All posts
Technology8 min read

Document Fraud Went Field-Level. Most Detection Still Scores the Whole Page.

Entrust, Sumsub, Inscribe, and Resistant AI all published the same story this year: AI fraud is up, deepfakes are up, everyone's scared. True, and beside the point. The real shift is that forgery moved from the page to the field - and most detection stacks are still scoring the page.

View as Markdown
document fraud detectionfield-level forensicsAI-generated documentserror level analysisdocument tampering detectionfraud detection trends 2026forensic document analysis
Document Fraud Went Field-Level. Most Detection Still Scores the Whole Page.. TamperCheck.ai blog cover
Document Fraud Went Field-Level. Most Detection Still Scores the Whole Page.. TamperCheck.ai blog cover

Open any fraud report published this year and you'll read some version of the same paragraph. AI-generated document fraud is up roughly 5x. Digital forgeries now beat physical counterfeits in some markets. Deepfakes show up in one in five biometric fraud attempts.

Entrust, Sumsub, Inscribe, and Resistant AI all told this story in 2026. They're not wrong. But when every vendor repeats the same stat in the same quarter, it stops being an insight. It just confirms fraud is getting worse - something you already knew. It doesn't tell you how to catch it.

There's a quieter shift hiding underneath those numbers. It's the one that actually decides whether your detection stack still works next year.

The unit of forgery got smaller

Document forgery used to happen at the level of the whole page. Someone would swap the photo on a scanned ID. Print a document, change it with a pen, and rescan it. Take a real PDF, edit it in an image tool, and save the whole file over again.

Each of these leaves a mark that spreads across the entire document: a shift in how the file was compressed, a new timestamp buried in the metadata, a camera signature that doesn't match the story.

That's why whole-document checks worked so well for so long. Run Error Level Analysis (a way of spotting parts of an image that were edited and re-saved) over a whole page. Check the metadata once. Compare the noise level across the whole file. All of these assume the fake edit is big enough, compared to the page, to move the average. A crude forgery plays along - because a crude forgery touches the whole file.

AI editing tools broke that assumption, and nobody announced it. They don't touch the whole document anymore. They touch one balance on a bank statement, one date of birth on an ID, one line on an invoice - and blend that single edit into its surroundings so well that the rest of the page never moves.

The fraud reports even hint at this, without naming it directly. In 2025, the share of fraudulent documents where both an identity field and a financial field were changed jumped from 40% to almost 60%. And "template-based" fraud - editing specific fields inside a real layout instead of faking a whole document - roughly tripled. That's field-level fraud, showing up in the data. The reports just call it a fraud-volume statistic instead of what it is: a detection problem.

~60%
of flagged documents in 2025 had both an identity edit and a financial edit, up from 40% in 2024. Inscribe
35%
of document fraud is now digital forgery, up from a 29% average 2022-2024. Entrust 2026 Identity Fraud Report
~5x
growth in detected AI-generated document fraud, April-December 2025. Inscribe / Resistant AI

Why a clean page score can still be wrong

Here's the problem, plainly. Say a document has forty fields, and someone edits one of them - a real edit, with real signs of tampering. If your detection method averages a signal across the whole page, that one bad field gets diluted by the other thirty-nine genuine ones. The page comes back "clean." Not because the forgery is good, but because the check was never precise enough to find it.

Think of it like running a spell-checker on an entire book to find one misspelled word in a single sentence. The book's overall error rate barely moves. The one word that matters disappears into the average.

Whole-document metadata checks, whole-file compression checks, and single global ELA passes are all, in effect, book-level spell-checkers. They were built for forgers who edited the whole file. Now they're being asked to catch forgers who edit one line and leave everything else alone on purpose.

A field-level edit doesn't need to be invisible. It just needs to be small enough that a whole-page average doesn't notice it moved.

Two answers the industry has tried - and where they fall short

Look at what vendors are actually recommending this year, and two camps show up.

Camp one: "stop looking at pixels, look at the numbers." The idea: even if a generative model can draw a perfect-looking bank statement, it still has to invent numbers that add up - across the document, and across every other document from the same person. That's much harder than drawing convincing pixels. It's a real, useful signal. Totals that don't sum, ID numbers that fail a checksum, dates that contradict each other - these catch a good share of AI-generated fakes, because most image-generation tools aim for realistic pixels, not correct math.

But it's not enough by itself. A generative tool that plans its numbers before it draws the page - a balance that adds up, an ID number that passes its checksum, a believable transaction history - sails through a reconciliation check while still being completely fake. Checking the data catches carelessness. It doesn't catch a careful fake.

Camp two: "add more layers." Pair document checks with face-liveness checks, injection-attack detection, device fingerprinting. That's the right instinct when a flow includes a selfie and a live camera capture, and "injection attacks" - feeding in a manipulated image or video instead of using a real camera - are a real and growing problem, up about 40% year over year by Entrust's count.

But most document fraud never goes through a live camera at all. A payslip attached to a loan application. A bank statement uploaded to a rental portal. An invoice sent for vendor onboarding. None of these have a face or a camera to check. Stacking more identity layers on top does nothing for the document itself if the way that document gets scored hasn't changed.

Both camps solve real problems. Neither one fixes the actual issue: the resolution of the check.

The fix: change what gets scored, not how many checks run

The fix isn't a third layer stacked on top of the first two. It's changing the unit that gets scored in the first place.

If forgery now happens field by field, detection has to run field by field too. Every part of a document a scanner can read - a name, a balance, a date, a signature - gets its own check:

  • How sharp is this one spot, compared to the rest of the page?
  • Was it saved or compressed differently than everything around it?
  • Does its brightness and grain match its neighbors?
  • Does the font match the rest of the document?

Each field gets compared to the other fields on that same document - not to some average threshold built from millions of unrelated files.

Here's why that works. A well-blended fake edit still has a hard problem to solve: it's a brand-new patch of pixels, dropped into the middle of an old, real document. It has to match the surrounding grain, the surrounding compression, the surrounding font - all at once, in one small spot. A whole-page average was never looking for that mismatch. A field-by-field check is looking for nothing else.

Diagram contrasting whole-page forensic scoring, where one altered field is diluted across many genuine fields into a single clean aggregate score, against field-level forensic scoring, where each field is scored independently and the altered field is isolated
Whole-page scoring averages one bad field into thirty-nine good ones. Field-level scoring isolates it.

This also fixes the gap in camp one's approach. A fake that adds up perfectly, but wasn't produced field-by-field the way a real document is, still shows small mismatches - a font that drifts slightly, a compression pattern that doesn't match its neighbor. Those signals sit below anything a reconciliation check can see. Field-level forensics and data checks aren't rivals. Run together, they cover each other's blind spot: one catches numbers that don't add up, the other catches numbers that add up too perfectly to have come from a real system, typed in field by field.

See field-level forensics on a real document

Upload a document - or a fake one - and get a per-field forensic verdict in about a minute. $5 in free credits, no contract.

Test a fake document

The real race, described plainly

Most 2026 commentary calls this fight "AI versus AI" - fraud models against detection models, both scaling with more compute. That's true, but too vague to act on. Here's the concrete version: it's a resolution race. Fraud keeps shrinking its edits into smaller, better-blended spots. Detection either keeps shrinking its unit of measurement to match, or it falls behind.

Right now, a single-word edit inside an otherwise real document is the cutting edge. A single-character edit - one digit in an account number, one character in a date - is the plausible next step, and no page-level score will ever catch that. The vendors who win this race won't be the ones with the biggest model. They'll be the ones who keep shrinking what actually gets measured, faster than fraud shrinks what it touches.

That reframes the question worth asking any document fraud vendor - us included. Don't ask "do you use AI to detect fraud." Every vendor says yes, and means something different by it. Ask instead: what's the smallest part of the document your system actually checks - the whole file, the page, or the field? That answer tells you more than any headline statistic whether a system was built for the fraud of five years ago, or the fraud showing up this quarter.

FAQ

What does 'field-level' document forensics actually mean?

Instead of scoring a whole page once, field-level forensics checks each part of a document on its own - each name, date, amount, and signature - and compares it to the other fields on the same document, not to one generic threshold.

Why can't whole-document checks just be made more sensitive?

Because turning up the sensitivity doesn't change what's being measured. A more sensitive whole-page average still gets diluted by the thirty-nine genuine fields around one bad one - and it also starts flagging genuine documents that just used an unusual scanner or print process.

Does field-level analysis replace data-consistency checks like reconciling totals?

No. They catch different problems. Data checks catch numbers that don't add up. Field-level checks catch numbers that were rendered differently than the rest of the page, even when they add up perfectly. Running both catches more fraud than either one alone.

Is this only relevant to financial documents like bank statements and payslips?

No - the same idea applies to ID documents. A real passport with just the photo swapped keeps every other security feature intact. That's exactly the case a whole-document check misses most often, and a field-level check is built to catch. See Forged ID Documents: How Every Industry Is Paying the Price and Fake Passport Detection: The Forensic Signals That Matter.


Run field-level forensics on a real document

TamperCheck.ai runs 200+ forensic checks per document, scored field by field instead of once per page, and returns a plain-English verdict in about a minute - with zero document storage.

Think you can spot a fake?

Upload a suspicious document and let TamperCheck do the forensics - a clear verdict in about a minute. $5 in free credits, no contract.