Deepfake Identity Threats: What Security Leaders Need to Prioritize Next
Learn what Gartner recommends for defending Identity Verification and biometric systems against evolving deepfake threats.
The conversation around deepfakes is accelerating, but many organizations are still asking the wrong questions. As attackers gain access to increasingly sophisticated AI tools, identity verification and biometric authentication programs are facing new forms of risk. Yet according to Gartner, focusing solely on deepfake detection may leave critical gaps in your defenses.
In this Gartner report, cybersecurity leaders will gain practical guidance on how deepfakes are actually used against face biometric systems, the attack methods that matter most, and the controls organizations should require from identity technology providers. The research highlights why presentation attack detection, injection attack detection, and broader risk signals should become core evaluation criteria.
- Why Gartner advises security leaders to think beyond deepfake detection alone.
- How attackers use presentation and injection attacks against biometric systems.
- The standards that should be considered essential when evaluating identity vendors.
- Why contextual risk signals play an increasingly important role in fraud prevention.
- Key considerations for protecting onboarding, authentication, and account recovery journeys.
- Practical recommendations for strengthening biometric defenses.
- How workforce and customer identity programs are being impacted by AI-generated attacks.
Access a Copy of the Report
For more than two decades, leading organizations around the world have trusted Daon to help them solve some of the most complex identity challenges. From customer onboarding to ongoing authentication, Daon enables secure, trusted digital interactions at every stage of the identity lifecycle.
.png?width=750&height=511&name=figure1%20(2).png)
Deepfake Identity FAQ
Gartner frames deepfake detection as the last line of defense, not the first. The more effective approach is stopping the two methods attackers use to introduce deepfakes: presentation attacks, where a fabricated image is displayed to a camera, and injection attacks, where synthetic media is inserted directly into the data stream. Detecting these attack methods at the point of introduction is more reliable than attempting to identify synthetic generation in the captured image, where no standardized testing methodology currently exists.
A presentation attack involves displaying a deepfake directly to a camera—pointing a device at a screen, or using printed photos or masks. An injection attack bypasses the camera entirely, using virtual camera software to insert a synthetic image into the data stream between capture device and processing application. The application receives what appears to be a live feed but is not. Both attack types require distinct defensive capabilities and vendors should be evaluated on their ability to detect both.
For presentation attack detection (PAD), the relevant standard is ISO/IEC 30107-3, which defines testing against fraudulent artifacts—any vendor without independent evidence against this standard warrants concern. For injection attack detection (IAD), CEN/TS 18099 was introduced in 2025 and defines testing across Basic, Substantial, and High evaluation tiers. Relatively few vendors have completed this testing. Gartner recommends treating completed IAD testing, or a credible contracted timeline, as a procurement requirement.
There is no standardized methodology for assessing deepfake detection efficacy and no independent framework for comparing vendor claims. Deepfake generation technology advances faster than detection capabilities, vendors use varying proprietary techniques, and the threat landscape shifts constantly. Detection accuracy figures, therefore, rest on an unverifiable foundation. Gartner recommends reorienting evaluation criteria toward standards-validated PAD and IAD capabilities rather than detection claims that cannot be independently validated.
When an attack slips past initial defenses, contextual intelligence creates additional detection opportunities independent of whether the deepfake itself is identified. Relevant signals include device intelligence flagging velocity anomalies or linking separate identities to one device, location signals identifying geographic mismatches, behavioral signals surfacing deviations in dwell time and interaction patterns, and velocity checks catching repeated use of the same identity attributes. These signals can reveal that something about the surrounding context does not add up even when the synthetic image goes undetected.
Gartner recommends shifting evaluation from "can you detect deepfakes?" to "can you detect how deepfakes are used?" The three key questions are: Has the vendor demonstrated PAD testing in conformance with ISO/IEC 30107-3, and from which independent laboratory? Has the vendor completed IAD testing against CEN/TS 18099, or can they provide a contracted timeline? And beyond the biometric capture event, what contextual signals does the vendor collect and how are they surfaced in the risk decision?
Orchestration combines biometric verification, document authentication, and contextual risk signals within a single configurable framework, so when one defensive layer misses an attack, others can still surface anomalies. Platforms like Daon's TrustX enable this through no-code workflows that reduce integration overhead and allow faster adaptation as threats evolve. Gartner's 2025 Magic Quadrant for Identity Verification recognized Daon's orchestration approach as a meaningful differentiator compared to vendors relying on developer-intensive integration models.
No single defensive layer catches every attack, and deepfake generation consistently outpaces detection methods. Resilient organizations build layered defenses: standards-validated PAD and IAD capabilities stopping attacks at introduction, contextual intelligence identifying surrounding anomalies, and orchestration infrastructure combining these layers into adaptive workflows. Anchoring strategy around a single detection capability creates a brittle security posture. The architecture as a whole must be designed to catch attacks that individual layers miss.
*Gartner, Inc. Deepfake Identity Threats: Mitigate Risk in Identity Verification and Face Biometrics. Akif Khan, Nayara Sangiorio, James Hoover. 11 May 2026.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Daon.
