TL;DR: Deepfakes and AI agents are undermining one-time identity checks, and Prove says organisations need continuous identity verification that evaluates trust signals throughout the customer journey. That shift matters because static login points no longer reflect real-time fraud risk or delegated identity behaviour.
NHIMG editorial — based on content published by Prove Identity: Deepfakes, AI Agents, and the Collapse of Traditional Identity Security
Questions worth separating out
Q: How do security teams know if continuous identity verification is working?
A: Look for a reduction in fraud that progresses beyond first-touch checks, plus faster escalation of risk scores when behaviour changes.
Q: Why do deepfakes make traditional authentication weaker?
A: Deepfakes weaken traditional authentication because they imitate the human signals that many approval processes still trust, including voice and video.
Q: What breaks when identity teams rely on static login thresholds?
A: Static thresholds are easy for attackers to work around and often too rigid for legitimate users.
Practitioner guidance
- Map trust-relevant journey stages Identify the points where identity risk changes materially, such as onboarding, password reset, payment, account recovery, and high-value actions.
- Use multiple trust signals per session Combine device, behavioural, network, and transaction context to decide whether the session should continue, step up, or be stopped.
- Separate human and delegated actions Treat automated or delegated actions as a distinct assurance class so that customer-facing workflows do not inherit human trust by default.
What's in the full article
Prove Identity's full blog post covers the operational detail this post intentionally leaves for the source:
- How continuous identity verification is applied across customer journeys and risk checkpoints
- The interview context from the Business of Cybersecurity podcast and Mary Ann Miller's perspective
- Operational examples of trust-signal evaluation across onboarding, login, and recovery
- The vendor's framing of how identity, fraud, and cybersecurity converge in customer-facing flows
👉 Read Prove Identity's post on deepfakes, AI agents, and continuous identity verification →
Continuous identity verification: are one-time checks already obsolete?
Explore further
One-time identity proof is now a broken assumption, not a control gap. The article’s core point is that a successful login no longer means a stable trust state. Deepfakes, bot-driven behaviour, and AI-assisted delegation can all change the risk profile after authentication. For identity programmes, that means the real failure is not the absence of a stronger login screen. The failure is the assumption that trust can be established once and then left untouched.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, 38% have no or low visibility, and a further 47% have only partial visibility, according to The State of Non-Human Identity Security.
- That visibility gap matters because 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months.
A question worth separating out:
Q: Who should be accountable when customer identity assurance fails after login?
A: Accountability should sit with the identity and fraud owners jointly, because the failure spans authentication, session policy, and transaction risk. If one team owns login and another owns fraud, but neither owns the trust state after sign-in, attackers exploit the handoff.
👉 Read our full editorial: Continuous identity verification is replacing one-time login checks