Abstract
The rapid escalation of financial deepfake fraud—driven by the emergence of Fraud-as-a-Service—has outpaced existing regulatory frameworks, creating a critical vulnerability in global digital security. This paper argues that the current legal response remains fragmented, trapped between the European Union’s rights-based architecture (General Data Protection Regulation, AI Act, Digital Services Act) and the United Kingdom’s safety-oriented technology-forcing imperatives (Online Safety Act). Through a doctrinal and functional comparative analysis, this study constructs a three-layered governance paradigm for the digital economy: Layer 1 (Source Control) identifies a compliance black hole in biometric data erasure; Layer 2 (Distribution Control) contrasts systemic risk management with proactive technical detection; and Layer 3 (Accountability) evaluates the shift toward strict corporate criminal liability. Critically, the study evaluates the June 2026 Digital Omnibus updates, identifying a 12-month governance vacuum created by the disparity between the December 2026 functional bans and the delayed December 2027 application timelines for high-risk systems. The paper concludes by advancing six strategic policy recommendations to counter scalable injection attacks, including the enforcement of NIST IAL2 zero-retention biometric standards and obligatory digital provenance (C2PA). Most notably, it proposes a Transatlantic Regulatory and Financial Interoperability Framework, advocating for the integration of biometric integrity protocols directly into ISO 20022 messaging schemas to enforce a real-time financial blockade against non-compliant jurisdictions.
| Original language | English |
|---|---|
| Article number | 106376 |
| Pages (from-to) | 1-26 |
| Number of pages | 26 |
| Journal | Computer Law & Security Review |
| Volume | 62 |
| Early online date | 17 Jul 2026 |
| DOIs | |
| Publication status | E-pub ahead of print - 17 Jul 2026 |
Keywords
- Deepfake fraud
- Generative AI
- Agentic AI
- Biometric integrity
- Privacy-Enhancing Technologies
- Online Safety Act
- General Data Protection Regulation
- EU AI Act
- Digital Services Act
- Digital identity assurance
- PETs
- UK OSA
- GDPR
- DSA
Fingerprint
Dive into the research topics of 'The enforced technical mandate: A multi-layered governance model for deepfake fraud and biometric integrity'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver