The enforced technical mandate: A multi-layered governance model for deepfake fraud and biometric integrity
The rapid escalation of financial deepfake fraud—driven by the emergence of Fraud-as-a-Service—has outpaced existing regulatory frameworks, creating a critical vulnerability in global digital security. This paper argues that the current legal response remains fragmented, trapped between the European Union’s rights-based architecture (General Data Protection Regulation, AI Act, Digital Services Act) and the United Kingdom’s safety-oriented technology-forcing imperatives (Online Safety Act). Through a doctrinal and functional comparative analysis, this study constructs a three-layered governance paradigm for the digital economy: Layer 1 (Source Control) identifies a compliance black hole in biometric data erasure; Layer 2 (Distribution Control) contrasts systemic risk management with proactive technical detection; and Layer 3 (Accountability) evaluates the shift toward strict corporate criminal liability. Critically, the study evaluates the June 2026 Digital Omnibus updates, identifying a 12-month governance vacuum created by the disparity between the December 2026 functional bans and the delayed December 2027 application timelines for high-risk systems. The paper concludes by advancing six strategic policy recommendations to counter scalable injection attacks, including the enforcement of NIST IAL2 zero-retention biometric standards and obligatory digital provenance (C2PA). Most notably, it proposes a Transatlantic Regulatory and Financial Interoperability Framework, advocating for the integration of biometric integrity protocols directly into ISO 20022 messaging schemas to enforce a real-time financial blockade against non-compliant jurisdictions.
| Item Type | Article |
|---|---|
| Identification Number | 10.1016/j.clsr.2026.106376 |
| Additional information | © 2026 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ ). |
| Keywords | deepfake fraud, generative ai, agentic ai, biometric integrity, privacy-enhancing technologies, online safety act, general data protection regulation, eu ai act, digital services act, digital identity assurance, pets, uk osa, gdpr, dsa |
| Date Deposited | 22 Jul 2026 08:03 |
| Last Modified | 30 Jul 2026 23:04 |
