87% of Companies Face AI-Powered Identity Check Attacks, Regula Study Finds
87% of Firms See AI Identity Attacks, Study Finds

A new study by Regula, a global developer of identity verification solutions, reveals a growing gap between organizations' exposure to AI-driven identity activity and their ability to recognize it as a security threat. While 87% of companies worldwide report signs of AI-assisted or automated activity within identity verification processes, only 26% classify such activity as a major risk.

The findings of The New Shape of Identity Threats study suggest that organizations are increasingly encountering behavior that appears legitimate, yet is difficult to clearly attribute, interpret, or distinguish from genuine user activity using existing verification approaches.

Organizations Are Seeing Activity They Can't Confidently Interpret

According to the study, 35% of organizations report signals consistent with automated or scripted behavior where attribution remains uncertain, while another 35% report suspected use of synthetic or AI-generated identity evidence. Organizations report widespread exposure to AI-assisted identity activity: Regula's study finds that AI-assisted interactions within identity verification and authentication workflows are already becoming common across many organizations.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Rather than appearing as clearly identifiable fraud, much of this activity exists in a gray zone between suspicious behavior and confirmed attacks. This makes it increasingly difficult for organizations to distinguish between legitimate users, automated systems, and artificially generated identity signals.

Visibility Remains Limited

Visibility into such activity also remains limited. While 39% of organizations report having clear visibility into AI-assisted interactions, nearly a third say AI-assisted tool use is already common but not fully understood. At the same time, 13% either report no detected activity despite monitoring efforts, have limited monitoring capabilities, or do not actively measure such interactions at all.

AI Agents Remain Underrecognized as a Threat

Despite growing operational exposure to AI-driven identity activity, only 26% of organizations identify AI agents acting as users among their top identity-related concerns. In comparison, organizations remain more focused on established threats such as identity spoofing (38%), document fraud (36%), and deepfakes (35%).

Pickt after-article banner — collaborative shopping lists app with family illustration