
"You can have the best models in the world, but if you don't adapt to today's attack and get that redeployed pretty quickly, you're just open for further attacks until you get that done."
"The attacks that cause the most damage, they are not the ones that fail onboarding. They're the ones that pass it."
Tedd Huff, CEO of fintech advisory firm Voalyre and founder of Fintech Confidential, spent 25 years advising financial institutions on payments infrastructure, fraud risk, and compliance strategy. When he sat across from Hal Lonas, Chief Technology Officer of Trulioo, the global identity verification platform operating across 195 countries and trusted by Google, JP Morgan Payments, Stripe, Airbnb, and Meta, the conversation did not stay surface-level. Lonas co-founded BrightCloud, a cloud-native threat intelligence company, before serving as CTO at Webroot and Carbonite, and now leads the technology behind one of the most consequential verification systems in global payments. These two have seen enough of how financial infrastructure actually gets built, and breaks, to skip the talking points entirely.
The threat most institutions are not accounting for is not the fraudster who trips an alarm. It is the one who passes every check. A sophisticated attacker today can pull a Social Security number from one breach, a name from public records, and an address from a mailing list, then combine those pieces into a profile that belongs to no real person but looks exactly like one. They apply for a small credit card. Get declined. Wait. Six months later, they try again. A year after that, the profile carries a clean payment history, a real-looking credit score, and just enough imperfection to pass automated checks. Thirty days after approval, they extract what they can and disappear. The account never belonged to anyone. The loss is already on the books. Trulioo breaks down the full anatomy of this pattern at trulioo.com/blog/fraud-prevention/synthetic-identity-fraud (http://trulioo.com/blog/fraud-prevention/synthetic-identity-fraud).
Here is where it gets uncomfortable. According to a joint Trulioo and PYMNTS Intelligence report (trulioo.com/blog/fraud-prevention/legacy-identity-verification-ai-fraud (http://trulioo.com/blog/fraud-prevention/legacy-identity-verification-ai-fraud)), 96% of fraud teams say they are confident in their ability to detect bots, yet industry experts estimate losses from synthetic identity fraud at as high as $95 billion annually. That gap is not a rounding error. Detection rates, the metric vendors lead with and compliance teams report to their boards, only tell you what got caught. They say nothing about what did not. False negatives are invisible by definition, until the damage shows up. Huff, who has spent years stress-testing how financial institutions actually measure fraud exposure, pushed Lonas on exactly this point: nobody talks about false negatives because that is precisely where the losses live.

Advertisment
Build secure, compliant crypto wallets without touching private keys.
Dfns - Wallets as a service provider offering API-first, multi-chain digital asset infrastructure with security, compliance, key orchestration, and blockchain integration for fintech platforms and custodians
Request your demo now at fintechconfidential.com/dfns
Most organizations treat identity verification as a one-time gate. A customer passes, the system moves on, and nobody looks back. The fraud that actually hurts comes from accounts that age quietly for weeks or months before anything goes wrong. The question that matters is not whether a system caught something today; it is how fast the system recognizes when it was wrong, and what it does about it. Lonas, who built his engineering instincts through early work at Northrop Aircraft after earning his MIT degree in aeronautics and astronautics, applies a reliability standard from that background to identity infrastructure: architect toward 100% reliability, because the fraction you write off as acceptable is where the catastrophic outcomes happen. As Lonas wrote in Inc. Magazine (inc.com/hal-lonas/why-i-traded-aerospace-for-the-front-lines-of-cybersecurity/91314860 (https://www.inc.com/hal-lonas/why-i-traded-aerospace-for-the-front-lines-of-cybersecurity/91314860 )), that standard shaped how he thinks about every system he has built since. Trulioo outlines its feedback loop framework at trulioo.com/resources (http://trulioo.com/resources).
There is a reasonable counterargument worth taking seriously: if companies collect less data, there is less to breach, and the raw material available to fraudsters shrinks. Lonas acknowledges the logic, then challenges it on a specific point. Collection restrictions hurt defenders far more than they hurt attackers. Fraudsters are already sourcing data from breaches of systems that comply with minimization rules. Limiting what defenders can see means fewer signals, more friction for real customers, and wider openings for synthetic profiles already assembled from breached data elsewhere. The better question, Lonas argues, is not whether data exists but how it is used, governed, and shared for protective purposes. Huff, who has worked on sponsor banking and embedded finance programs where this exact regulatory tension plays out in real product decisions, pushed that point further: legislation that treats data-for-advertising the same as data-for-fraud-prevention is likely to make both outcomes worse.
AI has added a new layer to the problem. Detection systems learned to flag AI-generated images that were too perfect, so attackers updated their models to add imperfections on purpose: blemishes, asymmetry, the kind of randomness that makes a face look real. They are running the same feedback loop defenders use, except on offense, testing against detection models until they pass. Trulioo counters with adaptive machine learning models that update continuously, 95%+ selfie deepfake detection rates, and over 160 real-time device and behavioral signals. More on that at trulioo.com/blog/document-verification/detecting-deepfakes (http://trulioo.com/blog/document-verification/detecting-deepfakes).
For fintech founders and compliance teams making vendor decisions this quarter, two things deserve immediate attention. Ask your identity vendor about their false negative rate, not just their detection rate. If they cannot give you specific numbers and a clear improvement plan, that tells you something important about how the platform is built. Also, check whether your verification setup treats identity as a one-time check or a continuous process. The ConsenSys case study is worth looking at: before working with Trulioo, their business verification process took hours per customer. After moving to an automated KYC and KYB workflow through a single API, that dropped to minutes, with better security and less friction at the same time. The full story is at trulioo.com/customers/consensys (http://trulioo.com/customers/consensys).
Most fintech leaders have not fully thought through what agentic AI means for their verification stack. Software that executes financial transactions on behalf of a user, without a human in the loop, is already running in production. Every trust framework in financial services today assumes a person or a legal entity is on the other side. KYC covers humans. KYB covers businesses. Neither was built to verify autonomous software that can be copied at zero cost, modified after authorization, and operate at machine speed. Trulioo published its Know Your Agent (KYA) framework in August 2025, proposing five verification layers: developer verification, code state locking, user consent capture, a credential called the Digital Agent Passport, and real-time action validation. The passport does not just authenticate an identity; it authenticates a state: who built this agent, what code is running, what the user agreed to, and whether the specific action falls within scope. The full KYA framework is at trulioo.com/blog/know-your-agent (http://trulioo.com/blog/know-your-agent).
Skyflow - Zero trust data privacy vault delivered as an API; collect, secure, and tokenize personal information like card data and payment details with built-in PCI, CCPA, GDPR, and SOC 2 compliance - skyflowsecure.com
Advertisment
Google launched the Agent Payments Protocol (AP2) in September 2025 as an open standard for how AI agents execute financial transactions. In December 2025, Trulioo was designated as the protocol's identity verification layer, as reported by Finovate (finovate.com/trulioo-joins-googles-agent-payments-protocol-ap2-to-secure-agent-led-payments (https://finovate.com/trulioo-joins-googles-agent-payments-protocol-ap2-to-secure-agent-led-payments/)). Lonas is clear on what that signal means: when the largest technology company in payments standardizes something, procurement and compliance decisions across the industry follow. Agentic commerce is not a future scenario; it is infrastructure being built right now. More on the AP2 designation at trulioo.com/press/google-agent-payments-protocol (http://trulioo.com/press/google-agent-payments-protocol).
Huff pressed Lonas on whether defenders are actually winning or just getting better at losing more slowly. Lonas did not hedge: "The bad guys are always ahead. Anybody that claims that they're ahead of the bad guys is not telling you the truth." The real measure is the size of the gap and how fast it is closing. His parting concern is that companies across SaaS and financial services are holding back on AI hiring and development while they wait to see what AI will replace, and that delay is creating an opening attackers are already using. They are not waiting.
The conversation draws on Trulioo's published research across synthetic identity fraud, deepfake detection, and the KYA framework, making this one of the most technically grounded discussions of AI-era identity infrastructure available in podcast form. Anyone responsible for fraud prevention, identity infrastructure, or compliance strategy will come away with a clearer view of where the real risk lives, why the metrics on their dashboard may be hiding it, and what the rise of AI agents means for every verification decision in the next 12 months.
TLDR:
Industry experts estimate synthetic identity fraud costs the financial industry as high as $95 billion annually, and the systems most financial institutions rely on were not built to catch it. Tedd Huff, CEO of fintech advisory firm Voalyre and founder of Fintech Confidential, brings 25 years of payments infrastructure and fraud risk experience to a direct conversation with Hal Lonas, CTO of Trulioo, the platform verifying identities across 195 countries for companies like Google, JP Morgan Payments, and Stripe. Huff challenges Lonas on the metrics that matter, the regulatory trade-offs most compliance teams have not fully worked through, and whether defenders are actually gaining ground. Lonas explains why detection rates hide more than they reveal, how AI-generated deepfakes now include intentional imperfections to beat detection models, and why agentic commerce requires a verification layer that does not yet exist at most institutions. Lonas also gives a straight answer on whether defenders are winning the fraud arms race, and it is not what most vendors would tell you. If you are making fraud prevention or identity infrastructure decisions right now, this conversation covers the ground that actually matters.
Hawk AI - Real-time payment screening, ML transaction monitoring, and dynamic customer risk rating tools designed to fight fraud and financial crime while reducing false positives - gethawkai.com
Advertisement
Key Highlights:
Google Backs AI Payment Standard
Google launched its Agent Payments Protocol (AP2) in September 2025 as an open standard for AI agents executing financial transactions, with Trulioo designated as the identity verification layer in December 2025, as reported by Finovate. The move signals that agentic commerce has shifted from concept to active infrastructure buildout, with real effects on compliance procurement and engineering decisions across payments.
AI Deepfakes Now Include Flaws
Fraudsters updated their AI-generated images to include skin blemishes, asymmetry, and lighting inconsistencies after detection systems learned to flag outputs that looked too clean. Human analysts are reaching the limits of visual detection, and machine learning models scanning over 160 real-time behavioral and device signals are likely the more reliable line of defense at this point.
Your Vendor's Detection Rate Is Lying
The metric most identity vendors lead with and most compliance teams report to their boards only measures what was caught: it says nothing about what slipped through. Pressed by Huff on what one piece of advice he would give compliance teams right now, Lonas was direct: ask your vendor specifically about their false negative rate, demand the numbers, and find out what they are doing to improve them.
Digital Agent Passport Explained
Trulioo's proposed Digital Agent Passport authenticates a state rather than just an identity. It encodes who built the agent, what code is running, whether that code has been altered, and what specific actions the user consented to. A standard password verifies who is logging in; the passport verifies whether the software itself is still trustworthy at the moment of each individual transaction.
As High as $95 Billion Exposed by Sleeper Accounts
Industry experts estimate synthetic identity fraud losses at as high as $95 billion annually, with much of that damage coming from accounts that age quietly for months before a single large extraction event. The attacker builds credit history with small purchases and on-time payments, creating a risk profile clean enough to pass every automated check before disappearing with the funds.
Aerospace Reliability Applied to Identity Infrastructure
Hal Lonas spent the early part of his career at Northrop Aircraft after earning his MIT degree in aeronautics and astronautics, where he absorbed a systems engineering standard: architect toward 100% reliability because the fraction you write off is where catastrophic outcomes happen. That standard now shapes how Trulioo builds identity infrastructure that processes verifications in under two seconds across 195 countries.
Industry AI Pause Helps Attackers
Companies across SaaS and financial services are pulling back on hiring and development spending while they wait to see what AI will automate, and that hesitation is delaying defensive investment. Attackers face no such hesitation: they are using AI tools every day, and the gap between offense and defense appears to widen with each quarter the industry holds back.
Business Verification Took Hours
ConsenSys ran a manual KYB process that took hours, sometimes days, to verify a single business before onboarding, creating a bottleneck that slowed growth. After moving to an automated workflow through a single API, verification time dropped to minutes while security outcomes improved at the same time.
One Size Fits All Identity Fails
The biggest mistake fintech leaders make with identity is treating it as a simple problem one tool or one vendor can solve, when global identity verification across 195 countries and thousands of document types is inherently complex. Predictive risk scoring can apply lighter friction to lower-risk transactions and heavier checks where signals warrant it, but that requires an architecture built for nuance.
Defenders Will Never Fully Win
Pressed by Huff on whether defenders are actually winning or just getting better at losing more slowly, Lonas answered without hedging: the bad guys are always ahead, and anyone claiming otherwise is not being straight with you. The honest measure is the size of the gap between attackers and defenders, and how fast that gap is closing through tighter feedback loops, faster model retraining, and continuous post-onboarding monitoring.
Hawk AI - Real-time payment screening, ML transaction monitoring, and dynamic customer risk rating tools designed to fight fraud and financial crime while reducing false positives - gethawkai.com
Advertisement
Takeaways:
1️⃣ Demand Your Model's Update Frequency
Your identity vendor might have strong machine learning, but if those models retrain once a quarter while attackers adapt daily, you are defending with last season's playbook. Get on the phone this week and ask one specific question: how often do your ML models update, and what triggers a retraining cycle? If the answer involves committee approvals or six-month timelines, start your vendor search.
2️⃣ Monitor Accounts After Onboarding Clears
Most verification setups focus everything on the front gate and move on the moment a customer passes. The fraud that actually hits the budget happens weeks or months later when a sleeper account activates. Build continuous monitoring into your post-onboarding workflow so your system is still watching on day 30, day 60, and day 90 after approval.
3️⃣ Make Your AI Decisions Explainable Now
Regulators at the OCC, FDIC, and state agencies are already asking financial institutions to explain how automated decisions get made. The black-box approach to fraud detection and identity scoring is no longer viable. Audit every model in your stack this quarter and document the decision logic before your next exam, because "the algorithm decided" is an answer that gets you a findings letter.
4️⃣ Use Step-Up Friction Instead of Flat Checks
Running every customer through the same verification process wastes time on low-risk transactions and still misses sophisticated attacks. Predictive risk scoring can flag suspicious activity early and apply heavier checks only where signals warrant it, while clearing the transactions that look safe. Map your verification flow this month and identify where you can tier friction based on real-time risk signals.
5️⃣ Align Your Compliance and Growth Teams
The compliance team wants to slow down and verify. The product team wants to speed up and onboard. In most organizations those two groups trade blame when fraud gets through or conversion rates drop. Get them in the same room with a shared dashboard showing both fraud loss rates and abandonment rates side by side, because the technology exists to improve both numbers at the same time.
Links:
Hal Lonas
Hal Lonas: https://www.linkedin.com/in/hal-lonas-4555b1
Website: https://www.trulioo.com
Tedd Huff
Tedd Huff: https://www.linkedin.com/in/teddhuff/
Fintech Confidential
Newsletter: https://fintechconfidential.com/access
Time Stamps:
00:00 Introduction
01:28 Meet Trulioo CTO
02:48 From Space to Security
04:11 Dfns: Wallets as a Service (sponsor)
05:32 Sleeper Accounts Explained
08:33 False Negatives Metric
11:43 Explainable Adaptive ML
13:23 Deepfakes Raise Stakes
15:03 Asymmetric Defense Signals
17:51 Privacy Versus Safety
21:25 Sky Flow: Building Fast and Secure (sponsor)
22:27 Friction Based Risk
24:16 Case Study ConsenSys
26:04 Know Your Agent Future
27:52 Agent Passport Checks
32:43 Open Standards AP2
34:35 Are Defenders Losing
36:05 Leader Advice Wrap
40:37 Final Thoughts and Outro
41:36 Hawk AI - Realtime Fraud Monitoring (sponsor)
42:23 Disclaimer

Advertisment
Transform Your Merchant Applications with Under. The Under platform revolutionizes how you handle merchant applications, offering a seamless transition to digital forms. Say goodbye to outdated processes and hello to efficiency. Discover the future of financial applications at https://under.io/ftc
Advertisement
About The Guest:
Hal Lonas
Hal Lonas is the Chief Technology Officer of Trulioo, where he leads the company's technology strategy, product development, and engineering operations. Lonas holds a B.S. in Aeronautics and Astronautics from MIT and started his career at Northrop Aircraft before moving into software and cybersecurity. He co-founded BrightCloud, a cloud-native threat intelligence company, and served as CTO at Webroot and later Carbonite. After Carbonite's acquisition by OpenText, he served as Senior Vice President and CTO for OpenText's SMB and Consumer division. Lonas joined Trulioo in February 2021 and has since led the development of the company's adaptive machine learning models, its Know Your Agent (KYA) framework for agentic commerce, and its role as the designated identity layer in Google's Agent Payments Protocol (AP2). He is a co-author of several patents and is based in Carlsbad, California.
Trulioo
Trulioo is a global identity verification platform founded in 2011 and headquartered in Vancouver, British Columbia. The company provides real-time person and business verification across 195 countries, covering more than 14,000 ID document types, over 6,000 watchlists, and 700 million business entities. Trulioo's platform powers KYC, KYB, and AML compliance workflows through a single API, enabling automated onboarding, document verification, fraud prevention, and continuous monitoring. Its customer base includes Google, JP Morgan Payments, Stripe, Airbnb, and Meta. In August 2025, Trulioo published its Know Your Agent (KYA) framework for verifying AI agents in financial transactions, and in December 2025, Google designated Trulioo's identity layer as part of its Agent Payments Protocol (AP2). The company has raised $477 million in total funding, including a $394 million Series D round in 2021.
About the Host:
Tedd Huff is CEO of Voalyre, a fintech advisory firm, and founder of Fintech Confidential. Over the past 25+ years, he has contributed to fintech startups as an Advisory Board Member, Co-Founder, and Chief Experience Officer, providing strategic and tactical direction for global companies. His expertise focuses on growth while delivering process improvements and user experience-driven value to simplify the complexity of payments. As host and executive producer of Fintech Confidential, Tedd brings entertaining and informative content focused on fintech industry insights, market trends, and stories from fintech leaders, thinkers, and doers. He is a recognized thought leader and U.S. Army veteran known for making complex financial technology approachable and engaging through his conversational storytelling style and deep understanding of global payments, cross-border transactions, and payment localization.
DD3 Media is a multimedia and marketing agency founded by Tedd Huff that specializes in content creation and production for the fintech and payments industry. As the production company behind Fintech Confidential, DD3 Media produces podcasts, live streams, video content, and onsite interview events that deliver engaging, educational content to global audiences. The company simplifies complex financial technology topics through storytelling and expert interviews, helping fintech companies and financial institutions build thought leadership across YouTube, podcast platforms, and social media.
Others you may enjoy
Why we moved to Beehiiv
The Newsletter Platform Built for Growth
When we started the newsletter, there were SO many choices. But until now, there hasn’t been a publishing tool built to help us grow our publications as quickly and sustainably as possible!
beehiiv was founded by some of the earliest employees of the Morning Brew, and they know what it takes to grow a newsletter from zero to millions.
It is an all-in-one publishing suite that comes with built-in growth tools, customization, and best-in-class analytics that actually move the needle - all in an easy-to-use interface.
We are excited to engage with you through — responsive audience polls (find out what you want to hear about most), custom referral programs( get rewarded for referring people to the Fintech Confidential newsletter), SEO-optimized webpages (make it easy to find the content you are looking for), and so much more.
If you have or are considering to starting a newsletter, there’s no better place to get started and no better time than now.







