Data Over Documents:  Why the Future of Identity Verification Must Prioritise Authoritative Data 

The age of artificial intelligence is ushering in an era of unprecedented convenience and efficiency—but also one of unprecedented risk. As generative AI and deepfake technology become more sophisticated, the ability to produce high-quality fake identity documents is reaching a point where traditional detection methods will no longer suffice. Fraudsters are already leveraging sophisticated AI tools to create realistic passports, driving licences, and other identification documents, rendering conventional document-based verification increasingly unreliable.  

In response to this emerging threat, the future of identity verification must shift away from reliance on physical documents and towards the validation of data itself. The only way to combat the rise of AI-driven fraud is to establish seamless, secure, and direct collaboration between authoritative data sources—such as government databases, financial institutions, and other verified repositories of identity information. This is the fundamental principle behind the push for “data over documents.” 

The Inherent Weakness of Documents 

Historically, verifying identity has relied on assessing documents: passports, ID cards, utility bills, and other forms of paper or digital credentials. But as fraud techniques evolve, even the most advanced document inspection technologies—such as holograms, watermarks, and digital chips—will not be enough. AI-generated forgeries can now replicate every detail of an official document, making it nearly impossible to distinguish a fraudulent ID from a real one with the naked eye or even with sophisticated scanning software.  

Compounding this issue is the increasing accessibility of deepfake technology, which allows criminals to create hyper-realistic images and videos of individuals that match stolen or synthetic identities. With deepfake-enhanced biometric fraud, identity criminals can bypass face-matching and liveness detection systems, rendering many legacy verification solutions obsolete. 

The Case for Authoritative Data 

Instead of relying on the inspection of documents alone, we must pivot towards verifying identity at the source—by validating personal data directly against authoritative, real-time sources. This approach moves verification from a subjective, visual process to an objective, data-driven one, making it far more resistant to manipulation.  

For example, rather than simply checking whether an identity document looks authentic, businesses and institutions should be able to cross-reference claimed identity details with government records, tax authorities, financial institutions, or other trusted databases. By directly confirming that an individual’s identity credentials match those held in secure, authoritative sources, the risk of fraud is dramatically reduced. 

Moreover, this method is not just about preventing fraud; it also streamlines and enhances user experiences. A data-first approach enables faster, frictionless verification, reducing the need for manual reviews and redundant document submissions while improving security and compliance with regulations like GDPR, AML, and KYC standards. 

Enabling Secure, Privacy-Preserving Collaboration 

While the concept of data-based verification is clear, the execution requires a paradigm shift in how organisations handle and share sensitive information. Privacy, security, and regulatory compliance are all paramount concerns, and solutions must ensure that identity verification processes remain fully secure and privacy-preserving. 

Advanced cryptographic technologies, such as zero knowledge proofs (ZKPs) and secure multiparty computation (MPC), are paving the way for privacy-enhancing verification systems. These methods allow institutions to verify identity data against authoritative sources without exposing unnecessary personal information or centralising sensitive records in a way that increases the risk of data breaches.  

By leveraging such techniques, identity verification can become both more secure and more privacy-conscious, addressing concerns about data sovereignty and personal information exposure while still ensuring that fraudsters cannot manipulate the system. 

A Call to Action: An All-of-Society Approach 

No single organisation, government, or financial institution can tackle the problem of AI-driven fraud alone. To build a truly robust identity verification system that prioritises data over documents, collaboration between authoritative data sources is essential. The private sector cannot do this alone, and neither can the public sector. It must be an “all-of-society” approach to ensure success. 

Governments must step up and provide the capability for this verification to happen, enabling secure, controlled access to identity records for legitimate verification purposes. This can be achieved using privacy-enhancing technologies (PETs) that allow identity data to be verified without exposing unnecessary personal information. Only through a coordinated effort, where governments provide the necessary frameworks and businesses integrate secure verification solutions, can we effectively combat the evolving threats posed by AI-driven fraud. 

The rapid rise of AI-powered fraud is not a distant threat—it is happening now. If we continue to rely on traditional document-based verification, we will fall behind in the fight against increasingly sophisticated identity fraud. The solution is clear: we must transition to a model where identity is verified based on real-time authoritative data, not just pieces of paper or digital images. The future of trust in digital identity depends on it. 

This article is part of Sedicii’s ongoing thought leadership in support of Project PHACKS, an initiative focused on building collaborative communities to address complex cybersecurity and data privacy challenges. PHACKS is funded by the European Union and brings together organisations to explore new approaches to secure data collaboration utilising privacy enhancing technologies. Through this work, Sedicii contributes its expertise in advanced cryptography, secure data collaboration and digital identity to promote safer, more transparent digital ecosystems across Europe. The views expressed herein reflect the author’s perspective and do not necessarily represent those of the European Union. Learn more about Project PHACKS.

Scroll to Top