How a European Brokerage Closed the Gap Between Deepfake Flags and Onboarding Decisions

Location
Europe
Industry
Brokerage
Use Case
KYC Onboarding
Status
Evaluation

1. Detection existed. Confidence to act did not.

The incumbent flagged the deepfake attempt. It still completed onboarding, because the flag carried no explanation and sat among false positives analysts had learned to dismiss.

2. Explainability turns a flag into a decision.

A pixel-level verdict with a heatmap and confidence output gives analysts evidence they can act on and defend, not another binary score to ignore.

3. Added alongside the stack, no workflow change.

The forensic layer sits at the biometric step next to the existing vendor, with a disagreement process and EU-only processing. Customers and reviewers add no step.

"My team had learned to second-guess every alert, because acting on the wrong one meant turning away a real customer. Having evidence behind a flag changed what they were willing to do with it."

Head of Authentication & Verification
,  
European brokerage
Table of Contents

Quick Summary

  • A genuine ID paired with an AI-generated selfie completed a European brokerage’s live onboarding, even though the incumbent vendor flagged it.
  • The real gap was decision confidence, not detection: analysts dismissed flags because of false-positive fatigue and no explanation to act on.
  • Adding DuckDuckGoose’s explainable DeepDetector alongside the existing stack turned bare flags into forensic verdicts analysts could defend.
  • [ILLUSTRATIVE] Any figures in this study are modelled examples, not measured client results. Verified data to be inserted before publishing.
At a glance

One controlled deepfake test moved a genuine ID and an AI-generated selfie through the live onboarding flow to completion. The incumbent vendor raised suspicion. No analyst acted on it.

0
Controlled test
Genuine ID + synthetic selfie, live flow
0
Incumbent flag raised
Suspicion signal did fire on the attempt
0
Acted on, before
Flag dismissed as false-positive noise
100%EU
Processing residency
AWS Frankfurt, no third-country transfer

Introduction

A genuine identity document. A real-looking selfie. Four onboarding controls passed. The account opened. The selfie was an AI-generated deepfake, and the firm’s incumbent verification vendor had actually flagged the attempt as suspicious. The flag changed nothing.

A European multi-asset brokerage ran a controlled test against its live remote onboarding flow: a genuine ID paired with a synthetic selfie of the same identity. The attempt completed verification. The incumbent liveness vendor did register suspicion, but the attempt succeeded anyway, because that suspicion signal was indistinguishable from the everyday false-positive noise the firm’s analysts had been trained by experience to ignore.

The gap was not in what the firm could detect. It was in what the firm was willing to act on.

The Onboarding Selfie as an Identity Attack Surface

A remote onboarding selfie produces two signals that look identical in the moment but answer different questions, and most stacks conflate them.

Liveness / presentation attack detection asks whether a real person is present rather than a photo, replay, or mask. It is mature in identity-verification platforms. It is also what injection and deepfake attacks are specifically engineered to satisfy.

Forensic deepfake detection asks a separate question: with a live person and a genuine stream, is the face being shown authentic? This is the specialist layer, and nothing in a standard liveness-and-document stack addresses it. A convincing synthetic face can pass liveness and still be a deepfake.

Aspect Liveness / PAD (incumbent) Forensic deepfake detection
Verifies A live person is present at capture Whether the face shown is synthetically generated or altered
Output Often a binary pass/suspicion signal A verdict with heatmap and confidence an analyst can act on
Defeated by Injection and deepfake attacks built to satisfy the liveness challenge Analysed independently of challenge behaviour, at the pixel level
Alone, it misses A convincing synthetic face that passes as a live person Nothing about deepfakes — but is not a liveness or document control
Together: both controls in the same onboarding flow cover the biometric attack surface. Neither replaces the other.

Liveness and forensic deepfake detection as complementary controls in remote onboarding.

The Approach: From Raw Detection to Decision Confidence

The reframe was the turning point. The question stopped being whether deepfakes could be detected, the incumbent had detected this one, and became whether analysts could be given enough evidence to act on a suspicious attempt without drowning in false positives. That required three things from any layer added to the stack.

Forensic, artefact-level analysis. Rather than inferring authenticity from movement or challenge-response behaviour, which injection and deepfake attacks are built to defeat, DuckDuckGoose’s DeepDetector examines the image at the pixel level for the generative artefacts synthesis leaves behind.

Explainability the reviewer can use. The value was not a second yes/no signal, the firm already had one and ignored it, but a heatmap and confidence output an analyst could point to when justifying a decision.

Deployment alongside the existing flow. The layer was scoped to sit next to the incumbent stack at the biometric step, with a defined process for handling disagreement between the two systems, and all processing kept within the EU.

Before — incumbent stack only
Document check
ID validated · pass
Selfie + liveness (incumbent)
real person present · pass
Suspicion flag fires
binary signal, no explanation
Analyst review
flag dismissed as false-positive noise
Blind spot
Account onboarded
synthetic identity admitted
Outcome: the deepfake completes onboarding — despite a flag.
After — + DDG forensic layer
Document check
unchanged · pass
Selfie + liveness (incumbent)
unchanged · pass
DDG DeepDetector — forensic verdict
pixel-level analysis + heatmap + confidence
New
Analyst review
acts on explainable evidence
Account stopped / escalated
defensible rejection
Outcome: a flag becomes a verdict an analyst will act on.

The Result: A Flag Becomes a Verdict Analysts Will Act On

The gap was never whether the deepfake could be caught. It was whether anyone would act on the flag when it fired.

The meaningful result is a change in operating posture, not a headline percentage. Before, the firm had a detection signal it did not trust and would not act on. After adding an explainable forensic layer, the same category of suspicious attempt produced a verdict an analyst could reason about and defend. The controlled deepfake test that had previously completed onboarding now surfaced a manipulation verdict with visual evidence, rather than a bare suspicion flag a reviewer would dismiss.

  • Defensible rejections: analysts gained pixel-level reasoning to stand behind stopping a suspicious account, instead of waving it through to avoid friction with a possible real customer.
  • No rip-and-replace: the forensic verdict was added alongside the incumbent vendor, with a clear path for resolving disagreements.
  • Confidence, not just coverage: the change addressed why a correctly detected attack had been getting through, not merely whether it could be detected.

The economics also shift. When a flag carries evidence, the cost of acting on it moves from delaying a genuine customer to stopping a real attack, which is what makes analysts willing to act on it at all.

Key Takeaways

1. The gap is often decision confidence, not detection. A flag no one acts on is not a control. Adding another opaque score to a stack analysts already distrust changes nothing.

2. False positives carry a hidden second cost. Beyond wasted review time, they train analysts to ignore the alerts that matter, which is how a genuinely detected attack still gets through.

3. Explainability converts flags into actions. Reviewers need evidence they can point to and defend, not a binary verdict.

4. Prove the exposure. A single controlled test on the production flow moves a risk conversation further than any threat briefing.

5. Add, don’t rip out. The strongest deployments sit alongside the existing stack with a clear process for handling disagreement between signals.

How This Proceeds

An engagement of this kind is not a single procurement decision. What the firm authorises first is the analysis only, with no commitment to what follows.

1
2
3
01
Controlled test
Controlled deepfake test
A genuine ID paired with a synthetic selfie is run against the live flow, plus optional retrospective review of prior suspicious cases. Establishes the exposure. No commercial commitment.
No commitmentEU-only
02
Design
Feasibility + integration
Technical session on where the forensic verdict sits in the existing flow, a disagreement matrix for conflicting signals, backtesting scope, and DPIA support with privacy and legal.
Add-on layerDPIA support
03
Coverage
Rolling analysis
Selfies route through DeepDetector at the biometric step as standard, verdicts reach analysts before onboarding completes, with calibrated thresholds and quarterly review.
Alongside incumbentQuarterly review

Last update: Q3 2026

Discover the Power of Explainable AI (XAI) Deepfake Detection

Send us what your team has flagged. Onboarding videos your fraud or KYC team has escalated on instinct, or thin-file customers whose post-funding behaviour does not look right. We will run them through our detection models and return what we see.