Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Passkeys for AI systems: what it means for IAM teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: Demand for phishing-resistant authentication remains solid as enterprises increasingly adopt YubiKey as a Service and extend hardware-backed passkeys into AI-facing workflows through its OpenAI partnership, according to Yubico. The bigger signal is that verified human intent is becoming a control point for high-consequence AI access, not just a login preference.

NHIMG editorial — based on content published by Yubico: a first-quarter update on passkeys, subscriptions, and AI security

By the numbers:

Questions worth separating out

Q: How should security teams handle AI-driven phishing in identity workflows?

A: Security teams should treat AI-driven phishing as an identity trust problem, not only an email filtering problem.

Q: Why do hardware-backed passkeys matter for identity governance?

A: They reduce the chance that a reusable secret becomes the weak point in a phishing or replay attack.

Q: What breaks when organisations treat multi-factor authentication as a complete identity solution?

A: Security teams can overestimate assurance and leave the real identity problem unresolved.

Practitioner guidance

  • Prioritise phishing-resistant authentication for high-risk roles Start with administrators, finance approvers, developers with production access, and anyone who can approve AI-assisted actions.
  • Tie AI approvals to explicit human intent Require a strong authentication event at the point of approval for high-consequence AI actions, such as publishing, provisioning, or privilege changes.
  • Review lifecycle controls for device-based authenticators Check enrolment, replacement, recovery, and revocation processes so service-based key distribution does not outpace deprovisioning.

What's in the full article

Yubico's full update covers the operational detail this post intentionally leaves for the source:

  • How YubiKey as a Service supports large-scale deployment, onboarding, and replacement workflows.
  • The OpenAI partnership context and how the Advanced Account Security program uses hardware-backed passkeys.
  • The company’s broader subscription model and how it is positioned for enterprise rollout.
  • Why the vendor sees verified human intent as important for high-consequence AI actions.

👉 Read Yubico’s update on passkeys, AI access controls, and enterprise rollout →

Passkeys for AI systems: what it means for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Verified human intent is becoming a control boundary, not a nice-to-have UX choice. As AI systems take on more operational influence, the real question is whether a human can be reliably bound to a high-consequence action at the moment it is authorised. That makes authentication quality part of decision integrity, not just account access. Practitioners should treat human approval in AI workflows as a security control with evidentiary value.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, which shows that process confidence and actual behaviour still diverge.

A question worth separating out:

Q: Who should be accountable for access decisions in agentic AI and machine-to-machine authentication programs?

A: Accountability should sit with the teams that own the identity policy, not with the agent itself. IAM, security architecture, and platform teams need clear responsibility for authorization design, secret handling, logging, and review. That is especially important when machine-to-machine trust is used to automate production actions or connect multiple systems.

👉 Read our full editorial: Hardware-backed passkeys and AI access controls are converging



   
ReplyQuote
Share: