TL;DR: Identity is moving beyond onboarding, login, and transaction checkpoints because AI-driven fraud can bypass static gates with deepfakes, injection attacks, and synthetic identities, according to Uniken. The practical shift is toward continuous, privacy-first assurance that verifies legitimacy across the full relationship, not just at discrete moments.
NHIMG editorial — based on content published by Uniken: The identity layer isn’t being rebuilt. It’s being outgrown
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How should security teams move from access reviews to continuous assurance?
A: Start by linking identity events to policy decisions.
Q: Why do point-in-time checks fail against AI-driven fraud?
A: Because the attack is no longer a single event.
Q: What do organisations get wrong about identity-first security?
A: They often treat it as an authentication project rather than an operating model.
Practitioner guidance
- Map your current trust checkpoints Identify where your customer or workforce journey still relies on a single onboarding or login decision being treated as durable proof.
- Reduce unnecessary identity data retention Review what personal data is being collected for assurance and remove fields that do not materially improve fraud resistance or legitimacy confirmation.
- Separate acceptance from assurance Distinguish between a successful transaction and an enduring trust state in policy, telemetry, and reporting.
What's in the full article
Uniken's full article covers the operational detail this post intentionally leaves for the source:
- How the continuous-assurance model is positioned against legacy authentication stacks in practice.
- The privacy-first design arguments behind reusable digital identity and what they mean for implementation choices.
- The regulatory context around eIDAS 2.0, PSD3, and DORA as they relate to live trust verification.
- The article's own framing of why legacy identity vendors may preserve gate-based architectures rather than replace them.
👉 Read Uniken's analysis of why continuous identity assurance is outgrowing point-in-time gates →
Point-in-time identity checks are failing, so what should teams do?
Explore further
Point-in-time identity assurance is now a broken premise, not a sufficient control. The article’s core claim matches what identity teams are already seeing in fraud and access governance: one-time checks cannot prove legitimacy across an adversarial relationship. Deepfakes, replayable credentials, and synthetic identities all exploit the gap between initial verification and subsequent behaviour. For practitioners, the conclusion is clear: trust cannot be treated as a moment.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which makes identity assurance harder to sustain across machine and automated workflows.
A question worth separating out:
Q: How can teams tell whether their identity controls are still gate-based?
A: Look for programmes that report success at onboarding or login but do not measure trust decay, behavioural drift, or legitimacy across the session. If the control only knows who passed a checkpoint, not who is using the identity now, it is still a gate model. Continuous assurance requires live confidence, not just historical approval.
👉 Read our full editorial: Why continuous identity assurance is outgrowing point-in-time gates