AI-powered deepfakes are more than just a headache for government agencies and law enforcement. According to Janice Kephart, CEO of Identity Strategy Partners, AI-powered deepfakes are initiating the collapse of verified identities, triggering a wave of fraud, and compromising national security. We had the opportunity to talk with Kephart about these serious threats to America’s security in advance of the 2025 Biometrics for Government and Law Enforcement Summit, coming up on November 19 and 20, 2025 in Reston, Virginia. Read on to learn more about these threats and strategies that law enforcement agencies are using to manage, mitigate, and eliminate these threats.
Government Technology Insider: What are some of the top threats that government and law enforcement organizations are facing today?
Janice Kephart (JK): One of the greatest threats confronting government and law enforcement today is the accelerating collapse of the boundary between real and fake identities—driven largely by the rapid advancement of artificial intelligence. Identity theft and fraud are already at record highs, but AI has amplified the scale, speed, and sophistication of deception. In hiring alone, job applicant fraud has increased by more than 1,000% each of the past three years according to INFIDO, and Gartner projects that by 2028, one in four job applicants will be fake. Traditional identity theft continues to plague the U.S. through stolen Social Security numbers and counterfeit IDs, but AI has expanded the threat surface exponentially.
We now face the proliferation of at least six distinct forms of deepfakes—hyper-realistic AI-generated images or videos that can convincingly mimic real people, including face swaps, expression swaps, photo editing, text-to-video, text-to-image, and AI avatars. These are compounded by synthetic faces, face morphs (where two or more facial images are merged to create a “new” identity that can fool algorithms), and synthetic identity documents that blend real and fabricated information. The result is an identity ecosystem under siege, with direct implications for economic stability, national security, and public trust.
The risks are not hypothetical. In 2024, the Department of Justice dismantled a North Korean state-sponsored network that stole over 160 U.S. citizen identities to fraudulently obtain remote jobs at major American corporations—including nearly every Fortune 500 firm. Over six years, the operatives used both traditional identity theft and deepfakes to pass background checks, earning more than $88 million in stolen salaries, while also exfiltrating proprietary corporate data later used to fund weapons and missile programs.
These same tactics now threaten the U.S. government’s own identity repositories, where biometric systems are increasingly vulnerable to presentation attacks—instances where a photo, video, or synthetic image is used to impersonate a live person. Many biometric algorithms still lack sufficient liveness detection and deepfake analysis capabilities, leaving systems exposed. This risk is particularly acute in our immigration infrastructure, which relies heavily on biometrics to verify identity authenticity. Without modernization and AI-resilient countermeasures, the integrity of these systems—and by extension, our national security—faces a ticking time bomb.
GTI: These threats also affect US allies. Why is it important to factor our allies into America’s homeland security?
JK: We must integrate the evolving identity landscape into every layer of our homeland security strategy. At its core, every national security threat begins with a person—real or fabricated. Whether it’s an individual hiding behind an AI-generated deepfake, a morphing synthetic image, or a counterfeit digital credential used to access sensitive systems, there is always a human actor seeking illicit advantage. Each fraudulent identity represents both a gain for the adversary and a loss for a victim—from financial institutions losing billions annually to fraud, to terrorists and state actors exploiting identity gaps to infiltrate U.S. borders, supply chains, and critical infrastructure.
These are not theoretical risks. The same technologies undermining our own systems are targeting our allies’ national identity infrastructures, creating ripple effects that threaten collective defense, intelligence sharing, and global economic stability. When allies are compromised, our homeland becomes more vulnerable—since shared data, international travel, and digital transactions are all interconnected.
The European Union’s model, which integrates national ID systems that “freeze” identity attributes while preserving privacy, demonstrates that it is possible to balance security, trust, and access. This approach enables governments to deliver services efficiently while safeguarding against synthetic identity attacks. In contrast, the United States lacks a cohesive identity framework, leaving both citizens and institutions disproportionately exposed. The North Korean infiltration case underscores this reality: when foreign adversaries can weaponize U.S. identities against both our private sector and our allies, it becomes clear that identity security is homeland security.
GTI: How do government and law enforcement organizations mitigate these threats today?
JK: Technology-wise, the United States is fully capable of countering presentation attacks and sophisticated identity fraud. A growing cohort of innovative technology companies has worked diligently to stay toe-to-toe with the accelerating pace of identity deception. Mature digital identity standards, certifications, and interoperable infrastructures already exist that allow identity verification to occur within secure, tamper-resistant workflows—far superior to today’s fragmented “wild west” of static images and easily forged IDs.
The rollout of mobile driver’s licenses (mDLs) exemplifies the art of the possible when federal, state, and private-sector actors collaborate effectively. Fifteen states now issue mDLs, and eleven are accepted by the TSA—clear evidence that modern, privacy-preserving digital credentials can enhance both convenience and security when properly governed and implemented.
However, the larger challenge lies not in technology but in government adaptability. Until agencies modernize procurement processes, accelerate requirements development, and align acquisition policy with emerging threats, new solutions will remain siloed or slow to deploy. Without more agile governance and end-to-end coordination, the gap between rapidly evolving identity-based attacks and our ability to mitigate them will continue to widen—leaving both public and private institutions exposed.
GTI: What does the future of threat mitigation look like?
JK: If identity-based threats are not addressed comprehensively, the future of mitigation will remain fragmented, reactive, and largely ineffective. We are witnessing an accelerating collapse of the boundary between real and fake identities—a phenomenon that is reshaping not only the nature of cyber and physical threats, but the very fabric of our society.
Unless we confront this erosion head-on, our institutions and citizens alike will continue to be bewitched by deception—by adversaries who weaponize synthetic and deepfake identities to infiltrate, manipulate, and exploit. The consequences are not abstract: they touch our cultural integrity, economic resilience, and national security.
The path forward demands a paradigm shift—one that treats identity integrity as critical infrastructure. True mitigation will require aligning policy, technology, and procurement to enable AI-resilient identity verification, liveness detection, and trust frameworks that can evolve as fast as the threats themselves. Without that alignment, we risk not only falling behind—but losing control of what it even means to be “real.”
GTI: Any final thoughts to share with our readers?
JK: When I began my career as Counsel to the Senate Judiciary Committee 25 years ago, one of my first assignments was to modernize the federal crime of identity theft—then defined merely as a paper-based offense. With the internet emerging and digital systems beginning to reshape society, my task was to craft statutory language that anticipated a new era of cyber-enabled identity crime—so no criminal could exploit a loophole. That legislation passed the Senate by unanimous consent, was signed into law by the President, and remains on the books today. Later, my recommendations in the 9/11 Commission Final Report to integrate biometrics into border management helped fortify global travel security. Yet despite this progress, the threats have evolved faster than our defenses. We must now do far more to safeguard identity—the foundation of both individual liberty and national security.
Identity is the new frontline of national security. As deepfakes, synthetic personas, and digital forgeries multiply, our ability to distinguish truth from deception is being tested like never before. The technology to fight back already exists, but it requires the will to modernize, the discipline to integrate, and the vision to treat identity as critical infrastructure. Protecting who we are, individually and collectively, is no longer a technical issue; it is a matter of sovereignty, trust, and survival in the digital age. The nation states and institutions that act decisively today will define the meaning of security and authenticity for generations to come.
I look forward to having more in-depth, forward-looking discussions on the issue of establishing identity in a multitude of threat vectors at the 2025 Biometrics for Government and Law Enforcement Summit on November 19 and 20 in Reston, Virginia. We will have the opportunity to do a critical deep dive on what next steps the U.S. needs to take to address the growing blur of boundaries between real and fake identities to protect homeland and national security.

Interested in learning more about the conference, or registering to attend? You can do that here.