That "99% Accurate" Badge Protecting Your Bank Account? It Expired Months Ago
Here's a fact that should bother you more than it probably does: a security system can be completely accurate and completely obsolete at the same time.
Not broken. Not hacked. Just... tested against the wrong threats. Certified in January against fraud methods that fraudsters abandoned by March. Still displaying its "99% accuracy" badge while the people it's supposed to stop have already moved on to six new techniques it's never seen.
That's not a hypothetical. That's the current state of identity verification — the systems that decide whether the face on your screen is really you.
Identity fraud now evolves faster than the tests used to catch it — so an "AI-powered" accuracy claim tells you almost nothing unless you also know when it was last tested against current fraud methods.
The Lock That Passed Every Test (Against Last Year's Burglars)
Imagine a company makes a door lock. They test it in January against every known break-in technique. It blocks all of them. They announce: "99% secure." Great.
By June, burglars have moved on. They're using six new tools the lock company never tested against. The lock hasn't changed. The threat has.
Now ask yourself: does that 99% number still mean anything?
That's exactly what's happening with identity verification right now. The tools that check whether you are who you say you are — the face scans, document checks, and "selfie match" steps you do when you open a bank account or verify your age — get tested, scored, and certified. Then they go live. And fraud keeps moving. This article is part of a series — start with Face Detection Before Identification How Facial Analysis Act.
The gap between those two things is the problem nobody talks about when an app brags about being "AI-powered."
Why Fraud Now Moves at Machine Speed
Here's what changed. Fraud used to require effort. A criminal had to manually create a fake ID, scout a target, figure out what worked. That took time. That time gave defenders a chance to catch up.
Not anymore.
Today's fraud operates more like a startup running A/B tests (that's the practice of trying two slightly different versions of something to see which one performs better — except here, "performing better" means getting past your bank's security). Attackers deploy hundreds of variations simultaneously. They adjust the lighting on a fake selfie, tweak a synthetic identity's address, change a payment method. Automation tracks which variations slip through. The ones that work get scaled immediately across thousands of targets.
This is what researchers call a "continuous test-and-learn cycle." And it's not a metaphor — it's literally how modern fraud operations run, according to reporting from Adyen's 2026 Fraud Report. The fraudsters are running experiments. The defenders are reading last quarter's results.
The cost collapse made this possible. Deepfake images, fake voices, synthetic identities built from scratch — you can access all of that for as little as $5, according to Protegrity's 2026 analysis. When attacking costs almost nothing, attackers can afford to try everything. When defending costs millions in engineering time, defenders can't possibly match that pace with old-school annual reviews.
Let that sink in. Deepfakes went from "a thing we're worried about" to "one in every five fraud attempts" in less than two years. And injection attacks — where fraudsters bypass the camera entirely and feed a fake video stream directly into the verification system — surged 40% year-over-year, according to Entrust's 2026 Identity Fraud Report. These aren't slow trends. This is a monthly redraw of the threat map. Previously in this series: A Fake Video Of Your Boss Just Dropped Do These 3 Things Bef.
The Misconception That Makes "99% Accurate" Sound Better Than It Is
Here's why people trust accuracy numbers — and why that trust is misplaced in this specific situation.
When you hear "99% accurate," your brain does something totally reasonable. It treats accuracy like a physical property. A thermometer that reads temperature correctly in January still reads it correctly in June. A ruler that measures twelve inches in 2024 measures twelve inches in 2025. Accuracy sounds stable, like a fact about the tool itself.
That instinct is correct for most things. It's wrong for identity verification.
In this context, accuracy isn't a fixed property of the technology. It's a score the technology earned against a specific set of fraud methods that existed at a specific point in time. Train a system to catch stolen photos and document forgeries, test it against those threats, and it might genuinely score 99%. Then a new attack category appears — say, AI-generated synthetic faces that don't belong to any real person — and suddenly the system is evaluating something it was never taught to recognize. The accuracy hasn't "dropped." The system has been outmaneuvered by something outside its test parameters.
Researchers call this "signature drift" — the idea that fraud patterns shift so fast that the rules a system learned become outdated before teams even have time to update them. As Protegrity puts it, static defenses expire not because they fail, but because the threat moves past them.
It's not that the tool got worse. It's that the world changed around it.
"What worked yesterday can be bypassed tomorrow, with patterns of fraud changing so rapidly that rule engines expire before teams have time to update them." — Protegrity, AI Fraud Detection in 2026
The Real Question Nobody Thinks to Ask
So what do you actually do with this information? Up next: Before Facial Recognition Names You It Has To Find You And T.
The shift happening across the identity verification industry right now — documented in detail by Biometric Update — is a move away from one-time accuracy claims toward continuous testing. Instead of "we scored 99% in our last evaluation," the better question is: "how often do you re-test against new fraud methods, and when was the last time you did?"
Think of it like food safety. You wouldn't trust a restaurant that says "we passed a health inspection in 2022." You want to know when the last inspection was — and whether the inspector knew what to look for this year.
Identity verification is heading toward the same logic. Static certifications are losing meaning. The tools that deserve trust are the ones that can show their testing is ongoing — continuously updated against the fraud techniques that exist today, not the ones that existed when the product launched.
At CaraComp, this is exactly the kind of gap that matters when evaluating any system making facial comparisons — whether that's verifying someone's identity at account opening or checking whether two images are the same person. A system's accuracy in controlled conditions can drop anywhere from 10% to 40% in real-world production environments, according to TechnoLynx research on facial recognition deployment. Add an evolving fraud environment and that gap gets wider. The right question was never just "how accurate?" It was always "accurate against what, and when?"
What You Just Learned
- 🧠 Accuracy is conditional, not fixed — a tool's accuracy score is tied to the fraud methods it was tested against, not a permanent property of the technology
- 🔬 Fraud now runs like software — attackers use automated test-and-learn cycles to find weaknesses faster than defenders can update their defenses
- 💡 The speed is the problem — deepfakes went from emerging to one in five fraud attempts in under two years; annual testing cycles can't keep pace with that
- 🧠 The right filter — don't ask "how accurate is this system?"; ask "when was it last tested against fraud methods that exist right now?"
"AI-powered" tells you nothing useful about a security system. The question that actually matters is whether it's being tested against the fraud methods that exist this month — not the ones it was designed to catch two years ago. Accuracy expires. Testing schedules don't lie.
Next time an app or service asks you to verify your identity and drops some version of "advanced AI security" in the fine print — know that this phrase tells you almost nothing. A system trained on last year's attacks, tested once, and left untouched is still "AI-powered." It's just AI-powered against threats that might not be the ones trying to get through the door anymore.
The badge that would actually mean something? "Last tested: this quarter, against current methods." You'll almost never see it. But now you know to wonder why.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
"Certified Safe" Doesn't Mean What You Think — And Your Face Is In the Database
When a company says it's "cyber certified," most people assume that means their data is protected. Here's what that label actually proves — and what it doesn't.
biometricsThat Voice on the Phone Isn't Your Boss — and Your Eyes Can't Save You
Companies are now running fake deepfake attacks on their own employees — and the goal isn't to catch anyone out. It's to build one 10-second habit that stops real attackers cold. Here's the science behind why it works.
facial-recognitionA Fake Moustache Just Broke the AI That's Guarding Your Kids Online
A high facial recognition score sounds definitive — but researchers just showed that adding a moustache or some eye makeup can break certain systems entirely. Here's what that means for anyone who relies on photo-based identity checks.
