PLATFORM

The Liminal MCP brings verified market intelligence into your AI tools

Read More

Blog

Doug Aley on why adaptability will define the next 12-18 months in identity security 

September 3, 2026

Doug Aley, CEO of Paravision, speaking on Liminal's Friday Five about identity security adaptability and AI deepfakes.

The conversation around deepfakes often focuses on the latest breakthrough. A new generative AI model is released, synthetic media becomes more convincing, and the headlines ask whether defenders can keep up.

That question gets at the right concern, but I think it misses the bigger issue. The challenge isn’t any single AI model or attack technique. It’s building security systems and operating models that can keep pace as the threat landscape continuously changes.

Deepfakes are evolving. Generative AI is making synthetic content easier to create and harder to distinguish from authentic media. Morphing attacks continue to challenge identity systems. Injection attacks are creating new ways for attackers to manipulate the verification process itself.

For organizations that rely on identity verification, security can’t be treated as a static capability tested once and deployed indefinitely. The systems, and the technology partners behind them, will increasingly need to evolve as quickly as the threats do.

I’m the CEO of Paravision, where we build face recognition and fraud-preventing AI tools for identity verification providers, financial institutions, and governments operating at global scale. Filip Verley recently asked me five quick questions for Liminal’s Friday Five, and when he asked what will matter most over the next 12 to 18 months, my answer was simple: organizations need to prepare for continuous innovation in AI-generated attacks.

Friday Five: Face Recognition Should Work for Everyone | Doug Aley, CEO at Paravision

AI-generated attacks are evolving faster than traditional security cycles

Generative AI has fundamentally changed what attackers can create, and how quickly they can create it.

As new models improve the realism of synthetic faces, video, and other media, techniques that once required specialized expertise are becoming increasingly accessible. Those same advances can make morphing and other forms of synthetic identity manipulation more sophisticated. Beyond synthetic media, attackers are also targeting the verification process itself through injection attacks and other forms of manipulation.

The important point isn’t whether one particular model is better than the last. It’s that new capabilities keep coming. A system that performed well against the attacks being tested six months ago may need to be reevaluated when new generative models or attack techniques emerge.

Continuous benchmarking needs to become operational

Preparing for this environment isn’t just about building a better detection model, but creating the infrastructure to understand when that model needs to change.

When a new generative AI model or attack technique emerges, providers will need to build the capability to test against it, benchmark existing performance, make improvements where necessary, and validate those improvements quickly.

For buyers of identity technology, this changes what they should start expecting from vendors in the future. While current performance in benchmarks still matters, so does the ability to respond when that performance is challenged.

How quickly can a technology provider evaluate a new attack technique? How frequently does it benchmark its models? Does it have the infrastructure and engineering resources to retrain, validate, and deploy improvements without long development cycles?

These are increasingly important questions to ask when evaluating identity technology partners.

What to look for in an identity security partner

It’s unrealistic for identity providers, financial institutions, and governments to accurately predict exactly which AI attack will emerge next. They do need to start making sure their technology ecosystem is prepared to respond when it does. That means looking beyond a partner’s current benchmark scores and understanding how it approaches innovation. Does it actively research emerging threats? How quickly can it incorporate new attack techniques into testing? Can it update models and defenses without waiting for a rigid product cycle? Does it have the engineering and infrastructure to support ongoing evolution at scale?

A single benchmark result is only a snapshot in time, but consistency across benchmarks over multiple years and submissions can also be a strong signal of sustained innovation and an ability to keep pace with evolving threats. The distinction matters because even strong performance today may not guarantee resilience as new generative models, morphing techniques, or injection attacks emerge.

The good news is that the same advances in AI that give attackers new capabilities can give defenders new tools. The strongest technology partners will be the ones that have the ability and willingness to turn those advances into better protection quickly, and keep doing so as the threat landscape changes.

For buyers, adaptability is likely to become an important evaluation factor alongside accuracy, performance, and scale. The question isn’t simply, Can this technology stop today’s attack? It will also become: Will this partner be ready for tomorrow’s attack?

In the coming months and years, that ability to continuously innovate may be one of the most important factors in maintaining trust in digital identity.

Key takeaways

  • The threat is bigger than deepfakes alone. Generative AI is advancing deepfakes, synthetic identities, and other techniques that can undermine identity verification.
  • Continuous benchmarking is essential. Identity systems need to be evaluated against new attack techniques as they emerge, not just against the threats that existed when a system was deployed.
  • Adaptability should be a vendor-selection criterion. Buyers should evaluate not only current performance, but how quickly a technology partner can test, improve, and deploy defenses.
  • The best partners won’t just react. They will have the infrastructure, expertise, and operating model to turn advances in AI into better defenses as the threat landscape evolves.

Image of Doug Aley - CEO of Paravision authoring a blog article about identity security adaptability.
Doug Aley
CEO at Paravision

Doug Aley is the CEO of Paravision, which builds face recognition, liveness, deepfake detection, injection attack detection, and age estimation technology for large-scale identity verification providers, financial institutions, and governments. Prior to his role as CEO, Aley built and grew innovative products and services at companies such as Amazon, Zulily, Minted, and Level Access, as well as at several startups he founded or joined early on.

Want real-time, personalized insights?

Get full access to real-time competitor tracking, buyer signals, and personalized intelligence delivered straight into your workflow.

introducing-liminal-mcp

PLATFORM

The Liminal MCP is live

Query Liminal's verified market intelligence from the AI tools your teams already work in.

Read more