Protecting citizen identity: Why secure biometric enrolment matters in the deepfake era

  • Public Security
  • Civil identity

© wondercorp © Thales

  • Type Insight
  • Published

As deepfakes and AI-enabled identity fraud become more sophisticated, governments are rethinking where identity security begins. Discover why biometric enrolment has become a critical point of trust, how technologies such as live capture, morph detection and biometric recognition strengthen resilience, and why a layered approach is essential to protecting digital identity.

Discussions about secure identity documents often focus on the security features embedded within passports and national identity cards. Yet one critical stage of the identity lifecycle is attracting increasing attention: biometric enrolment.

As governments expand digital identity services and adopt biometric technologies, enrolment has become fundamental to maintaining trust. Even the most secure credential is only as reliable as the biometric data used to create it.

At the same time, deepfakes, face morphing and increasingly sophisticated image manipulation techniques are becoming more accessible, creating new challenges for organisations responsible for issuing trusted identities.

More than ever, the question is not only how to protect identity documents, but also how to ensure the actual identity behind them is genuine from the very beginning.

Why enrolment deserves greater attention

For many years, identity programmes have focused on protecting issued credentials through advanced physical and digital security features. While these remain essential, they address only part of the challenge.

Enrolment is the point at which an individual's identity first enters an official system. If manipulated biometric data is accepted at this first stage, the resulting passport or identity card may be genuine despite having been obtained fraudulently.

This risk has grown as synthetic media evolves. It had been estimated that between the years of 2023 and 2025, AI created deepfake content increased from 500,000 to approximately eight million in 2025. An issue impacting both consumers and businesses: studies suggest people correctly identify deepfakes less than a quarter of the time and Thales’ 2026 Data Threat Report found that 59% of organisations had experienced a deepfake attack in the past year. 

As AI tools continue to make sophisticated image manipulation available to a much wider audience, protecting identity increasingly depends on preventing manipulated biometric information from entering systems in the first place.

© Adrien Daste - Thales

Understanding the evolving threat

Part of the challenge stems from the various forms that AI-enabled identity fraud can take. 

For example, face morphing is a specific deepfake which combines the facial characteristics of two people into a single image. If that image is used during enrolment, the resulting genuine document may subsequently be used by both individuals.

While morphing attacks are not new, generative AI has significantly lowered the technical expertise required to create convincing images. Combined with widely available editing tools, manipulated photographs are becoming increasingly difficult to detect through visual inspection alone.

To address this challenge, Morph Attack Detection (MAD) technologies analyse images for signs of manipulation, either by assessing a single image (S-MAD) or comparing it with a trusted biometric sample (D-MAD). However, as the NIST concludes in its report, the most effective defence is to prevent morphs from getting into operational systems in the first place with live enrolment.

Building resilience into enrolment

The strongest defence starts with live biometric enrolment, providing an important foundation by capturing biometric data directly from the applicant rather than relying on externally supplied photographs. This significantly reduces opportunities for manipulation.

From there, multiple layers of protection work together.

Presentation Attack Detection (PAD) provides an essential safeguard by identifying attempts to spoof biometric systems using photographs, masks, videos or artificial fingerprints. Moreover, biometric recognition compares applicants against trusted identity databases or a previous biometric-enabled credential to identify duplicate or suspicious enrolment attempts.

Together with trained officers, these capabilities create a far more resilient enrolment process than any single technology alone.

Learning from evolving enrolment practices

Technology is only part of the picture. Regulation and operational processes also shape the resilience of biometric enrolment.

Germany provides a strong example. As of 2025, new legislation requires photographs for identity documents to be captured digitally, either directly by issuing authorities or securely transmitted by certified photographers. Combined with the rollout of more than 8,000 automated biometric capture systems across around 6,000 municipalities, the approach significantly reduces opportunities for image manipulation.

Elsewhere across Europe, approaches remain varied. Sweden has deployed automated biometric kiosks since 2005, Spain has introduced live enrolment more recently, while some countries continue to rely on paper photographs supplied by applicants and scanned during the application process.

The direction is clear: live enrolment with trusted biometric capture and layered security approach are becoming the new benchmark. 

© wondercorp © Thales

Building trust from the very beginning

As digital identity services continue to expand, biometric enrolment is becoming a strategic capability rather than simply an administrative step.

Success depends on combining live capture, automated fraud attempt detection, biometric recognition and skilled personnel into a single enrolment strategy. Each layer addresses a different risk, creating greater confidence that the identity being enrolled genuinely belongs to the individual presenting it. 

At Thales, secure enrolment forms part of a broader approach to trusted digital identity. By combining advanced technologies and operational expertise, Thales is helping governments strengthen identity systems against emerging threats while maintaining trust across the entire identity lifecycle.

Receive the latest Cyber and Digital insights straight to your mailbox

Related Articles

  • Public Security

Championing International ID Day’s Core Pillars

Insight
Person presenting ID card during identity check
  • Public Security

Why transportation must become the next frontier in sustainable identity documents

Insight
Digital Identity wallet on smartphone
  • Public Security

Trusted Travel in the Digital Age: The future of biometrics and border management

Insight
  • Public Security

How OS and crypto agility strengthen identity security

Insight
  • Public Security

The importance of Post-Quantum Cryptography for eID documents

Insight
  • Europe

Mobile Identity Done Right: Why Distributed Digital Credentials Are the Future of Citizen Identity

Insight
  • Group

Vision4Rescue deployed by Paris Fire Brigade in major nighttime exercise

Insight
  • Public Security

Transforming Driver Services: Secure Identity Solutions for North American Agencies

Insight
Thales eGate Eurostar
  • Border control

The border security iceberg effect

Insight