For decades, the driver’s license check at a dealership meant a photocopy dropped into a deal jacket or a salesperson snapping a photo on a personal phone. That approach is becoming a liability rather than a formality. Regulators, fraudsters and the license itself are all changing faster than the process built around them, and dealers who have not updated how they capture and store this information are exposed on three fronts at once.
A New Kind of Fraud Walks Through the Door
The biggest shift is the sophistication of the fake ID itself. Fraud researchers have documented a wave of AI generated identification documents that reproduce holograms, barcodes and fonts convincingly enough to defeat a simple visual check. IDScan.net‘s most recent industry datafound fraudulent ID presentments at dealerships and rental counters rose 21% in 2025, much of it tied to dark web tools that let criminals blend a stolen identity’s credit history with a fabricated face and address.
This is not a niche problem. A 2026 fraud trend report from Persona notes that generative AI tools can now assemble a full document package, a license, a pay stub and a utility bill, in minutes, and because the images are generated rather than doctored, the visual cues staff were trained to look for no longer apply. Industry surveys cited by the Texas Independent Automobile Dealers Associationput the share of dealers reporting rising fraud incidents over the past two years above three quarters.
Scanning a License Is Not the Same as Verifying One
Most dealerships already scan a driver’s license as a matter of routine, whether to satisfy a compliance checklist, populate a CRM, or attach a record to a test drive. That scan captures the data on the card, but it does not confirm that the card, or the person holding it, is legitimate. A true verification step goes further: it checks the license against address records, watchlists and OFAC data, screens for signs of a synthetic identity, and can query the issuing state’s database to confirm the license is still active. Industry survey data puts the share of dealerships that skip this step at roughly 95%, and a related survey found that fewer than one dealer in a hundred compares a scanned license against DMV records, the check most likely to catch an altered document.
The gap is measurable. The FTC logged more than 9,500 reports of identity fraud tiedto forged driver’s licenses in 2024. Scanning alone was built for an era when a fake license looked different enough from a real one that a trained eye could catch it. Verification exists because that era has ended.
The Wallet on the Phone Changes the Rules
At the same time, the document dealers are trying to capture is disappearing from physical wallets and moving onto phones. Mobile driver’s licenses, or mDLs, are now live in roughly two dozen states and territories, with adoption accelerating through Apple, Google and Samsung Wallet each quarter, according to tracking from Credence ID. Illinois became the largest state to roll out a statewide Apple Wallet mDL in early 2026, and Arkansas, Connecticut and Arizona have each added or expanded programs this year, reporting from Biometric Update shows.
This matters at the sales desk because an mDL cannot be photocopied or photographed the way a plastic card can. It is a cryptographically signed credential that requires a compatible reader and a deliberate tap or scan, and it can selectively disclose only the fields a business actually needs. Dealers without that reader capability are left asking every mDL holding customer to fall back on a physical card, an inconsistent exception that is becoming more common, not less.
What a Modern Verification Step Actually Looks Like
Adding this step does not have to complicate the sales process, and dealers who have implemented it report that most customers do not object. In a typical setup, the dealership sends a secure link to the customer’s phone, which walks them through capturing an image of their license along with a live selfie.
Facial recognition software compares the selfie to the license, while separate document analysis checks the license for the fonts and security features specific to the issuing state. The extracted license data is then run against identity verification and fraud databases before the deal moves forward.
This same pattern is already standard in online banking, where remote account opening has faced synthetic identity fraud longer than automotive retail has. As more shoppers complete financing applications from home that same remote verification becomes just as relevant to a car deal as it is to opening a checking account.
Regulators Are Watching Two Things at Once
Layered on top of the fraud and technology shift is a compliance environment that has grown considerably more strict. The FTC has increased enforcement of its amended Safeguards Rule throughout 2026, with multi-factor authentication and documented risk assessments now treated as baseline expectations. Because dealerships that arrange financing are classified as financial institutions under the Gramm Leach Bliley Act, the license images, numbers and associated data they store fall squarely under this rule, and violations can carry penalties reaching six figures per instance, according to guidance published by Tekion.
Separately, a wave of state privacy laws taking effect beginning January 1, 2026introduces a requirement that is easy to overlook: formal risk assessments before deploying automated or AI driven decision tools, including systems used to score or verify identity documents. A dealership that adopts an AI-powered scanning tool to fight fraud may now need to document that same tool under a separate privacy statute.
Where This Leaves Dealership Operations
None of this points to a single fix. It points to a capture process that now has to do three things at once: verify a document that fraud rings can fabricate convincingly, accept a credential format that increasingly lives on a phone rather than in a wallet, and generate documentation that regulators expect to see. Dealers reviewing their current process would do well to ask whether it was built for the license customers carried five years ago or the one they are actually presenting today and whether the resulting paper trail would hold up if a regulator asked to see it.