Why we must close identity gaps before AI agents start transacting
/Frances Zelazny is general manager of new market initiatives at Prove, an identity verification and authentication company.
The future of identity is taking shape in real time, with agentic AI, digital wallets, and verifiable credentials becoming concrete infrastructure, not just conference themes. And yet, underneath all of it, legacy approaches are still holding the door open for attackers. The new architecture is being built on a cracked foundation, and that tension is the story nobody wants to tell.
We need to fix the identity systems people rely on today before trusting them to support what comes next.
The vision is real
The future of identity is organizing itself around four genuine frontiers: AI identity, continuous identity, passkeys and wallets, along with non-human and agentic AI identity.
It is clear that the agentic AI conversation has reached a fever pitch. Non-human identities now vastly outnumber human ones, and AI agents have ceased to be considered as passive processes. Instead, they are autonomous digital actors making decisions and initiating actions at machine speed, often without human oversight. The questions are urgent: who is accountable when an AI agent acts on your behalf? How do you govern an identity that can replicate, reason, and act independently?
On the credentials front, mobile driver's licenses are now active in over 20 U.S. states, stored in Apple Wallet and Google Wallet, built on ISO/IEC 18013-5, and manifest as cryptographically verifiable, privacy-preserving, machine-readable artifacts. The EU's eIDAS 2.0 framework mandates that banks, financial institutions, and telecoms accept the European Digital Identity Wallet by November 2027. The world is finally moving toward portable, user-controlled identity.
These are significant advances, and I believe in this future. I've spent my career working toward it. However, there are some painful truths that need to be exposed.
The industry needs to fix identity at its source before it gives AI agents more authority to act on people’s behalf. That means verifying a person at enrollment and carrying that assurance through device changes, authentication and account recovery, so attackers cannot exploit the gaps between those steps.
The foundation is cracked
While the industry talks about verifiable credential ecosystems, the world is still running on passwords, SMS codes, and your mother's maiden name.
The numbers are damning. There are an estimated 300 billion passwords in use worldwide. The average person manages 70 to 80 of them; the average professional manages over 100. Sixty percent of Americans reuse passwords across multiple accounts. Globally, 78% of people admit to doing the same. Three out of four passwords are considered unsafe due to reuse or simplicity. The most common password in the world remains "123456" (found, by the way, in breach datasets over 4.5 million times and crackable in under one second). In June 2025, a compilation of over 16 billion login credentials was exposed across 30 datasets, the largest credential dump ever discovered, fueled by infostealer malware.
SMS-based two-factor authentication is not the answer. NIST deprecated it back in 2016, citing its vulnerability to SIM-swapping, SS7 interception, and VoIP spoofing. The final guidelines (SP 800-63-4), updated in August 2025, formally classified SMS as a "restricted authenticator,” requiring organizations to have a migration plan away from it. And yet nearly 56% of IT professionals worldwide report their company still uses SMS-based one-time passcodes. We knew better a decade ago and still haven't acted.
Knowledge-based authentication is worse. The premise is that only the right person knows the answers. The reality is that the data broker ecosystem, breached repeatedly, holds all of it. And while fraudsters provide the correct answer 50% of the time, legitimate users fail to recall their own information 33% of the time.
Put another way, we are legally mandating authentication methods that our own standards bodies have declared insecure.
The stakes are no longer theoretical
North Korea's IT worker infiltration campaign is quite instructive in helping us understand the stakes involved. One American, Christina Chapman, was sentenced to over eight years in federal prison for helping North Korean workers gain employment at more than 300 U.S. organizations — including government agencies, using the stolen identities of 68 Americans. CrowdStrike's 2025 Threat Hunting Report documented over 320 such incidents in a single year, a 220% rise year-over-year. The UN estimates these schemes generate $600 million annually for the regime.
These operatives walked right in through the front door and through hiring processes defeated by synthetic identities, AI-generated photos, and credential stuffing. Society runs on trust, and the trust layer is broken.
On June 10, 2026, Visa announced a partnership with OpenAI to embed its global payment network into AI-agent-driven commerce, with ChatGPT agents independently browsing, selecting, and purchasing on a user's behalf. Tokenized. Fraud-monitored. Scoped permissions. On the surface, it sounds secure.
But the critical question is unanswered: How do we know the human who authorized that agent is actually who they say they are? An agent's authorization chain is only as strong as the human identity it inherits. If that human was onboarded with a reused password and a KBA question, the entire agentic commerce stack is compromised at the root. We are building agentic payment rails on top of an identity layer that remains fundamentally broken.
Close the circle
The fix requires persisting identity across the entire user lifecycle, including enrollment, device registration, authentication, account recovery, regardless of channel. I call this the Circle of Identity.
A foundational biometric-anchored identity established at enrollment becomes the persistent reference point for every subsequent interaction. A new device is provisioned against the original biometric binding.. A call center interaction is authenticated against the same reference. Account recovery traces back to the same verified human. The gaps that attackers exploit, the space between verification events, are closed because persistence is built into the architecture.
The technology and standards exist. Organizations need to use them to address the weaknesses in how people are verified and authenticated, especially as AI-driven fraud makes those weaknesses easier to exploit.