# Shahid Hanif, CEO and Co-Founder of Shufti – Interview Series

> Source: <https://www.unite.ai/shahid-hanif-ceo-and-co-founder-of-shufti-interview-series/>
> Published: 2026-07-29 14:43:43+00:00

###
[
Interviews
](https://www.unite.ai/series/interviews/)

# Shahid Hanif, CEO and Co-Founder of Shufti – Interview Series

[Add Unite.AI to your preferred sources on Google](https://www.google.com/preferences/source?q=unite.ai)

[Shahid Hanif](https://www.linkedin.com/in/shahidhanif/), CEO and Co-Founder of Shufti, is a technology entrepreneur with extensive experience building identity verification, fintech, blockchain, and decentralized software platforms. He co-founded Shufti in 2017 and spent more than seven years as Chief Technology Officer, leading the in-house development of its artificial intelligence-driven biometric and document verification technology before becoming CEO in December 2024. Hanif is also the founder of Developers Studio, a blockchain development company with more than 100 specialists, and previously served as CTO of Quickbit, where he helped develop its cryptocurrency payment technology ahead of the company’s initial public offering. Earlier, he co-founded Programmers Force and helped expand the software and data science company to more than 500 employees across ten offices on three continents.

[Shufti](https://shuftipro.com/) is an artificial intelligence-powered identity verification platform that helps organizations establish trust, prevent fraud, and meet Know Your Customer, Know Your Business, and Anti-Money Laundering requirements. Its platform brings together document and biometric verification, electronic identity verification, NFC-based checks, business verification, age assurance, fraud detection, ongoing monitoring, and case management through a unified infrastructure. The company supports thousands of document types and more than 150 languages across over 240 countries and territories, allowing businesses to verify customers and organizations through a single global integration. Its technology examines document authenticity, biometric liveness, device intelligence, and other risk signals to detect forged documents, deepfakes, account manipulation, and coordinated identity attacks.

**When you co-founded Shufti in 2017, you initially led the company’s technology development as Chief Technology Officer before becoming CEO in 2024. What shortcomings in digital identity verification originally motivated you to build the platform, and how has your understanding of the problem changed with the rise of generative AI?**

When we co-founded Shufti in 2017, the biggest challenges were slow verification, too much manual work, and systems that didn’t work well across different countries. Many identity verification solutions were inconsistent, especially in high-risk industries. They also struggled to verify documents in non-Latin languages and couldn’t reliably verify identities from around the world.

Today, generative AI has changed the problem. It’s no longer just about reading an ID document. It’s about knowing whether the document and the person presenting it are real. AI has made identity fraud faster, cheaper, and much easier to scale. We’ve learned that verifying someone once during onboarding is no longer enough. Businesses now need AI that can detect even the most advanced fake documents and identities.

**Belgian authorities recently warned that more than 10,000 people fell victim to AI-enabled identity fraud over the past year. What does this case reveal about how quickly identity crime is evolving, and why are AI-generated copies of legitimate documents especially difficult to detect?**

The warning from Belgian authorities regarding 10,000 victims is just the tip of the iceberg. It reveals that criminals have moved from basic document editing to full-scale identity synthesis.

AI-generated copies are difficult to detect because they can mimic government templates with pixel-level precision. Traditional OCR (Optical Character Recognition) focuses on extracting text, but it ignores the visual integrity of the image. AI can now replicate security features that previously required physical presence to verify, making a flat image of a document a liability rather than a proof of identity.

**How does an AI-generated copy of a stolen identity document differ from a conventional forgery, a manipulated document, and a fully synthetic identity?**

**It is important to distinguish between these methods:**

Conventional Forgery: A physical counterfeit document.

Manipulated Document: A legitimate ID where specific fields (like a name or DOB) have been altered.

Synthetic Identity: A “Frankenstein” persona built by combining stolen real data (like an SSN) with fabricated details.

AI-Generated Copy: A deepfake document created from scratch or a stolen template using Generative Adversarial Networks (GANs). These often lack digital history and contain forensic artifacts like sensor noise inconsistencies that the human eye cannot see.

**Shufti projects that document deepfakes could increase by nearly 3,900% this year. What activity is driving that projection, and which assumptions or limitations should organizations understand when interpreting it?**

We expect a 3,900% increase in document deepfakes because AI has made fraud much easier to create and scale. Criminals are no longer just swapping faces in photos. They can now generate entire fake identity documents that often slip past older verification systems.

It’s important to understand that this projection reflects how quickly AI-powered fraud is growing, not just how many fake documents exist. The biggest challenge is that many identity verification systems were designed years ago and can’t detect advanced AI-generated fakes, such as realistic holograms or face morphing. As a result, fake identities can get through checks and remain hidden in company databases.

**Many businesses still treat a photograph or scan of an identity document as sufficient proof of identity. What signals should a modern verification system examine beyond the visible information on the document?**

The biggest shift is that businesses can’t rely on traditional document checks anymore. They need what we call a “Digital Eye” approach. Instead of just reading the information on an ID, the system has to examine whether the document itself is genuine.

That means looking for subtle signs that humans can’t easily spot, like whether the image was captured from a screen, unusual pixel patterns, inconsistent lighting, or traces left behind by AI image generators. We also check for signs that parts of the document have been copied, moved, or digitally altered, along with inconsistencies in metadata and image quality. When you combine all of these signals, you’re much more likely to detect sophisticated AI-generated documents that older verification systems would simply accept as real.

**You have argued that identity assurance should be continuous rather than limited to customer onboarding. What would continuous verification look like in practice, and how can companies implement it without introducing excessive surveillance, privacy risks, or customer friction?**

The era of the “one-time check” is over. Continuous Identity Assurance means refreshing user risk against 1,700+ watchlists as frequently as every 15 minutes to prevent “retroactive non-compliance.”

To implement this without friction or privacy risks, we use biometric-bound reusable identities (FastID). Once a user is verified, they can re-verify for high-risk actions (like large withdrawals) in under two seconds using only a facial scan. This kills the need for repetitive document uploads while maintaining a high security posture.

**Fraudsters can now combine synthetic documents with face swaps, deepfake video, injection attacks, and stolen personal information. How should identity platforms connect document integrity, biometric liveness, device intelligence, and behavioural analysis to identify these coordinated attacks?**

Fraudsters are becoming much more sophisticated. Instead of using just one technique, they now combine AI-generated documents, face swaps, and injection attacks to bypass identity checks. That’s why businesses need to look at the full picture rather than relying on a single verification step.

At Shufti, we do this through context-aware risk scoring. We analyze the device being used to detect emulators or headless browsers, verify that the user is physically present with iBeta Level 2 certified passive liveness detection, and look for suspicious patterns across accounts by analyzing identity data, device fingerprints, and user behavior. Combining these signals makes it much easier to identify fraud before it causes damage.

**Generative models will continue improving, while fraudsters can deliberately compress, rescan, or alter synthetic media to hide manipulation artifacts. How do verification providers test whether their detection systems remain effective against new and previously unseen attack methods?**

The challenge is that AI-generated fraud evolves much faster than traditional security testing cycles. Verification providers need to continuously evaluate their systems against new attack techniques rather than relying on historical datasets. That means testing with synthetic documents, recompressed images, screen recaptures, injection attacks, and other manipulated media designed to hide obvious artifacts. Increasingly, the focus is shifting from detecting a specific type of deepfake to identifying inconsistencies across multiple signals, because those tend to remain harder for attackers to replicate as generative AI improves.

**Identity verification systems can create serious consequences when they incorrectly reject legitimate users. How should developers measure false positives, demographic performance, and accessibility alongside fraud-detection accuracy?**

Accuracy shouldn’t just be about catching the “bad guys”; it’s about ensuring a frictionless path for the “good guys.” In our industry, we focus on the Failure to Extract Rate (FTXR)—which measures how often a system simply fails to “read” a face or document—and the False Non-Match Rate (FNMR), where genuine users are incorrectly rejected. According to the sources, Shufti’s performance in the DHS RIVR 2025 Benchmark demonstrated a 0% extraction failure across multiple devices and a worst-case FNMR below 0.68%.

Developers must move beyond “lab averages” and measure performance against “worst-case” demographic results. This means testing specifically for consistency across diverse skin tones, facial structures, and cultural attire. We achieve this by training our AI on globally diverse datasets containing millions of frames. A robust evaluation isn’t complete until you’ve proven that your system is as accurate for a user in a rural region with poor lighting as it is in a controlled office environment. The goal is a Unified Identity Layer that remains fair, inclusive, and accessible to everyone.

**Looking ahead, will technologies such as government-backed digital identity wallets, cryptographically verifiable credentials, and biometric-bound identities eventually make uploaded document images obsolete, or will they simply create a new set of attack surfaces?**

We’re definitely moving toward a future where people won’t need to upload photos of their identity documents as often. Government-backed digital identity wallets and trusted digital IDs make proving your identity much faster and more secure because they allow information to be verified directly, rather than relying on an image of a document. They also create a smoother user experience by reducing the time it takes to complete verification.

That said, every new technology creates new opportunities for criminals. Instead of forging documents, attackers may try to steal digital credentials, take over accounts, or hijack trusted identities. That’s why digital credentials alone aren’t enough. It’s still important to confirm that the person using the identity is the legitimate owner, for example through biometric verification and liveness checks. The future of identity verification is likely to combine trusted digital credentials with biometrics, creating multiple layers of protection instead of relying on a single method.

*Thank you for the great interview, readers who wish to learn more should visit Shufti.*
