AI changes IAM

When organizations verify the identities of those they are transacting with online, they are not only identifying humans but also AI agents.

With the proliferation of agentic AI and its adoption at scale by consumers, agents are doing the shopping, booking travel, ordering from restaurants, and even doing banking transactions.

Agents are assimilating into the world of online communication and transacting at a rapid pace. This presents major challenges not only in identity management but also for organizations that need to provide a frictionless customer experience as part of the business offering.

The goal is to deliver on customer experience. But achieving this requires many moving parts working together to authenticate identity and grant access.

As the customer — either human or agentic — waits for access, identity documents, biometrics, trusted data sources, and fraud detection work together to verify the identity. At the same time, they ensure that all aspects of the process remain compliant with increasingly rigorous regulations.

Identity at the heart

This puts identity management right at the heart of day-to-day operations, not just of organizational risk.

“The real challenge for organizations is how to strengthen compliance and fraud protection while still giving customers a fast and smooth onboarding experience,” says Harvinder Singh, the regional vice president of identity security solutions at Entrust.

“But the way AI is scaling now, the verification of identities is no longer a checkbox activity anymore,” he adds.

“It used to be that genuine customers used to go through the interaction with very little friction in the beginning, and only the higher-risk cases were challenged more, but now the frauds are so convincing that we need identity to be managed continually through the life cycle.”

Entrust’s 2026 Identity Fraud Report notes what Singh says is a “massive jump in deepfake attacks from a biometric perspective on the document side.”

It is not possible to catch these with the “naked human eye” and requires the use of AI to spot fraud at all stages — whether that is onboarding at day one or in daily transacting.

In this new and escalating environment, says Singh, identity verification needs to “move beyond day one.”

“Most institutions have thought that identity should be protected on day one of the interaction, but my argument is that we need to look at identity from a life cycle perspective,” says Singh.

“If I am using a banking system and have been onboarded, my account can actually be taken over, and it’s very easy for a one-time password to be phished or compromised,” he explains.

“So I think it is now about building a security identity framework within the system so that I can be trusted at all times, and also so I can trust the system as well.”

Staying ahead of the game

Singh acknowledges the sophistication of the fraudsters and says that, in fighting back, Entrust has built an in-house Fraud Lab that replicates tactics they use.

“We create frauds from a deepfake biometric perspective and try to stay ahead of the game,” he says.

“It helps us train our models to identify these frauds, and whether it is IP address tracking, device binding, or a biometric injection attack, we need to up our own game to spot these fraudsters at the earliest stage.”

To maintain a high level of preparedness is an ongoing commitment. It will go up another level in the future with the advent of quantum computing, which is likely to enable even more sophisticated online fraud.

“In an era where AI is doing everything for you, we need to ensure we use AI to stop those fraudsters,” says Singh. “With the next generation of post-quantum supercomputers, you can create absolutely truthful documents and truthful faces which are not human, so it is a constant exercise.”

“We need to take all that learning and continually be training our models, so that we can stop fraudsters not just on day one but all through the lifecycle,” he concludes.

Image credit: iStockphoto/phuttaphat tipsana