When a Fake Face can pass for Real: What Canada’s New Deepfake Law Means for Financial institutions
Canada has just experienced its worst year for fraud on record—and the digital identities behind it are becoming sophisticated enough to fool not only people, but increasingly the systems designed to verify them.
A fake face can now pass as a real one under Canadian law. For Canada’s banks and financial institutions, that reality has profound implications.
Canadians reported more than $704 million in fraud losses in 2025, according to the Canadian Anti-Fraud Centre (CAFC), which estimates that reported cases represent only 5% to 10% of actual fraud activity. Since 2022, reported losses alone have exceeded $2.4 billion, with identity fraud ranking among the most frequently reported schemes nationwide.
Having spent nearly four decades in banking and financial-services technology—much of that time serving as a CIO within major financial institutions—I can confidently say that the fraud landscape has evolved more dramatically in the last two years than in the previous two decades.
This is no longer a world of stolen passwords and compromised credentials.
Artificial intelligence has industrialized identity fraud. Today’s threat actors can generate synthetic identities capable of passing customer onboarding processes, deploy deepfake videos designed to defeat Know Your Customer (KYC) checks, clone voices with remarkable accuracy, and purchase fraud-as-a-service toolkits that automate sophisticated attacks. Even distribution is becoming automated. The CAFC has linked the recent surge in large-scale text-message scams to AI-powered tools capable of targeting thousands of devices simultaneously.
What Canada’s Criminal Code Now Recognizes
The extent of this transformation can be seen in an unexpected place: Canada’s criminal law.
Last month, the Protecting Victims Act came into force, introducing new protections against non-consensual sexual deepfakes – an increasingly harmful form of digital exploitation that disproportionately affects women and minors. To make those protections enforceable, lawmakers had to acknowledge a new reality within the Criminal Code itself: that an AI-generated image may be “likely to be mistaken for a visual recording of that person.”
That language was crafted to protect victims and support prosecutions. Yet it also reflects a broader technological reality confronting every financial institution.
If a fabricated image is convincing enough for the law to recognize its potential to be mistaken for a real person, it is also convincing enough to challenge traditional identity verification systems.
Regulators have taken notice.
Canadian financial institutions are increasingly expected to demonstrate not merely that compliance programs exist, but that they are effective in practice. Supervisors are placing greater emphasis on controls that are demonstrably risk-based, appropriately designed, and capable of producing measurable outcomes.
Documentation alone is no longer sufficient. Institutions must be able to show that their controls work.
This is where many organizations risk approaching the problem from the wrong direction.
When compliance requirements intensify, the instinct is often to add friction: more forms, more identity documents, more verification steps. Yet effectiveness and friction are not the same thing.
In many cases, synthetic identities are better equipped to navigate rigid onboarding processes than legitimate customers. Additional hurdles often create frustration for honest users while doing little to deter sophisticated fraudsters. In an increasingly competitive financial-services market — particularly one moving toward greater data portability and open banking — customers who encounter excessive friction may simply take their business elsewhere.
Smarter Verification
The answer is not more visible verification. It is smarter verification.
Modern anti-fraud strategies increasingly rely on controls that operate invisibly in the background while providing stronger assurance. Advanced liveness detection can identify manipulated images and videos without disrupting the customer experience. Behavioral analytics can evaluate how a device is handled, how a session unfolds, and whether activity patterns align with legitimate user behavior. Continuous monitoring can validate trust throughout the customer relationship rather than relying solely on checks performed at account opening.
These capabilities target anomalies rather than forcing every customer to prove who they are repeatedly.
The record fraud losses reported in 2025 were not caused by a lack of regulation. They were the result of controls designed for a slower era—controls built to describe who a customer was at a particular moment, while modern fraud operates dynamically and at machine speed.
Today’s fraud schemes can activate dormant accounts, move funds across multiple institutions within hours, and adapt faster than conventional risk models can respond.
Canada’s financial institutions no longer need convincing that this reality exists. What they need now is proof—that their identity controls can reliably tell the difference, and that they can demonstrate it to a regulator.
Parliament has already acknowledged a reality that many security leaders have been warning about for years: a fabricated image can be mistaken for a real person. The implications extend far beyond the courtroom. For Canada’s banks, the next era of fraud prevention will be defined not by verifying documents, but by verifying trust itself.
I’ve spent nearly four decades watching banks compete on speed, then on convenience. The next battleground is trust—proving it, not just assuming it. The institutions that figure this out first won’t just avoid losses; they’ll win customers who no longer take ‘verified’ at face value.