Remote I-9 verification comes down to a video call
Since August 2023, employers enrolled in E-Verify have been permitted to examine Form I-9 documents over a live video interaction instead of in person. The procedure is careful, it was a genuine improvement on what came before, and it rests entirely on the assumption that a camera shows what is actually in front of it.
Nine minutes on a Tuesday
Picture the onboarding coordinator at a nine hundred person software company. It is Tuesday morning. She has twelve new hires starting this month and every one of them is remote, which is now unremarkable. Her calendar says: I-9 Section 2 verification, 15 minutes.
The scans arrived on Friday. Passport, front and back, uploaded through the onboarding portal, legible, the right size, nothing obviously wrong. She has already read them. The video call is the part where she does the thing the regulation asks her to do, which is look at the person and look at the document and decide whether they belong to each other.
He joins on time. The picture is a little soft, which is normal, because everybody's camera is a little soft. He holds the passport up near his face, turns it so the light does not blow out the laminate, holds it steady for a beat longer than necessary because he has clearly been told to. She looks at the photo page. She looks at him. They match. She thanks him, they exchange a sentence about the weather where he is, and the call ends.
She checks the box on the form indicating she used the alternative procedure. She files the copies to the retention folder. Nine minutes, start to finish, and it is honestly the most careful I-9 she will complete all week.
Every single thing she did was correct. She followed the Department of Homeland Security procedure precisely as written. And there is no step anywhere in that nine minutes that would have told her if none of it was real.
Short answer: Yes, synthetic video can defeat remote I-9 document examination. The DHS alternative procedure requires a live video interaction, and video is now inexpensive to generate and can be fed directly into the camera pipeline without a real camera ever being involved. The examiner's judgment is not the weak point. The channel is. The available fix is to move document capture and liveness onto the new hire's own enrolled device and sign the attestation from both sides.
What is the DHS alternative procedure for remote I-9?
Some background, because the rule is more specific than most people who follow it realise.
Every employer in the United States must verify the identity and employment authorisation of every person they hire, using Form I-9. The obligation comes from the Immigration Reform and Control Act of 1986 and the implementing regulations sit at 8 CFR 274a. The employee completes Section 1. The employer completes Section 2, which requires examining documents from the Lists of Acceptable Documents and attesting that they reasonably appear on their face to be genuine and to relate to the individual presenting them.
For most of the law's history, that examination was physical. Someone had to hold the passport. During the COVID-19 period DHS issued temporary flexibilities allowing remote inspection, and in July 2023 the department published a final rule creating a permanent optional alternative, which took effect on 1 August 2023 (USCIS, I-9 Central).
The alternative procedure is not simply permission to do it over Zoom. It has conditions. The employer must be enrolled in E-Verify and in good standing. The employer must obtain and examine copies of the front and back of the documents in advance. The employer must then conduct a live video interaction with the individual who is presenting them, during which the documents must reasonably appear genuine and to relate to that individual. The employer indicates on the form that the alternative procedure was used, and must retain clear and legible copies of the documents. Employers who choose the alternative procedure are expected to apply it consistently rather than selectively, which matters enormously and we will come back to it.
Why the procedure exists, and why it was a good idea
It is worth being fair to the rule before criticising it, because the alternative it replaced was considerably worse.
Before 2023, an employer hiring someone two thousand miles away had two realistic options. Fly the document to a person or the person to a document, which nobody did. Or use an authorised representative: any individual the employer designates to complete Section 2 on its behalf. In practice that meant a notary who had never examined an I-9 in their life, a manager at a coworking space, a friend, or in the more enthusiastic cases a relative of the new hire. The employer remained liable for whatever that person attested to. It was, to put it gently, a control with a wide variance.
Against that baseline, the alternative procedure is a real improvement. It puts a trained employee of the actual employer in the loop, requires document copies to be retained and examined, and restricts the whole thing to employers who are also running E-Verify. DHS did a careful job. The problem is not that the department was careless. The problem is that the rule was designed against a threat model in which the risk was that nobody looked carefully.
Why does the video call carry all the weight?
Walk through what each part of the procedure actually establishes, because they are not equal.
The document copies establish that a document image exists and can be inspected. An experienced examiner can catch a crude forgery from a scan. They cannot check a hologram, feel the substrate, tilt the card to see the optically variable ink, or run it under ultraviolet light, because those are physical properties and a scan is not a physical object.
E-Verify establishes that the data on the form corresponds to a record held by DHS or the Social Security Administration. That is genuinely useful and catches invented identities. It does not establish that the person in the video is the person that record describes, because E-Verify checks data, not people.
So the entire job of confirming that this human being is the human being on this document falls on the live video interaction. That is the one step that binds a person to a document. Everything else in the procedure is checking paperwork against paperwork.
Here is the analogy, and then the mechanism. A bouncer checking an identity card at a door does several things at once: they look at the photograph, they look at your face, they feel the card, they tilt it, and critically they know that the face and the card are both physically present in front of them at the same moment. The remote procedure asks the examiner to do the first two of those, through a lens, over a network, from a stream of pixels that arrives already decoded. It is a bouncer checking an identity card by looking at a photograph of someone holding an identity card.
For most of the history of video calls that was fine, because producing a convincing fake video of a specific person holding a specific document required a studio. It does not any more.
Can a deepfake defeat remote I-9 document examination?
Yes, and the reason is more structural than most coverage of deepfakes suggests. There are two different attack classes here and the difference between them is the whole story.
Presentation attacks versus injection attacks
A presentation attack means holding something up to a real camera: a printed photograph, a mask, a phone screen playing a video, a laptop displaying a rendered face. The camera is genuine and it is faithfully capturing something fake. This is the attack that liveness detection was designed for, and detection of presentation attacks is a mature field with an international standard behind it, ISO/IEC 30107. Ask the subject to turn their head, watch for screen glare, look for the moire pattern of a display. It works reasonably well.
An injection attack never touches a camera. The attacker installs a virtual camera driver, runs the session in an emulator, or modifies the client application, and feeds synthetic frames directly into the pipeline at the point where camera output would normally enter. The application receives a video stream that is well formed, correctly timed, and entirely manufactured. Every liveness cue the examiner or the software looks for is present, because the attacker generated all of them deliberately. Turn your head to the left, and the synthetic face turns to the left.
We have written about this attack class in detail in the camera is no longer evidence, because it is currently the most under appreciated shift in identity verification. The short version: capture integrity was always an assumption, and it has stopped holding.
Why video conferencing is especially exposed
Here is the uncomfortable part for anyone hoping this gets patched. Video conferencing software accepts a virtual camera as readily as a physical one, and that is a deliberate feature rather than a bug. Every person who has ever applied a background blur, used a streaming tool to composite their slides, or joined a call through a hardware mixer has used a virtual camera. It is load bearing functionality for millions of legitimate users.
So the examiner on the I-9 call is not using a hardened identity verification client with device attestation and injection countermeasures. They are using the same conferencing tool they use for standups, which is architecturally indifferent to where the pixels came from. There is no vendor to file a bug with, because nothing is broken.
Is this actually happening, or is it a thought experiment?
It is worth being precise here, because it would be easy to overstate and the honest picture is more interesting than the alarming one.
Most I-9 fraud is not sophisticated. It is borrowed documents, a cousin's identity, a mismatched name that a careful examiner catches. It has been that way for decades and it remains the bulk of the problem. A post claiming that every remote onboarding call is under synthetic attack would be wrong.
But the tail matters more than the volume here, because of who is in the tail. United States Department of Justice prosecutions and Treasury sanctions actions have documented an organised scheme in which workers acting for the Democratic People's Republic of Korea obtained remote employment at United States companies using stolen and borrowed identities, supported by domestic facilitators operating so called laptop farms that made the workers appear to be logging in from inside the country. The published actions describe infiltration across a large number of United States companies and revenue flowing to a sanctioned state. We have covered the operational detail in the laptop farm playbook.
Every one of those hires had a Form I-9. Somebody in an HR function looked at a document and a face and attested that they belonged together. Whatever else that scheme demonstrates, it demonstrates that a well resourced adversary treats the onboarding identity check as an obstacle to be routed around rather than a wall, and that they succeed at scale.
Alongside that, the research firm Gartner has published a widely cited projection that a substantial share of candidate profiles globally could be fake by the end of this decade. Treat projections as projections. The documented state actor cases do not require any projection at all.
Is the person who onboarded the person who works?
Now the larger gap, and the one that matters more than the video call.
The I-9 is an event. It happens once, in the first days of employment, and then it goes into a folder for the retention period. Employment, meanwhile, is a duration. It runs for months or years, across a laptop that was shipped to an address, through a VPN, into systems holding customer data and source code and payroll.
Nothing in the hiring stack rebinds the verified person to the working person. Not once. The I-9 verified a human in week one. The identity provider authenticates an account thereafter. Those are different objects, and the entire remote worker infiltration problem lives in the space between them: the person who interviewed and completed the I-9 can be a different person from the one at the keyboard in month four, and no system in the ordinary corporate stack is designed to notice.
We call this identity discontinuity, and it is the subject of a separate lesson on proving the same human from interview to offboarding. For the purposes of this post, the point is narrower: even a perfect I-9, examined in person, under a blacklight, by a trained officer, tells you nothing whatsoever about who is doing the work in the second quarter.
| Stage | What is actually verified | What is assumed |
|---|---|---|
| Application and interview | Nothing formally verified | The candidate is who the profile says |
| I-9 Section 1 | The employee attests to their own status | The attestation is truthful |
| I-9 Section 2, remote | Document images inspected; a face appeared on a video call | The video stream came from a real camera pointed at a real person holding a real document |
| E-Verify case | Form data matches a government record | The person on the call is the subject of that record |
| Device issue and first login | An account authenticated | The account holder is the verified hire |
| Ongoing employment | Sessions authenticate | The same human continues to do the work |
| Offboarding | Accounts disabled where known | All authority was known and revoked |
Read that table as a whole and the shape of the problem is clear. The column on the right gets longer and vaguer as employment proceeds, and the single strongest binding event in the entire sequence is a nine minute video call.
What would audit grade evidence actually look like?
Here is a reference design. It is not a product you can buy today and we will say so plainly in the limits section, but every primitive it uses is shipped and the assembly is straightforward.
The insight is that the employer is already conducting a verification event at exactly the right moment. The hire is present, motivated, and about to be onboarded. That is the cheapest opportunity anyone will ever have to bind this specific human to a key. Spending it on a video call that produces no durable evidence is the waste.
Step one: the hire enrols on their own device
The new hire receives a link and completes enrolment on their own phone. The device performs an on device face match with a liveness challenge. The face never leaves the phone. What is retained is a one way key, which is to say a value derived from the biometric that cannot be run backwards to reconstruct it. There is no template in a database anywhere. This matters for the state biometric privacy statutes, and it matters more for the ordinary reason that a company which does not hold biometric data cannot lose it.
Because this happens on the hire's own device rather than through a conferencing window, the liveness challenge runs against the device's camera stack with platform attestation available, which is a materially harder target than a virtual camera feeding a browser tab.
Step two: document capture happens on the same device
The hire photographs their documents through the same enrolled session, using on device capture. The pages are processed in the browser and are not transmitted until the hire shares them deliberately. The employer receives the images it is required to retain, and the images arrive with a cryptographic link to the capture session and the enrolled key rather than as anonymous files that appeared in a portal.
Step three: both parties sign
This is the part that produces the evidence. The hire signs the capture. The examiner signs the attestation. Two receipts, each verifiable offline against a published key, retained alongside the form for the full retention period.
Here is what the examiner's attestation payload contains, conceptually:
{
"type": "i9.section2.attestation",
"form_id": "I9-2026-004417",
"hire_key": "z6Mkf...9Qa2", // enrolled key, established at step one
"documents": [
{ "list": "A", "title": "US Passport",
"sha256": "9f2c...ab71" }, // hash of the retained image
{ "list": "A", "title": "US Passport (back)",
"sha256": "41d8...cc09" }
],
"procedure": "dhs_alternative",
"liveness_receipt": "rcpt_8e11c2...", // from step one, on device
"examiner": "u_2288",
"attestation": "documents reasonably appear genuine and to relate to the individual",
"examined_at": "2026-09-28T14:07:31Z"
}
The examiner's device signs the SHA-256 of that canonical object. Take each field in turn and ask what it forecloses.
The hire_key ties the attestation to a specific enrolled human rather than to a name typed into a form. If that person's key later signs a work event, the two are linked. If a different person shows up in month four, they cannot produce it.
The documents hashes tie the attestation to the exact images retained. Version drift between what was examined and what was filed becomes detectable rather than assumed, which is a small thing until the day an auditor asks.
The liveness_receipt ties the attestation to a liveness check that ran on the hire's own device rather than to an examiner's impression of a video window. This is the substitution that matters. The examiner's judgment is still in the loop and still required by the rule, but it is no longer the only evidence.
The examined_at timestamp and the examiner signature answer the question that audit defence actually turns on, which is who did this and when, with something better than a database row the employer wrote about itself.
The verification call for either receipt is a single request against a published key, documented in the developer docs, and it does not contact us to check.
An attacker now has a harder job. They must defeat liveness on a device they control, at enrolment, and then continue to hold that device for every subsequent event that checks continuity. That is not impossible. It is considerably more expensive than pointing a virtual camera at a conferencing app, and expense is the entire game.
Does this change the employer's legal obligation?
No. This needs to be said flatly because the compliance market is full of products implying otherwise.
None of this replaces E-Verify. None of it replaces the DHS alternative procedure. The examination described in the rule still has to happen, performed by the employer or an authorised representative, under the conditions the rule sets, with the retention the rule requires. A cryptographic receipt is not a legal substitute for a regulatory step, and no vendor can make it one.
What it is, is an internal control and an evidence layer sitting underneath a process you are already obliged to run. It improves what you can show later. It does not change what you must do now. This post is not legal advice, and any change to an I-9 process should go past immigration counsel before it goes past HR.
What does this cost the honest new hire?
Take this seriously, because in employment eligibility verification the discrimination risk is not a footnote, it is a body of law with an enforcement section attached.
The Immigrant and Employee Rights Section of the Department of Justice enforces prohibitions on unfair documentary practices, which include treating individuals differently in the verification process based on citizenship status or national origin. An employer that applies extra identity steps to some new hires and not others is creating legal exposure and, more importantly, is doing something wrong to real people. Any control described here must be applied uniformly to everyone hired under the same conditions, and the decision about who gets it cannot be made by a manager's intuition about a name or an accent.
There is a second cost that gets less attention. Device based enrolment assumes a device. Some new hires do not have a smartphone capable of running it, some have older hardware, some have accessibility needs that the flow must accommodate, and some are starting a job precisely because they have very little. A process that quietly excludes those people has failed regardless of how much fraud it stops. The staffed fallback path is not an exception to the design. It is part of the design, and it should be as ordinary to invoke as the main path.
Honest limits
What this control does not do, stated plainly.
- It does not verify that documents are genuine. Binding a human to a capture is a different problem from determining whether a passport is real. Document authentication is its own discipline and this composes with it rather than replacing it.
- An attacker who controls the device at enrolment wins. If the very first binding is fraudulent, everything downstream faithfully records a fraud. Enrolment remains the trust bottleneck, exactly as it does everywhere else in identity.
- It satisfies no legal requirement by itself. See the section above. The rule is the rule.
- Continuity only helps if later events check it. A receipt at day zero that nothing ever references again is a filing cabinet artefact. The value comes from the second, third and tenth check.
- A coerced or compensated real person still signs. Someone who genuinely enrols and then hands their device and credentials to another party defeats this, which is a documented pattern in the state actor cases and is not a cryptography problem.
- Manav has shipped no I-9 platform or E-Verify integration. The primitives described here are shipped: on device face match with liveness, on device document capture, per action signatures and offline verifiable receipts. The I-9 evidence bundle is a reference design, not a product listing. You can see the underlying flow at the employee verification demo and the capture primitive at docscan.
What to do this week
- Ask your examiners what they would do. Sit with the two or three people who actually complete Section 2 and ask them how they would detect a synthetic video. The answers will tell you how much assurance you currently have, and the conversation is usually more clarifying than any policy review.
- Check your alternative procedure eligibility and consistency. Confirm you are enrolled in E-Verify and in good standing, and confirm in writing which population you apply the procedure to and why, so that consistency is a documented decision rather than an accident.
- Audit the retention. Pull ten recent remote I-9s and verify that the retained copies are clear, legible, front and back, and that the alternative procedure indication is present. This is the most common finding in an audit and it has nothing to do with deepfakes.
- Write down what the video call is supposed to establish. One paragraph. Most organisations have never articulated it, and articulating it is what makes the gap visible to people who control budget.
- Separate the day zero binding from the ongoing question. Even if you change nothing about the I-9, ask separately how you would know that your remote engineer in month six is the person you hired. Those are two projects and conflating them stalls both.
- Bring immigration counsel in early. Any change to the verification flow, including one that only adds evidence, needs review against the anti discrimination rules before it touches a single new hire.
- Design the fallback first. Decide what happens for a hire with no suitable device before you decide anything else. If the fallback is embarrassing, the main path is not ready.
Frequently asked questions
Who can use the DHS alternative procedure for remote I-9? Employers enrolled in E-Verify and in good standing may use it, subject to the conditions in the rule, including examining copies of the documents in advance, conducting a live video interaction with the individual presenting them, indicating use of the procedure on the form, and retaining clear and legible copies. Employers are expected to apply it consistently rather than selectively.
Can a deepfake defeat remote I-9 document examination? Yes. The live video interaction is the step that binds a person to a document, and video can be synthesised and injected directly into the capture pipeline through a virtual camera or emulator, so every liveness cue an examiner looks for can be manufactured. The examiner is doing their job correctly; the channel does not carry the assurance the procedure assumes.
Does E-Verify solve this? No. E-Verify compares the information on the form against DHS and Social Security Administration records, which is valuable and catches fabricated identities. It does not establish that the individual on the video call is the person those records describe. It answers a data question, not a human question.
Is remote I-9 less secure than in person examination? Not because it is remote. It is less secure because it relies on a video call for the one step that binds a person to a document. Move capture and liveness onto the hire's own enrolled device, sign the attestation from both sides, and the remote path can produce better evidence than the in person one ever did, because in person examination produces no durable artefact at all.
Does a signed receipt satisfy the DHS requirement? No. The rule prescribes what the employer must do and no cryptographic artefact substitutes for performing it. A receipt is an internal control that improves what you can demonstrate afterwards. Treat it as evidence, not as compliance, and take any process change past immigration counsel.
Will extra identity checks create discrimination risk? They can, which is why uniform application is not optional. The Immigrant and Employee Rights Section enforces prohibitions on unfair documentary practices, and applying additional steps based on a person's name, accent, or perceived citizenship status is both unlawful and wrong. Any control must apply to everyone hired under the same conditions, with a staffed alternative for those who cannot use it.
What about hires without a smartphone? They must have a path that works, and it should be a normal path rather than an exception that signals suspicion. Design the fallback first. A verification design that excludes people at the bottom of the income distribution has chosen the wrong trade, whatever it does for fraud.
Sources
- USCIS, I-9 Central, including guidance on the alternative procedure for examining documents: uscis.gov/i-9-central
- E-Verify program information and enrolment requirements: e-verify.gov
- Employment eligibility verification regulations, 8 CFR Part 274a: ecfr.gov, Title 8 Part 274a
- Department of Justice, Immigrant and Employee Rights Section, on unfair documentary practices: justice.gov/crt/immigrant-and-employee-rights-section
- Department of Justice press releases on prosecutions relating to remote information technology worker schemes: justice.gov/news
- US Department of the Treasury, recent sanctions actions: home.treasury.gov, recent actions
- ISO/IEC 30107 on biometric presentation attack detection, catalogue entry: iso.org
Remote I-9 is not weak because it is remote. It is weak because the one step that binds a person to a document is a video call, and video stopped being evidence.