Shahid Hanif, CEO and Co-Founding father of Shufti, is a know-how entrepreneur with intensive expertise constructing identification verification, fintech, blockchain, and decentralized software program platforms. He co-founded Shufti in 2017 and spent greater than seven years as Chief Expertise Officer, main the in-house growth of its synthetic intelligence-driven biometric and doc verification know-how earlier than turning into CEO in December 2024. Hanif can be the founding father of Builders Studio, a blockchain growth firm with greater than 100 specialists, and beforehand served as CTO of Quickbit, the place he helped develop its cryptocurrency fee know-how forward of the corporate’s preliminary public providing. Earlier, he co-founded Programmers Drive and helped develop the software program and information science firm to greater than 500 workers throughout ten places of work on three continents.
Shufti is a man-made intelligence-powered identification verification platform that helps organizations set up belief, stop fraud, and meet Know Your Buyer, Know Your Enterprise, and Anti-Cash Laundering necessities. Its platform brings collectively doc and biometric verification, digital identification verification, NFC-based checks, enterprise verification, age assurance, fraud detection, ongoing monitoring, and case administration by means of a unified infrastructure. The corporate helps 1000’s of doc sorts and greater than 150 languages throughout over 240 international locations and territories, permitting companies to confirm prospects and organizations by means of a single world integration. Its know-how examines doc authenticity, biometric liveness, machine intelligence, and different danger indicators to detect solid paperwork, deepfakes, account manipulation, and coordinated identification assaults.
Whenever you co-founded Shufti in 2017, you initially led the corporate’s know-how growth as Chief Expertise Officer earlier than turning into CEO in 2024. What shortcomings in digital identification verification initially motivated you to construct the platform, and the way has your understanding of the issue modified with the rise of generative AI?
Once we co-founded Shufti in 2017, the largest challenges have been sluggish verification, an excessive amount of handbook work, and methods that didn’t work nicely throughout completely different international locations. Many identification verification options have been inconsistent, particularly in high-risk industries. In addition they struggled to confirm paperwork in non-Latin languages and couldn’t reliably confirm identities from world wide.
At the moment, generative AI has modified the issue. It’s not nearly studying an ID doc. It’s about understanding whether or not the doc and the individual presenting it are actual. AI has made identification fraud quicker, cheaper, and far simpler to scale. We’ve realized that verifying somebody as soon as throughout onboarding is not sufficient. Companies now want AI that may detect even essentially the most superior pretend paperwork and identities.
Belgian authorities lately warned that greater than 10,000 individuals fell sufferer to AI-enabled identification fraud over the previous 12 months. What does this case reveal about how shortly identification crime is evolving, and why are AI-generated copies of official paperwork particularly troublesome to detect?
The warning from Belgian authorities concerning 10,000 victims is simply the tip of the iceberg. It reveals that criminals have moved from fundamental doc enhancing to full-scale identification synthesis.
AI-generated copies are troublesome to detect as a result of they will mimic authorities templates with pixel-level precision. Conventional OCR (Optical Character Recognition) focuses on extracting textual content, nevertheless it ignores the visible integrity of the picture. AI can now replicate safety features that beforehand required bodily presence to confirm, making a flat picture of a doc a legal responsibility somewhat than a proof of identification.
How does an AI-generated copy of a stolen identification doc differ from a standard forgery, a manipulated doc, and a totally artificial identification?
It is very important distinguish between these strategies:
Typical Forgery: A bodily counterfeit doc.
Manipulated Doc: A official ID the place particular fields (like a reputation or DOB) have been altered.
Artificial Id: A “Frankenstein” persona constructed by combining stolen actual information (like an SSN) with fabricated particulars.
AI-Generated Copy: A deepfake doc created from scratch or a stolen template utilizing Generative Adversarial Networks (GANs). These typically lack digital historical past and comprise forensic artifacts like sensor noise inconsistencies that the human eye can’t see.
Shufti tasks that doc deepfakes might enhance by practically 3,900% this 12 months. What exercise is driving that projection, and which assumptions or limitations ought to organizations perceive when deciphering it?
We anticipate a 3,900% enhance in doc deepfakes as a result of AI has made fraud a lot simpler to create and scale. Criminals are not simply swapping faces in images. They’ll now generate complete pretend identification paperwork that usually slip previous older verification methods.
It’s vital to know that this projection displays how shortly AI-powered fraud is rising, not simply what number of pretend paperwork exist. The most important problem is that many identification verification methods have been designed years in the past and may’t detect superior AI-generated fakes, comparable to life like holograms or face morphing. In consequence, pretend identities can get by means of checks and stay hidden in firm databases.
Many companies nonetheless deal with {a photograph} or scan of an identification doc as ample proof of identification. What indicators ought to a contemporary verification system look at past the seen info on the doc?
The most important shift is that companies can’t depend on conventional doc checks anymore. They want what we name a “Digital Eye” strategy. As a substitute of simply studying the data on an ID, the system has to look at whether or not the doc itself is real.
Which means searching for delicate indicators that people can’t simply spot, like whether or not the picture was captured from a display screen, uncommon pixel patterns, inconsistent lighting, or traces left behind by AI picture turbines. We additionally examine for indicators that components of the doc have been copied, moved, or digitally altered, together with inconsistencies in metadata and picture high quality. Whenever you mix all of those indicators, you’re more likely to detect subtle AI-generated paperwork that older verification methods would merely settle for as actual.
You’ve gotten argued that identification assurance ought to be steady somewhat than restricted to buyer onboarding. What would steady verification appear like in observe, and the way can corporations implement it with out introducing extreme surveillance, privateness dangers, or buyer friction?
The period of the “one-time examine” is over. Steady Id Assurance means refreshing person danger towards 1,700+ watchlists as steadily as each quarter-hour to forestall “retroactive non-compliance.”
To implement this with out friction or privateness dangers, we use biometric-bound reusable identities (FastID). As soon as a person is verified, they will re-verify for high-risk actions (like massive withdrawals) in beneath two seconds utilizing solely a facial scan. This kills the necessity for repetitive doc uploads whereas sustaining a excessive safety posture.
Fraudsters can now mix artificial paperwork with face swaps, deepfake video, injection assaults, and stolen private info. How ought to identification platforms join doc integrity, biometric liveness, machine intelligence, and behavioural evaluation to establish these coordinated assaults?
Fraudsters have gotten way more subtle. As a substitute of utilizing only one method, they now mix AI-generated paperwork, face swaps, and injection assaults to bypass identification checks. That’s why companies want to take a look at the total image somewhat than counting on a single verification step.
At Shufti, we do that by means of context-aware danger scoring. We analyze the machine getting used to detect emulators or headless browsers, confirm that the person is bodily current with iBeta Degree 2 licensed passive liveness detection, and search for suspicious patterns throughout accounts by analyzing identification information, machine fingerprints, and person habits. Combining these indicators makes it a lot simpler to establish fraud earlier than it causes injury.
Generative fashions will proceed enhancing, whereas fraudsters can intentionally compress, rescan, or alter artificial media to cover manipulation artifacts. How do verification suppliers take a look at whether or not their detection methods stay efficient towards new and beforehand unseen assault strategies?
The problem is that AI-generated fraud evolves a lot quicker than conventional safety testing cycles. Verification suppliers have to repeatedly consider their methods towards new assault strategies somewhat than counting on historic datasets. Which means testing with artificial paperwork, recompressed photos, display screen recaptures, injection assaults, and different manipulated media designed to cover apparent artifacts. More and more, the main focus is shifting from detecting a selected kind of deepfake to figuring out inconsistencies throughout a number of indicators, as a result of these have a tendency to stay tougher for attackers to copy as generative AI improves.
Id verification methods can create critical penalties after they incorrectly reject official customers. How ought to builders measure false positives, demographic efficiency, and accessibility alongside fraud-detection accuracy?
Accuracy shouldn’t simply be about catching the “dangerous guys”; it’s about guaranteeing a frictionless path for the “good guys.” In our business, we concentrate on the Failure to Extract Price (FTXR)—which measures how typically a system merely fails to “learn” a face or doc—and the False Non-Match Price (FNMR), the place real customers are incorrectly rejected. In response to the sources, Shufti’s efficiency within the DHS RIVR 2025 Benchmark demonstrated a 0% extraction failure throughout a number of gadgets and a worst-case FNMR beneath 0.68%.
Builders should transfer past “lab averages” and measure efficiency towards “worst-case” demographic outcomes. This implies testing particularly for consistency throughout various pores and skin tones, facial buildings, and cultural apparel. We obtain this by coaching our AI on globally various datasets containing tens of millions of frames. A strong analysis isn’t full till you’ve confirmed that your system is as correct for a person in a rural area with poor lighting as it’s in a managed workplace setting. The objective is a Unified Id Layer that is still honest, inclusive, and accessible to everybody.
Trying forward, will applied sciences comparable to government-backed digital identification wallets, cryptographically verifiable credentials, and biometric-bound identities ultimately make uploaded doc photos out of date, or will they merely create a brand new set of assault surfaces?
We’re positively shifting towards a future the place individuals gained’t have to add images of their identification paperwork as typically. Authorities-backed digital identification wallets and trusted digital IDs make proving your identification a lot quicker and safer as a result of they permit info to be verified straight, somewhat than counting on a picture of a doc. In addition they create a smoother person expertise by decreasing the time it takes to finish verification.
That stated, each new know-how creates new alternatives for criminals. As a substitute of forging paperwork, attackers could attempt to steal digital credentials, take over accounts, or hijack trusted identities. That’s why digital credentials alone aren’t sufficient. It’s nonetheless vital to substantiate that the individual utilizing the identification is the official proprietor, for instance by means of biometric verification and liveness checks. The way forward for identification verification is more likely to mix trusted digital credentials with biometrics, creating a number of layers of safety as an alternative of counting on a single technique.
Thanks for the nice interview, readers who want to study extra ought to go to Shufti.
