In his latest piece with Gaming Eminence, our Chief Information Security Officer, Gerardo Prieto, explores why operators need to look beyond surface-level metrics and one-off onboarding checks to uncover hidden risks.
Gaming Eminence: You've suggested traditional KYC is breaking down. Which parts are actually failing today?
Gerardo Prieto: KYC as a regulatory obligation isn't going anywhere. What's breaking are the technical assumptions under it.
The clearest failure is liveness at onboarding. The old equation, document plus selfie equals verified human, worked when faking both was slow and expensive. It isn't anymore. Attackers feed a deepfake stream into the selfie flow through a virtual camera, and passive liveness checks can't tell a real face from a synthetic overlay. Tested against live selfie flows, those injection attacks bypass a wide range of implementations.
The second failure is the one-time gate. You check at the door, wave them through, and stop looking, but the dangerous behaviour happens after onboarding, at the bonus claim and the withdrawal.
And the worst one: synthetic identities don't fail your checks, they pass them. They slip past the checks themselves, not tired analysts, because the systems were built for a fraud world that no longer exists. To a legacy system, a synthetic identity with a valid document looks like a good customer. That's the part that should keep people up at night.
Gaming Eminence: Which fraud techniques are rising fastest in regulated gambling right now?
Gerardo Prieto: The boring stuff is still the biggest, bonus abuse and multi-accounting.
The fastest riser is the coordinated, multi-step attack that chains techniques together: bonus abuse plus synthetic identity plus laundering. It breaks single-purpose controls by design.
The mechanics evolved too. Abusers moved from manual multi-accounting to bot farms running thousands of accounts with unique fingerprints, while mule networks run deposit-withdraw cycles that mimic legitimate players.
Same old playbook. They just got a machine to run it a thousand times.
Gaming Eminence: How is AI-enabled fraud changing the cost equation for operators?
Gerardo Prieto: The shift isn't that deepfakes got better. It's that they got cheap. That's the whole game.
Deepfake-as-a-service and synthetic identities now cost almost nothing to produce. When attacks are that cheap, the maths inverts: you defend against something that cost a few dollars to launch while absorbing six-figure losses per incident. You have to block every attack; they need one to land.
For operators that means three things: volume is no longer a barrier for the bad guys, false positives rise as you tighten thresholds (real revenue lost), and spend has to move from the door to the lifecycle. The direction isn't in doubt, attacking got cheaper faster than defending did.
The only honest answer to cheap, scaled, AI-driven fraud is to fight it with AI of your own. You can't beat machine-speed attacks with manual review and static rules. Defence has to match the attacker's tooling — AI models that score behaviour and device signals in real time, spot synthetic patterns a human would miss, and adapt as the attacks do. Operators still relying purely on human teams and fixed rules are bringing a knife to a gunfight.
Gaming Eminence: Where are operators still relying on frameworks no longer fit for purpose?
Gerardo Prieto: Three places.
Treating identity as an event, not a state, "verified at onboarding = trusted forever." But behavioural shifts, odd transactions and sudden detail changes all signal takeover or mule activity a one-off gate never sees.
Over-trusting a single strong check. Defence now comes down to how well controls work together — rely on one check and attackers learn to bypass it.
And assuming the document is the source of truth. In a synthetic world that's backwards — when the document is technically valid, the only reliable signal is the inconsistency footprint across signals, not document quality.
Gaming Eminence: How should operators balance stronger verification with onboarding friction?
Gerardo Prieto: This tension is real, friction is churn you can measure. Bad KYC flows can push up to 40% of users to abandon onboarding. "Add more checks" isn't a serious answer.
The fix is risk-based, not uniform. Keep the default path light and trigger heavy verification only when a risk signal or threshold fires, using single-session flows. Then shift effort to the lifecycle: document and biometric checks at onboarding, plus device and behavioural monitoring during play and AML screening throughout. That lets you keep a light front door without going blind.
My framing for commercial colleagues: friction isn't the cost, misplaced friction is. A good system is invisible to 95% of players and brutal to the 5% who deserve it.
Gaming Eminence: What early warning signals should executives monitor?
Gerardo Prieto: A short list, watch these and you'll know you're slipping.
Watch your bonus and promotion spend. This fraud is quiet: the losses build with no single event loud enough to trigger an alert, and by the time you've mapped the network, weeks of payouts have already cleared. If money going out on promotions is climbing and nobody can fully explain why, that's often fraud, not marketing.
Watch the gap between sign-ups and real depositing players. At some operators, up to 30% of registrations have been estimated as fraud. Lots of new accounts but few who actually deposit and play means someone's farming accounts at scale.
Watch for approvals that look too smooth. A falling fraud-catch rate isn't always good news, synthetic identities are built to pass, so a suspiciously clean funnel can mean your controls have stopped seeing the sophisticated stuff.
And be honest about your own readiness: 63% of organisations have spent nothing on deepfake defence, and only 5% have a real strategy. If you don't know which group you're in, you're already behind.
The goal for the rest of 2026: assume the attacker's tools are cheaper and faster than yours, and build your monitoring as if compromise is always happening, because it is.
Interview originally appeared on Gaming Eminence.
Talk to our team about fraud and KYC on our platform.



