When AI Can Imitate the Customer, Can Banks Still Trust Identity?

For decades, financial identity rested on familiar signals. A face matched an identification document. A voice belonged to the account holder. A signature reflected consent. A video call appeared to prove that a real person was present, while a message written in the style of a senior executive carried authority.Artificial intelligence is weakening each of those assumptions. Generative systems can reproduce voices, faces, documents, writing styles and personal mannerisms with increasing precision. A criminal may no longer need to steal every element of a person’s identity; the missing pieces can increasingly be manufactured.

Vyas warns that this shift is changing the meaning of identity verification in finance. Banks may use AI to authenticate customers and detect fraud, while criminals use similar technology to construct synthetic identities, personalise social-engineering attacks and impersonate customers, employees or executives.

The result is an unusual contest: AI is being asked to detect deception produced by another AI system.

“The question is no longer only whether AI can identify fraud,” Vyas argues. “It is whether one automated system can reliably distinguish a real customer from a sufficiently convincing artificial one.”

When AI Checks AI
Banks already use automated systems to examine identification documents, facial movements, device characteristics, transaction histories and behavioural patterns. These controls can detect suspicious activity at a scale human reviewers cannot match.

The danger becomes greater when an institution treats one successful automated check as final proof. A face may match a document, but both could be synthetic. A voice may match previous recordings, but those recordings may have been cloned. Behaviour may appear normal because it was deliberately constructed to look ordinary.

In Vyas’s assessment, a technically successful verification should not automatically be treated as proof of a trustworthy identity.

The Synthetic Customer
Traditional identity theft typically begins with information stolen from a real person. Synthetic identity fraud may instead combine genuine information with fabricated names, photographs, addresses or financial behaviour. Such identities can open accounts, make small payments and establish transaction histories before attempting larger fraud, acquiring the appearance of legitimacy while passing several automated checks.

Generative AI can make this process more convincing. It can produce consistent documents, respond naturally during customer-service interactions and maintain a believable persona across different

channels. Future fraud operations may not depend on one false document or a single cloned voice; they may maintain artificial financial identities capable of interacting with multiple institutions over time.

Banks may therefore need to ask a broader question: not only whether each individual signal looks valid, but whether the identity has a credible origin and remains internally consistent over time.

When a Failure of Trust Becomes a Financial Event
Identity fraud is often treated as a cybersecurity problem, but at scale it becomes a financial risk. Impersonation can produce unauthorised payments, synthetic borrowers can create credit losses, and fake executives can trigger corporate transfers across multiple institutions.

Banks have spent years removing friction from account opening and payments. These advances improve access, but they also reduce opportunities to recognise uncertainty. “When identity itself can be generated, some carefully designed friction may need to return,” Vyas notes.

Verification Must Become Continuous
A single biometric scan or document match may no longer be sufficient for high-risk financial activity. Institutions may need to move from one-time authentication towards continuous verification.

That could involve examining whether a customer’s device, location, transaction history and communication patterns remain consistent over time. Additional confirmation may be required when an action differs materially from established behaviour, such as an unusual transfer, a new beneficiary or a sudden cross-border instruction.

Continuous monitoring, however, creates a second problem: privacy. A system that constantly evaluates customer behaviour may improve fraud detection while also becoming intrusive. Banks must identify artificial identities without treating every genuine customer as permanently suspicious.

Vyas argues that the answer is not unlimited data collection. It is stronger governance over the information already being used. Institutions should know where identity evidence came from, whether it has been altered, which system evaluated it and why an action was approved, delayed or blocked.

Verification must therefore become continuous without becoming indiscriminate.

Anshul Vyas is a researcher working across finance, macroeconomics, financial risk and AI governance. He is a full member of Sigma Xi, The Scientific Research Honor Society, an editorial advisory board member, and a referee for journals covering finance, economics and behavioural-market research. His financial AI governance framework is described in published patent application (20260154749), which is publicly searchable through the USPTO.

A Different Approach to Financial AI Control
“AI can help verify identity, but institutions should not assume that automated approval proves a real person is present,” Vyas explains. “When AI evaluates evidence that may itself have been generated by AI, additional layers of trust, risk review and accountability are required.”

Vyas has developed a financial AI governance framework that considers whether identity data is traceable, whether evidence remains consistent, whether behaviour suggests manipulation and whether a proposed action requires additional human or multi-party review.

He argues that identity verification and transaction approval should remain connected, because fraud often uses a credible-looking identity to initiate an abnormal financial action.

AI Can Also Fool Its Supervisor
A more difficult risk arises when several AI systems appear to provide independent checks but share similar data, assumptions or external technology providers.

One system may verify a face, another may analyse a voice and a third may assess the transaction. If all three systems share related weaknesses, their agreement may create false confidence rather than genuine confirmation.

Vyas warns that institutions must test not only individual models, but also the relationships between them. They should examine whether several controls can fail together, whether one model’s output influences another and whether a synthetic identity can move through the entire decision chain without encountering genuinely independent scrutiny.

AI supervision also needs an escape route. When systems disagree, confidence declines or behaviour changes unexpectedly, an institution should be able to delay the action, limit its scope, request additional evidence or refer the matter to qualified human review.

The Business Question for Banks
For banks and fintech companies, this is not merely a technical security question. It is an accountability question.

When a fraudulent payment is authorised through a deepfake call, synthetic identity or AI-generated instruction, responsibility may become difficult to locate. Was the customer careless? Did the identity provider fail? Did the bank rely too heavily on automation? Did an employee ignore a warning, or did the system fail to produce one?

As AI becomes part of operational infrastructure, Vyas argues that executives and boards must answer four questions:

  • What evidence did the institution trust?
  • Why did its systems trust it?
  • What controls could have stopped the action?
  • Who remained accountable when those controls failed?

Financial institutions cannot eliminate every form of deception. They can, however, reduce the chance that convincing synthetic evidence moves directly from an artificial identity to a real financial loss.

The next stage of digital finance may depend on treating identity not as something proved once, but as a continuing claim whose reliability changes as evidence, behaviour and risk evolve.

AI will remain essential to processing that evidence at scale. But, as Vyas concludes, it cannot become the unquestionable judge of whether another AI is telling the truth.

When machines can create the customer, imitate the executive and generate the evidence, financial trust will depend not on one perfect detector, but on whether institutions can challenge, trace and stop automated decisions before artificial identity becomes real financial harm.

Comments are closed.