We live in interesting times.
Between rocket ships, record-breaking IPOs and daily headlines about AI crossing thresholds that endanger humanity, it can feel like the earth is spinning off its axis. Amidst all of it, you may have missed a smaller milestone: last week Smile ID passed 500 million identity checks since inception — roughly one in three people on the African continent.
So what do the latest AI headlines have to do with identity? Everything.
This weekend, for the first time, the bitter rivals leading three of the frontier AI labs — Anthropic, OpenAI and xAI — all agreed on something: AI is moving too fast to ensure it is safe for humans.
If the CEOs of these companies are saying they believe in third party verification to prevent the misuse of AI, then certainly your bank, marketplace or fintech app needs to ensure you are using every tool at your disposal to protect your entry points and customers’ accounts.
That's a business we've been in for a decade.
What half a billion checks let us see
500 million verifications isn't a number on a scoreboard. It's a vantage point.
From verifying identity credentials to confirming whether someone online is in fact human, the best in class identity verification now requires AI-powered dynamic solutions that adapt and evolve daily, just like the tools used by bad guys.
Every time a new foundational model drops (this month it was GPT-6 Astra) fraudsters and criminals attempt to use these to exploit stolen identity information and credentials and break into banks.
Fraud is not one company’s, or country’s problem. It is a global threat that requires local solutions. This year we invested heavily in developing network defence capabilities, principally in our new 3rd Generation platform, built within the bounds of data protection and privacy law. The same fraudulent face or device turns up at a bank, then a lender, then a betting platform.
So the single most important signal about a verification attempt is often something that never happened at your company. It happened at someone else's, last week. We saw it, committed it to memory and can block it when we see it again in your bank.
That is what 500 million checks across more than 30 countries buys you. Even if you are running the latest AI models on the fastest possible NVIDIA GPUs like us, you might miss an attacker that you’ve never seen before.
Here is what that looks like in the last month alone:
- 5,000 confirmed fraud attempts
- one in three reused a face we had already caught elsewhere
- one in six reused a device we had seen before
- 73,000 automated rule triggerings in 45 days, from over 80 live dynamic fraud rules written by our AI models on their own, using a combination of 50+ fraud signals
At a scale of 15 - 20 million verifications / month, that is nearly 100M datapoints being evaluated by our AI suite to protect more than 500 enterprises every month.
To repeat that again. A third of the fraud we stopped last month was invisible to the company being attacked but obvious to us. No single customer can produce these numbers. Only a network our size can, and there is only one identity company at our size, in our markets.
Seeing is Believing: Examples from the Battlefield
Every figure below comes from live rules running in production right now. Here are four stories:
Same space, different faces
Fraud farms photograph different people, recruited or synthetic, often in the same physical (or virtual) space. Our models learned to recognise the environment around the person. So the third identity shot from that red brick wall or wooden desk gets recognized immediately even when the face is new. This “scene check” lifts fraud detection by nearly 10x.
One ring, three different banks
One linked fraud operation dynamically changed IP addresses. We blocked three of them across July as each one produced confirmed fraud. When a fourth IP address appeared — seven transactions, six confirmed frauds, three different companies, and three devices later — our systems could already identify the pattern, and blocked it before it attempted to send verification volumes. Each of the three companies was protected by fraud confirmed by the other two. None of them could have seen the whole ring.
A phone reported a chip it cannot have
One device sent us verifications from a Samsung Galaxy S21 Ultra running an Intel processor. The Galaxy S21 has only ever shipped with ARM chips. The submissions were an emulator wearing a Samsung costume. The rule our AI wrote did not just block the setup we encountered — it blocks any device that reports incorrect architecture, would your human risk team know how to do that instantly?
Blocking fraud without blocking real users
In July, 13 verifications from one Nigerian address were all confirmed as deep fake attacks. Blocking the IP address would have been the obvious move, but the wrong one: as the IP was a shared mobile gateway with hundreds of real customers too. Our AI models tightened the rule to IP addresses plus specific device models. All frauds were blocked, all real humans passed.
Precision is what separates superior commercial performance from merely good defence.
We decline hundreds of rules that would have worked — because each would also have blocked real people. The measure of a fraud system is not how much it blocks but how much fraud it stops without impacting real customers. Precision is the point.
The network compounds
Every fraud we confirm anywhere — a face, a device, an address — hardens every Smile ID customer everywhere, the same day. That advantage widens daily, and it cannot be copied. It simply improves, one verification at a time.
Dynamic defence for dynamic attacks
Cybercrime now adapts at machine speed, so cyber defences must as well. When OpenAI's agents broke out of their sandbox and into Hugging Face this summer, the detail that mattered got overlooked by most reporters: the attacking swarm adapted while the sandbox was static. Against AI, a defence that can't adapt isn't a defence, it's a target.
Where this goes
Our 500 millionth check is simply the end of the old era and the dawn of a new one.
Identity is becoming a continuous and dynamic challenge, not a one-time gate. The old KYC model is dead. Account takeover and mule activity drive the vast majority of fraud and simple KYC checks (name, phone number, ID number, etc) don’t stop them. So we must verify at the moments that matter — a login, a transfer, a settings change — and see the person and device.
And soon the next question will arrive: what happens when the customer is an AI agent, not a human? By year end, agents will open accounts and move money on people's behalf. Good agents and bad agents look identical to today's fraud checks. The challenge becomes proving that a real human, and the right human, authorised this agent, and granted it’s permissions.
As we work hard to keep the Internet safe for humans, we’ll keep sharing stories from the field and lessons on how to navigate this brave new world of artificial intelligence.
If we are to enable the abundance that AI promises we must first mitigate the risks.



