Artificial intelligence (AI) is enabling fraudsters to create highly convincing synthetic identities, and at industrial scale, at that. “This poses a severe and escalating risk to Know Your Customer (KYC) processes and anti-money laundering frameworks in South Africa and beyond,” warned Desigan Naidoo, Executive: Technology at LexisNexis, a legal technology provider.
Recent reports show beyond doubt that AI-driven fraud, including synthetic identities and deepfakes, now dominate biometric verification failures, with one analysis identifying only 100 AI-generated faces, amongst over 160,000 fraudulent attempts in a single month across Africa.
Financial institutions rely on robust identity verification to combat money laundering, terrorist financing, and other illicit activities. “Under South Africa’s Financial Intelligence Centre Act (FICA), accountable entities must verify customer identities per Section 21 before establishing business relationships or conducting transactions,” Naidoo explained. This includes obtaining reliable documentation, proof of residence, and conducting risk-based due diligence, in order to ensure transparency and accountability within the financial system.
Generative AI tools have, however, transformed the fraud landscape to an alarming degree. Fraudsters no longer merely steal existing identities; they fabricate entirely new ones by blending legitimate data, such as ID numbers or addresses, with AI-generated images, voices, documents, and backstories. “These synthetic profiles appear legitimate enough to bypass traditional checks,” he said, “and this allows criminals to open accounts, secure credit, and launder funds undetected.”
Industry insights from 2026 reveal the incredible scale of this shift: Smile ID’s ‘Digital Identity Fraud in Africa’ Report indicates that 87% of failed biometric verifications in South Africa stem from AI-driven impersonation and spoofing, with no-face-match and deepfake techniques accounting for the majority. “Globally and regionally, synthetic identity fraud ranks among the fastest-growing threats, fuelled by AI’s ability to automate and scale attacks,” Naidoo cautioned. PwC notes expectations of sharply escalating losses in 2026 as fraudsters escalate their operations to industrial scale.
The move to digital onboarding in the banking and fintech fields only serves to exacerbate these vulnerabilities. Remote processes depend on automated technologies such as facial recognition, document scanning, and biometric authentication. While these certainly improve efficiency and access, they still struggle in the face of sophisticated AI manipulations, which include deepfakes and fabricated biometrics. “And,” adds Naidoo, “Even that traditional assumption, that identity documents represent real individuals, is becoming increasingly unreliable.”
He spells it out quite directly: “If institutions cannot reliably distinguish genuine from synthetic identities, the integrity of financial systems erodes, potentially enabling greater illicit flows and organised crime.”
Regulators and policymakers are responding, and South Africa is advancing toward a national digital identity system with a mandatory 2026 rollout, with the aim of providing a trusted, government-backed single source for verification, and reducing synthetic fraud risks. Adds Naidoo, “The enhanced adoption of advanced tools, such as liveness detection in biometrics, behavioural analytics, device fingerprinting, and machine learning for anomaly detection, is being encouraged, in order to bolster defences.”
If AI is being employed on one side of this equation, then the time has arrived to fight fire with fire: Financial institutions are now countering the onslaught by leveraging AI themselves for fraud prevention. Machine learning analyses vast transactional data to spot unusual patterns, while continuous monitoring shifts the focus beyond initial onboarding onto ongoing risk assessment. “But,” adds Naidoo, “technology alone isn’t enough. Effective governance demands strong internal compliance programmes, senior oversight, suspicious transaction reporting, and adaptation to evolving threats.”
Failure to strengthen verification processes exposes banks, fintech companies, and other entities to financial loss, reputational harm, and regulatory penalties under FICA and related frameworks. As new identity recognition systems come on board, making the end-user experience quicker and more convenient, it becomes crucial to balance this innovation with complex security backups. Regulators worldwide, including in South Africa, are reassessing frameworks to ensure identity systems withstand AI-enabled challenges. The emergence of synthetic identity fraud underscores the urgent need for collaborative efforts among institutions, tech providers, and authorities, in order to safeguard the financial ecosystem.








