AI Is Reshaping Identity Security and Digital Trust

Learn how AI is reshaping identity security, from biometrics and deepfakes to vendor trust, human oversight, and secure identity infrastructure.

Written By
Ken Underhill
Ken Underhill
Oct 2, 2026
4 minute read
AI face recognition technology.

AI is reshaping identity security by improving verification while introducing new risks from deepfakes, synthetic identities, and biometric spoofing. Image: ChatGPT

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Artificial intelligence (AI) is changing how organizations verify identity and detect fraud. 

It can also help security teams make faster access decisions by evaluating signals that traditional authentication methods may miss. 

At the same time, attackers can use AI to create convincing deepfakes and synthetic identities designed to bypass those controls.

I recently spoke via email with B. Scott Swann, CEO of ROC, about what this shift means for identity security and how security teams should approach AI-powered technologies. Before joining ROC, Swann spent more than 20 years with the FBI. As a Unit Chief, he helped develop the Bureau’s Next Generation Identification (NGI) system.

Swann’s experience highlights an important point for security leaders. AI may introduce new ways to establish identity, but reliability and security remain essential to building systems organizations can trust.

AI is strengthening and challenging identity verification

Traditional identity systems have often relied on static credentials such as passwords, badges, and PINs. Swann explained that AI can incorporate additional signals and context to help organizations determine whether an access request should be trusted.

This can strengthen fraud detection and authentication while making the process less disruptive for legitimate users. It can also help security teams recognize suspicious activity earlier.

Those capabilities introduce new risks as well. Attackers can use AI to create deepfakes and synthetic identities that make fraudulent activity more difficult to distinguish from legitimate behavior.

For security teams, evaluating an AI-powered identity platform requires looking beyond what the technology can do. Swann said organizations need to understand how the technology is secured and governed. They should determine how its performance is evaluated as threats evolve.

Advertisement

Biometrics require a different security approach

AI-powered biometrics require organizations to think differently about how identity data is protected.

“A password or credential can be changed if compromised, but biometric information is tied to an individual and requires strong protection throughout its lifecycle,” Swann told me.

Before deploying biometric technology, organizations should examine its accuracy and ability to resist spoofing. They should also determine whether it performs reliably outside controlled environments.

Swann noted that performance can vary across locations and lighting conditions. Differences among user populations and operational environments can also affect results.

That makes biometrics most effective as one part of a layered identity strategy rather than a standalone control. Contextual signals can provide additional information about an access attempt, while monitoring can help identify suspicious activity after authentication.

Security teams need evidence before trusting AI identity vendors

Teams need strong evidence that AI-powered identity platforms can be trusted before using them to control access to sensitive resources.

Swann recommended asking vendors for independent performance data rather than relying on controlled demonstrations. For biometric technologies, CISOs can look for participation in National Institute of Standards and Technology (NIST) evaluations such as the Face Recognition Technology Evaluation and Evaluation of Latent Friction Ridge Technology.

Those results should be considered against the organization’s intended use case and acceptable error rates.

Security leaders should also determine what data the platform collects. They need to know where that information is processed and stored, as well as who can access it. Vendor evaluations should examine how vulnerabilities are addressed. They should also consider how the platform is updated and tested as conditions change.

Advertisement

The underlying technology supply chain warrants similar scrutiny. Organizations should know who developed the technology and identify any third-party dependencies. Swann said those supporting national security or critical infrastructure should also consider where identity technology is developed and governed.

Human oversight still matters

AI can help organizations make identity decisions faster, but Swann emphasized the importance of maintaining appropriate human oversight.

“The goal should be improving human decision-making,” he said.

Organizations should establish clear boundaries for when AI can act independently. Policies should also define when additional verification is required and when a decision needs human review.

That oversight becomes especially important in higher-risk environments. An incorrect decision could grant unauthorized access to sensitive systems or block a legitimate user from critical resources.

Treat identity as foundational security infrastructure

One lesson Swann believes commercial organizations can take from government identity programs is to treat identity as foundational security infrastructure rather than a point solution.

Organizations need confidence that the right people are accessing the right resources at the appropriate time. Independent testing can help validate that process, while auditable decisions provide visibility into how access is granted or denied.

For security teams evaluating AI-powered identity technologies, the focus should extend beyond the AI itself. They should consider how the technology fits into their broader security architecture without creating unnecessary complexity or vendor dependence.

AI may change how organizations verify identity. The underlying requirement remains the same because security teams still need identity systems that make reliable decisions they can trust.

As AI adoption expands, organizations should also consider how new identities and trust relationships can create additional attack paths across the enterprise. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.