Site navigation

Comment | Identity, Not Surveillance, is Facial Recognition’s Future

Tony Kounnis

,

CEO of Face-Int UK & Europe
In this contributed piece for DIGIT, Tony Kounnis, CEO of Face-Int UK & Europe, argues that while public debate continues to centre on policing, facial recognition is quietly becoming a critical tool for digital identity assurance.

Artificial intelligence might be the technology attracting the most public attention – or misunderstanding – over the past year. But make no mistake, facial recognition technology (FRT) has not been far behind.

In recent months, headlines have once again focused on its use by police forces. The government has doubled down on its intentions to deploy the tech multiple times since December, reigniting familiar concerns around surveillance, privacy and bias. These debates are important and necessary. But, a bit like boiling AI down to the use of ChatGPT, fixating on the use of FRT in a policing context risks obscuring a much bigger shift that is quietly taking place.

The future of FRT is not primarily about watching people. It is about proving who someone is in an increasingly hostile digital environment, and this expands across many industries and use cases.

The identity challenge

Across the UK, organisations are grappling with a profound identity challenge. Fraud is rising, remote interactions are now the norm, and the tools used by criminals are becoming more sophisticated by the month. Deepfakes, synthetic identities and account takeover attacks are no longer fringe threats; they are operational realities for banks, public services, transport providers and critical infrastructure operators alike.

For example, according to Deloitte, deepfake content on social media platforms exploded by 550% between 2019 and 2023. Meanwhile, data from Cifas shows that more than 217,000 fraud risk cases were recorded to the National Fraud Database (NFD) by Cifas members in H1 2025 – a record number of filings for the six-month period and something the organisation attribute, in large part, to the fact “criminals are using advanced AI to create fake identities, forge documents, and bypass verification systems with alarming accuracy”.

Against this backdrop, facial recognition is evolving into a core component of identity assurance – a way to establish trust in both physical and digital environments where traditional credentials are no longer sufficient.

The limits of legacy identity checks are becoming increasingly clear. Passwords can be stolen or guessed. Identity documents can be forged. One-time passcodes can be intercepted. As more services move online and more access decisions are made remotely, organisations need stronger, more resilient ways to confirm that a person is genuinely who they claim to be, and that they are present in real time.

Misconceptions are holding FRT back

It is important to note that FRT today differs markedly from the caricature often presented in public discourse. Today’s systems are not simply about matching a face to a database image. They combine secure facial matching with liveness detection, anti-spoofing measures and continuous risk assessment to determine whether an interaction is legitimate. In effect, they are designed to answer a far more complex question than “does this face match?” – namely, “is this a real person, acting legitimately, right now?”

The implications for cybersecurity are significant. Financial institutions are increasingly using facial recognition to protect customers during onboarding, high-risk transactions and account recovery processes. As authorised push payment fraud and identity theft continue to rise across the UK, these technologies offer a way to strengthen defences without adding unnecessary friction for legitimate users.

Border control and travel present another clear use case. Secure facial recognition can support faster, more reliable identity verification while reducing reliance on physical documents that are easily lost or falsified. Importantly, this is not about mass surveillance, but about controlled, purpose-limited checks at defined points in the journey, supported by clear governance and oversight.

But it extends well beyond digital environments. Access to controlled sites – from data centres and energy facilities to healthcare environments and residential accommodation – is also undergoing a shift. As threats to critical infrastructure grow, organisations are reassessing how they manage physical access. Facial recognition, used responsibly, can provide stronger assurance than cards or PINs that can be shared or stolen, while creating detailed audit trails that support compliance and incident investigation.

Concerns need to be addressed

Of course, none of this diminishes the legitimate concerns surrounding privacy, accuracy and bias. Facial data is inherently sensitive, and its misuse can have serious consequences. That is precisely why identity assurance use cases demand a higher standard of deployment than the more simplistic surveillance narratives suggest.

Accuracy must be demonstrated across diverse populations and real-world conditions, not assumed based on laboratory testing. Systems must be continuously monitored, not deployed and forgotten. Data must be minimised, securely stored and retained only for as long as necessary. And, crucially, organisations must be transparent about how and why facial recognition is being used, particularly when it affects employees, customers or citizens.


Recommended reading


Regulation and oversight will play an increasingly important role here. The UK already has a strong foundation in data protection, but as biometric technologies become more widespread, clearer guidance around best practice will be essential. This is not about slowing innovation; it is about ensuring that trust keeps pace with capability.

Thinking beyond surveillance

For technology and business leaders, it is important we shift perspectives. Facial recognition should no longer be viewed as an experimental or exceptional technology, reserved for niche scenarios. Nor should it be reduced to a symbol of surveillance. Instead, it should be understood as part of a broader identity and security toolkit – one that, when implemented correctly, helps organisations protect people, assets and services in a digital-first world.

As identity becomes the new perimeter in cyber security, the ability to verify that identity robustly and responsibly will define organisational resilience. Facial recognition is not a silver bullet, but it is becoming an essential layer in a multi-factor approach to trust.

The debate around facial recognition will and should continue. Scrutiny is healthy. But if we focus solely on surveillance, we risk missing the more pressing question: how do we protect identity in an era where deception is increasingly easy and increasingly automated?

The answer will shape not only the future of facial recognition, but the security of the digital economy as a whole.

Tony Kounnis

CEO of Face-Int UK & Europe

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data