The hologram problem
A security feature only works if someone can actually check it. Research says buyers confirm a hologram exists and stop there. What verifies instead.
Put a hologram on the product. For thirty years that was the reflex answer to counterfeiting, and it still gets sold as one. The problem isn't that holograms are easy to copy (though passable imitations are cheap now). The problem is sharper: a security feature only protects the person who can check it, and almost nobody can check a hologram.
The taxonomy, so the trade-offs are visible
The international standard for choosing authentication features, ISO 22383:2020, sorts them into three families. Overt features are checkable by human senses: holograms, colour-shifting ink, embossing. Covert features need a tool: UV inks, microtext, taggants. Forensic features need a lab. The ladder trades convenience against certainty: anyone can look at a hologram but learns little; a lab learns everything but nobody brings a lab to a purchase.
What the research says about the checker
Document-security research has documented the failure mode for years: most people cannot recall what the genuine hologram is supposed to look like, so they confirm that a shiny device is present and stop there. Decorative diffractive packaging gets mistaken for security. And because presence is what gets checked, a counterfeiter doesn't need to reproduce your hologram at all; any commercial hologram foil passes the only test most buyers apply. The feature performs authentication theatre while the actual verification never happens.
This is not an argument that overt features are useless. It is an argument about who they serve. A trained brand-protection investigator with a reference sample gets real value from a good overt feature. Your customer, standing at a market stall or opening a resale purchase, does not.
The device the buyer already carries
The escape from the trade-off is that the checking tool stopped being specialist equipment. Every modern phone reads QR codes and NFC natively, in the browser, with no app. That moves cryptographic verification, which ISO's taxonomy would file under covert or digital, into the one category that matters commercially: checkable by the buyer, at the moment of doubt, with zero training.
The distinction that still matters is what the scan proves. A printed QR code can be photocopied pixel-perfectly, so a static code proves only that a label points at a web page. The cryptographic version (the industry-standard part is NXP's NTAG 424 DNA) computes a fresh one-time code inside the chip on every tap. A photocopy, a replayed URL, or a cloned tag cannot produce the next valid code, so the verdict "this tag is genuine, verified this second" is actually earned. We walk the full ladder from serial to QR to cryptographic NFC in Product identity without an app.
The test to apply to any feature
Before paying for any anti-counterfeit feature, ask one question: who checks it, and against what reference? If the honest answer is "the buyer confirms something shiny exists," you have bought decoration. If the answer is "the buyer's phone checks a cryptographic proof against the item's own record," the check happens where the doubt happens. You can try that check yourself: one genuine tag, one clone, both verdicts in the browser.
Sources: ISO 22383:2020 (authentication solution selection criteria); document-security literature on hologram verification behaviour. The behavioural finding, that users confirm presence rather than verify the image, is consistent across industry and academic write-ups; we cite the pattern, not a single study.
General information, not legal advice. Verify obligations against the cited regulations on EUR-Lex, or with counsel. Citations checked August 11, 2026.