← All guides Identity

AI-generated fake IDs: what gets caught

Wholly fabricated documents are the easy case. The one that passes most checks is a genuine document with a single field altered, and it needs a different kind of look.

· 10 min read · Best AI Image Detector

A fabricated document reads hot across the whole frame and is straightforward to flag. A real document with one changed field barely moves the overall score, and only the region map shows it.

Why altering beats fabricating

Producing a convincing identity document from nothing is genuinely hard. It has to survive more than a look: a number that validates, a format matching the issuing year, security features that photograph correctly, and data that agrees with a register somewhere.

Altering a real document skips almost all of that. The card stock is real, the security printing is real, the layout is correct by construction, and only one field has to be convincing. Everything the fraudster did not touch is doing the work of authenticity for them.

That is why the alteration case dominates in practice, and why it is the one worth building a check around. It also explains the shape of the evidence: a frame that is overwhelmingly genuine with one small region that is not.

The economics point the same way. A fabricated document is worth the effort once and is burned when it fails. A reliable technique for altering documents can be used against every organisation that only looks at the picture as a whole.

What the region map does here

A whole-frame score averages across the entire image. On a document photograph where most of the pixels are a real print of a real card, that average is going to be low, and it stays low whether or not somebody changed the date of birth.

Scoring overlapping regions separately removes the dilution. A replaced field is measured against its own neighbourhood rather than against the whole document, and a patch of software-generated text sitting inside photographed print stands out sharply.

13 16 11 14 12 88 15 10 17 13 12 16

The card stock, the portrait and the layout are authentic. One tile covering a data field is not.

A genuine ID card photographed normally, with one data field replaced. Whole-frame score: 27.

Position matters as much as magnitude. Heat over a data field is the classic alteration. Heat over the portrait is a photo substitution. Heat spread evenly across the whole card is either a fabricated document or, far more often, a heavily compressed scan.

Why local analysis matters more here than anywhere

Sending an identity document to a third-party scoring service creates a processing relationship covering some of the most sensitive personal data there is, and in several jurisdictions it covers biometric data specifically.

That means a contract, a lawful basis, a retention position, a transfer assessment where the service sits in another country, and a line in a privacy notice. For many compliance teams that review costs more than the tool it is reviewing.

Running the check in the browser removes the question rather than answering it. There is no processor to appoint because nothing is transmitted, which is frequently the difference between a control being adopted and being abandoned in procurement.

What a check does not establish

This reads whether pixels were produced or reshaped by software. It is not a document verification service, and the distinction matters the moment somebody asks what a result means.

  • Whether the document is genuine. That needs the issuing authority, a register lookup or a physical inspection.
  • Whether the number is valid. Checksum and format validation are separate, cheap, and worth doing first.
  • Whether the person presenting it is the holder. A live video step answers this and nothing else does.
  • Whether it has expired or been reported lost. A register question, not an image one.
  • Whether a bad photograph is just a bad photograph. Compression and poor light raise scores on entirely real documents.

The last point produces most of the false alarms in practice. A passport photographed at an angle, in poor light, then sent through two messaging apps, will score high for reasons that have nothing to do with fraud.

What each finding should trigger
What you seeLikely explanationResponse
One hot tile on a data fieldField alteredRequest the original, route to a person
One hot tile on the portraitPhoto substitutedEscalate, add a live video step
Hot across the whole cardFabricated, or badly compressedRequest a better capture first
Cool and flatAn ordinary documentContinue with normal checks
Warm and flatA poor photographAsk for a flat, well-lit capture

Where this belongs in a process

At identity verification, applied to everybody, with the result routed to a person rather than to a decision. That is the only placement that is both useful and defensible, and the one regulators are least likely to object to.

It does not belong at application or screening stage, where it becomes a filter on the quality of a phone camera. It also does not belong as an automatic refusal, because a detector result cannot be examined or contested by the person it affects.

Write the response down before deploying it. A flag means request a better copy or move to a live check; it never means refuse. Teams that leave this to individual judgement end up with inconsistent outcomes and no way to explain them afterwards.

Record what you did rather than what you scored. An audit trail saying that a document was flagged, a better copy was requested and a person reviewed it is defensible. A stored list of numbers against named applicants is a profiling exercise nobody asked for.

The capture instructions that prevent most flags

Most of the work in making this control usable happens before any analysis runs, in how the document is photographed. Four instructions remove the majority of false positives, and they cost nothing to publish alongside an upload form.

Flat and square to the camera, filling the frame without cropping the edges. Angled captures introduce perspective correction, and correction is software rewriting pixels, which is exactly what the model reads.

Even, indirect light with no flash. Flash produces blown highlights on laminated cards and heavy noise reduction in the shadows, and both push a score upward on a document that is entirely genuine.

Sent as a file rather than pasted into a chat, and never as a photograph of a screen. Each additional hop re-encodes the image, and by the third one a real passport is scoring like a suspicious one.

Questions people ask

Can it detect a fake passport?
It can often detect that part of a document image was produced by software, which is a narrower claim. A fabricated document reads hot across the frame; a genuine document with one altered field shows as a single hot tile while the overall score stays low. Neither is proof, and neither replaces a register check.
Why did a real passport score high?
Almost always the photograph rather than the document. Angled captures, poor light, phone processing and recompression through messaging apps all push scores upward on genuine documents. Ask for a flat, well-lit capture of the original before treating a flag as meaningful.
Is it legal to run this on customer documents?
Running the analysis locally is generally straightforward, because nothing is transmitted or shared. What attracts regulation is using the output to make an automated decision about a person. Keep a human in the loop, and ask your own legal team about the rules where you operate.
Should the result be stored?
Store the outcome with the identity record under the same retention period, not a running log of scores against named individuals. The second is a profiling exercise that needs its own lawful basis and rarely has one.
What about a photo of a screen showing a document?
Treat it as unusable. A photograph of a screen adds a display, a camera and a fresh compression pass, which destroys most of what the check reads and pushes any genuine document well up the scale. Ask for a direct capture of the document itself.
Does this replace a document verification provider?
No. Providers check numbers, formats, security features and registers, which are different signals entirely. A pixel check adds one thing those often miss, a genuine document with one field edited in software, and it complements them rather than replacing them.