Invest1 distinct publisher3 min readUpdated
The AI Act's tagging duty is live. The rules that would make biometric verification vendors prove they resist manipulation are not, and fraud does not label itself.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
Last week the EU's transparency rules for synthetic content came into force, requiring that AI-generated material carry a machine-readable tag [3][4]. The obligations that would hold the systems banks use to check a customer's face or voice to a standard of manipulation resistance did not arrive with them, and that gap is where the fraud actually lives [9][10].
The argument comes from an opinion piece in American Banker by a deepfake forensics practitioner based in Amsterdam, who founded a detection company after a close friend's likeness was used in a romance scam [1][12]. Their point about Article 50 is structural rather than technical: the tagging duty catches synthetic content that wants to be noticed, while fraud runs on the opposite logic and needs discretion [5]. Nobody attacking a bank's onboarding flow is going to attach the marker that identifies them, and the author is explicit that this is a boundary of the rule rather than a defect in it [5][15].
The consequential detail is a definitional one. Biometric identification, matching a face or voice against a database of many, appears on the AI Act's high-risk list [6]. Biometric verification, checking one person against their own record, does not [6]. Verification is the cheaper, faster one-to-one check, and it is increasingly the mechanism for onboarding remote customers [7]. The author cites a trial in the Netherlands earlier this year in which the check the bank relied on was precisely that unregulated category [8].
Compliance teams may read an exemption as relief. The author argues the opposite: high-risk classification would eventually require providers to demonstrate greater resilience against manipulation, and verification vendors will not be held to that [9][16]. The industry has built its identity layer on the assumption that a voice or a face is sufficient evidence of who someone is, and AI has broken that assumption [2]. What has not happened, in the author's view, is any requirement that verification platforms carry liability for their own system errors [14].
The timing compounds it. The high-risk obligations were originally meant to land alongside Article 50 and were pushed back, so for roughly the next year banks operate under a regime that tells them to label AI-generated material while leaving the systems they depend on unaccountable [10][17]. The proposed fix is narrow and worth noting for its modesty: add biometric verification to Annex III [11]. That is a drafting change, not a new regulatory architecture.
For US operators this is not a foreign story. AI-driven fraud in banking is occurring on both sides of the Atlantic, banks in both markets are buying the same categories of defensive technology, and the author expects US rules to follow Europe's [13]. The EU version is simply the version you can read now.
Watch three things. Whether biometric verification gets pulled into Annex III, which would change vendor procurement questions from accuracy claims to manipulation-resistance evidence [11][9]. When the delayed high-risk obligations actually apply, because the interim is the exposure window [10]. And whether liability for verification failures starts moving from the bank to the vendor in contracts before it moves in statute [14].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The author argues that high-risk requirements would eventually mean providers falling under them must demonstrate greater resilience against manipulation, and that verification vendors will not be required to do the same.
The high-risk requirements were originally supposed to land at the same time as Article 50 but were delayed; for the next year the labelling rules are in force while the rules that would hold the systems banks use to account are not.
The author states that no good enough solution to this kind of fraud has been found in either the US or EU, and believes a big part of the reason is that verification platforms have not yet been required to be liable for their system errors.
The author notes it can be easy to assume that not classifying biometric verification as high-risk is good news for banks because less regulation means less red tape, but says they do not believe that is the case here.
An American Banker opinion piece argues that US bankers watching the rollout of the EU's AI Act should notice the gaping hole where rules about identity verification ought to be.
The banking industry has spent years building systems around the idea that someone's voice and/or face is sufficient evidence to verify who they are, and artificial intelligence completely challenges that assumption.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One opinion column, uncited law
All material rests on a single American Banker opinion piece. Its central legal assertions (Article 50 now in force, biometric verification absent from the high-risk list, high-risk duties delayed about a year, Annex III as the fix) are plausible and internally consistent but carry no citation to regulatory text, and the one concrete incident is described in truncated, unidentifiable form. No second publisher, vendor, or supervisor corroborates any element.
Rule live, usage anecdotal
There is one hard uptake fact: the AI Act transparency obligation is described as already in force, which makes the labelling duty a live compliance surface. Everything else about real-world use is anecdotal, with biometric verification's spread through remote onboarding asserted without counts, vendors, or market data, and a single unnamed Dutch trial standing in for fraud prevalence.
Framing outruns shown proof
The piece is more restrained than its headline: it explicitly predicts Article 50 will work well against synthetic content abuse and calls the limitation a boundary rather than a failure. But 'gaping hole' framing, the claim that no adequate solution exists in either jurisdiction, and the prediction that the US will soon follow all rest on unquantified assertion, one truncated court reference, and no cited legal text, so the rhetorical weight modestly exceeds the demonstrated evidence.
Detection founder urges vendor duties
The author self-identifies as a deepfake-detection practitioner who founded a company in the space, and the recommended remedy, pulling biometric verification into Annex III and making verification platforms liable for system errors, would expand demand and compliance obligations in the market their firm serves. The disclosure is voluntary and prominent, and the personal motive (a friend's likeness used in a romance scam) is stated, which partially offsets the alignment, but the company is unnamed and no competing interest is represented.
Plausible but uncorroborated
Confidence is limited by structure rather than plausibility: one publisher, one opinion source, no cited statute text, an unidentifiable incident, and an author with disclosed commercial alignment. The timing claim (labelling live, high-risk duties delayed) is the most checkable element and would raise confidence substantially if a second source or the regulation itself were present in the cluster.
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
build
The Aug 2 AI labelling rules are a provider problem. Your list is three disclosures.1 distinct publisher
build
A 14,000-star watermark remover, and no detector to test it against1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026