<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Biometric Update</title>
	<atom:link href="https://www.biometricupdate.com/feed" rel="self" type="application/rss+xml" />
	<link>https://www.biometricupdate.com</link>
	<description>Biometrics News, Companies and Explainers</description>
	<lastBuildDate>Wed, 26 Aug 2026 12:24:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">66434804</site>	<item>
		<title>USPS finalizes mail-in voter ballot rule that would give law enforcement voter-linked data</title>
		<link>https://www.biometricupdate.com/202608/usps-finalizes-mail-in-voter-ballot-rule-that-would-give-law-enforcement-voter-linked-data</link>
					<comments>https://www.biometricupdate.com/202608/usps-finalizes-mail-in-voter-ballot-rule-that-would-give-law-enforcement-voter-linked-data#respond</comments>
		
		<dc:creator><![CDATA[Anthony Kimery]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 12:24:37 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Elections]]></category>
		<category><![CDATA[Government Services]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[U.S. Government]]></category>
		<category><![CDATA[USPS]]></category>
		<category><![CDATA[voter identification]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353607</guid>

					<description><![CDATA[
		<img width="1200" height="675" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2021/01/12175146/usps.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="usps" decoding="async" fetchpriority="high" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2021/01/12175146/usps.jpg 1200w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2021/01/12175146/usps-300x169.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2021/01/12175146/usps-1024x576.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2021/01/12175146/usps-150x84.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2021/01/12175146/usps-768x432.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" />
		The U.S. Postal Service (USPS) finalized new rules for mail-in ballots in federal elections that would require states to give the postal service individual voters’ names and addresses together with unique barcodes assigned to their outbound and return ballot envelopes.

The rule would also create a new federal source of voter-linked data whose stated purposes include assisting law enforcement.

The rule was ordered by President Donald Trump in a March 31<a href="https://www.whitehouse.gov/presidential-actions/2026/03/ensuring-citizenship-verification-and-integrity-in-federal-elections/"> executive order</a> aimed at verifying citizenship and tightening federal oversight of mail voting.

Trump directed USPS to create uniform standards for federal ballot mail, require unique barcodes on ballot envelopes and establish state-specific lists linking mail voters to those identifiers.

The order says the system is intended to help ensure that only eligible citizens receive and cast federal ballots and directs the Postal Service to coordinate with its inspector general and the Justice Department in investigating suspected unlawful use of the mail involving election materials.

The rule has provoked a broader constitutional fight because it would use the Postal Service to impose federal conditions on how states administer mail voting, an area in which the Constitution gives the president no independent regulatory authority.

In June, U.S. District Judge Indira Talwani<a href="https://www.democracydocket.com/wp-content/uploads/2026/04/2026-06-25-Order.pdf"> ruled</a> those key provisions of Trump’s order violated the constitutional separation of powers and the states’ authority over elections.

In an August 11<a href="https://docs.justia.com/cases/federal/district-courts/massachusetts/madce/1%3A2026cv11549/298449/183"> ruling</a> blocking the USPS requirements nationwide, Talwani reiterated that “the executive branch has no authority to regulate elections.”

The rule has an August 21 effective date, but implementation remains blocked by litigation.

The Supreme Court on Monday<a href="https://www.supremecourt.gov/opinions/25pdf/26a124_hgci.pdf"> stayed</a> a separate injunction obtained by California and other states.

The August 11 nationwide preliminary injunction in <em>League of Women Voters of Massachusetts v. </em><em>Trump</em> remains in place and bars USPS from implementing the mail ballot provisions for the November 3 election or any earlier federal election.

The USPS’ 95-page<a href="https://public-inspection.federalregister.gov/2026-17238.pdf"> final rule</a>, scheduled for publication in the <em>Federal Register</em> August 26, requires states using the mail for covered federal elections to enroll mail voters through a new Federal Ballot Mail Portal and provide USPS with each voter’s name, address, issuing state and two unique Intelligent Mail barcodes (IMbs).

USPS says the resulting information would give federal law enforcement a list identifying people states planned to send ballots to and the corresponding identifiers for those specific pieces of election mail.

“Currently, law enforcement lacks such information regarding the use of the mail,” USPS says in the rule.

The system would rely on the Intelligent Mail barcode, the 65-bar identifier USPS uses to sort mail and generate information about individual mail pieces as they pass through automated processing equipment.

Unique IMbs are already widely used for election mail. USPS<a href="https://about.usps.com/kits/kit600/kit600_v04-2026_016.htm"> guidance</a> says uniquely serialized barcodes can facilitate tracking individual ballot mail to and from individual voters and allow election officials to know when and where a particular piece was processed.

Election officials currently maintain the relationship between a barcode’s serial number and the voter to whom it was assigned.

The final rule would make that relationship part of a standardized federal reporting requirement.

Both the outbound envelope sent by an election office and the return envelope provided to the voter would have to carry a unique IMb. Before an outbound ballot mailing is accepted, an authorized portal user would submit the voter’s name and address, issuing state and the barcodes for both envelopes.

Postal workers would scan outbound ballot envelopes and check the barcodes against the portal.

USPS says its verification process is limited to determining whether election officials complied with the portal’s data and mail piece requirements and that USPS itself will not determine a voter’s citizenship or eligibility.

That is narrower than the purpose described in Trump’s executive order, which says unique ballot envelope identifiers can help confirm that only citizens receive and cast ballots and directs federal agencies to use citizenship data and prioritize investigations of ballots issued to ineligible voters.

Return ballots would not undergo the same acceptance verification. But when a return envelope carrying its unique barcode passes through automated postal equipment, USPS systems can generate scan data associated with that identifier.

On or around Election Day, USPS would produce a state specific Mail-In and Absentee Participation List containing each enrolled voter’s name and address together with the outbound and return barcodes assigned to that person

USPS describes the list as a form of manifest intended to help election officials and law enforcement identify potentially anomalous incidents that could warrant investigation.

The agency says it would give federal law enforcement greater visibility into who was supposed to receive a ballot through the mail and the barcode data associated with it.

The list would not establish that a person voted or returned a ballot, nor would it itself contain scan records showing a ballot envelope moving through the postal network.

USPS also says portal information supplied by election officials would not be matched with Department of Homeland Security databases, Social Security Administration records, National Change of Address data or other federal lists when the participation lists are created.

But the final rule discusses those records alongside USPS’s separately generated barcode scan data.

The agency says existing scan data for some ballot mail can have law enforcement value and that making barcode and reporting requirements uniform would “significantly improve the quality” of information available to investigators.

USPS has separately proposed a new Privacy Act System of Records to govern the portal.

The July 17<a href="https://www.federalregister.gov/documents/2026/07/17/2026-14508/privacy-act-of-1974-system-of-records"> notice</a> for USPS 820.225 Federal Ballot Mail says the system would be maintained at USPS headquarters and in a “supplier cloud computing environment.” One of its stated purposes is to determine adherence to federal law and facilitate law enforcement efforts.

Records would include voters’ names and addresses, the unique IMb numbers for their outbound and return ballot envelopes and the issuing state. They could be retrieved by name, address, state or barcode and would be retained for five years.

USPS says it will not begin collecting information through the portal until the new system of records takes effect.

USPS says it will not collect political party affiliation or inspect the contents of ballots and that access to the system would be restricted to personnel whose duties require it, transmissions would be encrypted and system access logged.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/usps-finalizes-mail-in-voter-ballot-rule-that-would-give-law-enforcement-voter-linked-data/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353607</post-id>	</item>
		<item>
		<title>Login.gov explores persistent device fingerprinting to strengthen fraud detection</title>
		<link>https://www.biometricupdate.com/202608/login-gov-explores-persistent-device-fingerprinting-to-strengthen-fraud-detection</link>
					<comments>https://www.biometricupdate.com/202608/login-gov-explores-persistent-device-fingerprinting-to-strengthen-fraud-detection#respond</comments>
		
		<dc:creator><![CDATA[Anthony Kimery]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 12:17:43 +0000</pubDate>
				<category><![CDATA[Access Control]]></category>
		<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Government Services]]></category>
		<category><![CDATA[AI agents]]></category>
		<category><![CDATA[device fingerprinting]]></category>
		<category><![CDATA[digital identity]]></category>
		<category><![CDATA[GSA]]></category>
		<category><![CDATA[Login.gov]]></category>
		<category><![CDATA[procurement]]></category>
		<category><![CDATA[RFI]]></category>
		<category><![CDATA[U.S. Government]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353597</guid>

					<description><![CDATA[
		<img width="2048" height="992" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/04/15163059/digital-government-services-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/04/15163059/digital-government-services-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/04/15163059/digital-government-services-300x145.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/04/15163059/digital-government-services-1024x496.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/04/15163059/digital-government-services-150x73.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/04/15163059/digital-government-services-768x372.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/04/15163059/digital-government-services-1536x744.jpg 1536w" sizes="(max-width: 2048px) 100vw, 2048px" />
		The U.S. General Services Administration (GSA) is exploring a new device fingerprinting capability for<a href="https://www.biometricupdate.com/tag/login-gov"> Login.gov</a> that could recognize returning computers and phones even when users change IP addresses, delete cookies, browse in private mode or use technologies intended to obscure their devices.

The<a href="https://sam.gov/workspace/contract/opp/a6de63ce78ec4f28b250d3d3c8cf34de/view"> Request for Information</a>, issued by GSA’s Technology Transformation Services, seeks vendors offering device intelligence and fingerprinting technology that could supplement fraud controls already used by Login.gov. Responses are due September 11.

The draft requirements remain subject to change, but they show that GSA is considering a fraud detection layer built not only around what credentials a user presents, but around whether Login.gov recognizes the device behind them, what techniques that device is using to conceal itself and how its activity compares with what the system has seen before.

Despite the terminology, the “fingerprinting” contemplated by the RFI does not involve physical fingerprints. Device fingerprinting attempts to distinguish one computer, phone or browser from another by analyzing combinations of browser, device and network characteristics.

GSA says Login.gov already uses device fingerprinting during identity verification but is considering extending complementary device intelligence to other parts of the user journey, including account creation, sign-in and the conclusion of identity verification.

The draft requirements call for a persistent device identifier that remains associated with the same device across sessions.

The technology would have to recognize returning devices despite<a href="https://www.biometricupdate.com/tag/vpn-virtual-private-network"> VPN</a> use, private or incognito browsing and cookie deletion.

It also needs to identify devices using Apple’s iCloud Private Relay, detect browser tampering and device-attribute spoofing, and recognize traffic routed through residential or data center proxies.

The system would generate real-time risk signals intended to help Login.gov distinguish trusted visitors from potentially fraudulent ones.

GSA wants detection of automated and headless browsers, anti-detect browsers, VPNs, virtual machines, Tor traffic and attempts to spoof location or time zone information.

Mobile requirements include detection of rooted or jailbroken devices, cloned applications, geolocation spoofing and tampered requests.

Those indicators could be combined into a configurable risk score, with Login.gov able to adjust how much weight individual signals receive.

One of the RFI’s more consequential provisions asks whether all generated device identifiers, risk scores, risk indicators and event details can be exported so the government can conduct its own historical and behavioral analysis of retained information.

The RFI calls this “pattern-of-life” analysis and asks vendors whether data could be provided through streaming, batch transfers, webhooks or APIs, potentially in real time.

The RFI also reflects GSA’s concern about autonomous AI.

The system would need to distinguish humans from legitimate automation and malicious bots, including credential stuffing tools and scrapers.

GSA also wants detection of AI agents operating autonomously for people or organizations, explicitly citing agents based on ChatGPT, Claude and Gemini, along with AWS, Microsoft and Google cloud AI services and autonomous browsing tools. For detected AI agents, the system would identify the provider and product, determine whether the agent’s identity has been verified and whether its requests contain valid authentication credentials.

Login.gov would then be able to allow approved agents, block suspicious ones, challenge unverified agents, impose rate limits and log their interactions.

GSA says the capability should function as a targeted component rather than requiring Login.gov to adopt another broad fraud management platform.

The agency also wants to know whether the system can operate within a government-controlled environment without sending user data to a non-FedRAMP external service.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/login-gov-explores-persistent-device-fingerprinting-to-strengthen-fraud-detection/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353597</post-id>	</item>
		<item>
		<title>Judge blocks Trump administration bid for driver identity database</title>
		<link>https://www.biometricupdate.com/202608/judge-blocks-trump-administration-bid-for-driver-identity-database</link>
					<comments>https://www.biometricupdate.com/202608/judge-blocks-trump-administration-bid-for-driver-identity-database#respond</comments>
		
		<dc:creator><![CDATA[Anthony Kimery]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 21:04:38 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[Government Services]]></category>
		<category><![CDATA[AAMVA]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[driver's license]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[immigration]]></category>
		<category><![CDATA[U.S. Government]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353586</guid>

					<description><![CDATA[
		<img width="2048" height="1365" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/02135548/truck-driver-biometric-monitoring-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/02135548/truck-driver-biometric-monitoring-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/02135548/truck-driver-biometric-monitoring-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/02135548/truck-driver-biometric-monitoring-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/02135548/truck-driver-biometric-monitoring-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/02135548/truck-driver-biometric-monitoring-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/02135548/truck-driver-biometric-monitoring-1536x1024.jpg 1536w" sizes="(max-width: 2048px) 100vw, 2048px" />
		A federal judge in Virginia has temporarily blocked the Trump administration from taking custody of a nationwide database containing Social Security numbers and other identifying information for roughly 17 million commercial drivers.

Senior U.S. District Judge Anthony J. Trenga of the Eastern District of Virginia ruled that the government has not adequately explained why it needs the records and that there is a “compelling inference” they are being sought largely for immigration enforcement.

Trenga granted a<a href="https://www.justsecurity.org/wp-content/uploads/2026/08/State-of-Illinois-v.-United-States-Department-of-Transportation-Order-Aug.-20-2026.pdf"> temporary restraining order</a> to 21 states and the District of Columbia that sued the Department of Transportation (DOT) and Federal Motor Carrier Safety Administration (FMCSA) after the agencies demanded a bulk transfer of records from the Commercial Driver’s License Information System (CDLIS).

The Department of Homeland Security (DHS) separately subpoenaed the same data for immigration enforcement.

The ruling prevents the American Association of Motor Vehicle Administrators (<a href="https://www.biometricupdate.com/tag/aamva">AAMVA</a>), which operates CDLIS, from transferring the plaintiff states’ records to DOT, FMCSA or any other federal agency while Trenga considers whether to issue a preliminary injunction.

The judge’s ruling also prohibits federal officials from cutting off or threatening AAMVA’s contracts and funding because it has not provided the records.

The distinction between ordinary federal access to CDLIS and what the administration is seeking is central to the dispute.

Congress created CDLIS in 1986 as a clearinghouse that allows states to determine whether someone applying for a commercial driver’s license (CDL) is already licensed elsewhere or has an out-of-state driving record that could disqualify the applicant.

AAMVA has operated the system since 1988.

At its central site, CDLIS contains what are known as Master Pointer Records. They include a driver’s name, date of birth, Social Security number or alternative identifier, sex, driver’s license number and state of record.

The pointer record identifies which state holds the driver’s underlying licensing record. It is not itself the driver’s complete history, which remains with the states.

According to the states’ complaint, FMCSA asked AAMVA on June 25 to provide the name, date of birth, state, license number and Social Security number for every driver represented in the CDLIS central database going back five years, approximately 17 million pointer records.

It also requested information about when Social Security numbers had been removed from records that no longer contained them.

AAMVA told the government the request raised privacy and legal concerns.

After additional exchanges, FMCSA told AAMVA on August 11 that unless it produced the records by August 17, DOT could cancel AAMVA’s grants, seek enforcement of a subpoena and consider terminating its contract with the organization.

The threatened funding included about $10 million supporting operation of CDLIS itself.

Trenga said cutting it off could impair states’ ability to issue and renew commercial licenses and potentially disrupt broader driver licensing operations.

DHS entered the dispute after AAMVA initially resisted the FMCSA demand. It issued an administrative subpoena seeking essentially the same records, withdrew it after AAMVA indicated it would provide the information to FMCSA and then issued another subpoena when states objected and AAMVA considered allowing individual states to opt out.

The states filed a separate<a href="https://www.mass.gov/doc/motion-to-quash-dhs-fmcsa/download"> motion to quash</a> the DHS subpoena, arguing that DHS was using its subpoena power to obtain identifying information about millions of people who were not identified as subjects of an investigation.

DHS has said the information is needed to investigate illegal practices involving commercial driver licensing and for immigration enforcement.

Trenga’s ruling goes considerably further than the administrative stay he entered when the states sued August 13. Although it is not a final decision on the legality of the government’s demands, the judge concluded that the states had demonstrated a likelihood of succeeding on several of their central claims.

Among them are claims under the <em>Driver’s Privacy Protection Act</em> (DPPA), the <em>Privacy Act of 1974</em>, the <em>Administrative Procedure Act</em> (APA) and the Constitution’s Spending Clause.

The court found that FMCSA had not explained how obtaining all 17 million records fell within the DPPA exception permitting government agencies to obtain motor vehicle information to carry out their functions.

FMCSA said it wanted the records to perform its safety and regulatory responsibilities and analyze the national commercial licensing program. But Trenga noted that the agency has performed those responsibilities for decades through individual CDLIS queries and audits of state licensing programs.

When pressed during the hearing, the judge wrote, federal officials were unable to identify something FMCSA could do with a bulk copy of the records that it could not already do through its existing access.

The court also pointed to the government’s acknowledgment that the records would be shared with DHS for immigration enforcement, which is not part of FMCSA’s statutory transportation-safety mission.

“In the absence of any substantive explanation” connecting the bulk transfer with FMCSA’s responsibilities, Trenga found a “compelling inference” that obtaining the files was driven in substantial part by immigration enforcement.

That conclusion directly challenges the administration’s public explanation for the demand.

Transportation Secretary Sean Duffy<a href="https://www.transportation.gov/briefing-room/trumps-transportation-secretary-slams-radical-state-ags-lawsuit-obstruct-data-sharing"> said</a> August 13 that federal access is necessary to identify improperly licensed or unqualified drivers and argued that administrations have had access to CDLIS since 1988.

DOT also said AAMVA operates the system on behalf of the federal government and is legally and contractually obligated to provide the records.

The court drew a different line between having access to CDLIS and taking possession of a bulk copy.

Trenga noted that federal policy has long stated that CDLIS records are not controlled by FMCSA and that a DOT policy statement issued as recently as May described Master Pointer Records as owned by the states.

Other federal agencies can seek CDLIS information under established procedures, but that does not necessarily entitle the federal government to take custody of the entire central repository, the judge said.

The judge also found that FMCSA had never before demanded information on this scale and had not consulted the states before changing how the system would be used.

The Privacy Act presents another obstacle. Trenga found the states are likely to succeed on their argument that FMCSA cannot simply ingest the CDLIS data into a new or modified federal system of records without satisfying the law’s requirements governing notice, collection and subsequent disclosure.

The government also had not provided confidentiality assurances for the bulk data while acknowledging that it intended to distribute the records to DHS, which makes the case broader than a dispute over commercial driver regulation.

At issue is whether the federal government can convert a system built to let states conduct individualized identity and licensing checks into a centrally held federal dataset that can be analyzed and shared for purposes beyond those for which the information was originally assembled.

The ruling does not eliminate federal access to CDLIS. FMCSA can continue making the individualized queries it has historically used, and the underlying detailed driver records remain with the states. Nor has Trenga issued a final ruling that the administration can never obtain the data.

For now, the government cannot obtain the plaintiff states’ Master Pointer Records as part of the requested bulk transfer or punish AAMVA or those states for refusing to provide them.

The states have until August 27 to seek a preliminary injunction. The administration’s response is due September 3, and Trenga has scheduled a hearing for September 10.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/judge-blocks-trump-administration-bid-for-driver-identity-database/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353586</post-id>	</item>
		<item>
		<title>Deepfake detection evolving beyond onboarding into continuous financial trust</title>
		<link>https://www.biometricupdate.com/202608/deepfake-detection-evolving-beyond-onboarding-into-continuous-financial-trust</link>
					<comments>https://www.biometricupdate.com/202608/deepfake-detection-evolving-beyond-onboarding-into-continuous-financial-trust#respond</comments>
		
		<dc:creator><![CDATA[Joel R. McConvey]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 19:30:42 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Industry Analysis]]></category>
		<category><![CDATA[Liveness Detection]]></category>
		<category><![CDATA[Accenture]]></category>
		<category><![CDATA[AI fraud]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[continuous verification]]></category>
		<category><![CDATA[deepfake detection]]></category>
		<category><![CDATA[deepfakes]]></category>
		<category><![CDATA[IngenID]]></category>
		<category><![CDATA[injection attack detection]]></category>
		<category><![CDATA[JPMorgan]]></category>
		<category><![CDATA[Resemble AI]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353578</guid>

					<description><![CDATA[
		<img width="1992" height="2048" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/01/19133926/deepfake-detection-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/01/19133926/deepfake-detection-scaled.jpg 1992w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/01/19133926/deepfake-detection-292x300.jpg 292w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/01/19133926/deepfake-detection-996x1024.jpg 996w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/01/19133926/deepfake-detection-146x150.jpg 146w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/01/19133926/deepfake-detection-768x790.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/01/19133926/deepfake-detection-1494x1536.jpg 1494w" sizes="auto, (max-width: 1992px) 100vw, 1992px" />
		As forecasted in <i>Biometric Update</i>’s <a href="https://www.biometricupdate.com/202607/the-deepfake-fraud-detection-market-2026-securing-identity-in-the-ai-era">2026 Deepfake Detection Market Report</a>, deepfake detection continues to evolve from an onboarding tool to a system integrated across the lifecycle. “Static, one-time authentication to access enterprise or consumer accounts has become obsolete,” the report says. “Banking, fintech, and high-value gaming platforms are hemorrhaging money to postlogin fraud. They need a system that continuously evaluates risk throughout the entire user session.”

New products and resources from <a href="https://www.biometricupdate.com/companies/ingenid">IngenID</a> and <a href="https://www.biometricupdate.com/companies/resemble-ai">Resemble AI</a>, alongside new guidance from JPMorgan and Accenture, reinforce the significant market shift from point-in-time identity verification toward continuous protection. In effect, as deepfakes and the techniques to use them for fraud expose more vulnerabilities across the customer journey, <a href="https://www.biometricupdate.com/202608/why-deepfake-detection-is-becoming-trust-infrastructure">deepfake detection</a> has gained the dimension of time: not just checking that the person who arrives at the point of access control is real, but making sure they stay that way while they’re inside.
<h2><b>IngenID levels up to continuous voice authentication </b></h2>
An update to IngenID’s Twilio connector adds continuous, real-time deepfake detection to its existing voice biometric authentication and classification system. A release from the <a href="https://www.biometricupdate.com/202602/corsound-ai-ingenid-partnership-unites-biometric-voice-intelligence-offerings">voice security</a> firm says the upgraded connector lets contact centers verify callers and provides assurance they’re dealing with real callers throughout the entire conversation – not just at login.

Deploying natively on <a href="https://www.twilio.com/en-us" target="_blank" rel="noopener">Twilio</a>, IngenID’s connector streams audio continuously via Twilio Media Streams to re-verify caller identity throughout an interaction. It also flags synthetic or manipulated audio as it happens, and makes continuous protection viable at high call volumes without the pricing overhead associated with legacy systems.

“Fraud doesn’t happen at the same moment of every call,” says Nick Bartolotti, CTO at IngenID. “It can happen at any time. Attackers know a one-time check only protects the start of a call, so we made authentication continuous: our Twilio connector now listens for a live, consistent voice for the full duration of the call, catching a synthetic voice swap, a hijacked session, or a fraudulent handoff the instant it happens.”
<h2><b>ResembleAI resource unpacks deepfakes for AML compliance</b></h2>
A new resource on Resemble AI’s blog explores how deepfake detection is being integrated into AML compliance workflows.

“Deepfake detection for AML compliance is becoming an important part of modern risk management,” it says. As onboarding, authentication and interaction go remote, synthetic media can be used for identity fraud at a greater number of pressure points – driving the need for continuous monitoring.

Deepfake detection, says <a href="https://www.resemble.ai/resources/deepfake-detection-for-aml-compliance" target="_blank" rel="noopener">the blog</a>, “may contribute to ongoing monitoring by supporting high-risk account verification, account recovery processes, authentication events and sensitive transaction approvals.” It thus becomes part of an architecture that complements existing AML frameworks, and also includes biometric verification, risk-based authentication and other controls.

That said, Resemble AI also recognizes that these relatively recent market mutations are currently loose in an unstable regulatory landscape. “Expectations around synthetic media risks and deepfake detection <a href="https://www.biometricupdate.com/202608/podcast-deepfake-fraud-goes-industrial-as-identity-defenses-evolve">continue to evolve</a>. Financial institutions may need to adapt their controls as regulatory guidance becomes more defined.”
<h2><b>‘A static defense posture is a losing one’</b></h2>
An <a href="https://www.jpmorgan.com/insights/payments/security-trust/deepfake-fraud-prevention-strategies" target="_blank" rel="noopener">article</a> co-authored by executives from J.P. Morgan Payments and <a href="https://www.biometricupdate.com/companies/accenture">Accenture</a> argues that effective defense against deepfake fraud now requires “a layered technology approach that meets the threat at the critical window between when a payment is initiated and when it’s executed.”

“This window is shrinking: as <a href="https://www.biometricupdate.com/202605/ai-agents-operating-continuously-at-machine-speed-are-breaking-human-centric-iam">payment rails get faster</a>, the opportunity to recall funds narrows or disappears entirely,” the authors say. This calls for behavioral analytics; real-time validation systems for verifying payment details against authoritative sources before funds move; and phishing-resistant multifactor authentication (MFA). Finally, identity, device and context are continuously verified for every request to to enforce zero-trust identity and access management.

“These technologies must evolve as fast as the threats they’re designed to counter. A static defense posture is a losing one.”

The authors underscore the necessity of collaboration in facing the <a href="https://www.biometricupdate.com/202607/ai-fraud-fuels-debate-over-continuous-identity-verification">barrage of AI fraud</a>. “No single organization can solve the problem of deepfake fraud alone. By sharing intelligence, best practices and technology innovation, organizations can strengthen collective defenses in ways no one can achieve independently.”
<h2><b>The future is layered </b></h2>
Evidence continues to build that deepfake detection is transitioning from a standalone identity verification capability into a <a href="https://www.biometricupdate.com/202607/ai-fraud-drives-identity-verification-toward-continuous-trust-and-layered-assurance">continuous trust layer</a> spanning onboarding, authentication, communications, payments and fraud prevention.

The identity ecosystem is labeled as such because of how it all connects. Digitization is as much a story of convergence as it is one of plenty: more and more things happen online, and one searches for simpler ways to govern all of the connected parts. Meanwhile, fraud attacks once confined to skilled hackers targeting high-stakes financial and security institutions can now be <a href="https://www.biometricupdate.com/202607/cost-of-ai-fraud-has-fallen-by-a-hundredfold-unico-liminal-report">engineered at scale</a>, enabled by AI technology that also powers biometric injection attacks as a primary vector for deepfakes.

The ecosystem, then, presents itself as a cacophony in need of structure – or <a href="https://www.biometricupdate.com/202509/the-roles-of-identity-attribute-and-orchestration-service-providers">orchestration</a>. The term, which connotes both arrangement of the component pieces and active guidance in how they interact, is a buzzword, but also an apt metaphor for what the modern identity stack needs. The soldier at the gates is no longer a lone giant stationed by the front door, but a gamesmaster meeting the shifting threat with nimble hands and a diverse arsenal of defenses, always on the lookout for alerts.

Should that test a general tolerance for whimsy, the <a href="https://www.biometricupdate.com/202608/biometric-update-publishes-2026-deepfake-fraud-detection-market-report"><i>Biometric Update</i> 2026 Deepfake Detection Market Report</a>, co-authored with Goode Intelligence, gives it to you straight: “defense is increasingly delivered as part of a layered identity security architecture rather than as a standalone product. Many vendors combine deepfake detection with presentation attack detection (PAD), <a href="https://www.biometricupdate.com/202606/2026-injection-attack-detection-market-report-and-buyers-guide">injection attack detection</a> (IAD), liveness detection and broader fraud prevention capabilities. While the technologies and target markets differ, the common objective is to help organizations detect and prevent AI-enabled identity fraud.”

The threat is expanding across digital pipelines and getting more efficient. <a href="https://www.biometricupdate.com/202608/ai-fraud-pushes-identity-defenses-toward-iad-and-continuous-verification">Defenses</a> must do the same: specific security elements working in concert to provide unbroken, ongoing protection against AI-driven fraud.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/deepfake-detection-evolving-beyond-onboarding-into-continuous-financial-trust/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353578</post-id>	</item>
		<item>
		<title>Scotland weighs LFR policies as police request mask ban, ethics study launches</title>
		<link>https://www.biometricupdate.com/202608/scotland-weighs-lfr-policies-as-police-request-mask-ban-ethics-study-launches</link>
					<comments>https://www.biometricupdate.com/202608/scotland-weighs-lfr-policies-as-police-request-mask-ban-ethics-study-launches#respond</comments>
		
		<dc:creator><![CDATA[Chris Burt]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 18:12:04 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Facial Recognition]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[facial recognition]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[live facial recognition]]></category>
		<category><![CDATA[Police Scotland]]></category>
		<category><![CDATA[Scotland]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353568</guid>

					<description><![CDATA[
		<img width="1200" height="777" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2019/12/17152505/police-scotland-body-cameras-biometrics.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="police scotland body cameras biometrics" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2019/12/17152505/police-scotland-body-cameras-biometrics.jpg 1200w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2019/12/17152505/police-scotland-body-cameras-biometrics-150x97.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2019/12/17152505/police-scotland-body-cameras-biometrics-300x194.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2019/12/17152505/police-scotland-body-cameras-biometrics-768x497.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2019/12/17152505/police-scotland-body-cameras-biometrics-1024x663.jpg 1024w" sizes="auto, (max-width: 1200px) 100vw, 1200px" />
		If police in Scotland are able to use live facial recognition in public then people should not be allowed to cover their faces with masks, the Scottish Police Federation says. The policy request comes just as a new project launches to consider how Scottish police’s use of real-time face biometrics should be governed.

“There is little point investing millions of pounds in sophisticated technology capable of recognizing a face if an individual intent on committing crime can simply hide that face behind a mask or covering,” according to Federation General Secretary David Kennedy says, as reported by <a href="https://www.scottishlegal.com/articles/police-call-for-powers-to-remove-face-coverings-before-any-facial-recognition-rollout" target="_blank" rel="noopener">Scottish Legal News</a>.

England’s recently-passed Crime and Policing Act 2026 allows police to establish 24-hour “<a href="https://www.legislation.gov.uk/ukpga/2026/20/section/158">mask-free zones</a>,” which Kennedy would like to see copied in Scotland. Allowances would have to be made for religious, cultural, medical and occupational reasons, he says.
<h2>A deliberative approach to setting up LFR governance</h2>
While LFR has been deployed in England and Wales for years now, Scotland is taking a deliberative approach to deciding how it wants to the technology to be governed. To that end, the Scottish Institute for Policing Research (SIPR) is backing an academic study into the administration of live facial recognition in law enforcement.

The “<a href="https://sites.google.com/view/facerecproject/home" target="_blank" rel="noopener">Face[REC]</a>” project combines legal analysis with workshops to draw insights from police officer and citizen participants. The research will focus on the ethical implications of LFR and appropriate regulations. Outcomes will include a physical deck of cards “to enable collective deliberation between policymakers, academics, police, and regulators about governing LFR now and in the future.”

Police Scotland stated its <a href="https://www.biometricupdate.com/202508/scottish-police-confirm-live-facial-recognition-plans">commitment to adopting real-time facial recognition</a> last year, touching off a series of reactions and responses ranging from pleas to <a href="https://www.biometricupdate.com/202510/amnesty-international-urges-scotland-to-ban-live-facial-recognition-for-law-enforcement">ban the tech</a> to <a href="https://www.biometricupdate.com/202602/police-scotland-plans-lfr-business-case-consultation-on-the-way-to-a-decision-spa">assurances about governance requirements</a>. Scotland still could be the first country in the world to pass <a href="https://www.biometricupdate.com/202605/will-scotland-be-the-first-nation-to-pass-primary-legislation-covering-live-frt">primary legislation</a> directly addressing the use of LFR by police.

In recent months, the UK BSCC has expressed support for a <a href="https://www.biometricupdate.com/202606/uk-biometrics-watchdog-backs-expanded-oversight-role-for-scotland">greater oversight role</a> for his Biometrics Commissioner colleague in Holyrood, and the country’s chief inspector of constabulary urged <a href="https://www.biometricupdate.com/202608/scotlands-police-inspector-backs-faster-rollout-of-facial-recognition-ai">faster adoption advanced technologies</a>, including LFR.

A pair of biometrics experts who are directors at the Centre for Research into Information, Surveillance and Privacy (CRISP), Dr. Diana Miranda of the University of Stirling and Dr. Lachlan Urquhart of the University of Edinburgh, will lead the research.

The project is getting £20,000 (roughly US$27,000) in funding from SIPR, and support from the two universities. Miranda is a senior lecturer in criminology, and Urquhart a senior lecturer in technology law and human-computer interaction.

The project is expected to be completed in the Spring of 2027.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/scotland-weighs-lfr-policies-as-police-request-mask-ban-ethics-study-launches/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353568</post-id>	</item>
		<item>
		<title>Iraq takes over refugee identity registration from UNHCR</title>
		<link>https://www.biometricupdate.com/202608/iraq-takes-over-refugee-identity-registration-from-unhcr</link>
					<comments>https://www.biometricupdate.com/202608/iraq-takes-over-refugee-identity-registration-from-unhcr#respond</comments>
		
		<dc:creator><![CDATA[Lu-Hai Liang]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 17:07:30 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Government Services]]></category>
		<category><![CDATA[ID for All]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[civil registration]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[Iraq]]></category>
		<category><![CDATA[legal identity]]></category>
		<category><![CDATA[refugee registration]]></category>
		<category><![CDATA[UNHCR]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353548</guid>

					<description><![CDATA[
		<img width="2048" height="1200" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25130059/iraq-refugee-registration-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25130059/iraq-refugee-registration-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25130059/iraq-refugee-registration-300x176.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25130059/iraq-refugee-registration-1024x600.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25130059/iraq-refugee-registration-150x88.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25130059/iraq-refugee-registration-768x450.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25130059/iraq-refugee-registration-1536x900.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		Iraq is assuming responsibility for refugee and asylum-seeker registration, taking over a process previously led by UNHCR.

The Ministry of Interior’s Permanent Committee for Refugee Affairs (PC‑MOI) has begun issuing official identity cards to refugees and asylum seekers as part of a phased transition to nationally managed registration.

The process has families booking appointments through UNHCR’s online portal. They receive referral letters before completing registration at PC‑MOI. Biometric data is collected during registration as part of the process for issuing government identity documentation.

Officials verify documents and conduct short interviews. The PC‑MOI cards can be issued within minutes. For refugees the card provides recognized legal identity, reduces risks of arrest or detention, and opens access to healthcare, education and other services.

Mobile registration missions and home visits ensure those outside Baghdad or with limited mobility are included. Brigadier General Nadhim Abdullah Ahmed, PC‑MOI Secretary, <a href="https://www.unhcr.org/iq/news/stories/government-led-registration-enhances-protection-refugees-and-asylum-seekers-iraq-s">said</a> the process takes about 15 minutes, supported by UNHCR’s database tools.
<h2>Transition to nationally managed refugee identity</h2>
The transition reflects years of partnership between <a href="https://www.biometricupdate.com/202601/iraq-measures-dpi-progress-90-digital-id-uptake-859-egov-services">Iraq</a> and UNHCR, backed by donors such as the EU and governments including Sweden, Germany, Denmark and Norway.

The joint registration process was launched in April 2026 with the expectation that responsibility for asylum registration would gradually transfer from UNHCR to the Iraqi government.

The transition reflects a broader trend in which governments, including <a href="https://www.biometricupdate.com/202607/fayda-digital-id-critical-for-ethiopias-five-year-refugee-inclusion-strategy">Ethiopia</a> and <a href="https://www.biometricupdate.com/202606/rwandas-digital-id-rollout-expands-access-for-refugees">Rwanda</a>, are integrating refugee registration into <a href="https://www.biometricupdate.com/202605/id4africa-speakers-urge-legal-identity-inclusion-for-refugees-stateless-persons">national digital identity systems</a>, shifting responsibility for identity management from international agencies to sovereign institutions while expanding access to public services.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/iraq-takes-over-refugee-identity-registration-from-unhcr/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353548</post-id>	</item>
		<item>
		<title>BSI warns AI can reproduce 3D fingerprints from online photo of hands</title>
		<link>https://www.biometricupdate.com/202608/bsi-warns-ai-can-reproduce-3d-fingerprints-from-online-photo-of-hands</link>
					<comments>https://www.biometricupdate.com/202608/bsi-warns-ai-can-reproduce-3d-fingerprints-from-online-photo-of-hands#respond</comments>
		
		<dc:creator><![CDATA[Joel R. McConvey]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 16:43:15 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Fingerprint Recognition]]></category>
		<category><![CDATA[Liveness Detection]]></category>
		<category><![CDATA[AI fraud]]></category>
		<category><![CDATA[biometric liveness detection]]></category>
		<category><![CDATA[fingerprint biometrics]]></category>
		<category><![CDATA[German Federal Office for Information Security (BSI)]]></category>
		<category><![CDATA[spoofing]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353535</guid>

					<description><![CDATA[
		<img width="2048" height="1080" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25124141/shutterstock_2706564033-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25124141/shutterstock_2706564033-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25124141/shutterstock_2706564033-300x158.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25124141/shutterstock_2706564033-1024x540.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25124141/shutterstock_2706564033-150x79.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25124141/shutterstock_2706564033-768x405.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/08/25124141/shutterstock_2706564033-1536x810.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		A warning from the German Federal Office for Information Security (<a href="https://www.bsi.bund.de/EN/Home/home_node.html">BSI</a>) highlights an emerging AI-assisted fraud risk  – this one focused on your hands. A post on the cyber agency’s Bluesky account, translated from German, <a href="https://bsky.app/profile/bsi.bund.de/post/3mtsq74c74h2i">says</a> “attackers can use AI and a 3D printer to create fingerprint copies from photos of your hands.”

“Unlike passwords, fingerprints cannot be easily replaced. Therefore, anyone protecting sensitive access with biometrics should not rely on it as their sole security measure.”

The warning reflects a broader trend in which AI is reducing the cost and expertise required needed to reproduce biometric characteristics once considered difficult to spoof.

Nonetheless, according to the BSI, even throwing a peace sign is enough to expose <a href="https://www.biometricupdate.com/202608/nist-picks-11-contactless-fingerprint-biometrics-providers-for-certification-testing">fingerprint biometrics</a> that sophisticated AI tools can reproduce using 3D printing.

A <a href="https://www.bankinfosecurity.com/german-cyber-agency-warns-fingerprints-be-spoofed-a-32643">report</a> from ISMG quotes a BSI spokesperson, who says that, “among other things, criminals can use a representation of a fingerprint to create a synthetic fingerprint that is sufficiently similar to the real one and can thus potentially unlock smartphones if those devices lack additional security measures capable of detecting such <a href="https://www.biometricupdate.com/202402/scientists-recreate-fingerprints-from-the-sound-of-swiping-on-a-touchscreen">synthetic fingerprints</a>.”

The warning does not suggest fingerprint biometrics are obsolete. Instead, it reinforces a broader industry trend toward layered authentication, combining biometrics with liveness detection, device security and additional authentication factors as AI-powered spoofing techniques become more accessible. A 2020 Cisco Talos study, for example, showed 3D-printed fingerprints could bypass biometric authentication on selected devices under test conditions.

As AI lowers the barriers to reproducing biometric traits, the challenge is shifting from preventing spoofing altogether to detecting and mitigating increasingly sophisticated attacks.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/bsi-warns-ai-can-reproduce-3d-fingerprints-from-online-photo-of-hands/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353535</post-id>	</item>
		<item>
		<title>Meta loses bid to end BIPA voiceprint suit as case moves forward</title>
		<link>https://www.biometricupdate.com/202608/meta-loses-bid-to-end-bipa-voiceprint-suit-as-case-moves-forward</link>
					<comments>https://www.biometricupdate.com/202608/meta-loses-bid-to-end-bipa-voiceprint-suit-as-case-moves-forward#respond</comments>
		
		<dc:creator><![CDATA[Anthony Kimery]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 16:24:03 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Voice Biometrics]]></category>
		<category><![CDATA[biometric identifiers]]></category>
		<category><![CDATA[Biometric Information Privacy Act (BIPA)]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[lawsuits]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[voice biometrics]]></category>
		<category><![CDATA[voiceprints]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353526</guid>

					<description><![CDATA[
		<img width="2048" height="1366" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/02/27105611/voice-biometrics-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/02/27105611/voice-biometrics-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/02/27105611/voice-biometrics-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/02/27105611/voice-biometrics-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/02/27105611/voice-biometrics-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/02/27105611/voice-biometrics-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/02/27105611/voice-biometrics-1536x1025.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		A federal judge in California <a href="https://drive.google.com/file/d/1tukTEIykdLetL1TH3guYcI-iRflFSzUT/view?usp=sharing">rejected</a> Meta Platforms’ attempt to end a biometric privacy lawsuit over voice recordings collected through Facebook and Messenger, finding that evidence about Meta’s own voice processing technologies and its ability to connect audio files with user accounts creates a factual dispute over whether the recordings could be used to identify people. Illinois resident Natalie Delgado, who brought the lawsuit in 2023 under the state’s <a href="https://www.biometricupdate.com/tag/bipa-biometric-information-privacy-act">Biometric Information Privacy Act</a> (BIPA), filed a motion August 21 asking U.S. District Judge Susan Illston of the Northern District of California to certify an Illinois class. A hearing on class certification is scheduled for December 18.

BIPA expressly protects “voiceprints” as biometric identifiers, along with fingerprints, retina or iris scans and scans of hand or face geometry. But the statute does not define what makes recorded speech a voiceprint rather than simply an audio recording.

Meta argued that distinction should end Delgado’s case.

According to the company, the audio files it received through Facebook and Messenger were merely voice recordings. To identify a speaker, Meta argued, a recording would first have to be processed into different data representing characteristics of the speaker’s voice, which it called an “Output Representation.”

That representation would then have to be compared with data linking it to a known person. Meta said it had not created such representations from Delgado’s recordings and did not possess information linking the voices in her uploaded recordings to her identity.

Illston concluded the evidence was not that simple.

The central question under BIPA, she said, was not whether Meta had used Delgado’s voice recordings to identify her. Citing a 2024 Ninth Circuit ruling involving Meta’s facial recognition technology, she said the relevant issue is whether the biometric data can identify a person. As Illston put it, “BIPA applies if it could.”

Delgado’s expert, Carnegie Mellon University professor Rita Singh, presented evidence about Meta’s internal capabilities that Illston found sufficient to create a genuine dispute for trial.

Singh said Meta uses technical pipelines to process audio received through Facebook and Messenger, converts the data into standardized formats suitable for speech analysis, stores voice data in interconnected systems associated with user accounts and maintains the data in formats compatible with speaker-identification and verification technologies.

Singh also cited Meta research and technologies that she said showed the company possessed and had used systems capable of identifying individuals from digital voice data.

Evidence provided to the court showed that voice recordings uploaded through Facebook and Messenger can be associated with a Facebook user ID or account identifier, which can in turn be associated with information about the account holder that can include a name, email address, hometown, date of birth, employer, IP address and other personal information.

Singh also described methods through which voice data could be associated with an individual using direct account links or statistical and probabilistic techniques.

In one experiment described in the court record, Singh analyzed 10 Messenger voice messages sent from Delgado’s account and used statistical comparisons of the voices to demonstrate how the most frequently occurring speaker could be associated with the account holder.

Meta disputed the significance of the experiment and maintained that a user can upload recordings containing someone else’s voice, multiple voices or no human voice at all.

Illston found that those competing interpretations underscored why summary judgment was inappropriate.

The judge said Delgado had produced admissible evidence that Meta possessed proprietary technologies and internal systems capable of processing a voice recording and connecting it with a user account and the personally identifiable information associated with that account.

Singh also pointed to Meta’s previous research and speaker identification work in concluding that the company’s capabilities went beyond a merely theoretical ability to identify speakers.

Meta warned that accepting Delgado’s theory could make virtually anyone possessing a voicemail and having access to readily available speaker identification software potentially liable under BIPA.

Illston rejected that characterization, saying her decision “does not open the floodgates.”

Just as importantly, however, Illston did not decide that a voice recording itself is necessarily a voiceprint and explicitly declined to draw a precise line at which ordinary voice data becomes a BIPA-protected voiceprint.

She ruled that Delgado had produced enough evidence to create a genuine dispute over whether Meta collected biometric data capable of identifying her using technology the company possessed.

The judge’s June decision was not a finding that Meta violated BIPA. Delgado still must prove her claims, and no class has yet been certified.

Delgado alleges that she used Facebook and Messenger voice functions on multiple occasions in 2022 and 2023, including sending voice messages and making audio calls. She contends that Meta created, collected or stored voiceprints and related biometric information without satisfying BIPA’s requirements.

Delgado’s surviving claims invoke two portions of the Illinois law, Section 15(a) and Section 15(b).

Section 15(a) requires companies possessing biometric identifiers or biometric information to maintain a publicly available retention schedule and destruction guidelines.

Section 15(b) generally requires companies to provide written notice and obtain a written release before collecting or obtaining a person’s biometric identifier or biometric information.

Delgado alleges Meta failed to comply with those requirements.

The complaint also points to evidence predating the lawsuit that Meta had explored voice-based identification.

Delgado cited a Meta privacy disclosure stating that voice recordings could be collected and could be used to identify users, as well as a Facebook patent issued in 2020 titled “<em>User identification with voiceprints on online social networks</em>.”

The patent describes comparing audio from an unknown speaker against stored voiceprints of candidate social-network users and assigning probability scores to identify the speaker.

The June ruling marked another turn in the fight over Singh’s role in the case.

Meta previously sought to have Singh disqualified after Delgado retained her as an expert, arguing that attorneys for the company had discussed the litigation with her in 2024 while considering whether to hire her themselves.

Illston denied that motion in November 2025, finding Meta had no retainer or confidentiality agreement with Singh, had not paid her and had not established the kind of confidential relationship that would justify barring her from working for Delgado.

Singh’s analysis subsequently became central to the evidence Illston relied upon in refusing to grant Meta summary judgment.

Meta attempted after the ruling to obtain permission for an immediate appeal to the Ninth Circuit appeals court, arguing that whether the voice recordings at issue qualify as “voiceprints” under BIPA presented a legal issue appropriate for appellate review.

The litigation continues in the district court and has moved into class certification proceedings.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/meta-loses-bid-to-end-bipa-voiceprint-suit-as-case-moves-forward/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353526</post-id>	</item>
		<item>
		<title>India’s CSM Technologies joins MOSIP to connect GovTech with digital identity</title>
		<link>https://www.biometricupdate.com/202608/indias-csm-technologies-joins-mosip-to-connect-govtech-with-digital-identity</link>
					<comments>https://www.biometricupdate.com/202608/indias-csm-technologies-joins-mosip-to-connect-govtech-with-digital-identity#respond</comments>
		
		<dc:creator><![CDATA[Chris Burt]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 16:12:00 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[ID for All]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[CSM Technologies]]></category>
		<category><![CDATA[digital identity]]></category>
		<category><![CDATA[digital public infrastructure]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[MOSIP (Modular Open Source Identity Platform)]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353516</guid>

					<description><![CDATA[
		<img width="2048" height="1307" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/18143928/biometric-dpi-cybersecurity-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/18143928/biometric-dpi-cybersecurity-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/18143928/biometric-dpi-cybersecurity-300x191.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/18143928/biometric-dpi-cybersecurity-1024x653.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/18143928/biometric-dpi-cybersecurity-150x96.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/18143928/biometric-dpi-cybersecurity-768x490.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/18143928/biometric-dpi-cybersecurity-1536x980.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		India-based multinational GovTech provider <a href="https://www.csm.tech/">CSM Technologies</a> is moving into foundational digital identity and digital public infrastructure (DPI) through a strategic expansion. Part of that expansion involves engagement with MOSIP to join its technology partner ecosystem.

CSM is now listed as a systems integrator on the <a href="https://marketplace.mosip.io/system_integrators/143">MOSIP Marketplace</a>.

Technical teams with CSM completed comprehensive training on the Modular Open Source Identity Platform and built up the expertise to design, integrate, customize and implement digital identity solutions based on MOSIP, according to the announcement. The process for joining the MOSIP ecosystem as a system integrator, and the role of SIs in MOSIP implementations are explained in <em>Biometric Update</em>’s report on “<a href="https://www.biometricupdate.com/202605/understanding-mosip-what-the-modular-open-source-identity-platform-is-and-how-it-is-used">Understanding MOSIP: What the Modular Open-Source Identity Platform is and how it is used</a>.”

The company argues MOSIP’s modular architecture gives countries the opportunity to develop digital identity infrastructure with greater flexibility and ownership than they would otherwise have.

CSM Technologies MD and CEO Priyadarshi Pany notes the importance of digital identity to modern DPI.

“Our engagement with MOSIP strengthens our ability to help governments build identity systems that are secure, scalable, interoperable and aligned to their own institutional and citizen needs,” Pany says in the announcement. “For CSM, this is not simply an addition to our technology portfolio; it is a significant capability that complements our experience of building mission-critical digital platforms for governments across emerging economies."

CSM Technologies launched its stock to the Bombay Stock Exchange (BSE) and National Stock Exchange (NSE) of India in July. The company booked revenue of just under 2.3 billion Indian rupees (roughly US$24 million) in the full 2026 fiscal year.

<a href="https://www.sahi.com/news/csm-technologies-adopts-mosip-framework-to-expand-global-digital-identity-footprint-8176423-PE1_">Sahi</a> notes the adoption of MOSIP positions CSM to bid on complex, multilateral-funded DPI Projects, and says the company is planning to scale its international business following its recent listing.

The World Bank’s 2026 Global Digital Public Infrastructure Program says 2.9 billion people, the majority of them living in Sub-Saharan Africa and South Asia, do not have digital IDs they can use for online transactions, CSM points out.

The “<a href="https://www.biometricupdate.com/202605/understanding-mosip-what-the-modular-open-source-identity-platform-is-and-how-it-is-used">Understanding MOSIP</a>” report also delves into the growing emphasis across the ecosystem on sustainability and effective service delivery.

CSM’s experience in GovTech provides a competitive position for countries looking to integrate their identity programs with government services and other DPI components.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/indias-csm-technologies-joins-mosip-to-connect-govtech-with-digital-identity/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353516</post-id>	</item>
		<item>
		<title>India drops shared biometric database from telecom verification rules</title>
		<link>https://www.biometricupdate.com/202608/india-drops-shared-biometric-database-from-telecom-verification-rules</link>
					<comments>https://www.biometricupdate.com/202608/india-drops-shared-biometric-database-from-telecom-verification-rules#respond</comments>
		
		<dc:creator><![CDATA[Lu-Hai Liang]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 15:24:15 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[Consumer Electronics]]></category>
		<category><![CDATA[Aadhaar]]></category>
		<category><![CDATA[biometric database]]></category>
		<category><![CDATA[biometric verification]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[KYC]]></category>
		<category><![CDATA[SIM card registration]]></category>
		<category><![CDATA[telecom]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=353478</guid>

					<description><![CDATA[
		<img width="2048" height="1365" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/21144537/india-train-station-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/21144537/india-train-station-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/21144537/india-train-station-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/21144537/india-train-station-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/21144537/india-train-station-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/21144537/india-train-station-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/21144537/india-train-station-1536x1024.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		India is not proceeding with the Biometric Identity Verification System, but biometrics firmly remain in the plan.

The country’s Department of Telecommunications (DoT) has dropped its proposal to create a single cross‑industry biometric database known as the Biometric Identity Verification System (<a href="https://www.biometricupdate.com/202509/australia-india-and-malaysia-turn-to-digital-id-to-stem-sim-fraud">BIVS</a>).

The final “Telecommunications (User Identification) Rules, 2026” <a href="https://www.publicnow.com/view/BE8C92E6882E1B9712541960A56171C6F8B6C348">rules</a>, notified last Friday, replace the idea of cross‑company biometric matching with e‑KYC and D‑KYC processes.

Under the Telecommunications Act 2023, operators must verify the identity of users through biometric methods. The draft rules published last September had included BIVS, which would have assigned a unique ID to every telecom customer and allowed companies to check identities against each other’s records.

Civil society groups, including the Internet Freedom Foundation, criticized the plan as an unnecessary parallel collection of biometric data without the safeguards of the Aadhaar Act.

The final rules now require operators such as Airtel, Jio, Vodafone Idea and BSNL to <a href="https://www.uniindia.com/new-telecom-rules-tighten-sim-verification-biometrics-for-new-connections-replacement-and-disconnection/north/news/3952023.html">confirm user identity</a> before issuing SIM cards, updating records or disconnecting numbers. Aadhaar holders will be verified through UIDAI’s authentication facility, while non‑Aadhaar users will undergo D‑KYC, which involves live face capture, ID document scans, and, if necessary, field visits or police checks.

Mandatory biometric checks before disconnection is another provision, along with an alert system to notify users of any SIM or account changes, and reporting requirements for failed biometric verification. Companies have three months, extendable to six, to implement the systems.

While BIVS has been abandoned, the DoT has introduced a separate mechanism through its Digital Intelligence Platform. From August 23, the platform will pull subscriber data and photos from all telecom operators to identify individuals holding more than the permitted number of mobile connections nationwide.

India’s telecom verification framework is clearly working out how to balance identity assurance with privacy concerns raised during the consultation process.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202608/india-drops-shared-biometric-database-from-telecom-verification-rules/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">353478</post-id>	</item>
	</channel>
</rss>
