By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Prove IdentityPublished July 14, 2026

TL;DR: Deepfakes and AI agents are undermining one-time identity checks, and Prove says organisations need continuous identity verification that evaluates trust signals throughout the customer journey. That shift matters because static login points no longer reflect real-time fraud risk or delegated identity behaviour.


At a glance

What this is: This is a Prove Identity podcast summary arguing that one-time login checks are no longer sufficient because deepfakes and AI agents can change trust conditions during the customer journey.

Why it matters: It matters because IAM, fraud, and identity teams need controls that can sustain assurance after initial authentication, especially where customer identity, delegation, and automation intersect.

By the numbers:

👉 Read Prove Identity's post on deepfakes, AI agents, and continuous identity verification


Context

Deepfakes, synthetic media, and AI-assisted fraud are weakening the assumption that a single login event can establish trust for the rest of a session. In identity security, that assumption only works when the subject stays stable, the signal stays reliable, and the risk does not change after authentication. This article focuses on customer identity and continuous verification, not workforce IAM.

The governance gap is straightforward: many identity programmes still treat authentication as a point-in-time checkpoint rather than an ongoing trust decision. Once AI agents, bots, and impersonation techniques can alter the risk profile mid-journey, organisations need identity controls that re-evaluate assurance as behaviour, device, and context change.


Key questions

Q: How do security teams know if continuous identity verification is working?

A: Look for a reduction in fraud that progresses beyond first-touch checks, plus faster escalation of risk scores when behaviour changes. Good signals include fewer successful account takeovers after onboarding, better detection of unusual session transitions, and more accurate risk decisions during recovery flows.

Q: Why do deepfakes make traditional authentication weaker?

A: Deepfakes weaken traditional authentication because they imitate the human signals that many approval processes still trust, including voice and video. When those cues can be fabricated, organisations need independent verification paths such as out-of-band confirmation, device checks, and transaction-specific controls for high-risk actions.

Q: What breaks when identity teams rely on static login thresholds?

A: Static thresholds are easy for attackers to work around and often too rigid for legitimate users. Five failed logins, a new country, or an off-hours access event may mean very different things depending on role, travel, or device. When thresholds are fixed, teams either miss real compromise or drown in false positives.

Q: Who should be accountable when customer identity assurance fails after login?

A: Accountability should sit with the identity and fraud owners jointly, because the failure spans authentication, session policy, and transaction risk. If one team owns login and another owns fraud, but neither owns the trust state after sign-in, attackers exploit the handoff.


Technical breakdown

Why one-time identity checks fail against deepfake-driven fraud

Traditional identity verification is usually front-loaded. A user proves who they are, the system issues trust, and downstream steps assume that trust remains valid. Deepfakes break that model because the initial proof can look legitimate while the later behaviour is synthetic, delegated, or manipulated. The security problem is not only impersonation. It is that the authentication moment and the risk moment are no longer the same thing. Continuous identity verification extends the trust decision beyond the first login by re-evaluating signals across the session or journey.

Practical implication: move from a single authentication checkpoint to risk re-evaluation at key journey milestones.

Continuous identity verification as a trust-signal loop

Continuous identity verification uses multiple signals, such as device posture, behavioural consistency, transaction context, and session anomalies, to decide whether trust should hold. That makes it different from simple step-up authentication, which usually responds to a single trigger. The point is not just to ask for more proof. The point is to reduce blind trust after the first successful login. In customer-facing flows, this becomes especially important where AI-assisted fraud can shift from account opening to takeover to monetisation without a clean boundary between stages.

Practical implication: define which trust signals can extend, reduce, or revoke access during the customer journey.

Where AI agents change the identity risk model

AI agents complicate identity because they can act with delegated authority, not just human intent. In practice, that means the system may need to verify whether the actor behind a transaction is a person, a bot, or an automated workflow acting on behalf of a person. That distinction matters for fraud, consent, and accountability. Once an organisation accepts that some actions are initiated or completed by software acting at runtime, identity assurance has to address provenance and continuity, not just initial authentication. This is where human identity controls start to overlap with non-human identity governance.

Practical implication: classify automated customer actions separately from human actions and verify them with different assurance rules.


Threat narrative

Attacker objective: The attacker wants to preserve a trusted identity state long enough to complete fraud, takeover, or monetisation without triggering re-verification.

  1. Entry occurs when an attacker uses deepfake media or synthetic identity signals to pass an initial trust check in a customer journey. Escalation follows when the actor continues the session through reused credentials, delegated workflows, or weakened step-up controls. Impact arrives when the attacker completes fraud, account takeover, or illicit transaction activity under a trusted identity state.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

One-time identity proof is now a broken assumption, not a control gap. The article’s core point is that a successful login no longer means a stable trust state. Deepfakes, bot-driven behaviour, and AI-assisted delegation can all change the risk profile after authentication. For identity programmes, that means the real failure is not the absence of a stronger login screen. The failure is the assumption that trust can be established once and then left untouched.

Continuous identity verification is becoming the practical control layer for customer identity risk. The industry has spent years optimising initial authentication, but fraud increasingly happens after the first accepted signal. That creates a runtime governance problem: security teams need to decide when trust should decay, when additional proof is required, and when a session should be challenged or stopped. The implication is that customer IAM now needs policy and telemetry beyond sign-in.

Journey trust drift: identity assurance degrades when a customer session moves from onboarding to transaction to recovery without re-evaluation. That drift is what synthetic identity and AI-assisted fraud exploit. The practitioner takeaway is that journey-stage verification must be designed as a policy problem, not a point solution problem.

AI agents raise the same governance question from the opposite direction. When software can act with delegated authority, identity teams cannot rely on user-centric assumptions about intent, continuity, or accountability. The article is about fraud, but the underlying governance issue is broader: identity assurance must now distinguish a person proving intent from a system executing it. That pushes IAM and fraud teams toward shared runtime controls.

From our research:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, 38% have no or low visibility, and a further 47% have only partial visibility, according to The State of Non-Human Identity Security.
  • That visibility gap matters because 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months.
  • The next step is to apply the same governance logic to customer journeys and delegated software actions, using the Ultimate Guide to NHIs as the operational baseline.

What this signals

Journey-stage identity assurance is becoming the default design problem for customer-facing security teams. One-time authentication still matters, but it is no longer sufficient where trust can change after the first proof. Programmes that only measure login success will miss the larger issue, which is whether identity evidence remains credible at the point of transaction, recovery, or payout. That shift requires tighter alignment between fraud policy, risk scoring, and identity controls.

Continuous identity verification will increasingly sit alongside NHI governance, not apart from it. As more customer actions are initiated, assisted, or completed by automation, teams need a common way to distinguish human intent from software execution. That is the same governance pressure seen in machine identity and agentic systems, where non-human identity controls become the baseline for delegated access management.

Identity assurance should now be measured as a runtime control, not a sign-in metric. In practice, that means asking whether your current model can still challenge, step up, or revoke trust after the session begins. If it cannot, the organisation is optimising entry while leaving the rest of the journey exposed.


For practitioners

  • Map trust-relevant journey stages Identify the points where identity risk changes materially, such as onboarding, password reset, payment, account recovery, and high-value actions. Add re-verification at those stages instead of relying on login alone.
  • Use multiple trust signals per session Combine device, behavioural, network, and transaction context to decide whether the session should continue, step up, or be stopped. A single successful login should not carry all downstream authority.
  • Separate human and delegated actions Treat automated or delegated actions as a distinct assurance class so that customer-facing workflows do not inherit human trust by default. This is especially important where AI-driven workflow completion is possible.
  • Align fraud and IAM policy decisions Make sure fraud teams and identity teams share the same risk thresholds for revocation, challenge, and review. If each function is using a different trust model, attackers will find the gap between them.

Key takeaways

  • Deepfakes and AI-assisted fraud are eroding the assumption that a single login can establish trust for an entire customer journey.
  • The control gap is not just authentication strength, but whether identity confidence can be reassessed after the session begins.
  • Security teams should align fraud policy, IAM controls, and delegated identity handling around continuous trust evaluation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Identity proofing and access decisions are central to customer trust continuity.
NIST SP 800-63SP 800-63BAuthenticator and session assurance are directly relevant to one-time versus continuous identity proof.
NIST Zero Trust (SP 800-207)Zero trust aligns with continuous verification across changing session risk.
GDPRArt.32Customer identity assurance often involves personal data and security of processing.

Review whether continuous verification controls support appropriate security of processing under Art.32.


Key terms

  • Continuous identity validation: A governance model that checks identity trust throughout execution rather than only at login or periodic review. For AI and machine identities, this means verifying access, scope, and behaviour in real time so actions can be constrained while they are happening.
  • Journey-Stage Risk: The idea that identity risk changes as a customer moves through onboarding, login, recovery, payment, or support flows. It matters because the level of assurance needed at the start of a journey is often not enough to protect later actions with higher fraud impact.
  • Delegated Identity: Delegated identity is when one actor acts on behalf of another with explicit permission and bounded authority. In AI-assisted commerce, it requires clear consent, limited scope, and traceable records so the retailer can distinguish authorised delegation from unauthorised automation.

What's in the full article

Prove Identity's full blog post covers the operational detail this post intentionally leaves for the source:

  • How continuous identity verification is applied across customer journeys and risk checkpoints
  • The interview context from the Business of Cybersecurity podcast and Mary Ann Miller's perspective
  • Operational examples of trust-signal evaluation across onboarding, login, and recovery
  • The vendor's framing of how identity, fraud, and cybersecurity converge in customer-facing flows

👉 The full Prove Identity post expands on the podcast discussion and the shift from one-time checks to continuous trust evaluation.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org