US bank regulators have said for the first time that banks and credit unions may rely on mobile driver’s licences and other digital credentials to check who a new customer really is. The Financial Crimes Enforcement Network issued the position jointly with the Federal Reserve, the Federal Deposit Insurance Corporation, the National Credit Union Administration and the Office of the Comptroller of the Currency on 8 September 2026. The timing is pointed: digital identity verification is becoming the main battleground in a fraud fight that increasingly involves generative AI.
What changes for digital identity verification
The joint guidance answers two new questions and updates a third under the Customer Identification Program rule, the regulation that sets out how a bank confirms a new customer’s identity. It defines a verifiable digital credential as a data structure about an individual that is digitally signed by whoever issued it, cryptographically bound to a specific device and protected by an activation factor such as a PIN or a fingerprint. A state-issued mobile driver’s licence is one format of that credential.
The regulators are deliberately cautious about what this permits. The FAQ states that the CIP rule “neither requires nor prohibits reliance” on a government-issued digital credential, and a bank may only count an unexpired one as valid identification when it evidences nationality or residence and carries a photograph or similar safeguard. A bank that accepts one still has to maintain the systems needed to read it, and still has to form a reasonable belief that it knows the customer’s true identity, the same standard that applies to a physical driving licence. If the credential shows signs of tampering, that obligation does not disappear.
Where the credential comes from a source other than a government body, the bar is higher again. The FAQ makes the bank responsible for confirming that the issuer authenticates its credentials to the same standard the bank would apply itself, and points back to existing Federal Financial Institutions Examination Council guidance on authentication in electronic banking. The regulators are explicit that none of this changes existing Bank Secrecy Act requirements or creates new supervisory expectations.
The fraud problem driving the shift
The new FAQ did not appear in a vacuum. FinCEN’s alert on fraud schemes involving deepfake media, FIN-2024-Alert004, issued on 13 November 2024, remains in force and is still cited in FinCEN alerts issued this year. It describes what generative AI-enabled fraud looks like at onboarding: a photo that is internally inconsistent or conflicts with a stated date of birth, identity documents that contradict each other, a reverse-image search that traces a selfie back to a gallery of AI-generated faces, or a live verification check that keeps glitching until the customer switches to a different method. A bank filing a related suspicious activity report is told to cite the term FIN-2024-DEEPFAKEFRAUD in the filing.
Deepfake-enabled fraud is distinct from, and often confused with, synthetic identity fraud, where a fraudster builds a new identity by combining one real detail, often a Social Security number belonging to a child or someone with no credit history, with fabricated name and address details. A deepfake defeats the check that a real, present person matches their documents. Synthetic identity fraud defeats the check that the person described exists at all. Banks now have to screen for both within the same onboarding flow, often from the same selfie and document upload.
The response from identity verification vendors has been fast. iProov, Mitek, Incode, Socure and Jumio have each published new deepfake-detection guidance so far this year, a sign of how central the threat has become to the sector’s own marketing, even in cases where a specific bank or credit union partnership has not been disclosed publicly.
How banks and credit unions are responding
Some of the clearest evidence of what this is costing, and what works against it, comes from account activity rather than onboarding. Alkami Technology, a digital banking platform used by US banks and credit unions, said on 9 October 2026 that customers running BioCatch’s behavioural biometrics through its platform prevented more than $263 million in fraud during 2025. BioCatch does not check a customer’s identity document. It builds a baseline of how a genuine account holder types, scrolls and navigates, then flags sessions that deviate from it, a different layer of defence from the document and liveness checks used at onboarding.
Two of Alkami’s customers published their own results. Gate City Bank reported a 97% account takeover capture rate and $650,000 in deterred fraud losses over six months. Raiz Federal Credit Union said it prevented more than $286,000 in fraud in its first year of running the tool, alongside other layered security measures. “Effective fraud prevention ultimately comes down to recognising risk early enough to do something about it,” said Jay Whoriskey, BioCatch’s vice president of global partners and alliances, in the announcement.
A parallel push outside the US
The US is not alone in rethinking how a bank confirms who a customer is. In the UK, six major banking groups are preparing to pilot a service that would let customers prove their identity to third parties using data their own bank already holds, a different route to a similar goal: fewer standalone document checks, more reliance on information an institution already trusts.
For US banks, the practical question is no longer whether to use digital identity tools but how to combine them. A mobile driver’s licence can now clear a regulatory bar at onboarding that it could not clear before September 2026, the deepfake red flags from a 2024 alert still have to be checked against every new photo and video submitted, and behavioural biometrics are catching fraud that document checks miss entirely. A fuller list of identity and fraud-prevention providers working with US and UK institutions is on Fintechly’s regtech sector directory.