October 1, 2026
Zero Trust identity is built on one principle: never trust, always verify. But most enterprise identity stacks verify credentials, devices, and sessions, not the human using them. That leaves a gap attackers are now exploiting at scale: the right credential in the hands of the wrong human.
Why identity is the weak point in Zero Trust security
Across the major enterprise breaches of recent years, identity controls have been a critical point of failure. In 2023, Scattered Spider reportedly demonstrated that a single phone call to an IT help desk was sufficient to bring down MGM Resorts at a cost of $100 million. They proved the same point again in 2025, with social engineering attacks on M&S and Co-op causing disruption estimated at £270-440 million.
A similar attack was launched against Jaguar Land Rover, halting car production for five weeks, disrupting hundreds of suppliers, and causing an estimated £1.9 billion in damage to the UK economy.
The Arup deepfake attack showed that adversaries can place synthetic executives on video calls convincing enough to authorize $25.6 million in wire transfers.
And the North Korean remote worker infiltration, active since at least 2018, has placed thousands of IT workers inside Fortune 500 companies and is estimated to have generated nearly $800 million for the regime in 2024 alone.
How AI is changing identity-based attacks
AI has been a force-multiplier in the effectiveness and scale of identity-based attacks. What once required skilled operators, significant time, and manual effort can now be executed at scale, with greater precision and lower cost. Every stage of the identity attack chain has been affected: target research, credential harvesting, phishing, social engineering and impersonation, initial access, and evasion. Agentic AI promises to scale attacks further, enabling semi-autonomous workflows that continuously refine phishing campaigns, improve targeting, and adapt techniques.
Why the Zero Trust identity gap is structural
The reason today’s attacks are so effective is that this gap is structural. IAM modernized how we verify credentials, devices, and sessions, but it inherited an assumption: if the credential is valid, the human is valid. It ultimately relies on the integrity of the binding between a credential and its legitimate human owner, rather than the human itself.
A credential can seem correctly authenticated, but doesn’t prove that the person using, resetting, or recovering it is the human it was originally issued to. AI has turned this gap into a scaling and systemic threat.
62% of organizations experienced a deepfake attack (Gartner survey, September 2025), and voice phishing has overtaken email as the primary social engineering vector, rising to 11% of intrusions while email phishing fell to 6% (Mandiant’s M-Trends 2026 report).
Why phishing-resistant MFA doesn’t stop impersonation
Phishing-resistant Multi-factor Authentication (MFA), such as passkeys and FIDO2 security keys, strongly mitigates credential phishing and replaying credentials. But it can’t help when an attacker persuades the help desk to reset an authenticator, enrolls their own device during onboarding, or was hired under a false identity. In each case, MFA works exactly as designed. It just authenticates the wrong human.
Extending Zero Trust identity to AI agents
The same gap is compounding in a second direction. Organizations are deploying semi-autonomous agents with the ability to execute high-stakes, legally binding actions under delegated human authority. Yet governance approaches designed specifically for autonomous AI agents are still emerging. Initiatives such as iProov’s Human Approval and Presence Specification (HAPS), an experimental specification for verifying human approval of AI agent actions, are beginning to address one part of this challenge.
The issue is not simply whether an agent has permission to act, but whether a genuine human authorized the specific action it is about to take. Without a reliable way to establish that link, accountability becomes harder to maintain.
In a world where identity is not only synthetic but agentic, how do you verify the human behind the action?
How biometric verification closes the Zero Trust identity gap
Closing the gap requires moving beyond verifying what you know or have to verifying who you are. iProov establishes that binding at hiring and onboarding, verifying genuine human presence before the enterprise identity lifecycle begins. That creates a reusable credential that follows the individual throughout the identity lifecycle, invoked at every high-risk moment: remote onboarding, step-up authentication, account recovery, and agentic authorization.
The capability that makes this possible is Genuine Presence. By illuminating the device with a randomized light sequence and reading the reflection from the person’s face, iProov creates a verification event that requires a genuine human in a real physical environment to complete. It cannot be pre-recorded, replayed, or generated by AI. Gartner identifies genuine human presence detection as one of seven forces shaping identity.
Closing workforce identity security gaps across the lifecycle
In today’s AI-enabled environment, a mature enterprise identity framework is not sufficient if you can’t verify the genuine human. The gaps across remote hiring and onboarding, privileged access, and account recovery are common across most enterprise environments and are being attacked at scale. Each stage of the identity lifecycle carries its own risk:
- Hiring: remote hiring lets attackers interview and join under a false identity.
- Onboarding: credentials go to whoever completes the process, so every later check inherits any error made here.
- Privileged actions: wire transfers, admin changes, and data exports are where the wrong human does the most damage.
- Account recovery: resets exist for when normal credentials fail, which makes them the easiest place to take over an identity.
- Agentic authorization: when an agent acts on a person’s behalf, you need proof that a genuine human approved it.
iProov closes those gaps with a biometric identity assurance layer integrated into existing identity stacks, covering Identity and Access Management (IAM) platforms, managed and non-managed devices (Microsoft, iOS, and Android), and communication and video-conferencing tooling.
Visit our Workforce Solution Suite page or book your consultative iProov demo today!


