For most of the last decade, remote identity checks asked one question: does the face in the camera match the face on the document? Generative AI made that question easy to answer falsely. A convincing face, a synthetic video feed or an edited document image can now be produced in minutes.
The attacks fall into two families. Presentation attacks hold something up to the camera: a printed photo, a screen, a mask. Injection attacks skip the camera altogether and feed a fabricated video stream into the verification app. Physical front desks were once protected by the fact that a person was standing there. As check-in moves to kiosks, tablets and phones, that protection goes with it.
What still works
The controls that hold up are the ones that test for a live person in the physical room, not the ones that inspect an image:
- Liveness and presentation attack detection tested against a recognised method, such as the ISO/IEC 30107 series, rather than a vendor's own claim.
- Trusted capture: the camera and document reader belong to the site, not to whatever device the visitor brings.
- Machine-readable data from the document, cross-checked against what is printed, rather than trusting the photo page alone.
- Per-site policy that decides when a mismatch goes to a person, and records who approved the exception.
The audit trail is part of the defence
Detection is never perfect, so the second line is evidence. When every verification is stored as one recorded decision (the document read, the liveness result, the match score, the policy applied and the staff member who acted), a fraudulent entry can be traced, the gap closed and the same pattern caught next time.
ENTRIX is built on that assumption. It runs on the site's own tablets and kiosks, checks the document, the person and the match together, and records a single decision that staff and auditors can review.

