TL;DR: A widening gap between security perception and actual authentication hygiene is evident in a 2025 global survey of 18,000 employed adults across nine countries, according to Yubico. The practical lesson is that phishing resistance now spans human identity, digital identity, and emerging NHI trust models, not just password replacement, including 70% who say AI has made phishing more successful and 29% who still lack MFA on personal email.
At a glance
What this is: This is Yubico’s 2026 outlook on authentication, digital identity, and AI-driven phishing, with the key finding that perception of security remains ahead of real-world authentication hygiene.
Why it matters: It matters because IAM, PAM, and identity architects now have to govern human access, verifiable credentials, and NHI-adjacent trust patterns in the same programme.
By the numbers:
- 29% still do not have MFA set up for their personal email accounts, showing that basic authentication hygiene remains uneven even as threat sophistication rises.
- The ratio of non-human to human identities now reaches 25x to 50x in modern enterprises, which changes the scale of identity governance work.
👉 Read Yubico's 2026 outlook on phishing resistance, digital identity, and AI
Context
Phishing resistance now sits at the intersection of human identity, digital identity, and machine-mediated trust. The article’s core concern is that attackers are using generative and agentic AI to scale deception faster than users and organisations are improving authentication hygiene, which makes the primary problem an IAM problem, not just an awareness problem.
The article also points to a broader shift in enterprise identity thinking: digital identity, verifiable credentials, and passkey-based authentication are moving from consumer convenience into operational security. For identity teams, that means the boundary between human access governance and broader identity assurance is narrowing, especially as AI-assisted workflows increase trust ambiguity across the stack.
As a baseline for that shift, the Ultimate Guide to NHIs shows that 92% of organisations expose NHIs to third parties, which is why identity assurance now has to account for delegated access paths as well as users.
Key questions
Q: How should security teams reduce phishing risk when AI makes scam messages more convincing?
A: Teams should stop relying on obvious spelling mistakes and train people to verify the sender, destination, and request through a separate channel. The better control is a combination of realistic simulations, password managers, and simple confirmation habits for urgent or payment-related messages. That reduces both click risk and downstream credential theft.
Q: When should organisations prioritise PKI over another MFA method?
A: Prioritise PKI when the business needs certificate-based trust for devices, secure email, document signing, or regulated communications. If the main requirement is user login convenience, another MFA method may be enough. If the requirement is cryptographic assurance across interactions, PKI becomes the stronger fit.
Q: What do IAM teams get wrong about AI-driven identity security?
A: They often treat AI-driven features as a tooling upgrade rather than a governance shift. The real issue is whether policy, lifecycle control, and telemetry can work together across human and non-human identities when access patterns are more dynamic than traditional review cycles.
Q: Who is accountable when AI-assisted access workflows make the wrong trust decision?
A: Accountability stays with the organisation that defines the workflow and the access policy, even if the workflow uses AI or automation. If an agent or assistant can initiate actions, the programme must define the authority boundary, the approval point, and the evidence trail before the action is allowed to complete.
Technical breakdown
Why AI-driven phishing changes authentication risk
AI lowers the cost of producing convincing lures, but the real security change is scale and adaptation. Traditional phishing controls assume humans can spot a small number of repetitive attacks, yet AI-generated content can be personalised, iterated, and distributed faster than user training can keep up. That makes the remaining control surface heavily dependent on phishing-resistant authentication, strong identity verification, and prompt detection of anomalous login behaviour. In practice, the problem is not just message quality. It is that the attacker can now sustain a high-volume, high-credibility credential capture loop across channels.
Practical implication: prioritise phishing-resistant MFA and stronger identity verification where users and external parties authenticate into high-value workflows.
Passkeys, verifiable credentials, and enterprise identity
Passkeys shift authentication away from reusable shared secrets and toward device-bound cryptographic proof, which reduces the value of stolen credentials. Verifiable credentials extend that idea by making identity assertions portable and more tamper-resistant, especially in high-assurance digital identity use cases. For enterprises, the architectural issue is trust chaining: a credential only helps if issuing, binding, and verification are all governed consistently. That is why passkeys alone are not the whole story. They need lifecycle controls, attestation decisions, and integration with broader IAM policy.
Practical implication: treat passkeys and verifiable credentials as governance assets that require lifecycle, attestation, and revocation design.
Why agentic AI raises the identity bar
Agentic AI introduces runtime behaviour that can look like delegated identity, even when the system is still constrained by policy. Once AI-assisted workflows can trigger onboarding, support, or access actions, trust decisions become harder to separate from automation logic. That creates a governance problem for identity teams because authentication no longer maps cleanly to a single human operator. The more an agent can act across systems, the more identity assurance has to prove who or what is authorised to initiate the action, not just who logged in.
Practical implication: define which AI-assisted workflows remain advisory and which require explicit identity controls before any action is executed.
Threat narrative
Attacker objective: The attacker wants to turn believable digital deception into authorised access that can be reused for fraud, impersonation, or downstream system compromise.
- Entry begins with AI-generated phishing or scam content that reaches users at scale through email, chat, or web channels and bypasses weak human detection.
- Credential capture or trust abuse follows when users authenticate with passwords, shared secrets, or low-assurance login flows that the attacker can replay or weaponise.
- Impact occurs when the attacker uses the stolen access to impersonate a legitimate user, commit fraud, or move into enterprise systems that trust the compromised identity.
Breaches seen in the wild
- CoPhish OAuth Token Theft via Copilot Studio — CoPhish campaign exploits Microsoft Copilot Studio agents to steal OAuth tokens via AI-assisted phishing.
- Moltbook AI agent keys breach — Moltbook breach exposed 1.5M AI agent keys.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Phishing resistance is no longer just a human IAM control, it is a trust architecture decision. AI has reduced the cost of deception, which means the security value shifts from spotting bad messages to proving legitimate identity at the point of access. That is why passkeys, verifiable credentials, and phishing-resistant MFA now matter as programme design choices, not only authentication features. The practical conclusion is that identity leaders must measure how much of their access model still depends on user judgment.
Digital identity is moving into the enterprise because delegated trust now reaches outside the perimeter of direct employment. Vendors, partners, contractors, and machine-mediated workflows all need assurance models that can survive scale. That is where identity governance, not just login security, becomes the control plane for modern access. Enterprises should expect digital identity to be evaluated alongside joiner-mover-leaver and third-party assurance processes, not separated from them.
Agentic AI changes the meaning of authentication because a logged-in actor may no longer be the full decision-maker. That does not make every AI-assisted workflow autonomous, but it does mean identity teams must ask who is initiating actions and under what authority. The current IAM model was built around human intent being stable across the session. Practitioners should treat AI-mediated action paths as a signal to re-evaluate authorization boundaries and accountability.
Identity assurance is now a cross-domain discipline, and the old split between consumer and enterprise identity is breaking down. The article points to a future where verifiable credentials, passkeys, and stronger authentication are used to establish trust in business interactions as much as in consumer logins. That matters because the same governance patterns now influence employee access, external collaboration, and machine-adjacent trust. Security teams should unify identity policy around assurance level, not identity type alone.
From our research:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- Another finding in that research shows that 97% of NHIs carry excessive privileges, which widens the attack surface when trust is delegated across vendors and external systems.
- That is why practitioners should also review the 52 NHI breaches Report alongside passkey and phishing-resistance planning, because identity exposure and breach patterns now overlap.
What this signals
Passkey adoption will increasingly be judged as part of identity governance, not as a point authentication project. As enterprises expand phishing-resistant MFA, they will also need to decide how attestation, recovery, and assurance levels map to workforce, partner, and machine-adjacent access. The control question is shifting from whether passkeys work to where they are authoritative enough to replace weaker trust signals.
With 80% of identity breaches involving compromised non-human identities in our research, the enterprise boundary between human login risk and machine trust risk is narrowing. That means teams should not treat authentication hardening in isolation from service account governance, especially where automation and delegated access can amplify the impact of a single compromised trust path.
Digital identity programmes will increasingly need a named assurance concept, such as phishing-resistant trust chain, to align policy across users, partners, and AI-mediated workflows. The practical move is to define where cryptographic proof is mandatory and where other signals remain acceptable, then align those thresholds with business criticality and revocation speed.
For practitioners
- Expand phishing-resistant MFA coverage Move high-risk users and workflows to device-bound authentication first, then extend coverage to external collaboration and privileged access paths. Prioritise the places where account takeover would create the largest blast radius.
- Create a cryptographic bill of materials for identity systems Inventory which identity platforms, authenticators, and trust services depend on algorithms that may require post-quantum updates. Use the inventory to identify where protocol changes, attestation changes, or vendor engagement will be needed.
- Define assurance levels for digital identity workflows Set explicit policy thresholds for when passkeys, verifiable credentials, or stronger verification are required. Apply those thresholds to employee access, vendor trust, and high-stakes business interactions rather than handling each as a separate exception.
- Review AI-assisted workflows for hidden authority transfer Map where chatbots or agentic systems can trigger onboarding, access, or support actions without a clear human approval step. Reassign approval boundaries so the identity programme knows whether the action is human-initiated or system-initiated.
Key takeaways
- AI-driven phishing is making weak authentication assumptions more expensive, which puts phishing-resistant MFA back at the centre of identity strategy.
- The security gap is not only technical, it is behavioural and governance-based, because many users still rely on low-assurance authentication in high-risk contexts.
- Enterprises should connect passkeys, digital identity, and NHI governance now, or they will keep solving related trust problems in separate silos.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B | The article centres on MFA strength, phishing resistance, and authentication assurance. |
| NIST CSF 2.0 | PR.AC-7 | The article focuses on identity proofing and access assurance against phishing. |
| NIST Zero Trust (SP 800-207) | 3.2 | Zero Trust access decisions depend on continuous verification rather than weak trust signals. |
| OWASP Non-Human Identity Top 10 | NHI-01 | The post touches on non-human identity trust paths and external exposure. |
| NIST AI RMF | GOVERN | Agentic AI and AI-assisted workflows require explicit accountability for action authority. |
Align authentication policy to PR.AC-7 and require stronger verification for high-risk access.
Key terms
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Verifiable Digital Credential: A verifiable digital credential is structured identity data that can be checked cryptographically by a relying party. Instead of relying on visual inspection, the verifier validates issuer signatures and presentation rules, which gives the control a clearer trust basis than an image-based document.
- Cryptographic Bill of Materials: A cryptographic bill of materials lists the cryptographic capabilities built into software components, such as supported algorithms and libraries. It is useful for component visibility, but it does not show live configuration, deployment context or actual runtime usage. That makes it a partial input, not the full governance record.
- Phishing-Resistant Trust Chain: A governance model in which identity assurance depends on cryptographic proof and controlled verification steps rather than user judgment alone. It is useful when access decisions must stay valid across employees, partners, and AI-mediated workflows without relying on weak trust signals.
What's in the full article
Yubico's full post covers the operational detail this post intentionally leaves for the source:
- Survey breakdown by country that shows how phishing perception and MFA adoption differ across regions.
- The post’s discussion of post-quantum cryptography planning, including the cryptographic bill of materials approach.
- More context on digital identity wallets and the enterprise use cases Yubico expects to expand in 2026.
- Additional commentary on agentic AI, social engineering, and how leaders should raise the security bar.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or lifecycle governance, it is worth exploring.
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org