Henry Patishman is Executive VP of Identity Verification Solutions at Regula.gettyFor years, identity verification has circled one question: How do we keep bad actors out? Fair enough, that question still matters. It just doesn’t cover what’s happening anymore. It also assumes that a person is actively present and consciously participating in every interaction.The User Is Disappearing From The Verification MomentWhat’s changing, and fast, is the role of the user at the exact moment verification happens. In more and more cases, there won't be a person sitting there. AI agents are taking steps on someone’s behalf. Onboarding is becoming automated. KYC refreshes or routine updates of the information companies hold about existing customers run in the background. Work gets delegated across tools and systems, meaning that one system can initiate an action that another completes without the person controlling every step. Identity actions keep firing, even when the human isn’t really present.And yet plenty of identity verification systems still behave like the user is right there, patiently moving through a human-paced flow. That creates a growing gap between how these systems are designed and how digital identity interactions actually happen.Fraudsters aren’t waiting for the industry to catch up. They already operate in this world, and they are increasingly using automation to exploit that gap. Anthropic reported a cyber-espionage campaign where AI did more than give guidance to the attackers; it carried out significant portions of the operation on its own.Deepfakes Are The Distraction, Automation Is The ShiftDeepfakes are what everyone points to, but the bigger shift isn’t the fake face, it’s the automated identity misuse—the use of software to repeat, accelerate or coordinate fraudulent identity actions with little or no human involvement. Attackers don’t always need cinema-quality synthetic selfies or perfectly forged documents. Often, what they need is simpler and more scalable: repeatable scripts that take advantage of the assumptions baked into human-centered verification. We’re still tuning systems for the visible user, while fraudsters are getting good at exploiting the invisible one.An AI agent can initiate an action the person never intended. A compromised device can run a flow quietly, end to end. A basic script can replay legitimate credentials at scale. In all these cases, the identity signals may look valid even when the legitimate person is not truly behind the action.Identity Is Not The Same As IntentThat’s why identity provides the foundation, while context and apparent intent help determine whether the action itself can be trusted. It can establish who appears to be involved. It does not always establish whether that person initiated, understood or authorized a specific action.Someone can be real. Their document can be real. The biometric match can be real. And the action can still be unauthorized, manipulated or inconsistent with what that person intended. And that creates another challenge: A business may later have to explain why it treated the action as legitimate.The Decision Has To Hold UpGetting identity right means not only blocking fraud in real time, but also ensuring that every decision can withstand scrutiny when something goes wrong, a complaint lands or regulators come calling. This is no longer only a technical issue. Identity decisions now affect liability, compliance, customer trust and a company’s ability to defend the actions taken by its systems.Regula’s latest research puts numbers on the problem: 92% of organizations say bad identity verification decisions have led to real business fallout, from financial losses and regulatory trouble to reputational hits, operational headaches and customers walking away. And there’s a second squeeze at the same time. While 82% report they’re expected to justify identity decisions, only 56% say they can actually produce evidence that meets an audit standard. That gap matters because justifying a decision requires more than confirming that a verification check took place.In practice, justifying a decision means being able to reconstruct how it was made. When a customer challenges an outcome, “the account was verified” does not carry much weight. The business has to show why it was reasonable to believe that this specific customer was responsible for that specific action.That requires answers to a much more detailed set of questions. Which device did the request come from, and what did the session look like? What changed right before the event? Which identity and behavioral signals were checked and how were they weighed? Did the activity match the customer’s previous behavior, or did it break the pattern? And, most importantly, what evidence made the request appear legitimate at the time?Systems often compress all of that information into a risk score to make a fast decision. But the score alone does not show how the system reached that conclusion. If the outcome is challenged later, the business still needs the evidence behind it: which signals were checked, what they showed, and why they supported the decision.Verifying The Actor, Not Just The SignalsThe next stage of identity verification must consider more than whether a document, face, device or credential is valid. It must assess the context of the action: who initiated it, how it unfolded and whether it was consistent with the legitimate user’s behavior and apparent intent.The systems best equipped for this future will be the ones that can spot non-human behaviour hiding inside human-shaped workflows, produce audit trails sturdy enough to survive scrutiny, and function in AI-mediated environments where the “user” is, in practice, software.And this cannot stop at onboarding. The same questions apply whenever an identity is used again, whether during a high-risk transaction, an account recovery, a device change or an action initiated through another system.Identity verification is moving from a single moment of proof to understanding who or what is behind each action across the identity lifecycle. That will shape how digital identity works in the AI era.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Are You Building Identity Verification For The Wrong User?
Identity verification is moving from a single moment of proof to understanding who or what is behind each action across the identity lifecycle. That will shape how digital identity works in the AI era.








