All posts
4 August 2026· 2 min read

The Compliance Gate AI Regulation Just Opened

One fraudster opened 46 bank accounts at ABN Amro with stolen IDs and deepfake video. As eIDAS 2.0 makes identity assurance a regulatory requirement, that's the failure mode regulators are now writing rules against.

One person opened 46 separate bank accounts at ABN Amro. Each application used a stolen identity document paired with deepfake video to pass the bank's remote verification. Not one attempt in isolation, discovered later. Forty-six, through the same gate, before anyone caught the pattern.

That's the case now cited when regulators explain why identity verification needs to change. Under eIDAS 2.0, the European Union requires every member state to offer citizens a European Digital Identity Wallet by the end of 2026, and regulated-sector acceptance of state identity becomes mandatory from 2027. The regulation exists because the previous generation of verification, a selfie matched to a document photo, a liveness prompt answered on camera, no longer proves what it was built to prove. The ABN Amro case is what happens when that gap goes unaddressed at scale rather than in a single incident.

This is where compliance stops being a checkbox and starts being a technical requirement a platform's models either meet or don't. Any system selling into government or regulated contexts now has to satisfy assurance requirements that assume its detection can tell a real applicant from a synthetic one. Most can't. The evidence for that isn't theoretical: tested against realistic synthetic identities, frontier vision-language models accept them as genuine at rates from 94 to 100 percent. A platform that fails that test in evaluation fails it in production too, just later and more expensively, once the account is open and the funds have moved.

Sovereign-AI programs feel this most acutely, because clearing the assurance gate isn't optional for them, it's a condition of the government contract itself. A national AI stack that can't demonstrate identity assurance doesn't get procured, regardless of how good the rest of the system is.

Closing that gap requires the same thing regulators are now asking for by name: a detection layer proven against realistic synthetic fraud, not just real fraud that happened to get caught after the fact. That means training data that reproduces the specific failure modes, the specific document types, the specific liveness-evasion techniques, a platform's current models miss, at a scale and demographic breadth no incident log alone can supply.

TessLabs' generator and discriminator were built together inside a live identity-verification business, hardening detection against real fraud at population scale for eight years before either became a product. That's the assurance layer platforms building toward eIDAS 2.0, or toward any regulated-AI procurement gate, are now being asked to demonstrate.

Read the white paper or book a call to see how the compliance evidence is structured.

Case study: ABN Amro fraud case via Biometric Update.

Measuring this on your own model

The first step is a sample built to your specification, which you score on your own detectors and benchmarks. No cost and no commitment.