By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: CallsignPublished July 30, 2026

TL;DR: As passkeys, verified credentials, and AI agent authentication evolve, behavioral intelligence, continuous authentication, and fraud prevention are entering the standards conversation through Callsign’s move into the FIDO Alliance, according to Callsign. The governance question is no longer whether login is enough, but how identity assurance holds up across the full session and beyond.


At a glance

What this is: This is Callsign’s announcement that it has joined the FIDO Alliance, positioning continuous behavioral authentication and fraud intelligence as a standards issue.

Why it matters: It matters because IAM and fraud teams must decide how passkey adoption, session monitoring, and trust signals work together without weakening user experience or over-trusting login alone.

👉 Read Callsign's statement on joining the FIDO Alliance and continuous authentication


Context

Authentication security increasingly fails when organisations treat login as the end of the control plane rather than the start of it. Passkeys and verified credentials improve resistance to phishing, but they do not by themselves answer whether the same user is still present throughout a session, especially when fraud tactics adapt quickly and AI lowers attacker effort. In identity verification and IAM terms, the challenge is not just initial proofing, but continuous assurance.

The article is about standards participation, but the real issue is governance: how behavioural signals, device telemetry, and credentials should be combined without creating opaque, over-privileged trust decisions. That is relevant to IAM, fraud prevention, and emerging AI agent authentication discussions because the same control questions recur whenever identity assurance must persist beyond a single authentication event.


Key questions

Q: How should security teams use behavioural signals without over-trusting them?

A: Use behavioural signals as risk indicators, not as proof of identity on their own. They are best for spotting anomalies, session drift, and fraud patterns after initial authentication. Teams should pair them with clear escalation rules, explicit reauthentication for sensitive actions, and auditability so the control remains explainable and proportionate.

Q: Why do passkeys not eliminate the need for continuous authentication?

A: Passkeys reduce phishing and credential replay, but they only prove the user at the point of login. They do not prove the same user is still present after session hijack, device compromise, or account takeover. Continuous authentication addresses that gap by reassessing trust during the session, not just at entry.

Q: What breaks when organisations treat login as the whole authentication control?

A: They miss post-login fraud, session theft, and impersonation that happens after initial access is granted. A login-only model also overstates assurance in environments where attackers reuse sessions, share credentials, or move through delegated access paths. The control fails because trust is assumed to persist without being revalidated.

Q: Who is accountable when behavioural authentication data influences access decisions?

A: The IAM, fraud, and security governance owners are accountable for defining the policy, not just the vendor supplying the signal. They must specify what data is collected, how it is interpreted, when it triggers step-up, and how users can challenge false positives. Standards and internal controls should make that responsibility explicit.


Technical breakdown

Why session-based authentication is more fragile than login-based trust

Traditional authentication answers a narrow question: did the claimant satisfy the entry check at a point in time? Continuous authentication tries to answer a broader one: does the session still look like the same legitimate user as context changes? That shift matters because phishing-resistant login methods reduce credential theft, but they do not stop account takeover after a device is compromised or a session is hijacked. Behavioral intelligence extends trust using signals such as movement patterns, device state, and location consistency, but those signals are probabilistic and need governance. Practical implication: define where passive signals can inform risk scoring, and where they must never override explicit reauthentication or step-up controls.

Practical implication: Define where passive signals can inform risk scoring, and where they must never override explicit reauthentication or step-up controls.

How passkeys and behavioral intelligence fit together in FIDO-based IAM

FIDO standards strengthen authentication by binding the user to a phishing-resistant authenticator such as a passkey or hardware key. That solves a major credential replay problem, but it does not fully address fraud patterns that emerge after successful login, including bot-assisted abuse, session sharing, and synthetic identity use. Behavioral intelligence can complement FIDO by adding confidence about user continuity, while FIDO provides the cryptographic proof at entry. The architectural challenge is to avoid turning behavioral telemetry into a silent, unchallengeable gate that the organisation cannot explain or tune. Practical implication: treat passkeys as the primary authenticating factor and behavioural signals as bounded risk inputs, not as a substitute credential layer.

Practical implication: Treat passkeys as the primary authenticating factor and behavioural signals as bounded risk inputs, not as a substitute credential layer.

Why AI agent authentication will pressure existing identity models

The article’s forward-looking point about AI agent authentication is well placed. Agents are not just tools with API keys, because they can make runtime decisions and chain actions in ways that resemble non-human identity behaviour. That means identity systems will need to distinguish between a human authenticating, a workload presenting a credential, and an agent acting under delegated authority. Standards bodies will have to clarify how trust, provenance, and session continuity apply when the actor is neither a person nor a static machine account. Practical implication: start separating human, workload, and agent assurance policies now, so AI-enabled automation does not inherit human-session assumptions by default.

Practical implication: Start separating human, workload, and agent assurance policies now, so AI-enabled automation does not inherit human-session assumptions by default.


NHI Mgmt Group analysis

Continuous authentication is becoming a standards problem, not just a fraud-control problem. The article shows that login-only assurance is too thin for modern digital services, especially where fraud tactics are adaptive and session abuse happens after the authenticator has already been accepted. FIDO solves an important part of the problem, but standards now need to account for the assurance that continues after entry. Practitioners should expect more pressure to justify how post-login trust is established and audited.

Behavioral intelligence creates a verification trust gap unless its scope is clearly bounded. Passive signals can improve fraud detection, but they also introduce opacity, bias risk, and inconsistent decisioning if they are treated as invisible truth rather than one input among many. The named concept here is the verification trust gap: the space between cryptographic proof at login and operational confidence during the session. Organisations should map where that gap is tolerable and where explicit reauthentication remains mandatory.

AI agent authentication will force IAM teams to separate human identity assumptions from non-human identity reality. The article’s reference to AI agent authentication is an early signal that identity standards will need to handle actors that act independently but are not human users. That creates governance questions around delegation, provenance, and accountability. The practical conclusion is that current IAM patterns cannot simply be extended unchanged to AI agents or autonomous workflows.

Standards participation is a governance signal because it shapes future control boundaries. When a vendor participates in working groups, the issue for practitioners is not the vendor’s brand but the control logic that will influence future interoperability expectations. That matters most where fraud prevention intersects with identity verification, because standards can either preserve open architecture or embed assumptions that are hard to unwind later. Practitioners should track draft standards for where continuous trust is being normalised.

The market is moving toward layered assurance, but layered does not mean unlimited collection. The article reflects a broader identity trend: organisations want stronger assurance without making users reauthenticate constantly. That often pushes teams toward more telemetry, more risk scoring, and more session visibility. The discipline challenge is to keep those controls proportionate, explainable, and tied to specific threat models rather than using data volume as a proxy for security. Practitioners should tighten control objectives before expanding signal collection.

What this signals

Verification trust gap: identity programmes will increasingly need a formal boundary between entry assurance and session assurance, because attack pressure is shifting beyond the login event. That means continuous signals should be treated as governed risk inputs, not a blanket replacement for authentication. Where workloads and AI agents enter the picture, the same discipline must extend to non-human identity and delegated access patterns.

The security implication for practitioners is that authentication roadmaps now touch fraud controls, IAM architecture, and AI governance at the same time. Teams should expect pressure to use more behavioural telemetry, but they should also expect regulators and auditors to ask whether those signals are proportionate, explainable, and tied to explicit control decisions rather than left as opaque vendor scoring.


For practitioners

  • Define where continuous authentication is mandatory Map journeys where login-only assurance is insufficient, such as high-risk payments, step-up transactions, and account recovery, then require explicit reauthentication before privilege-bearing actions.
  • Separate cryptographic proof from behavioural risk signals Use passkeys or other phishing-resistant authenticators for entry, then constrain behavioural telemetry to bounded risk scoring, not silent access grants.
  • Create a policy for session continuity checks Document which contexts can use passive signals like device posture, location drift, and behavioural anomalies, and which contexts must trigger interruption or step-up authentication.
  • Plan now for AI agent identity governance Split human, workload, and agent assurance policies so delegated automation does not inherit user-session assumptions or unaudited trust from human authentication flows.

Key takeaways

  • Continuous authentication is moving from a fraud feature to an identity governance requirement because login alone no longer captures session trust.
  • Behavioural intelligence can strengthen assurance, but only when it is bounded by policy, auditability, and explicit reauthentication rules.
  • AI agent authentication will push IAM teams to separate human, workload, and non-human identity assumptions before automation scales further.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BPasskeys and phishing-resistant authentication are central to the article.
NIST CSF 2.0PR.AA-01Identity proofing and authentication are directly implicated by continuous assurance.
NIST SP 800-53 Rev 5IA-2Authentication assurance and verification are core to the topic.
GDPRArt.5Behavioural and telecoms signals can implicate personal data governance.

Limit collection and use of behavioural signals to what is necessary, documented, and proportionate under Art.5.


Key terms

  • Continuous authentication: A model where access is re-evaluated after the initial login instead of being trusted for the full session. It uses live signals such as posture, telemetry, and policy to detect when a session should be stepped up, constrained, or revoked.
  • Behavioral Intelligence: Behavioral intelligence is the use of session patterns to judge whether an action looks normal for a specific user. In banking, it compares cadence, navigation, pauses, and correction patterns against prior sessions to detect coercion, guidance, or automation that authentication alone cannot reveal.
  • Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.
  • AI Agent Authentication: The method an autonomous software agent uses to prove identity and obtain access to systems, APIs, and data. In enterprise settings, this is an NHI control point because the authentication choice determines scope, revocation speed, and whether access can be governed as part of the identity lifecycle.

What's in the full analysis

Callsign's full article covers the operational detail this post intentionally leaves for the source:

  • How the Intelligence Engine uses passive signals from device, location, behaviour, and telecoms data to build a user profile
  • What participation in FIDO working groups means for draft-specification influence and standards alignment
  • Why the article frames verifiable credentials and AI agent authentication as the next pressure point for identity standards
  • How the vendor positions continuous authentication as a complement to passwordless and phishing-resistant authentication

👉 The full Callsign article covers the standards context, behavioral intelligence framing, and future authentication priorities in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management. It helps identity and security practitioners build the control literacy needed for human, machine, and agentic access models.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 30, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org