TL;DR: Banks are facing a wider identity threat surface as autonomous agents, phishing-resistant authentication gaps, and AI-amplified fraud erode trust in static login models, according to OneSpan. The governing assumption that identity can be verified once and then trusted no longer holds when attackers can fake, steal, or automate their way through every step of the session.
NHIMG editorial — based on content published by OneSpan: Why yesterday’s identity security standards no longer work for banks
By the numbers:
- 91% of global customers rate a bank’s customer experience as important as its products, and 28% say it is more important.
- 47% said they’d leave a bank over poor user experience.
- 81% of businesses have experienced attempted or successful AI-powered fraud.
Questions worth separating out
A: When passwords are the main control, attackers can exploit reuse, phishing, credential stuffing, and social engineering to gain access.
Q: Why do AI-powered fraud and account takeover remain so effective in banking?
A: They remain effective because attackers combine social engineering, fake websites, session abuse, and increasingly convincing AI-generated messages to defeat human trust cues.
Q: How do banks know if their fraud controls are actually working?
A: They should test whether suspicious transactions are declined or challenged in real time, whether payee verification stops redirection attempts, and whether risky sessions are suspended when the runtime environment changes.
Practitioner guidance
- Bind high-risk transactions to stronger identity signals Require transaction approval to depend on device-bound or cryptographic signals that cannot be replayed from a fake portal or stolen session.
- Harden account recovery as a primary attack path Treat recovery resets, help-desk escalation, and fallback verification as first-class fraud controls rather than convenience features.
- Extend controls beyond first login Review session lifetime, step-up prompts, and payment confirmation logic so that trust is continuously revalidated during the interaction.
What's in the full article
OneSpan's full article covers the operational detail this post intentionally leaves for the source:
- The practical argument for passkeys in banking journeys, including where phishing-resistant authentication fits best
- The customer-experience trade-offs banks face when strengthening authentication without adding friction
- The reimbursement and regulatory pressure banks are under when fraud losses reach the account holder
- The authors’ examples of how cryptography, biometrics, and device-bound authentication can be combined in practice
👉 Read OneSpan's analysis of why bank identity standards no longer hold up against agentic AI →
Agentic AI and bank identity controls: what is breaking now?
Explore further
Static login is no longer a sufficient trust boundary for banking identity. The article describes a world where passwords, phishing, session hijacking, and AI-generated impersonation all attack the same control assumption. Once identity is verified only at login, the rest of the transaction is effectively trusted on stale evidence. For banks, that means identity governance has to extend into sessions, recovery, and payment approval, not stop at authentication.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: Should banks prioritise passkeys over other identity changes first?
A: Passkeys are a strong priority where phishing and credential theft are dominant, but they should not be treated as a standalone fix. Banks should pair them with hardened recovery, transaction binding, and session governance, because attackers will shift to whichever control remains easiest to exploit.
👉 Read our full editorial: Identity security standards for banks are failing under agentic AI