UIDAI launches face-authentication tools for banks and fintechs while expanding AI fraud detection and preparing Aadhaar infrastructure for up to 30 crore daily authentications.

UIDAI Expands AI Fraud Detection as Aadhaar Hits 10 Crore Daily Authentications, Targets 30 Crore

The420 Web Correspondent
8 Min Read

UIDAI is preparing its infrastructure for up to 30 crore Aadhaar authentications a day while expanding AI-based fraud detection and launching new face-authentication tools for banks, fintech companies and other service providers.

Chairman Neelkanth Mishra said at the Global Fintech Fest on September 9 that Aadhaar currently handles approximately 10 crore authentications daily, up from seven crore when he first contributed to the authority’s annual report. UIDAI is preparing for a future workload of 25–30 crore transactions a day.

The expansion comes as more than 600 entities use Aadhaar for identity verification. Mishra described fraud prevention as a continuing contest in which criminals and security systems keep adapting to one another.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

AI Used to Detect Fake Faces and Fingerprints

Mishra said UIDAI has been using artificial intelligence and advanced technology to identify fraudulent authentication attempts.

The authority has deployed liveness testing for facial and fingerprint verification for some time. These checks are intended to establish that the person presenting a biometric is physically present, rather than an artificial representation being used to deceive the system.

For example, facial liveness technology may analyse signals that help distinguish a real person from a photograph, replayed video or other spoofing attempt. Fingerprint systems can also use checks designed to identify artificial or manipulated inputs.

The precise detection methods and performance rates were not disclosed during the session. No biometric system should be assumed to be incapable of error or fraud.

Mishra said the growing sophistication of fraudsters requires UIDAI to keep improving its defences as authentication volumes rise.

New SDK Lets Banks Integrate Face Authentication

UIDAI also launched the Aadhaar Face Authentication Software Development Kit and a Face Authentication Sandbox at the festival.

An SDK is a package of software tools that allows developers to add a particular function to their own applications. In this case, it is intended to help authorised organisations integrate Aadhaar face authentication into their digital services.

The new model allows partner banks and businesses to run authentication processes locally on their own servers rather than routing every processing step through UIDAI’s central infrastructure, according to the event release.

This is intended to make integration more flexible while limiting exposure of critical central systems. It does not mean that organisations can independently access or copy Aadhaar’s central biometric database.

The initiative may also ease restrictions that have complicated authentication for Indians travelling or living overseas. The exact eligibility and rollout arrangements will depend on UIDAI’s technical and regulatory requirements.

Sandbox Allows Testing Without Affecting Live Systems

The Face Authentication Sandbox provides a controlled environment for developers to test their integration before deploying it for real users.

A sandbox is similar to a practice environment. Banks and fintech companies can check whether their application communicates correctly with the authentication system, handles errors and follows the required security processes without affecting the live Aadhaar infrastructure.

The supplied technical description also refers to testing consent, face capture, liveness checks, invalid signatures, network interruptions and spoofing scenarios.

The complete SDK and sandbox documentation was not independently examined, so the exact availability of each test feature should be confirmed by developers before implementation.

The broader purpose is to allow experimentation while protecting the operational identity system from unnecessary risk.

Why UIDAI Is Preparing for Three Times the Load

Aadhaar authentication is used across banking, telecommunications, government services and other digital processes. Each additional service increases the demands placed on the identity infrastructure.

Mishra said the authority must prepare for a dramatic rise in transaction volumes while maintaining reliability and security.

The scale also creates a challenge for fraud detection. A system processing crores of requests daily must identify suspicious activity without causing excessive failures for genuine users.

UIDAI is working on infrastructure capabilities comparable with large technology platforms, according to the event reporting. Mishra said sovereignty concerns meant the authority could not rely entirely on global hyperscalers and needed to develop its own capabilities.

The 25–30 crore figure is a capacity objective. It is not a forecast that daily authentication demand will reach that level by a specified date.

Agentic AI Could Create New Identity Challenges

Mishra also predicted that agentic AI use cases could grow substantially over the next three years.

Agentic AI refers to systems that can carry out multi-step tasks on behalf of a user, rather than merely responding to individual questions. For example, an agent might help complete an application or coordinate a sequence of digital services.

He suggested that people could eventually delegate some authentication-related processes to such agents, creating use cases that are difficult to anticipate today.

This was a forward-looking observation, not an announcement that AI agents can already perform Aadhaar biometric authentication independently or bypass a person’s consent.

Any future system would need to address identity verification, authorisation, accountability and the risk of an agent acting beyond the user’s intended instructions.

What This Means for Users and Financial Institutions

For banks and fintech companies, the new tools could simplify digital onboarding and reduce the need for users to switch between applications during verification.

The benefits will depend on secure implementation, proper consent and reliable handling of authentication failures. Organisations integrating the SDK will remain responsible for protecting their own systems and complying with applicable requirements.

Users should continue to verify that they are dealing with an authorised service provider. A genuine Aadhaar authentication request should not require sharing an OTP, PIN or banking password with an unknown caller.

What this means for you: Use only official Aadhaar services and authorised banking or fintech applications. Never approve an authentication request you did not initiate, and do not share OTPs or banking credentials with anyone claiming to be from UIDAI. If you suspect misuse of your Aadhaar, check your authentication history through the official UIDAI portal and report suspicious activity promptly.

The420 Insight: UIDAI’s challenge is to increase capacity without allowing the larger ecosystem to become a weaker security link. Local integration may improve speed and flexibility, but it also places greater responsibility on partner institutions to secure their applications and servers. Independent testing, clear consent controls and effective fraud monitoring will matter as much as the headline transaction capacity. Future AI-agent use cases will require especially careful rules about what users can authorise and how that authority can be revoked.

https://www.linkedin.com/company/policetechnology/

Stay Connected