Deepfakes and AI Agents Top Identity Threats: Regula Study 2026
Deepfakes and AI Agents Top Identity Threats in 2026

Identity fraud is no longer limited to fake documents or stolen credentials. According to a new study by Regula, a global developer of identity verification solutions, deepfakes now concern businesses almost as much as document fraud and identity spoofing using stolen credentials. At the same time, AI agents and automated systems acting on behalf of users are emerging as a new identity-related concern. Notably, digital interactions increasingly appear legitimate even when their origin remains unclear.

Identity Threats Are Converging

Regula’s The New Shape of Identity Threats study suggests that identity fraud is evolving from isolated fake artifacts toward coordinated, legitimate-looking AI-assisted behavior. Modern attacks increasingly combine deepfakes, automation, biometric impersonation, behavioral mimicry, legitimate identity fragments, and software acting on behalf of users to blend into normal digital workflows. Today’s fraud increasingly imitates trusted identity behavior rather than simply presenting fake artifacts.

This shift is already reflected in organizations’ threat perceptions. Deepfakes and AI-generated impersonation now rank nearly as high as document fraud and identity spoofing, while AI agents and automated systems acting on behalf of users are emerging as a growing identity-related concern.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Deepfake Concerns Are Highest Where Digital Identity Flows Are Most Mature

The Regula study reveals that concern around deepfake impersonation is strongest in countries and industries where digital onboarding and remote identity verification are already deeply embedded into everyday operations. Singapore (42%) and the UK (41%) report the highest levels of concern about deepfake globally. So do the gaming and gambling organizations (40%) and banking and crypto industries (37%). In these sectors and markets, identity verification increasingly depends on remote interactions, biometrics, automated onboarding flows, and continuous authentication. As a result, attacks based on AI-generated faces, voice cloning, behavioral mimicry, and synthetic identity signals become operationally relevant much faster.

Trustworthy-Looking Signals Become the New Challenge

The Regula study suggests that organizations are entering a new phase of identity security, in which attacks are increasingly designed not to bypass systems directly but to operate normally within them. This creates growing pressure on businesses to move beyond isolated verification checks toward more adaptive systems capable of correlating identity signals, validating consistency, and detecting synthetic behavior patterns over time.

“Identity fraud is evolving from static fake artifacts toward synthetic, AI-powered identity behavior designed to appear trustworthy throughout the entire verification flow. The challenge for organizations is to determine whether the overall interaction itself can be trusted — whether the person behind the session is genuine, whether the behavior is authentic, and whether the identity signals remain consistent across the entire customer journey,” says Henry Patishman, Executive Vice President of Identity Verification Solutions at Regula.

Pickt after-article banner — collaborative shopping lists app with family illustration