> ## Content Index
> Fetch the complete content index at: https://newsletter.electe.net/llms.txt
> Use this file to discover other available public pages before exploring further.

# The Person Is Real. The Deception Is Too.
- URL: https://newsletter.electe.net/problems-with-facial-recognition/
- Published: 2026-10-01T11:31:09.000Z
- Updated: 2026-10-01T11:31:09.000Z
- Description: Real people. Useful work. Valid credentials. A false story can contain all three.
- Author: Fabio Lauria
- Tags: facial recognition, AI governance, EU AI Act, biometric bias, vendor risk, #en

*A video call is supposed to settle the doubt. There is a person on the other end. They move, respond and look back at you. You can stop wondering whether you have been talking to a bot.*

In one reported fraud operation, that reassurance was part of the service.

[Anthropic’s September 2026 threat report](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=newsletter.electe.net) describes a deceptive dating-app network combining AI personas with paid human workers. Over two weeks in April, it observed more than 4,700 AI personas interacting with at least 25,000 people. Real workers supplied live video calls and social-media follow-backs that helped reassure users. Even those workers were AI-assisted: a separate model proposed their replies, and they tapped one. These are the provider’s findings from one operation, not market-wide estimates.

The detail worth pausing over is the human labour. A defence organised entirely around detecting synthetic media would leave an obvious question unanswered: what happens when the person who reassures you is real, but the relationship being sold to you is fabricated?

**The genuine element can be what makes the deception convincing.**

In [my previous edition on deepfakes and business risk](https://newsletter.electe.net/deepfakes-the-new-emergency-rewriting-the-rules-of-business/), I examined impersonation and the controls available to companies. The next question reaches beyond the authenticity of a face: how much of a story do we accept once one part of it checks out?

## The work can be real too

Consider an employee who submits useful code, answers colleagues promptly and understands the project. These are reasonable grounds for judging performance. They are much weaker grounds for establishing who employs that person, where they operate or whose identity they are using.

[Microsoft’s March 2026 research](https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/?ref=newsletter.electe.net) describes North Korean IT-worker operations using AI to sustain everyday correspondence, technical responses and coding work under fraudulent identities. Its account extends beyond recruitment to maintaining employment. Microsoft describes AI helping actors to:

> “get hired, stay hired, and misuse access at scale”  
>  
> — Microsoft Threat Intelligence

For a business, repeated competent performance is reassuring. An adversary who can provide it may accumulate the very history that later makes additional access seem reasonable.

There is a documented economic foundation for this kind of operation. In the [Christina Chapman case](https://www.justice.gov/usao-dc/pr/arizona-woman-sentenced-17m-it-worker-fraud-scheme-illegally-generated-revenue-north?ref=newsletter.electe.net), the US Department of Justice reported 309 US businesses defrauded and more than $17 million generated by a remote-worker scheme supported by stolen identities and a domestic laptop farm. It ran from 2020 to 2023; those figures are not a measure of losses caused by generative AI.

My reading is that AI can reduce the effort required to maintain the supporting story: the correspondence, the professional presentation, the daily responsiveness. A fraud does not have to remain spectacular. It can become routine enough that nobody thinks to reopen the question.

This creates an uncomfortable distinction for employers. **Evidence that someone can do the work is not evidence that every claim surrounding their employment is true.**

![Three genuine signals with distinct limits: a real person does not establish their whole identity story; useful work does not establish an affiliation; a company device does not establish who controls it.](https://newsletter.electe.net/content/images/2026/10/01-four-questions-1.png)

**An authentic component supports a limited conclusion. The wider claim still needs evidence of its own.*

## Several checks can still be one source

Imagine a candidate supplying a CV, a portfolio, a professional profile and a referee’s email address. Everything agrees. The dates line up; the language sounds credible; the referee responds.

That consistency can mean two very different things. Independent records may corroborate an honest account. Alternatively, one operator may control all four surfaces.

This is an illustrative scenario, but the reasoning matters: **agreement between sources is valuable only to the extent that those sources are meaningfully independent.** Four documents supplied by the same party do not automatically constitute four independent confirmations.

The practical consequence is quite specific. A reference reached through contact details independently obtained from the former employer tests a different relationship from a reference reached only through the applicant’s preferred address. A record checked with its issuer establishes something different from a plausible-looking copy.

Neither step guarantees honesty. Both make the source of the assurance clearer.

The same distinction applies to a video call. The question is what the call connects: a face to a claimed identity, an identity to an organisation, or a person to a particular request. A convincing interaction should not silently settle every connection at once.

## The breach that did not happen

[KnowBe4’s disclosure in July 2024](https://blog.knowbe4.com/north-korean-fake-it-worker-faq?ref=newsletter.electe.net) offers a useful corrective to the idea that one failed identity check means everything is lost. It said a worker using a stolen US identity passed video interviews and background checks. It also said onboarding permissions were limited, customer data remained inaccessible and attempted malware execution was blocked. The device was quarantined within minutes of suspicious activity.

> “KnowBe4 was not breached.”  
>  
> — KnowBe4’s published incident FAQ

The distinction is important. Recruitment failed to establish the identity correctly. According to the company’s account, later restrictions prevented that failure from becoming unrestricted access.

For an employer, that suggests a better question than whether a candidate has passed enough checks: **what changes immediately after the checks are passed?**

If the answer is that the person receives broad repository access, customer exports and the ability to register new authentication methods, one decision has carried a great deal of weight. A more limited start leaves room to resolve uncertainty before the consequences become difficult to reverse.

This is also a reason to resist treating satisfactory work as an automatic basis for expanding privileges. Someone can deserve a positive performance review without needing access to another team’s data.

## Detection still matters. Its result has a boundary.

None of this makes deepfake detection pointless. It makes the claim attached to the result more important.

A [September 2026 preprint introducing DF26](https://arxiv.org/html/2609.07369v1?ref=newsletter.electe.net) found that participants correctly identified 52.6% of its fake clips, compared with 74.5% on CelebDF++ and 69.8% on DeepSpeak v2\. The experiment used five-second clips with no audio and mostly technical-university volunteers; these are fake-identification rates, not overall accuracy or live-call results.

A separate [March 2026 preprint](https://arxiv.org/html/2603.14658v1?ref=newsletter.electe.net) found mean human accuracy of 78.4%, versus 53.7% for the tested detector variants, on its everyday-activity video dataset. Participants were explicitly assessing authenticity. The different tasks and samples prevent a direct comparison between the two papers.

There is no useful universal score for how well “people” or “AI” detect deception. A buyer needs evidence about the actual material, attack and decision involved.

More fundamentally, even a correct finding that footage is authentic cannot establish the honesty of the interaction. Detection addresses a technical question. The organisation still owns the decision about what that answer justifies.

![Several documents controlled by one party provide consistency. Checks with independently contacted issuers and organisations provide separate grounds for confidence.](https://newsletter.electe.net/content/images/2026/10/02-benchmark-gap-1.png)

**Ask who controls the evidence, as well as whether it agrees. This is a conceptual comparison, not a measured security score.*

## Who gets to certify the story?

A commercial response is already taking shape. [Cloudflare’s 2026 announcement with Nametag](https://blog.cloudflare.com/deepfakes-insider-threats-identity-verification/?ref=newsletter.electe.net) describes adding identity verification to workplace access: a selfie and government-issued ID check produces a token used in the access decision. That establishes the proposed workflow; the announcement is not independent evidence of its effectiveness.

For buyers, the appeal is understandable. An organisation cannot investigate every interaction from first principles. It needs reusable assurances.

But the scope of the purchased assurance matters. **A check linking a person to an identity document does not, on its own, establish that a request serves the employer, that a business relationship is honest or that an account is being used for its agreed purpose.** Those are further claims.

Researchers proposing privacy-preserving [personhood credentials](https://arxiv.org/html/2408.07892v1?ref=newsletter.electe.net) acknowledge a related institutional risk: issuers and large service providers may concentrate power through decisions about which credentials and uses they accept. Personhood credentials address a different question from employment vetting, but the warning about dependence is relevant.

As an entrepreneur, I would ask two things of any such purchase. What precise uncertainty does the provider reduce? And which decisions will my organisation still have to defend itself?

Buying a narrower, testable assurance can be valuable. Buying a comforting label and treating it as a conclusion about the whole relationship is where the reasoning breaks down.

## What survives the check

The useful question to take into a hiring review, a supplier discussion or an access decision is simple:

**What would still be unproven if every item in front of us were genuine?**

That question changes the next action. It can lead to contacting an organisation independently, narrowing the requested access or establishing why a payment belongs to this counterparty. It does not require someone to win an argument about whether a face looks fake.

A genuine video call establishes less than a genuine relationship. Competent work establishes less than a truthful employment history. A valid credential establishes less than an honest purpose.

**The mistake is granting a true piece of evidence authority over a story it cannot prove.**

---

**Fabio Lauria**

*CEO & Founder,* [ELECTE](https://electe.net/?ref=newsletter.electe.net)

Every week, we explore AI without the hype — using data, analysis and an independent perspective.

[![](https://newsletter.electe.net/content/images/2026/09/933ba771-1ece-4f55-9523-be68e02be6fc_Image-for-linktr.webp)](https://www.electe.net/?ref=newsletter.electe.net)

If you found this analysis useful, please share it with someone who might be interested. And if you’d like to find out how ELECTE uses AI to automate data analysis and reporting, you can find out more at [electe.net](https://www.electe.net/?ref=newsletter.electe.net).

[Subscribe Now](https://newsletter.electe.net/#/portal/signup)