CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
ai-regulationBy Cara Candelario

Non-Documentary Identity Verification: What Strahler Changed

First Federal Deepfake Conviction Puts Every Investigator's Methodology on Trial
A digital forensic scene illustrates online identity verification challenges highlighted by the Strahler deepfake conviction.

Quick answer

What is online identity verification and how does it work?

Online identity verification confirms that a person is who they claim to be without meeting them face to face. It usually combines an ID document check, a selfie or face comparison, liveness detection and database cross-referencing. Using several independent checks matters because any single one, including a face match, can be spoofed by synthetic media.

A Columbus, Ohio man named James Strahler II just made history, not the kind anyone wants. He became the first person convicted under the Take It Down Act, a 2025 federal law targeting non-consensual AI deepfakes. Prosecutors proved he used more than 100 AI models to generate and distribute fabricated intimate imagery of at least six women and multiple children. That conviction didn't just end his freedom, it sent a signal to every investigator, attorney, and fraud examiner working digital identity cases: the era of "it looks like them" is over.

TL;DR

The first federal deepfake conviction, combined with a wave of age verification mandates and 169 new laws since 2022, means investigators must now pair facial comparison with documented ID verification steps, or risk having their methodology torn apart in court.

The Strahler case is the tip of a very large iceberg. According to deepfake legislative data compiled by Programs.com, 169 laws addressing deepfakes have been passed since 2022, and 2025 alone saw nearly 150 new bills introduced at the state level. At least 45 states now have some form of deepfake-specific legislation on the books. That's not a trend, that's a tidal wave. And it's moving faster than most investigators have updated their intake workflows.

How Strahler's Case Changed AI Identity Verification

Here's the part that matters most for anyone doing identity work: to secure a conviction on counts related to "publication of digital forgeries," prosecutors in the Strahler case had to prove the content was synthetically generated. That's a technical evidentiary argument. It required establishing authenticity, or lack of it, as a forensic fact, not a visual impression.

That standard is now precedent. Not just for criminal prosecutors, but for civil litigators, insurance defense teams, and compliance investigators who are about to start asking the same question in depositions: How exactly did you determine that face was real? This article is part of a series, start with China Made Creating A Deepfake The Crime Not Sharing It U S .

81%
of reported AI fraud cases in recent analysis were driven by deepfake technology
Source: Regula Forensics Q1 2026 Identity Verification Report

That number, 81% of 132 documented AI fraud cases tied to deepfakes, comes from Regula Forensics' Q1 2026 identity verification review, and it demolishes the old mental model where deepfakes were a niche celebrity problem. They're now the dominant method in AI-assisted fraud. If you're investigating a financial crime, an insurance claim, or a corporate identity dispute, the odds are genuinely better-than-even that synthetic media is somewhere in your case files, whether you've spotted it or not.

"One check or one security layer is not enough, verification flows can also fail when the overall configuration is too relaxed for the level of risk, and the next wave of identity fraud will not rely on one forged document or one deepfake alone, but on fast, repeated attempts that test which controls are easiest to get through." Industry analysis, Shufti Pro

Read that twice. "Fast, repeated attempts that test which controls are easiest to get through." That's not a compliance warning, that's a description of how sophisticated fraud actors actually operate. And it means investigators who rely on a single-point facial comparison check are handing adversaries a map of their weak spots.

How Platforms Verify Online Identity After Strahler Conviction

While the Strahler conviction grabbed the headlines, two other developments this year deserve equal attention from investigators, because they'll affect where your evidence lives and how long it stays there.

First, platforms are getting age verification mandates at scale. Greece announced mandatory social media age verification with a push for EU-wide tools. Roblox rolled out its own verification system to protect minors. Brazil's Digital ECA, which took effect in March 2026, now requires every operating system, app store, and gaming platform accessible to minors to implement age verification, with fines up to R$50 million for non-compliance. Rest of World's deep dive on these rollouts found that minors are already using VPNs and AI-generated selfies to bypass verification flows, which tells you exactly how quickly the offense adapts to the defense.

Second, and this one is operationally critical, the Take It Down Act requires covered platforms to remove reported non-consensual material within 48 hours. As the Washington Times reported in its coverage of the Strahler case, platforms were required to have formal removal processes in place by May 19th. Think about what that means mid-investigation. You identify a deepfake on a social platform as key evidence. A victim or their attorney files a removal request. Forty-eight hours later, your evidence is gone, legally and permanently. Investigators who aren't screenshot-and-archiving immediately, with metadata intact, are going to lose critical chain-of-custody documentation. Previously in this series: Investigators Cant Explain Their Own Facial Recognition Evid.

What This Regulatory Wave Actually Changes Day-to-Day

  • ⚡ Evidence preservation windows just got shorterThe 48-hour platform takedown requirement means you must archive social media evidence immediately on discovery, with full metadata, not "when you get to it"
  • 📊 Facial comparison alone won't hold upCourts and clients will increasingly expect documented ID cross-reference steps alongside any facial match finding, not just a visual assessment
  • 🔮 Geographic complexity is multiplying fastWith 45 states now having deepfake laws and 169 statutes since 2022, case admissibility standards vary significantly by jurisdiction, your methodology needs to be documented well enough to satisfy the strictest venue you might end up in
  • 🛡️ Multi-layer verification is now the baseline, not a premium featureBiometric matching needs to be layered with liveness detection and ID document cross-referencing; single-point comparison is a liability, not a methodology
Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

The Bank Account Problem Nobody's Talking About

Here's a case that should be keeping investigators up at night. In the Netherlands, a fraudster opened 46 separate ABN AMRO bank accounts, all in other people's names, by using deepfake technology to defeat the bank's facial recognition checks. Forty-six accounts. The same face-matching system that's supposed to guarantee identity was the exact attack surface that got exploited.

This matters for investigators because it destroys a core assumption: that a face successfully matched to an ID document is a verified person. It's not. Not anymore. It's a face successfully matched to a document, and both of those can be synthetic if your detection layer isn't checking for liveness signals and metadata consistency simultaneously.

This is precisely where tools like CaraComp's facial comparison platform, built with audit trails and documented methodology baked in, become operationally relevant rather than just convenient. Courts aren't going to accept "I ran the photo through a tool and got a match." They're going to want to know what the tool checked, how it checked it, and what the documented confidence level was. That's a workflow question as much as a technology question.


The Standard Is Shifting, With or Without You

Look, nobody is saying this is simple. The verification burden is real. Liveness detection adds friction. Multi-factor identity checks take longer. And deepfake creators, as Rest of World's reporting on age verification bypass makes painfully clear, evolve faster than the detection systems chasing them.

But here's the thing about regulatory waves: they don't wait for practitioners to feel ready. The Take It Down Act is live. The state-level patchwork is live. Greece is rolling out EU-pressure-tested age verification right now. USCIS is exploring remote identity verification for immigration services. Brazil's fines are already on the books. The infrastructure of verified identity is being rebuilt around you, whether or not your case intake form has caught up. Up next: Law Enforcement Biometrics Facial Comparison Compliance.

Key Takeaway

Every digital face and voice in your case files now starts as "untrusted until verified." The Strahler conviction proved that courts will demand you show your work, not just your conclusion. Investigators who document their ID cross-reference steps today will win the cases that single-check practitioners lose tomorrow.

The practical upgrade isn't complicated. It's a checklist change. Before accepting a photo or video as real evidence: archive it immediately with metadata, verify the face against a government-issued ID source where possible, run liveness detection if the media was captured digitally, and document every step in a format a judge could read. That's not a technology overhaul, it's a workflow discipline.

Investigators who build that discipline now have a genuine competitive advantage. The ones who don't will be the ones trying to explain, in a deposition two years from now, why they closed a case on a match that turned out to be generated by one of the same 100-plus AI models James Strahler had on his hard drive.

So here's the question worth sitting with: If someone handed you a photo right now and asked you to confirm the person's identity for a court filing, what's your documented process? If the answer is "I compared it to another photo," you already have your answer about what needs to change.

Document Verification: Why the ID Itself Now Needs Its Own Check

Document verification means confirming that a passport, driver's license, or other government-issued ID is genuine and unaltered before it's used to confirm someone's identity. In practice, that means checking security features, font consistency, hologram placement, and data formatting against known templates for that document type. A growing number of investigators are learning that a convincing photo match means nothing if the underlying document itself was digitally forged, so document verification has to happen as its own separate step rather than an assumed prerequisite.

Digital Verification: Moving Past a Single Photo Comparison

Digital verification covers the full set of electronic checks used to confirm a person is who they claim to be, including liveness detection, metadata analysis, and cross-referencing an ID document against a database. Unlike older methods that relied on a human reviewer eyeballing two photos side by side, digital verification pulls in multiple independent data signals so that a single spoofed input can't carry the whole decision. Investigators building a defensible file should treat digital verification as a layered process, not a single pass-or-fail moment.

Verify Identity: What "Verified" Actually Has to Mean Now

To verify identity today means producing a documented chain connecting a real person to a government-issued credential through more than one independent check. That's a higher bar than it was even two years ago, back when a facial comparison alone was often treated as sufficient. Given the ABN AMRO case and the Strahler conviction, any investigator who still equates "the faces matched" with "the identity is verified" is working from an outdated definition.

Customer Onboarding: Where Verification Gaps First Appear

Customer onboarding is the point where a new user or account holder first proves who they are, and it's also where weak verification does the most damage because it sets the baseline the rest of the relationship depends on. The ABN AMRO case shows what happens when onboarding checks lean too heavily on facial recognition alone, 46 fraudulent accounts got approved because the deepfake cleared the one check the system relied on. Strengthening customer onboarding with layered checks catches problems before an account exists, which is far cheaper than untangling fraud after the fact.

Identity Authentication: The Ongoing Check, Not Just the First One

Identity authentication is what happens every time someone who was already verified needs to prove, again, that they're still the same person accessing the account or filing the claim. It's easy to treat authentication as a one-time event that happened at signup, but the regulatory wave described above makes clear that repeat, ongoing checks matter just as much as the initial approval. Investigators reviewing a disputed case should ask not just how the person was verified once, but how authentication was handled at every subsequent touchpoint.

Non-Documentary Identity Verification Methods Investigators Should Know

Non-documentary identity verification refers to any method that confirms who someone is without relying on a physical or scanned ID document as the primary check. Instead of reading a passport or license, a non-documentary approach cross-references data the person already has on file, a phone number, an address history, a bank account, a social security number, against independent databases to see if the pieces line up. Non-documentary CIP, the customer identification program version of this idea, reduces application review time tremendously because there's no document image to inspect, no hologram to check, and no font template to compare against. Non-documentary identity verification can be achieved using multiple methods, including database cross-referencing, knowledge-based questions, and out-of-wallet verification that asks something only the real account holder would know.

For investigators, the distinction between documentary and non-documentary verification matters because each has a different failure mode. Documentary verification fails when the document itself is forged or digitally altered, the exact scenario document verification is built to catch. Non-documentary verification fails differently: it fails when the underlying data itself has already been compromised, so a bank account, address, or social security number that was stolen or spoofed passes every non-documentary check cleanly. A file built only on non-documentary methods can look complete while resting on data that was never legitimate in the first place, which is why non-doc checks work best layered alongside documentary verification rather than replacing it.

Non-Documentary CIP, KYC, and the AML Compliance Layer

KYC, know your customer, programs sit at the center of most non-documentary identity verification workflows, since KYC compliance rules are what require a bank or financial institution to confirm a customer's identity before opening an account. AML, or anti-money-laundering, requirements often run alongside KYC obligations, and both frequently accept non-documentary verification methods when a customer can't or doesn't provide a physical ID document. Contacting a customer directly to confirm details by phone is one accepted non-documentary method under many KYC and AML programs, used alongside database checks rather than instead of them.

The privacy trade-off in non-documentary verification deserves attention too. Because non-documentary methods pull data from multiple independent sources, credit bureaus, phone carriers, address records, rather than a single scanned document, more personal data touches more systems during the check. A clear privacy policy, one that explains what data gets pulled and why, helps a compliance program stay defensible if a customer or regulator asks how their information was used during onboarding. Investigators reviewing a compliance file should confirm that the privacy policy covers the specific non-documentary data sources that program actually uses, not a generic boilerplate that predates the current verification method.

Online Identity Verification Best Practices for Investigators

Online identity verification best practices now start with layering: facial comparison paired with document verification, liveness detection, and metadata review, documented at every step. Tools like id.me have built reputations around exactly this kind of layered, government-grade approach, combining ID document checks with biometric confirmation rather than relying on either alone. Any investigator building a repeatable process should model their workflow on that same layered logic, whether or not they use id.me specifically, because the courts are increasingly expecting to see the layers, not just the conclusion.

The second best practice is documentation discipline. Every check performed, the document scan, the liveness test, the database cross-reference, needs a timestamped record showing what was checked, what tool or method was used, and what the result was. This is the exact gap the Strahler case exposed: prosecutors needed forensic proof, not a visual impression, and that same standard is now migrating into civil and compliance contexts.

Investigators should also explore how account information flows between an initial verification step and later authentication events, since gaps there are where fraud tends to hide. A phone number, an account login, and a passport scan can each look fine in isolation while still adding up to a synthetic identity when reviewed together. Building the habit of cross-checking account details against the original verification record closes that gap before it becomes a courtroom problem.

Passport data deserves particular attention because it's often treated as the single most authoritative document in a verification chain, when in practice it's just one input among several. An investigator who confirms a passport number and photo without independently checking liveness or cross-referencing account information is leaving exactly the kind of single point of failure that the Shufti Pro warning above describes. Provide multiple independent checks, not one strong one, and the whole file becomes harder to attack.

Ultimately, the shift toward documented, multi-layer online identity verification isn't optional anymore, it's what courts, regulators, and platforms are already building their systems around. Investigators who explore and adopt these best practices now, before a case forces the issue, will be the ones with a file that holds up when someone asks how, exactly, identity was confirmed.

Explore the Layers Before a Case Forces the Question

Investigators who explore each layer of a verification stack ahead of time, rather than during a live dispute, build a documented identity verification habit that holds up under cross-examination. Take time to explore how facial comparison, document verification, and liveness detection interact, because a weakness in one layer often only shows up when you explore how the others compensate for it. This kind of proactive exploration is what separates a defensible online identity verification file from one that falls apart under a single pointed question.

Provide documentation at every stage of an identity verification review, not just at the final conclusion. When an investigator can provide a timestamped record of the document check, the liveness result, and the database cross-reference, a judge or opposing counsel has no room to argue that the identity verification process was a guess dressed up as a finding. Teams that provide this level of detail as a matter of routine spend far less time defending their methodology later.

Selfie verification has become one of the more common ways platforms confirm someone's identity remotely via electronic means, asking a user to submit a live selfie that gets compared against a government-issued ID photo. This kind of online process that uses digital data points, comparing presented data from the selfie against the ID's stored photo, is a useful first layer, but the Netherlands case shows that selfie verification alone can be defeated by convincing synthetic video. Investigators evaluating a platform's identity proofing setup should ask whether selfie verification stands alone or feeds into a broader digital identity verification chain that also checks liveness and document authenticity, and whether that chain also satisfies non-documentary verification requirements where a physical ID isn't available.

Identity verification helps confirm that users are who they claim to be, and in practice that confirmation increasingly depends on documents beyond a driver's license or passport photo page. Some verification flows now enter your social security number as an additional cross-reference point, matching it against other records to confirm the applicant's history lines up with the claimed identity, a document-free verification path that non-documentary identity verification programs rely on when a scanned ID isn't practical. Investigators reviewing a customer file should note which documents were checked, since a single document, even a government-issued one, is only as strong as the process used to verify it against other data.

Building a stronger customer verification habit also means paying attention to how many independent documents were checked before an account or claim was approved. A customer who provides a passport, a utility bill, and a selfie that all cross-reference cleanly presents a far stronger identity verification case than one confirmed by a single document. Investigators should document which documents were reviewed, what the presented data showed, and how each piece compares against the others, since that comparison record is exactly what a court will ask to see.

Non-documentary verification and documentary verification are not competing systems, they are complementary layers that cover each other's blind spots. A compliance program that treats documentary verification as the default and reserves non-documentary methods for edge cases where a customer lacks acceptable ID documents tends to build the strongest file, because it forces reviewers to justify which method they used and why. When both nondocumentary identity checks and documentary checks point to the same person, that agreement between two independent data paths is far harder to challenge in court than either method standing alone. Investigators drafting an internal verification policy should spell out, in plain language, which situations call for documentary verification, which call for non-documentary verification, and which call for both run side by side before a case is closed.

Frequently asked questions

What is online identity verification and why is it changing?

Online identity verification is the process of confirming a person is who they claim to be, typically through facial comparison and ID document checks. It is changing because the Strahler deepfake conviction, 169 new deepfake laws since 2022, and mandates like Brazil's Digital ECA are pushing investigators and platforms toward documented, multi-layer verification instead of a single visual facial match.

Can deepfakes bypass online identity verification systems?

Yes. In the Netherlands, a fraudster opened 46 separate ABN AMRO bank accounts in other people's names by using deepfake technology to defeat facial recognition checks. This shows that a face matched to an ID document is not proof of a real person, since both the face and the document can be synthetic if liveness and metadata checks are missing.

How long do platforms have to remove deepfake content under the Take It Down Act?

Covered platforms must remove reported non-consensual material within 48 hours, with formal removal processes required by May 19th. This shortens the window for investigators to preserve evidence, since content tied to a deepfake case can be legally and permanently removed before proper documentation and metadata are archived.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search