RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 5, 2026

A Notary Saw a Face on a Screen. Prove It Belonged to a Person.

Remote online notarization rests on three controls: questions only the signer should be able to answer, an automated look at a photographed ID, and a live video call. Each was designed against a human impostor with stolen paperwork. None was designed against generated video, and the legal weight the notarial act carries has not moved down to compensate.

Three controls
Knowledge-based authentication, credential analysis, live audio-video
The recording
Journal plus session video is usually the only evidence of what happened
Loss lands first
Whoever relied on the document absorbs it, then pursues recovery

What a Notarization Is Doing, Legally

A notarial act is a narrow and specific thing that is routinely over-read. The notary is not verifying that a contract is fair, that its terms were understood, or that the signer had authority to bind an entity. In an acknowledgment, the notary is attesting that a person appeared, was identified by a permitted method, and acknowledged signing. That is the whole job.

The reason it carries weight anyway is procedural. A properly acknowledged instrument is generally eligible for recording in the public land records, and in many jurisdictions an acknowledged document is self-authenticating for evidentiary purposes — meaning nobody has to bring the notary to court to establish that the signature is what it claims to be. Recordability and self-authentication are why forgery rings care about notaries in the first place.

Remote online notarization kept that legal weight and replaced the in-person identification step with a technology stack. The stack is where the AI question lives.

The Three Controls, and Why Each Is Under Pressure

  • Knowledge-based authentication. Dynamic multiple-choice questions generated from public and commercial records — prior addresses, vehicles, lenders. Its premise is that only the real person knows the answers. A decade of large-scale data breaches has weakened that premise on its own merits; language models make searching and assembling a person's public record trivially fast. Identity guidance from standards bodies has been steadily de-emphasizing knowledge-based approaches for exactly this reason.
  • Credential analysis. Automated inspection of a captured image of a government ID for security features, font and layout consistency, and signs of manipulation. It is analyzing an image, and image generation has improved substantially. Physical-document forgery is a manufacturing problem; a convincing photograph of a document is now a much cheaper one.
  • The live audio-video session. Historically the strongest control, because a human notary talking to a human signer catches a great deal that automation misses. The assumption underneath it — that the video feed originates from a camera pointed at a live person — is precisely what real-time face synthesis and virtual-camera injection attack.

The mitigations are known and increasingly required by platforms and regulators: liveness detection that resists replay, detection of injected video sources rather than only presentation attacks, chip-based reading of the identity document rather than photographing it, and cross-checks against authoritative issuing sources. Which of these your counterparty's platform actually performs is a question worth asking in writing.

The Legal Landscape Is Still a Patchwork

Remote online notarization is authorized state by state. Most states now permit some form of it, many building on the Revised Uniform Law on Notarial Acts, but the implementing rules differ in ways that matter operationally: which identity proofing methods are permitted, what passing standard applies to knowledge-based authentication, how many attempts a signer gets, how long the recording must be retained, what the journal must contain, and what registration or technology-approval a notary needs before performing remote acts.

Federal legislation to establish nationwide minimum standards and interstate recognition has been introduced in successive Congresses without being enacted, so the patchwork remains the operating reality. Meanwhile the substantive requirements are tightening in a predictable direction — more emphasis on liveness and anti-injection controls, more scrutiny of knowledge-based authentication as a standalone factor — and a platform integration built to the rules of two years ago should not be assumed to be current.

Where the Loss Actually Falls

The fraud pattern that has driven most of this attention is seller impersonation: someone identifies an unencumbered property whose owner is absent or unlikely to notice, impersonates the owner, and executes a sale or a loan. The transaction closes, proceeds are wired out, and the real owner discovers it later.

Untangling that is expensive and slow. A deed forged by an impostor is generally void rather than merely voidable, meaning it conveyed nothing even to a buyer who acted in good faith — which is why title insurance exists and why insurers have grown pointed about identity verification standards. The notarization does not save the transaction. It determines who has a claim against whom afterward, through the notary's bond, their errors and omissions coverage, the platform's contractual allocations, and the title policy.

The same structure appears well outside real estate: powers of attorney, vehicle title transfers, corporate authorizations, estate documents. Anywhere a notarized document functions as a substitute for the signer being present, an impersonation defeats the substitution.

What to Verify If Your Business Relies on Notarized Documents

  • Which platform performed it, and what does it do. Ask specifically about liveness detection, injection-attack detection, whether the ID is read from its chip or photographed, and whether identity is checked against an issuing source.
  • Who holds the recording and for how long. Retention is set by state law and the custodian is often the platform. Know how to request it before you need it urgently.
  • Whether the notary's commission and remote authorization were valid on the date. Commission status is generally verifiable through the commissioning state, and remote authorization is frequently a separate registration.
  • Independent contact on high-value transactions. A callback to a phone number obtained independently of the transaction file — not the one on the paperwork — remains one of the most effective and least technical controls available.
  • Consistency signals in the file. A counterparty who insists on remote notarization, is unreachable by any channel except one, and requests proceeds be directed somewhere unexpected is describing the established fraud pattern.

Frequently Asked Questions

Is remote online notarization less secure than in-person notarization?

Not straightforwardly. In-person notarization is often weaker than people assume — a glance at an ID by someone with no training in document examination, frequently with no meaningful journal entry. RON at least produces a recorded session, a structured journal and automated credential checks. The honest comparison is that RON has different failure modes, better evidence when something goes wrong, and a threat model that generative video is actively changing.

Can a notary refuse to proceed if something feels wrong?

Yes, and this is an important and underused control. Notaries generally may and often must decline an act where they cannot satisfy themselves of the signer's identity, where the signer appears not to understand or to be acting under duress, or where required elements are missing. A notary who proceeds despite doubt because the platform returned a pass is misreading what the automated check is for.

Does knowledge-based authentication still count as adequate identity proofing?

It remains a permitted component under many state RON rules, so it currently counts where the rule says it does. Whether it is adequate as a matter of security is a different question, and the direction of both federal identity guidance and platform practice is toward treating it as insufficient on its own. If you are designing a process rather than merely complying with one, do not build the whole assurance on it.

What if a signer is in another country?

State RON statutes generally locate the notary rather than the signer, so a signer abroad is often workable. Complications arise elsewhere: whether the receiving jurisdiction will accept the document, whether an apostille or consular legalization is needed, and whether local law restricts the act. Cross-border document execution deserves specific advice rather than an assumption that the RON platform resolved it.

We are building identity verification into a product. What is the takeaway?

Assume the artifact you are examining can be generated, and design so that no single artifact is dispositive. Prefer signals with an authoritative source behind them — chip-read credentials, issuing-source checks, verified device and account history — over signals that are only an image or a set of remembered facts. And retain what you saw, because the dispute is always later and always about what the system actually observed at the time.

Should we tell customers which identity checks we run?

Describe the assurance level honestly and avoid absolute language. Claims that identity is verified or that fraud is prevented are the ones quoted back after an incident. Biometric processing also carries its own disclosure and consent obligations in several states, so the description of what you collect is a compliance artifact in its own right, not only marketing copy.

Does Your Site Overstate What Your Verification Does?

Identity and fraud-prevention claims accumulate quickly across a product site, and the strongest-sounding version is usually on the oldest page. After an incident, those sentences are read literally.

See every verification, security and compliance claim on your site in one pass. Run a free scan and check them against what you actually perform.

This article is general information and not legal advice. Notarial law is state-specific and the rules governing remote online notarization change frequently. Confirm current requirements with the applicable commissioning authority and with qualified counsel.

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.