TL;DR: AI-powered phishing, deepfakes, and synthetic voice attacks are making passwords and SMS codes unreliable for proving who is really behind an authentication attempt, according to KOBIL. The practical issue is not just stronger login security, but identity verification that can withstand manipulated human, agent, and machine interactions.
At a glance
What this is: This is an analysis of how AI-generated deception is undermining human identity verification and why layered authentication now has to account for humans, AI agents, and automated processes.
Why it matters: It matters because IAM teams now have to treat identity proofing, phishing resistance, and access governance as a cross-actor problem, not just a human login problem.
👉 Read KOBIL's analysis of AI-driven identity theft and verification controls
Context
AI-driven identity theft is a human identity problem first, but it increasingly reaches into machine and delegated access paths as well. Passwords and SMS codes can authenticate a login event, yet they do not reliably prove that the person, agent, or automated process on the other end is legitimate when deepfakes, synthetic voices, and phishing bots are part of the attack chain.
For identity teams, the governance gap is clear: existing authentication controls were designed for human-paced interaction and are being tested by AI-generated deception at runtime. That means the question is no longer whether access was entered correctly, but whether the actor behind the request can be trusted before permissions, data, or business processes are exposed.
Key questions
Q: How should security teams reduce fraud when attackers use deepfakes and synthetic identities?
A: They should combine document validation, liveness detection, behavioural analytics, and risk-based step-up checks rather than relying on a single identity proofing event. Deepfakes and synthetic identities are strongest when a programme trusts one signal too much. The goal is to make spoofed evidence fail across multiple independent checks before approval.
Q: Why do passwords and SMS codes no longer provide enough identity assurance?
A: Because they confirm a secret, not a real actor. AI-generated phishing and voice or video spoofing can capture or mimic those factors while still leaving the organisation exposed. Modern assurance has to prove presence, device integrity, and behavioural consistency, not just successful credential entry.
Q: How does identity governance change when AI identities enter the mix?
A: AI identities force governance teams to manage more subjects, more access paths, and more change than human-only programmes were designed for. That means data models, approvals, and automation have to scale beyond workforce assumptions. Organisations should plan for identity diversity now, because AI growth will expose governance designs that were built for a smaller world.
Q: What should organisations review when they add biometrics to authentication?
A: They should review enrolment, fallback, recovery, and exception handling as carefully as the biometric itself. Biometrics improve resistance to impersonation, but weak recovery can undo the benefit. The safest design couples biometrics with liveness checks, auditing, and tightly governed recovery paths.
Technical breakdown
Why passwords and SMS codes fail against AI-generated deception
Passwords and one-time codes verify possession of a credential, not the authenticity of the claimant. AI-generated phishing, deepfake video, and synthetic voice attacks exploit that weakness by creating a convincing but false authentication context. In practice, the attack succeeds when the verifier accepts the interaction as genuine before it has enough evidence of liveness, device trust, or behavioural consistency. That is why traditional login factors are increasingly insufficient on their own, especially in high-risk workflows such as finance approvals, executive access, and partner support channels.
Practical implication: Move high-value authentication flows away from credential-only assurance and toward layered verification that includes liveness and contextual signals.
How liveness checks and biometrics change the trust model
Liveness checks are designed to prove that a real person is physically present, not a replayed image, generated voice, or synthetic recording. Biometrics add a stronger binding to the individual, but only when they are paired with anti-spoofing controls and a secure enrolment and recovery process. That combination shifts the trust model from “does the secret match” to “is the actor real, present, and consistent with the expected identity state.” For identity programmes, that is a meaningful change because the control is aimed at deception, not just credential theft.
Practical implication: Use biometrics and liveness where impersonation risk is material, and surround them with strong recovery and exception handling.
Centralized identity management for humans, AI agents, and automated processes
The article’s broader point is that identity verification cannot stay limited to human users. AI agents and automated processes also need clear identity boundaries, because delegated access can be abused if permissions are unclear or overbroad. Centralized identity management helps by keeping roles, permissions, logging, and monitoring in one governance model, even when the actor type changes. That matters because attacks are increasingly moving across channels, from fake humans in calls and meetings to manipulated access attempts against systems and workflows.
Practical implication: Align human IAM, NHI governance, and delegated access monitoring under one control model instead of treating them as separate risk domains.
Threat narrative
Attacker objective: The objective is to impersonate a trusted human or delegated actor well enough to obtain access to sensitive data, business systems, or privileged workflows.
- Entry begins with AI-generated deception through deepfake video, synthetic voice, or automated phishing that convinces a target to engage.
- Escalation follows when the attacker captures credentials, access permissions, or workflow trust through the fraudulent interaction.
- Impact is achieved when sensitive systems, documents, or internal processes are accessed using the compromised trust relationship.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Passwords and SMS codes are now verification signals, not trust signals. AI-generated deception has reduced the evidentiary value of traditional authentication because a valid response no longer proves a legitimate actor. Deepfakes, synthetic voices, and automated phishing can all satisfy a login workflow without proving the claimant's real-world presence. For identity programmes, the consequence is plain: factor success is no longer enough to establish actor legitimacy.
Human identity assurance now has to be designed against machine-assisted impersonation. The article is really about the collision between human IAM and synthetic adversaries, where the human behind the screen may not be human at all. That changes the governance burden on MFA, recovery, and step-up policies because the attack is aimed at the trust assumptions around identity proofing, not just at the password store. Practitioners should treat impersonation resistance as a first-class control objective.
Unified identity governance is becoming unavoidable across humans, AI agents, and automated processes. The source correctly points out that identity verification cannot stop at people. The same governance model needs to cover delegated access, service workflows, and emerging AI-driven actors because attackers move across those boundaries when one path becomes harder to abuse. The implication for IAM and IGA teams is that identity state, not just account type, has to become the shared control plane.
Biometrics and liveness checks address the right problem only when they are part of a larger assurance chain. These controls help with spoofing resistance, but they do not replace authorization design, logging, or privilege minimisation. That makes this a governance issue as much as an authentication issue: the control stack has to assume that some interactions will be convincing but false. Teams should therefore avoid treating stronger authentication as a standalone answer to AI-enabled identity theft.
From our research:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, which leaves identity state exposed long after access should have ended.
- The 52 NHI Breaches Analysis helps teams connect exposed credentials to breach patterns before they become the next impersonation or delegation failure.
What this signals
Identity programmes built only around human login assurance will miss the fastest-moving abuse paths. AI-assisted impersonation compresses the time between trust establishment and misuse, so the control objective has to shift from successful authentication to resilient verification across the whole access journey. Teams should expect more pressure to combine liveness, device trust, and behavioural analysis in a single decision flow.
Human IAM and NHI governance are converging at the point of attack. The more organisations rely on delegated workflows, the more an attacker can pivot from impersonating a person to abusing a credential, token, or automated process. That is why IAM, IGA, and NHI teams need shared visibility into identity state rather than separate control silos.
The next maturity jump is not another factor at login, but assurance choreography: the ordered use of identity proofing, step-up, audit, and recovery controls based on risk. When that choreography is missing, synthetic attacks can still look legitimate long enough to matter.
For practitioners
- Strengthen high-risk human authentication flows Add liveness checks and phishing-resistant factors to executive access, finance approvals, and partner support paths where impersonation would have high impact.
- Reclassify trust decisions by actor type Separate human login assurance, NHI credential governance, and delegated process access so that one control model does not mask the risks of another.
- Instrument identity monitoring for synthetic deception Correlate login telemetry, device context, and behaviour anomalies so that deepfake-driven or bot-assisted attempts trigger step-up review before access is granted.
- Review recovery and exception paths Test password reset, account recovery, and manual override processes for abuse paths because attackers often bypass the strongest factor by targeting the weakest recovery route.
- Use the NHI breach corpus as a control benchmark Compare delegated access and exposed credential patterns against the 52 NHI Breaches Analysis to identify where human and non-human trust assumptions overlap.
Key takeaways
- AI-generated deception weakens the evidentiary value of passwords and SMS codes because they verify a secret, not a real actor.
- The practical response is layered identity assurance that combines liveness, biometrics, contextual checks, and governed recovery paths.
- IAM teams now have to align human authentication, NHI governance, and delegated workflow controls because attackers move between them.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B | The article centres on authenticating human users against spoofing and phishing. |
| NIST CSF 2.0 | PR.AC-7 | Continuous identity verification aligns with authentication and access control outcomes. |
| NIST Zero Trust (SP 800-207) | 4.0 | The article's context-based checks fit continuous verification in Zero Trust. |
| OWASP Non-Human Identity Top 10 | NHI-01 | The article extends into machine and delegated identity governance as well as human access. |
Review non-human and delegated identities with the same lifecycle discipline applied to human authentication flows.
Key terms
- Liveness Detection: Liveness detection is the mechanism that checks whether a biometric sample comes from a real, present person rather than a spoof such as a photo, screen, or mask. In identity programmes, it is a core defence against presentation attacks and should be tested under realistic operating conditions.
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Context-based Authentication: An access control approach that evaluates the situation around a login before granting access. It uses signals such as device posture, location, behavior, and time to decide whether a session should be allowed, challenged, or denied. The goal is to make trust conditional rather than permanent.
- Identity Assurance: The confidence an organisation has that a person or system is truly who it claims to be before access or action is granted. In modern IAM, assurance depends on evidence quality, channel trust, and the strength of verification around high-risk decisions.
What's in the full article
KOBIL's full article covers the operational identity controls this post intentionally leaves at a higher level:
- Step-by-step guidance on combining biometrics, hardware tokens, and liveness checks in real authentication flows
- Examples of how context-based authentication can trigger step-up decisions without breaking user experience
- Integration considerations for audit logging, access monitoring, and compliance reporting across enterprise systems
- Practical deployment patterns for protecting employees, partners, and customers against AI-generated impersonation
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org