Research by identity verification provider Shufti found that 47 per cent of users abandon digital onboarding when verification becomes too lengthy or cumbersome. For Shahid Hanif, the company’s chief executive and co-founder, that number is the clearest symptom of what he calls the friction paradox: the conflict between a user’s demand for a near-instant experience and an institution’s need for forensic security.

Hanif told The Fintech Times why the friction has proved so difficult to fix, and why he believes AI-generated identities are exposing the limits of traditional document-based verification.
Much of the friction, Hanif says, comes from onboarding fatigue. “Legitimate users are still being forced into manual document hunts for things like physical utility bills, or rejected by rigid systems that lack the fuzzy matching needed to forgive something as simple as a typo.” Solving it has become harder because verification is no longer only about documents. “We are in a forensic war against the industrialisation of fraud,” he said, and the extra checks that war demands introduce complexity that older, speed-optimised systems cannot manage.
The scale of that war is set out in Shufti’s own projections: the company expects AI-powered identity fraud to increase by 495 per cent by the end of 2026, and document deepfakes to surge by 3,900 per cent. “The 495 per cent surge represents more than just a rise in volume. It signals the industrialisation of the synthetic persona,” Hanif said. In practice the company is seeing document deepfakes and identities generated by adversarial networks, alongside field manipulation, copy-move edits and simulated holograms that legacy optical character recognition systems were never built to detect.
More concerning still, he says, is the rise of digital stream injection and screen-sharing liveness hacks. “These methods allow bad actors to bypass the physical camera and inject pre-recorded synthetic video directly into the verification flow.” Shufti’s answer is to look for what Hanif calls invisible signals, using techniques such as 3D mesh reconstruction and skin texture analysis to distinguish real human skin from AI-generated imagery.
The consequence, Hanif argues, is that businesses can no longer choose between robust fraud prevention and a seamless customer experience: the industrialisation of AI-driven crime has turned speed-optimised legacy systems into backdoors for synthetic identities, while cumbersome journeys drive legitimate users away. “Asking users to go on a manual document hunt during a high-stakes moment, such as a market bull run, can quickly push them toward a competitor.”
AI-generated identities are exposing structural weaknesses in the document-first model itself. “AI-generated identities are making traditional document verification increasingly obsolete by separating digital trust from physical reality,” Hanif said. Older systems designed for data extraction and text readability can approve a sophisticated deepfake simply because
the layout is correct and the fields are readable. Synthetic personas that pass a weak, point- in-time check at onboarding can then lie dormant in corporate databases, a pattern Hanif calls sleeper fraud, creating liabilities the original systems were never designed to detect.
Europe’s expanding digital identity ecosystem, anchored by eIDAS 2.0 and the upcoming EUDI Wallet, represents for Hanif a major shift toward the document-free future needed to resolve the paradox. By moving from static image capture to secure cryptographic handshakes, verified attributes such as legal name, age and address can be pulled directly from authoritative registries through trusted schemes like BankID, MitID or DIIA; Shufti estimates the approach can reduce user drop-offs by up to 30 per cent. “Reducing friction does not have to mean reducing security,” he said, since assurance comes from government- vetted credentials rather than physical document templates.
So what should organisations do now? Hanif’s first step is an audit of existing customer portfolios to uncover “synthetic identities that may have passed through legacy OCR systems between 2020 and 2023”. Next, move beyond basic image checks toward what he calls forensic presence, using certified passive liveness detection and 3D biometrics to confirm a real person is present; he points to a zero-failure result Shufti claims in the US Department of Homeland Security’s RIVR 2025 benchmark. The final piece is making verification easier for legitimate users, with government-backed digital wallets and fast biometric re-authentication. “Businesses need to give users the speed they expect without compromising the security required in the AI era.”
The post Shufti’s Shahid Hanif on Onboarding Friction and AI Fraud appeared first on The Fintech Times.