practice?

Treating identity verification as a one-time check during onboarding is no longer enough because identity risk changes over time. A customer who passes KYC today could later appear on a sanctions list, have their account taken over, or become linked to suspicious activity. At the same time, generative AI has made it much easier to create synthetic identities and deepfakes that can pass legacy verification systems during the initial check.

Continuous identity assurance means businesses don’t stop verifying identity after onboarding. Instead, they keep checking for new risks throughout the customer relationship. In practice, this includes ongoing sanctions, PEP, and adverse media screening, asking users to re-verify their identity before high-risk transactions, and combining biometric verification with device and behavioural signals to detect account takeover or identity misuse. Rather than relying on a single approval at sign-up, businesses continuously reassess identity as new risk signals appear, allowing them to detect fraud earlier and stay compliant.

Deepfakes and synthetic identities are becoming increasingly convincing, making it harder for both businesses and consumers to distinguish genuine interactions from fraudulent ones. How can organisations strike the right balance between stronger identity verification and delivering a seamless customer experience?

To stop increasingly convincing deepfakes without creating unnecessary friction for customers, organisations need to move away from a one-size-fits-all approach and adopt risk-based orchestration. This means applying the right level of identity verification based on the level of risk. For low-risk interactions, businesses can use Passive eIDV, which verifies identity through trusted data sources in the background, often in just a few seconds. If a transaction or user presents a higher level of risk, the system can automatically step up verification by using technologies such as 3D liveness detection to stop AI-generated faces or AI-powered document forensics to detect fake or manipulated identity documents.

Reusable identity solutions, such as FastID, can also improve both security and the customer experience. Instead of asking trusted users to upload documents every time, they can re-verify themselves with a quick facial scan before completing a high-risk action. By only introducing stronger verification when risk increases, businesses can reduce fraud, stay compliant, and keep the experience fast and seamless for legitimate users.

Financial services have traditionally been at the forefront of identity verification, but AI-powered fraud is now affecting organisations across every sector. Which industries do you think are currently the most underprepared, and what lessons can they learn from more mature sectors?

While banking and fintech are adapting to the “technological reset” caused by AI, sectors that have traditionally prioritized rapid growth and low-friction onboarding; specifically e-commerce, the gig economy, social media, healthcare, and online education are currently the most underprepared for sophisticated synthetic identity and deepfake threats. These industries often rely on lightweight or “point-in-time” checks that create significant “blind spots,” allowing AI-generated fraud to hide within their databases undetected. To catch up, these sectors must adopt lessons from mature financial institutions by shifting to continuous identity assurance, which involves ongoing monitoring of risk signals throughout the entire customer journey rather than just at signup.

Practical steps include implementing blind spot audits to rescan historical data for hidden forgeries, using biometric-bound reusable identities (like FastID) to ensure the rightful owner is always in control without repetitive document uploads, and adopting risk-based orchestration that triggers stronger security measures; such as 3D liveness detection—only when a high-risk signal is detected.

Looking ahead, as AI agents begin interacting with other AI agents and carrying out transactions on behalf of people, how do you see digital trust evolving over the next five years? What should technology leaders be doing today to prepare for that future?

Over the next five years, digital trust will shift from humans proving their identity to machines to a future where AI agents must continuously prove their “right to act” to other machines. We are moving toward an era of “machine identity,” where digital trust is no longer a one-time event at signup but an invisible, continuous lifecycle where every automated transaction is verified in real-time using biometric-bound reusable credentials. Leaders should perform blind spot audits today to clean their existing databases; because AI agents will carry out transactions based on established accounts, any undetected “sleeper fraud” currently hiding in your system will become a legitimate gateway for large-scale automated theft tomorrow.

About The Author

Avatar photo
Ricardo Oliveira

Ricardo Oliveira is a Senior Director at TechFinitive, where he frequently collaborates with TechFinitive's editorial team to write and produce content. He's based in Sydney, Australia.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.