Three in ten fraud attempts at major retailers last year weren't just sophisticated—they were synthetic. Entirely AI-generated, according to industry estimates. Which raises an uncomfortable question for anyone building authentication systems: if the old biometric playbook no longer works, what comes next?
VeryAI, a lean Miami-based startup founded in 2025, thinks it has part of the answer. Not a single stronger lock, mind you. Multiple locks, working together. Specifically: palm recognition layered with deepfake detection, all of it running on the camera that's already in your pocket.
It's an unusual pitch. Palm biometrics have come and gone before—remember those infrared vein readers at the airport, or Amazon's short-lived One payment system? But VeryAI's founders believe the technology deserves a second look, especially now that the fraud landscape has shifted beneath everyone's feet.
When the Numbers Stop Making Sense
The statistics around deepfake fraud have begun to feel almost numbing in their severity. Pindrop reported a 1,300% jump in deepfake voice fraud between 2024 and 2025 in its Voice Intelligence & Security Report—a dramatic surge that reflects the growing sophistication of synthetic voice attacks rather than absolute volume alone. Sumsub clocked deepfake fraud up 1,100% year-over-year in the first quarter of 2025 alone, with synthetic document fraud surging 300% in the U.S. A Regula survey from September found that a third of companies had already been hit.
Contact centers, perhaps predictably, absorbed much of the damage. The average center faced roughly $343,000 in deepfake fraud exposure in 2025, Pindrop calculated, with daily synthetic voice attempts becoming routine rather than exceptional. By early this year, Experian was listing agentic AI and deepfake job candidates among the top operational risks businesses face. A Thales study found nearly 60% of companies reporting deepfake-driven attacks, with 61% naming AI their top data security concern.
Gartner had seen some version of this coming. Back in February 2024—which now feels like a different era—the firm predicted that by 2026, 30% of enterprises would deem identity verification and authentication "unreliable in isolation" due to deepfakes. That forecast, as it turns out, may have been conservative.
The attack surface had fundamentally changed, and the defenses hadn't kept pace.
Palm Biometrics, Redux
So palm recognition has quietly re-entered the conversation. Not as a vein-reading payment novelty this time, but as a software-based authentication layer that might—might—prove less vulnerable to the generative AI tools that have become so proficient at mimicking faces.
The logic is straightforward enough. Facial recognition operates in the same visual domain that tools like Midjourney and Stable Diffusion have mastered. Palmprint patterns present a different set of challenges for synthetic generators, at least for now. The palms don't smile for the camera. The lines and ridges follow different biometric principles, harder to replicate convincingly without specialized training data.
Market projections reflect renewed interest, though as always with emerging sectors, the exact numbers vary depending on who's counting. 360iResearch pegged the palm vein biometrics market at $1.28 billion in 2025, projecting growth to $3.52 billion by 2032—a 15.5% compound annual growth rate. Mordor Intelligence estimated 2025 slightly higher at $1.7 billion, forecasting $4.42 billion by 2031.
More revealing than the forecasts are the actual deployments. Pearson VUE, the giant that administers millions of certification exams annually, integrated Redrock Biometrics' PalmID into its proctoring infrastructure this January. iProov, already known for facial verification, introduced Palm Verifier in 2025 and was reporting over a million daily transactions by February of this year.
Then there's the cautionary tale. Amazon announced in February 2026 that it would discontinue Amazon One—its palm vein payment system for retail businesses—effective this June. The hardware requirements, user friction, and privacy concerns had apparently outweighed the benefits, at least in Amazon's calculus. Consumer retail, it seems, wasn't ready. Or perhaps the infrastructure costs simply didn't pencil out.
Two Layers, No Hardware

VeryAI's bet is that the hardware is precisely the problem. The company's "Proof of Reality" platform runs entirely through standard smartphone cameras. No specialized sensors, no infrared readers, no dedicated scanners at the point of sale. Users open a mobile app, scan their palms, and the system captures liveness through gesture detection and what the company calls "photometric cues."
The technical claims are ambitious. VeryAI reports a false acceptance rate of 1×10^-7 and a false rejection rate of 1.5×10^-2 for single-palm enrollment. Scale that up to dual-palm enrollment with five scans per palm, and the company claims a combined false acceptance rate of 2.5×10^-14 and false rejection of 1×10^-9. For context, that would make the system "10× more accurate than Apple Face ID," according to VeryAI, referencing Apple's published Face ID false match rate of less than one in a million.
Bold numbers. The company says it has processed over 28 million scans and invested 10+ years in R&D, with SOC 2 certification and iBeta-certified accuracy testing. These performance metrics, while impressive on paper, await broader independent validation beyond VeryAI's own reporting—though that's not unusual for a startup at this stage.
But here's where VeryAI's approach diverges from pure biometrics: the palm scan is only half the platform. The company integrates proprietary deepfake classifiers that analyze uploaded video, audio, images, and documents for signs of synthetic generation or manipulation. The system generates what it calls "content authenticity scores," layering biometric verification (Proof of Personhood, in VeryAI's terminology) with media integrity checks (Proof of Authenticity).
For developers, there are two integration paths. An anonymous mode using zero-knowledge proofs, and a pseudonymous OAuth2 flow with app-scoped user IDs. The documentation, updated through early this year, shows use cases ranging from fintech and e-commerce to Web3 governance and Sybil resistance—the problem of fake accounts flooding online systems. One live integration, ClawKey, uses VeryAI palm scans to verify human operators controlling OpenClaw agents on Solana, the blockchain platform.
The executive team brings some relevant pedigree, at least on paper. CEO Zach Meltzer previously led growth at Galxe, where the company says he helped build relationships with over 6,000 partners and 34 million users. Chief Science Officer Hua Yang is described as a "pioneer of palm biometrics" with more than 10 patents, having worked at Leap Motion and Redrock Biometrics. (An industry article from October noted that legal allegations involving Yang and Redrock had been withdrawn and characterized as misinformation, for what that's worth.)
The company itself remains small. LinkedIn lists VeryAI at 2-10 employees, operating remotely from Miami, New York, and San Francisco. No disclosed funding rounds. Which means VeryAI is either bootstrapped, operating on friends-and-family capital, or keeping its funding very quiet.
The Software Trade-Offs

Eliminating hardware solves one problem—deployment friction—but introduces others. Software-based palmprint recognition, which extracts patterns from standard RGB camera images, inevitably faces accuracy variance across different lighting conditions, camera qualities, and skin tones. Those aren't trivial challenges. They require robust preprocessing and feature extraction algorithms, the kind that separate functioning systems from vaporware.
VeryAI's documentation references handling "variable lighting and skin tones," but the proof, as they say, is in the testing. And independent validation under widely recognized standards remains scarce.
The liveness component matters enormously here. Remote palm authentication faces the same presentation attack risks as any camera-based biometric: photographs, video replays, and—more worryingly—potentially AI-generated palm images trained on enough real palmprint data. VeryAI's gesture-based liveness detection and photometric analysis aim to counter these attacks. The company claims "iBeta-certified accuracy"—iBeta Quality Assurance conducts ISO 30107-3 conformance testing for presentation attack detection—but the specific nature and scope of VeryAI's certification wasn't detailed in publicly available materials.
Which is to say: the claims sound promising, but the devil lives in the validation details.
A Crowded Field
VeryAI isn't exactly pioneering empty territory. On the palm biometrics front, Redrock Biometrics offers a pure palmprint SDK that Pearson VUE adopted for exam proctoring. iProov combines facial and palm verification with what it calls Injection Attack Detection (IAD) capabilities, which the company says achieved "High" certification under CEN/TS 18099 and Ingenium Level 4 standards last September.
In the broader proof-of-personhood space, Humanity Protocol has built momentum around palm-scan-based verification for Web3 applications, claiming rapid testnet growth and a seed valuation of $1 billion as of May 2024. World (formerly Worldcoin) reached 10 million verified humans this January using iris-scanning Orbs, though it continues to face regulatory headwinds in multiple jurisdictions. Human Passport—the Gitcoin Passport successor acquired by Holonym in February 2025—reports 34.5 million credentials issued to 2.1 million users, though it uses attestation-based verification rather than biometrics.
On the deepfake detection side, Pindrop focuses specifically on voice and audio deepfakes in contact center environments. Sensity AI raised $2.1 million in early 2026 for forensic-grade deepfake detection tools. The push toward testable, certifiable deepfake resilience is accelerating—iProov's IAD testing under emerging standards signals that enterprise security teams increasingly want measurable benchmarks, not just vendor promises.
What distinguishes VeryAI's positioning—at least in theory—is the explicit bundling of biometric verification with content authenticity scoring in a single platform, delivered without hardware dependencies. Whether enterprises actually want that bundled approach, as opposed to assembling their own best-of-breed stack from specialist vendors, remains an open question.
Regulatory Tailwinds and Headwinds

The regulatory landscape is tightening from multiple directions. The EU AI Act entered force in August 2024, with transparency requirements for AI-generated content already in effect and high-risk AI system regulations taking hold by August this year. The U.S. passed the TAKE IT DOWN Act addressing deepfake revenge porn in May 2025. States like Texas enforce biometric identifier consent laws under their CUBI statute. NIST's SP 800-63-4 Digital Identity Guidelines, drafted through 2024-2025, now include controls specifically for injection attacks and forged media.
Platform policies are adapting too. YouTube mandated synthetic media disclosure starting in March 2024 and expanded deepfake detection tools last October. The C2PA Content Credentials specification—a coalition effort involving Google, Adobe, and others—reached version 2.2 in May 2025, exploring content provenance standards that could eventually become table stakes.
For VeryAI and its competitors, the path forward involves threading several needles simultaneously. Proving accuracy and liveness robustness under emerging test standards. Achieving enterprise compliance requirements—SOC 2, GDPR, CCPA, BIPA, and the alphabet soup that follows. Building developer ecosystems in multiple verticals. Navigating the privacy concerns that have dogged biometric systems generally and palm scanning specifically, given its association (however unfair) with surveillance infrastructure.
The Amazon One discontinuation serves as a sobering reminder that consumer retail adoption isn't guaranteed, even with Amazon's resources and brand. Enterprise use cases—exam proctoring, workforce authentication, high-risk financial transactions—may prove more forgiving. Pearson VUE's palmprint integration and iProov's million-plus daily transactions suggest that demand exists, at least in specific sectors.
Forrester recommended in February 2025 that organizations deploy layered defenses: spectral artifact analysis, liveness detection, behavioral analytics, adversarial training, and process playbooks. No single technology could shoulder the burden alone. Gartner's prediction that standalone authentication would prove "unreliable in isolation" by this year has essentially come to pass, perhaps faster than even Gartner expected.
The Waiting Game
So the question for VeryAI isn't whether deepfake fraud is a crisis—that ship sailed somewhere in 2024. The question is whether the company's dual-layer solution—palm biometrics married to deepfake detection—represents the kind of layering enterprises actually need, or whether they'll prefer assembling those defenses from specialist vendors with deeper track records in each domain.
With a team of fewer than ten, zero disclosed funding, and technology claims still awaiting broader independent validation, VeryAI faces the classic early-stage gauntlet: proving the platform works as advertised, at scale, under adversarial conditions. The 28 million scans the company claims suggest real-world usage beyond demos and pilot programs. The deepfake crisis is undeniable. The regulatory deadlines are approaching fast.
Whether palm biometrics coupled with AI content detection emerges as a standard countermeasure in the enterprise authentication playbook—or gets relegated to a footnote in the broader war over identity verification—will become clearer over the next year and a half as fraud losses mount and compliance requirements harden.
For now, VeryAI is betting that when one lock isn't enough, two might be. The market will decide if they're right.
