The rise of deepfakes is changing the authentication conversation.
For years, the industry has focused on proving that someone is who they claim to be. Now we have another problem: proving that the person, face, or voice presented to us is even real.
The scale of the threat is hard to ignore. iProov recently reported a 1,151% surge in iOS-targeted injection attacks in the second half of 2025, while Reality Defender says a Tier One global bank analyzed more than 1.7 million customer calls in 2024 and detected nearly 1000 synthetic voice calls. The threat is not theoretical. Voice cloning, deepfake video, injected media, and replay attacks mean we need to rethink what we trust.
Understandably, liveness has become one of the industry's biggest priorities. But in some recent conversations, I have heard a more provocative argument: perhaps biometrics are no longer necessary.
“If you can establish that the person is real and alive, why do you need biometrics at all?”
I think this is a fundamentally misguided way to think about authentication. Liveness and deepfake detection tell you that the interaction is real. Biometrics tell you whether it is the right person.
The call center may be where the difference is easiest to understand. Imagine a fraudster calls a bank. They are using their own voice, so there is no deepfake to detect. They pass liveness checks because they are, in fact, a live human being. They also know the customer's date of birth, address, account information, recent transactions, and answers to whatever knowledge-based questions the bank uses.
Where did they get it?
A data breach. A phishing attack. Social engineering. Malware. A criminal marketplace. The details vary, but the basic problem is the same: a great deal of the information we still use for authentication is available to criminals.
So what has liveness established? It tells us that a live person knows the information. It does not tell us that the live person is the account holder. And this is the point I think we risk losing in the rush to solve the deepfake problem, because as long as we authenticate people using information that can be bought, stolen, intercepted, or socially engineered, liveness detection technologies alone will not solve this problem.
We need biometrics.
Biometrics are not simply another fraud signal. They can provide continuity of identity across channels, devices, and interactions, creating the ability to thread identity throughout the customer lifecycle, from onboarding to authentication and transactions, whether the customer is in a branch, online, at the point of sale or, yes, at the contact center.
This makes biometrics a foundational identity layer, one that can help prevent fraud while also improving the customer experience.
Consider the difference: A legitimate customer may call from a new phone while traveling. The channel is unfamiliar, but the person may still be recognizable. Conversely, a fraudster may take over a legitimate phone number. The channel may appear entirely consistent with the customer, while the person speaking is someone else.
This is why I do not think the future is liveness instead of biometrics.
The future is understanding what each signal can actually prove. Liveness helps establish that the interaction is authentic. Biometrics help establish continuity with the person. And other signals, like phone and device intelligence, assess the risk of the channel, while behavioral analytics look for suspicious patterns.
These distinctions matter because not every authentication decision requires the same level of certainty.
For a low-risk interaction, liveness combined with phone, device, and behavioral signals may be entirely sufficient. An organization may reasonably decide that the interaction presents an acceptably low level of risk without needing to recognize the individual. But it is important to understand that that is risk-based authentication. It is not the same thing as recognizing the person.
The distinction becomes much more important when the customer is trying to recover an account, reset credentials, change contact information, or authorize a high-risk transaction.
In those moments, knowing that the interaction looks legitimate may not be enough. Knowing that the person is live may not be enough, especially when the information used to authenticate them may already be sitting in a database somewhere on the dark web.
The irony is that deepfakes have made biometrics more important, not less.