Israel-based D-ID, which is working on tech to make faces unrecognizable to face recognition software, raises $13.5M led by AXA Ventures
If only Facebook had been using the kind of technology that TechCrunch Startup Battlefield alumnus D-ID was pitching, it could have avoided exposing … Tweets: @dtunkelang Tweets: Daniel Tunkelang / @dtunkelang : De-identifying images and videos to make them human-recognizable but not machine-recognizable is a nice idea. But I'm curious if this sort of adversarial AI can work indefinitely. If it can't, then past images and videos will eventually be recognizable. https://techcrunch.com/...
Context & Ripple Effects
D-ID was profiled back in 2017 as a Startup Battlefield alumnus pitching an unusual idea: alter images and videos so humans still recognize the person but face-recognition software does not. Three years on, the round led by AXA Ventures — an insurer's arm — converts that pitch into a funded company, arriving just as the same Israeli ecosystem scales the opposing technology: AnyVision's face and body recognition, which went from a $28M Series A led by Bosch to a $235M Series C co-led by SoftBank's Vision Fund 2.
The demand signal runs through the coverage: Facebook AI Research built its own system to modify faces in live video to thwart recognition (reported October 2019), meaning even the largest platforms see de-identification as infrastructure rather than novelty.
First-order effects
- D-ID gains capital to move from research demos toward deployable products for platforms and enterprises that store identifiable imagery of users.
- AXA Ventures' lead role puts an insurer at the front of the cap table — the buyer most exposed to liability over leaked biometric data now has a stake in the masking layer.
Second-order effects
- Recognition vendors like AnyVision face an escalating technical contest: every improvement in de-identification pressures their accuracy claims, which underpin government and enterprise contracts.
- Platforms storing years of user photos must decide whether to adopt adversarial masking proactively or accept that today's unprotected archive is tomorrow's recognition dataset.
Third-order effects
- As Daniel Tunkelang notes, adversarial AI may not hold indefinitely — if de-identification proves temporary, protected images eventually become machine-recognizable, shifting the market from one-time masking toward continuous re-protection of archives.
- If the pattern holds, the facial-recognition industry splits structurally into offense (AnyVision-style identification) and defense (D-ID-style de-identification) stacks, each pulling separate institutional capital.
The trend: Institutional capital is funding a defensive counter-industry to facial recognition, turning biometric privacy from a policy debate into a commercial arms race between Israeli-funded识别 and masking startups.