By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: OneSpanPublished September 11, 2026

TL;DR: Banks are facing a wider identity threat surface as autonomous agents, phishing-resistant authentication gaps, and AI-amplified fraud erode trust in static login models, according to OneSpan. The governing assumption that identity can be verified once and then trusted no longer holds when attackers can fake, steal, or automate their way through every step of the session.


At a glance

What this is: This analysis argues that banks can no longer rely on one-time identity checks because agentic AI and AI-enabled fraud make static authentication, recovery, and transaction trust too easy to subvert.

Why it matters: It matters because IAM, fraud, and digital identity teams must treat authentication, session trust, and recovery as continuously verified controls across human and non-human actors.

By the numbers:

👉 Read OneSpan's analysis of why bank identity standards no longer hold up against agentic AI


Context

Bank identity security is no longer just about stopping password theft. In this article, the primary issue is that static authentication models assume identity can be checked once and then trusted for the rest of the interaction, even as AI-driven fraud, session hijacking, and autonomous agents increase the speed and credibility of attacks across banking channels.

That assumption is now too weak for modern financial services. Banks have to balance stronger identity assurance with low-friction customer experience, while also governing account recovery, authenticated sessions, and transaction approval in ways that survive phishing, impersonation, and machine-assisted social engineering.

This is a human IAM and fraud-resistance problem first, but it also has clear implications for non-human identity governance because banks are increasingly exposing agent-driven workflows, device-bound trust, and cryptographic credentials that need lifecycle control, not just login control.


Key questions

Q: What breaks when financial institutions rely on passwords and account resets without stronger authentication controls?

A: When passwords are the main control, attackers can exploit reuse, phishing, credential stuffing, and social engineering to gain access. Weak reset processes also become a pathway for takeover if identity proofing is poor. The result is higher fraud risk, more support burden, and weaker assurance that the person signing in is the real user.

Q: Why do AI-powered fraud and account takeover remain so effective in banking?

A: They remain effective because attackers combine social engineering, fake websites, session abuse, and increasingly convincing AI-generated messages to defeat human trust cues. When the bank’s controls focus only on entry, the attacker can move the fraud to recovery, approval, or payment steps that are often less protected.

Q: How do banks know if their fraud controls are actually working?

A: They should test whether suspicious transactions are declined or challenged in real time, whether payee verification stops redirection attempts, and whether risky sessions are suspended when the runtime environment changes. If fraudulent activity is still completed before detection, the control is reacting too late.

Q: Should banks prioritise passkeys over other identity changes first?

A: Passkeys are a strong priority where phishing and credential theft are dominant, but they should not be treated as a standalone fix. Banks should pair them with hardened recovery, transaction binding, and session governance, because attackers will shift to whichever control remains easiest to exploit.


Technical breakdown

Why one-time authentication no longer holds in banking

Static authentication verifies identity at a single point in time, but banking sessions now extend far beyond that moment. If the attacker can steal credentials, hijack a session, or persuade a customer to approve a payment, the original login check has little remaining value. AI reduces the cost of producing convincing phishing, fake portals, and impersonation at scale, which makes identity proofing weaker after the first interaction. In practice, the control boundary has shifted from login to continuous trust validation across the whole transaction flow.

Practical implication: Treat authentication as a starting signal, not a complete trust decision, and extend control design into the session and transaction layers.

How agentic AI changes the identity threat model

Agentic systems introduce a new actor type that can execute actions, interact with tools, and amplify fraud workflows without the slow cadence of human decision-making. That changes identity risk because the attacker can use autonomous or semi-autonomous behaviour to scale reconnaissance, impersonation, and transactional abuse far faster than human-operated fraud. The issue is not just more automation. It is that identity systems built for human users assume stable intent, observable behaviour, and reviewable states. Agentic execution can collapse all three.

Practical implication: Design controls for runtime behaviour, not just named accounts, when AI agents participate in customer-facing or back-office workflows.

Why passkeys help, but do not solve the whole problem

Passkeys reduce dependence on shared secrets by using public-key cryptography, which makes credential theft and phishing much harder. But phishing-resistant authentication does not, by itself, solve account recovery risk, session abuse, or fraudulent transaction authorisation. If a bank strengthens primary login while leaving recovery paths, step-up prompts, and payment approval flows weak, attackers will simply move to the softest control point. That is why identity assurance must span the full lifecycle of access, not just the first login event.

Practical implication: Combine phishing-resistant authentication with hardened recovery and transaction-binding controls, or the attack path will shift rather than disappear.


Threat narrative

Attacker objective: The attacker wants to convert trusted banking identity into immediate financial loss by taking over accounts or coercing fraudulent payments.

  1. Entry begins with phishing, fake banking sites, social engineering, malware, or session hijacking to obtain initial access to a legitimate customer account.
  2. Escalation occurs when attackers use AI-generated impersonation or agentic workflows to pressure the user, bypass trust cues, or trigger fraudulent approvals at speed.
  3. Impact is account takeover, authorised push payment fraud, or loss of funds, with customer trust and reimbursement costs compounding the operational damage.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Static login is no longer a sufficient trust boundary for banking identity. The article describes a world where passwords, phishing, session hijacking, and AI-generated impersonation all attack the same control assumption. Once identity is verified only at login, the rest of the transaction is effectively trusted on stale evidence. For banks, that means identity governance has to extend into sessions, recovery, and payment approval, not stop at authentication.

Agentic behaviour creates a new fraud acceleration layer, not just a new automation layer. When AI agents can be used to scale social engineering, impersonation, and transaction pressure, the attacker’s identity workflow becomes faster than the bank’s review workflow. That shifts the governance problem from user authentication to runtime assurance across human and machine-mediated actions. The implication is that banks must treat agent-influenced interactions as a distinct trust class, not a minor variation on customer login.

Phishing-resistant authentication reduces one attack path, but it does not close the identity lifecycle gap. Passkeys matter because shared secrets fail under phishing and credential theft, yet recovery channels, session controls, and transaction binding remain exploitable if they are governed separately. This is where IAM, fraud, and privileged access thinking need to converge. Banks that harden entry but leave downstream trust loose will still absorb fraud through the weakest lifecycle stage.

Transaction trust must become identity-bound, not channel-bound. The article’s central message is that attackers can fake channel signals, so the bank has to rely on evidence that is harder to steal or imitate. That pushes the discipline toward device binding, cryptographic assurance, and stronger decision points around high-risk payments. Practitioners should read this as a warning that authentication design is now inseparable from fraud prevention architecture.

From our research:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
  • That gap is why OWASP Agentic AI Top 10 and banking identity controls now need to be considered together, not in separate governance silos.

What this signals

Identity programmes in banking need to move from authentication-centric thinking to trust orchestration. Passkeys, device binding, and transaction binding are not isolated controls. They become part of a broader decision system that must survive phishing, fraud pressure, and AI-generated deception across the full customer journey. For practitioners, the programme signal is clear: if recovery and payment approval are weaker than login, the overall identity posture is still brittle.

With 80% of organisations reporting AI agents acting beyond intended scope, per AI Agents: The New Attack Surface report, the governance gap is now operational rather than theoretical. Banking teams should assume that agent-influenced workflows will increasingly intersect with customer identity, payment approval, and support operations. That means fraud, IAM, and digital channel owners need shared controls and shared evidence, not separate narratives.

Transaction binding is becoming the decisive control concept. If a payment can be authorised using signals that an attacker can steal, replay, or socially engineer, the control is too weak for the current threat model. Banks should prepare for a governance model where approval, device trust, and session context are treated as one decision surface rather than three disconnected checks.


For practitioners

  • Bind high-risk transactions to stronger identity signals Require transaction approval to depend on device-bound or cryptographic signals that cannot be replayed from a fake portal or stolen session.
  • Harden account recovery as a primary attack path Treat recovery resets, help-desk escalation, and fallback verification as first-class fraud controls rather than convenience features.
  • Extend controls beyond first login Review session lifetime, step-up prompts, and payment confirmation logic so that trust is continuously revalidated during the interaction.
  • Adopt phishing-resistant authentication for customer access Prioritise passkeys or equivalent phishing-resistant methods for customer-facing journeys where credential theft and impersonation remain common.

Key takeaways

  • Banks can no longer rely on a one-time login decision when AI-assisted impersonation, session abuse, and fraud pressure can continue after authentication succeeds.
  • The evidence shows the problem is already material, with major customer-experience sensitivity, large account takeover losses, and broad AI-powered fraud activity across organisations.
  • The practical answer is to bind recovery, sessions, and high-risk payments to stronger identity signals than attackers can fake or steal.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationThe article centers on phishing-resistant authentication and session trust in banking.
Recommendation — Adopt SP 800-63B aligned authentication methods that reduce phishing and credential replay risk.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsThe article argues for stronger control over access decisions across login and transaction flow.
Recommendation — Apply PR.AC-4 to extend authorisation checks beyond login into sessions and payment decisions.
OWASP Non-Human Identity Top 10NHI-03 — Insecure Authentication MethodsThe article highlights static login methods and shared secrets as weak identity controls.
Recommendation — Review authentication methods for shared-secret dependence and replace weak mechanisms with phishing-resistant options.
NIST SP 800-53 Rev 5IA-2 — Identification and AuthenticationBank authentication and step-up assurance map directly to identity and authentication controls.
Recommendation — Strengthen IA-2 enforcement for sensitive banking journeys and high-risk account actions.
ISO/IEC 27001:2022A.8.2 — Privileged Access RightsThe article’s governance message extends to high-trust access and recovery paths requiring stricter control.
Recommendation — Tighten privileged and recovery-path access so attackers cannot reuse weak fallback routes.

Key terms

  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.
  • Transaction binding: Transaction binding links a user's identity, the document they approved, and the workflow state into a single evidence record. This matters in digital lending because a signature alone is not enough to prove the right person approved the right version at the right stage.
  • Session Hijacking: Session hijacking is the takeover of an authenticated session after the original login has completed. The attacker does not need to know the password if they can use the active session token, which is why session monitoring and revocation are essential controls in SaaS identity governance.

What's in the full article

OneSpan's full article covers the operational detail this post intentionally leaves for the source:

  • The practical argument for passkeys in banking journeys, including where phishing-resistant authentication fits best
  • The customer-experience trade-offs banks face when strengthening authentication without adding friction
  • The reimbursement and regulatory pressure banks are under when fraud losses reach the account holder
  • The authors’ examples of how cryptography, biometrics, and device-bound authentication can be combined in practice

👉 OneSpan's full article expands on passkeys, device-bound authentication, and the fraud and UX trade-offs banks must manage.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org