Permissive Models, Unequal Risk: Auditing AI Identity-Document Forgery as a Systemic Infrastructure Risk
Sebastian Soto
Submitted to Global South AI Safety Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
Two 2021 breaches exposed the identity records — including ID photographs — of essentially all of Argentina (RENAPER, ~45M, attacker-claimed) and Brazil (the megavazamento, ~223M). Frontier text-to-image models supply the forgery half, recomposing leaked photos into credentials that defeat appearance-based KYC. Our thesis: identical model behavior yields unequal societal risk — where one leaked, cosmetically-verified credential gates civil and financial life and AI collapses the marginal cost of forgery at scale, danger is set by identity infrastructure, not model behavior. To show the model layer is an unreliable control, we release DocRefusal, a vendor-neutral refusal scorecard (model × jurisdiction × escalation × language) across six models (key cells 5× on three): refusal is a model property — large, replicated provider differences, not a capability gradient — and single draws overstate (“English→Spanish flips” were artifacts; a weak Spanish lean survives). We map source-grounded, coordination-aware controls to FATF 2025.
Reviews
This project provides a highly valuable methodological validation by demonstrating that AI safety cannot rely solely on the model layer. It also generates actionable recommendations with the potential to inform real-world governance practices. As a natural next step, incorporating a fidelity metric to assess how convincingly outputs could deceive production infrastructure would further strengthen the work. The project offers a solid foundation for future research and development.
This is a powerful and unusually well‑framed paper: recasting ID‑document forgery as a systemic infrastructure risk—via credential centrality, the “forgery as scaling problem” insight, and the defense‑in‑depth ladder—adds real value beyond yet another “can the model forge?” audit, and the DocRefusal harness plus 5× replication give the empirical spine more credibility than most single‑shot studies. At the same time, the empirical core is still relatively narrow: only three of six models are replicated, L3 escalation cells (arguably the most worrying) remain single‑draw, compliance is treated as a binary upper bound without systematic fidelity scoring, and all coding comes from a single rater, so several key findings are rightly framed as suggestive rather than robust. A natural next step would be to (i) extend replication to all models and include L3, (ii) operationalize the proposed 0–3 fidelity rubric with a second rater to distinguish “toy prop” from KYC‑plausible output, and (iii) move from a qualitative to at least a semi‑quantitative credential‑centrality index, so that the excellent governance story can be backed by a more formal, comparable measure across jurisdictions.
Read full reviewShow less
The credential-centrality framework is the paper's most policy-relevant contribution, but it is currently qualitative and applied to only three jurisdictions. The most impactful next step would be to develop a scoring rubric that allows a third party to assess credential centrality for any jurisdiction so that the framework can be applied systematically across Latin America and used in procurement or policy documents.
The paper makes a strong case that the defense must move downstream (from document forensics to source-grounded biometric verification to coordination detection), but the governance recommendations section is brief relative to the depth of the preceding analysis.
Finally, this paper would benefit from a cleaner summary statement at the outset of the Discussion section.
Cite this project
@misc{soto2026permissive,
title = {{Permissive Models, Unequal Risk: Auditing AI Identity-Document Forgery as a Systemic Infrastructure Risk}},
author = {Sebastian Soto},
year = {2026},
month = jun,
note = {Submitted to Global South AI Safety Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/permissive-models-unequal-risk-auditing-ai-identitydocument-forgery-as-a-systemic-infrastructure-risk-9c7o}},
url = {https://apartresearch.com/sprints/projects/permissive-models-unequal-risk-auditing-ai-identitydocument-forgery-as-a-systemic-infrastructure-risk-9c7o}
}More from Global South AI Safety Hackathon
- View project: Pragmatic Sophistry in Vietnamese Multi-Agent Oversight
Pragmatic Sophistry in Vietnamese Multi-Agent Oversight
AI Safety Enthusiasts
AI safety monitors are usually evaluated on the assumption that risky behavior is lexically visible in the text being watched. We test this assumption in a multilingual, multi-agent setting: Vietnamese-language workflow …
- View project: JusticIA: A Counterfactual Benchmark for Auditing Contextual Biases in Language Models for Transitional Justice
JusticIA: A Counterfactual Benchmark for Auditing Contextual Biases in Language Models for Transitional Justice
JusticeMiners
JusticIA is a counterfactual benchmark for auditing contextual bias in LLMs applied to Colombian transitional justice. It tests whether six LLMs change their sanction recommendations when only one contextual attribute …
- View project: Coldron
Coldron
ColDron
En Colombia, los grupos armados ilegales ya atacan con drones comerciales modificados y ya han herido y matado a civiles. Una pregunta decide cómo gobernar esta amenaza: ¿quién elige el blanco y aprieta el gatillo? Hoy, …