If your work involves accepting documents from people you cannot see in person — a degree certificate from an applicant, an ID from a new customer, a bank statement from a borrower — you have relied for years on an unspoken assumption: that a document which looks right probably is right. That assumption no longer holds. A convincing fake certificate, passport or payslip that once needed a skilled forger and specialist equipment can now be produced by almost anyone with a text prompt in a few seconds.
This guide sets out what has changed, the main forms document fraud now takes, why the defences most organisations still rely on have stopped working, and the shift that restores trust: from inspecting documents to verifying them.
What is document fraud in the GenAI era?
Document fraud in the GenAI era is the use of generative AI to create or alter documents and identities that pass as genuine. The difference from traditional forgery is one of effort. Producing a believable fake no longer requires skill, time or money, so fraud that was once rare because it was hard has become common because it is easy.
Traditional document fraud meant altering a real document or copying one convincingly, work that demanded some expertise and usually left tell-tale flaws. Generative tools remove those constraints. A model can produce a certificate, an invoice or a photorealistic ID from a short description, complete with plausible logos, layouts, fonts and signatures. The barrier that used to keep casual fraud in check, the difficulty of making a fake look real, has largely gone.
How generative AI changed document fraud
Generative AI has pushed the cost, skill and time needed to forge a document close to zero, while the volume and quality of fakes have risen sharply. The result is more fraud attempts, more convincing ones, and more of them aimed at automated systems.
The numbers from identity-verification providers point the same way. In Sumsub’s 2025 analysis, the share of detected fake documents created entirely by generative AI tools rose from effectively zero in April 2025 to around 2%, roughly one in fifty forged documents, by that August. Digital onboarding fraud attempts rose 73% year on year, and the proportion Sumsub classes as “advanced”, meaning multi-step and AI-driven, climbed from about 10% in 2024 to 28% in 2025. A Gartner survey in September 2025 found that 62% of organisations had experienced a deepfake attack in the previous year.
For the full set of figures on deepfakes, AI-generated documents and synthetic identities — each attributed to its primary source and updated quarterly — see our statistics round-up.
Deepfake and AI Document Fraud Statistics (2026) →The main types of GenAI document fraud
GenAI document fraud takes four main forms: forged or altered documents, deepfakes used in identity checks, synthetic identities, and attacks aimed at remote onboarding.
- 1 Forged and altered documents. Fake certificates, diplomas, invoices and financial statements generated or edited to order, in a form that looks indistinguishable from a real scan or PDF.
- 2 Deepfakes in identity proofing. AI-generated images, video and voice used to defeat the selfie and liveness checks meant to confirm a real person is present.
- 3 Synthetic identity fraud. Identities assembled from a mix of real and fabricated details, often paired with an AI-generated face of a person who does not exist. Sumsub found synthetic identities behind around one in five first-party frauds detected in 2025.
- 4 Attacks on remote KYC and onboarding. Combinations of forged documents and deepfakes aimed at the automated checks that open bank accounts, verify customers and grant access.
Why visual inspection and fraud detection now fail
Two defences most organisations still rely on — checking whether a document looks right, and detecting fakes after they arrive — both fail against generative AI. The first fails because a generated document has no visible flaws to catch. The second fails because detection is an arms race against models that improve faster than the detectors chasing them.
Human inspection was never rigorous, but it worked well enough while good fakes were rare and expensive. That condition has gone. In a 2025 iProov study, people correctly identified high-quality deepfakes only about a quarter of the time, and just 0.1% spotted every fake they were shown; a static PDF or scan carries even fewer cues than video. Automated detection helps, but it is reactive by design: every detector is trained on yesterday’s fakes while generative models release new versions constantly. Watermarking and provenance signals on AI outputs are useful, yet professional fraudsters strip or avoid them.
The deeper problem is that all of these approaches ask the same losing question: does this artefact look genuine? Once anything can be made to look genuine, the question stops telling you anything.
Who is most exposed
The organisations most exposed are those that accept high-stakes documents from people they cannot meet in person: education, financial services, government, and recruitment.
In education, degree and certificate fraud undermines admissions and hiring alike; we cover the scale of it in the Digital Credentials in Education guide. In financial services and regulated onboarding, forged documents and deepfakes target the KYC checks that open accounts. In government and licensing, fraudulent permits, business licences and identity documents carry real downstream authority. And in recruitment and HR, fabricated qualifications and references clear checks that were only ever a visual glance.
The wider exposure: anyone running an agentic workflow
Agentic workflows extend that exposure from a few sectors to almost any organisation automating document handling. When an AI agent, rather than a person, receives and acts on documents, an unverified file becomes both a fraud risk and a security risk. Two problems arise, and they compound.
First, fraud that clears automated checks. An agent processing applications, invoices or onboarding documents runs whatever checks it was given. If those checks amount to reading a document and judging whether it looks right, a generated fake passes an agent as easily as it passes a person, and far faster and at greater scale. Sumsub’s 2025 report warns that agentic AI scams are set to surge in 2026, with a single agent able to orchestrate a whole fraud chain, from generating a fake ID document to passing a live selfie check with a deepfake video, at machine speed.
Second, and less obvious, the document itself can be the attack. Large language models cannot reliably separate the instructions they are meant to follow from the data they are meant to process. A file that looks like an ordinary invoice or CV can carry hidden instructions that an agent, on ingesting it, executes as commands. This is indirect prompt injection, and it sits at number one on the OWASP Top 10 for LLM Applications (2025). A single poisoned document can compromise every workflow that processes it, and security researchers have already observed these attacks in the wild. OpenAI has said prompt injection is “unlikely to ever be fully ‘solved’”, because it stems from how these models take in text, treating trusted instructions and untrusted data alike.
Both problems share a root cause and a fix. If an agent cannot establish where a document came from and whether it is authentic before acting on it, it is exposed. The organisations adopting agentic workflows fastest are not only the traditional fraud targets, which is why exposure now reaches well beyond the sectors above.
What actually works: verifying, not inspecting
The durable defence is to verify a document’s origin cryptographically rather than judge its appearance. A Verifiable Credential proves who issued a document and that it has not been altered, so authenticity can be confirmed in seconds by a person or a machine, no matter how convincing a forgery looks.
A Verifiable Credential is a digital document signed by its issuer using a cryptographic key, similar to a seal that cannot be copied or reused. When a recipient receives one, their software checks the signature against the issuer’s published key. If a single character has been changed, or the document did not come from the claimed issuer, the check fails. There is nothing to inspect and nothing to detect: the credential either verifies against its issuer or it does not. We explain the receiving side of this flow in how verification works for a Verifiable Credential.
This moves the question from “does this look genuine?”, which generative AI has made unanswerable, to “was this issued by who it claims, and is it unaltered?”, which cryptography answers definitively. It also addresses the agentic problem directly: an agent can require every incoming document to be a Verifiable Credential and refuse to act on anything that does not verify, closing the fraud route and the prompt-injection route at once.
Accredify builds on open standards, including W3C Verifiable Credentials and OpenAttestation. It is the model behind Singapore’s HealthCerts and the verifiable business records issued with government bodies such as ACRA — credentials designed to be checked by anyone, instantly, without contacting the issuer.
See how Accredify’s TrustView lets people and systems verify a credential’s authenticity in seconds, cryptographically, without inspecting a single pixel.
Learn more about TrustView →What organisations should do now
The practical response is to stop treating appearance as evidence and move high-stakes documents to a verifiable format. What that means depends on your role.
Issuers
Organisations that produce documents others must trust — a certificate, licence, statement or record — should issue them as Verifiable Credentials, so recipients can check them rather than judge them.
Verifiers
Organisations that receive and check documents should stop relying on visual checks for anything consequential. Where a decision depends on a document being genuine, a look-and-see check is no longer evidence: ask for a verifiable version, or a way to confirm the original with the issuer.
Processors
Organisations automating document handling should verify a document’s origin and integrity before an agent ingests it, not after.
None of this means every document needs cryptographic assurance. Plenty do not, and it is worth being honest about where the effort is warranted rather than applying it everywhere. The case is strongest wherever a forged document could cause real harm, or wherever a machine, not a person, is the one deciding to trust it.
Accredify works with governments, institutions and businesses across Southeast Asia and the Middle East to issue Verifiable Credentials built on open standards. If document fraud is a risk you are trying to manage, talk to our team about a pilot.
Schedule a demo →Frequently asked questions
Can AI create fake certificates and IDs?
Yes. Generative AI tools can produce photorealistic certificates, diplomas, IDs and financial documents from a short prompt, with plausible logos, layouts and signatures. What used to require a skilled forger now takes seconds.
Can you detect an AI-generated document?
Not reliably. Human reviewers miss high-quality fakes most of the time, and automated detectors are always trained on older fakes while generative models keep improving. Detection can reduce the volume of fraud, but it cannot be depended on for high-stakes decisions.
Is a PDF or scanned document safe from forgery?
No. A static PDF or scan carries no proof of who created it or whether it has been altered, which makes it one of the easiest formats to forge. A Verifiable Credential, by contrast, is cryptographically signed and any change breaks the signature.
How is document fraud a security risk for AI agents?
In two ways. A fraudulent document can pass an agent’s automated checks the same way it passes a person’s, and a malicious file can carry hidden instructions that the agent executes when it reads the file. This second route, indirect prompt injection, is the top risk on the OWASP list for LLM applications. Verifying a document’s origin before an agent acts on it addresses both.
How do Verifiable Credentials prevent document fraud?
A Verifiable Credential is signed by its issuer with a cryptographic key. Anyone receiving it can confirm in seconds that it came from the claimed issuer and has not been changed, without inspecting how it looks or contacting the issuer. Authenticity becomes a check, not a judgement.