Skip to main contentScroll Top

DEEPFAKE FRAUD & SYNTHETIC IDENTITY THEFT: RECONCILING RBI’S ‘ZERO LIABILITY’ POLICY WITH AI BIOMETRIC SPOOFING

The Reserve Bank of India has reported a substantial increase in bank frauds, revealing that the amount reported has skyrocketed eightfold from the previous year, reaching ₹21,367 crore

INTRODUCTION

The Reserve Bank of India has reported a substantial increase in bank frauds, revealing that the amount reported has skyrocketed eightfold from the previous year, reaching ₹21,367 crore in the first half of FY 2024-25. This phenomenon is explained mainly by the RBI as having to do with frauds concerning loans and advances, rather than AI-powered identity fraud. [1]While it is difficult to establish the exact dimension of fraud enabled by Deepfake technology, there are reports from the industry that the number of frauds involving financial institutions considerably increased during FY 2023-24, so that a notable share of nearly 300,000 video-KYC calls is subjected to some sort of spoofing today.[2]. At this point, four aspects that can easily be confused.

  • Unauthorized electronic banking transaction — an existing customer’s credentials misused by a third party.
  • Biometric spoofing — a fake face or voice used to defeat a liveness or face-match check.
  • Deepfake fraud — AI-generated audio or video used to impersonate someone.
  • Synthetic identity fraud — an “identity” onboarded by a bank that does not correspond to any real person at all.

This blog focuses mainly on the last two concepts and the consequences of their applications at the KYC gateway. The RBI’s 2017 circular, which limits the liability of customers for unauthorized online banking transactions, is the primary consumer-protection measure in digital banking in India.[3]. This measure poses a simple question: whether the loss was due to the fault of the banking system, of a third party, or due to the delayed response by the customer. The question presupposes that a real customer existed whose access data was compromised. The issue does not arise in the case of biometric spoofing with the use of deep fake technology since it does not steal the credentials but creates fake ones.[4]

HISTORICAL BACKGROUND

Banking identification has gone through five stages, with each one countering the fraud that defeated the previous one:[5]

  • Passwords and PINs were used, relying on a static secret that only the account holder knew.
  • OTP authentication took care of SIM cloning and card skimming by utilizing a second factor that connected the device.
  • Biometric authentication eliminated the possibility of interception of OTPs as well as SIM swapping by making sure that identity is linked to a piece of information that cannot be shared or lost by the customer.
  • Aadhaar e-KYC and video KYC enabled biometric security in remote onboarding without a need to visit the branch.
  • Generative AI goes against the assumption made by each layer.

Liability law changed with every new layer. The circular issued in 2017 has not been updated because none of the identified fraud tactics are aimed at the verification layer.[6]

THE ZERO LIABILITY FRAMEWORK AND ITS ASSUMPTIONS

The 2017 circular introduced the concept of liability in relation to unauthorized transactions.[7]

  • In the case of zero liability, losses occur as a result of a failure on the part of the bank, or through the actions of a third party. Notification of the incident is made within three working days.
  • With regard to limited liability, it applies to certain transactions, whereby the losses incurred correspond to the value of the transaction and account type. Notification of the incident is made within four to seven days.
  • Lastly, liability based on the bank’s policy occurs when the notification period exceeds seven days.

The above-mentioned framework primarily targets unauthorized transactions in existing accounts. It does not specifically address onboarding fraud, where a customer technically does not exist. The present article applies the framework to synthetic identity fraud.

The judiciary has interpreted the concept of protection provided under the present structure in an effective manner. The Allahabad High Court stated in Suresh Chandra Singh Negi v Bank of Baroda: Who bears the burden of proof regarding customer negligence in relation to the bank? [8]But the argument is not one-sided. In State Bank of India v Hare Ram Singh, one judge stressed that the bank is liable even where OTP has been used for authentication as clever engineering can contravene the authentication process without the fault of the customer, only for the ruling to be overturned later on by the Division Bench. [9]A consistent theme is the source of compromise: there is one identifiable victim, and the question is what had gone wrong. However, this line of reasoning is ineffective with respect to synthesized identity theft, where the victim may not be a client but rather a construct of the generative model.

WHERE BIOMETRIC SPOOFING BREAKS THE MODEL

RBI’s Master Direction on KYC has mandated that video-based customer identification must provide live confirmation and detect spoof attempts. [10]Deepfake attacks can occur in two ways.

  • Presentation: screen or print is displayed to the camera.
  • Injection: a fabricated video stream is fed directly into the device’s camera pipeline, bypassing any physical presentation.

And blinking or head movement checks are able to contain the first method, but they can be easily foiled with the second method. Therefore, there remains a conceptual inconsistency in the view of the zero-liability scheme, which seeks to allocate the loss to an erroneous bank or negligent/diligent customer.

Section 66C of the Information Technology Act punish fraudulent acts of the unauthorized use of another person’s unique identification feature, while Section 66D punishes cheating via impersonation by means of computer resources. [11]The two provisions are seen to be intended to protect a specific victim who loses his identity or credentials through fraudulent actions. It is not known if they would also be applicable to an identity that never belonged to anyone.

REGULATORY MOVEMENT, AND ITS LIMITS 

Through 2026, the regulator has sought to close this gap from multiple angles:

  • Under IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026, effective from February 2026, “synthetically generated information” is defined, with responsibilities imposed for labelling and removing such content. This regulation applies to content providers only, and it does not cover the case of using mass-produced content directly in bank’s KYC module and not published anywhere else.[12]
  • The RBI’s draft Guidance on Regulatory Principles for Model Risk Management 2026 was issued for public consultation on 24 June 2026, thus suggesting that banks and non-banking finance companies (NBFC) are obliged to be responsible for results generated through third-party AI models.[13]RBI (Commercial Banks — Responsible Business Conduct) Third Amendment Directions, 2026 – issued on the same day and coming into force for transactions from January 1, 2027, is changing the “unauthorized” transaction category into the wider “fraudulent electronic banking transaction” concept, defining bank and customer negligence separately, and shifting the reporting timeframes to calendar days. It is a real move but is still focused on transactions with existing accounts. [14]
  • The suo motu order of the Supreme Court in the context of digital arrest scams ordered banks to use AI monitoring to identify suspicious transactions before they are completed. Hence started a new judicial trend towards AI-enabled fraudulent transaction detection, although it is still focused on transaction monitoring rather than preventing synthetic identity fraud at the onboarding stage.[15]

RECONCILING THE TWO REGIMES

As one of the viable solutions to the problem stated, we may suggest treating the fact of the failures of anti-spoofing technologies, according to the accuracy criteria available in the KYC Master Directive, as a kind of negligence on the part of the bank within the framework of the negligence doctrine in Third Amendment Directions issued back in 2026, irrespective of the fact of any reporting timeline. If the fraud occurs at the verification level, then there is no customer who may cause any delay and start the reporting clock in the first place. Thus, if the KYC system claims to be resistant to spoofing cases, it shall take the loss by default.

in keeping with the refusal in the Model Risk Management draft to permit banks to offload accountability to their vendors.[16]

This is not an assertion that the zero liability rule works in this fashion. It is a case that the two–party licensing system – the bank and the customer – should also include a third element of fraud that creates its own “customer.” Banks have the motivation to see deepfake-enabled onboarding fraud as a customer or third-party issue rather than a matter of the institution until the Regulation 2026 instruments are read together and finalized where they are still draft.

CONCLUSION

Deepfake-facilitated synthetic identity fraud illustrates a structural loophole in India’s customer-liability framework designed for stolen accounts and recognizable customers, not for completely synthetic identities that could pass AI-based KYC auditing. As impersonation moves into the verification stage, the question changes from who has committed an error between the bank and the customer to whether the financial institution has utilized adequate technological precautions in the process of creating, operating, and approving its verification system. The developments of 2026, namely the development of Model Risk Management, the Third Amendment Directives, and the urging from the Supreme Court to implement AI-based monitoring procedures, indicate the recognition of institutional responsibility without establishing it in a definitive form.

Author(s) Name: Gagan P (Presidency University)

References:

[1] Reserve Bank of India, Report on Trend and Progress of Banking in India 2023-24 (RBI, 26 December 2024).

[2] HyperVerge, ‘What Is a Deepfake? Definition, Examples & Detection in India’ (HyperVerge Blog, 2026) <https://hyperverge.co/blog/what-is-a-deepfake/> accessed 10 September 2026; Gridlines, ‘The New Face of Fraud: Deepfakes and the Future of Video KYC’ (Gridlines Blog, 18 July 2025) <https://gridlines.io/blogs/deepfake-fraud-video-kyc/> accessed 6 September 2026

[3] Reserve Bank of India, Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (Circular No RBI/2017-18/15, DBR.No.Leg.BC.78/09.07.005/2017-18, 6 July 2017).

[4] RBI (n 3).

[5] Reserve Bank of India, Master Direction – Know Your Customer (KYC) Direction, 2016 (as amended); UIDAI, Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Rules 2020; HyperVerge, ‘RBI Video KYC Deepfake Guidelines: 2026 Compliance Guide’ (HyperVerge Blog, 23 March 2026) <https://hyperverge.co/blog/rbi-video-kyc-deepfake-guidelines/> accessed 9 September 2026.

[6] RBI (n 3).

[7] RBI (n 3).

[8] Suresh Chandra Singh Negi v Bank of Baroda, Writ-C No 24192 of 2022, 2025:AHC:115460-DB (Allahabad HC).

[9] State Bank of India v Hare Ram Singh, 2026:DHC:4833-DB (Delhi HC); for the single-judge decision under appeal, see Hare Ram Singh v Reserve Bank of India, WP(C) 13497/2022 (Delhi HC).

[10] RBI, Master Direction – KYC Direction, 2016 (n 5) para 18(b); HyperVerge (n 5).

[11] Information Technology Act 2000, ss 66C, 66D; Facia, ‘How Deepfakes Are Used to Bypass KYC Onboarding: A Technical Breakdown’ (Facia Blog, 27 March 2026) <https://facia.ai/blog/how-deepfakes-are-used-to-bypass-kyc-onboarding-a-technical-breakdown/> accessed 9 September 2026.

[12] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026, Gazette Notification GSR 120(E), 10 February 2026 (in force from 20 February 2026).

[13] Reserve Bank of India, Draft Guidance on Regulatory Principles for Model Risk Management, 2026 (24 June 2026, for public comment); LawBeat, ‘RBI’s AI Draft Rules Put Liability Squarely on Banks, NBFCs; Third-Party Models No Defence’ (LawBeat, 25 June 2026) <https://lawbeat.in/news-updates/rbis-ai-draft-rules-put-liability-squarely-on-banks-nbfcs-third-party-models-no-defence-1605784> accessed 10 September 2026.

[14] Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Third Amendment Directions 2026 (24 June 2026, effective 1 January 2027).

[15] In Re: Victims of Digital Arrest Related to Forged Documents, SMW (Crl) No 3/2020 (SC), order dated 9 February 2026; Banking Finance, ‘SC Pushes AI Fraud Detection; RBI Plans Rs 25K Relief’ (Banking Finance, 13 March 2026) <https://www.bankingfinance.in/legal-news-for-march-2026.html> accessed 10 September 2026.

[16] RBI (n 3); RBI, Master Direction – KYC Direction, 2016 (n 5); RBI, Draft Guidance on Regulatory Principles for Model Risk Management, 2026 (n 13).