There is a growing gap between how secure organisations think they are and how prepared they actually are for AI-driven identity threats. That is the central finding of an IDC white paper, sponsored by Ping Identity, which surveyed 794 organisations worldwide.
More than half of respondents said they believed they were ahead of their peers in establishing trusted digital identity, yet only 9% met IDC’s standard for “verified trust” leaders.
The report also found that 94% of leaders are already operating at scale, while 596% of starters remain stuck in pilot mode. For a market racing to deploy AI, that is an uncomfortable disconnect.
The problem is not the front door.
It is everything that happens after the first login: password resets, privileged approvals, partner API calls, onboarding workflows and, increasingly, machine-led decisions.
IDC’s argument is that identity can no longer be treated as a one-time authentication event. Instead, organisations need what it calls verified trust: continuous assurance that every digital interaction, whether initiated by a person or an AI agent, is tied to an independently verified identity and remains trusted over time.
In practice, that means using contextual signals such as device posture, liveness-backed biometrics, behavior and real-time risk monitoring to decide whether access should still be trusted.
Timing matters
AI is already making identity abuse cheaper, faster and harder to detect.
Hong Kong authorities said in 2024 that police had recorded three deepfake-related fraud cases by the end of May that year, including one in which a victim was tricked through a fake video conference into authorising transfers worth about HK$200 million, and another involving nearly HK$4 million.
In a separate case, UK engineering firm Arup confirmed that fraudsters used AI-generated deepfakes in a scam that led to a $25 million loss. Microsoft, meanwhile, has warned that fake employees are slipping through remote hiring and onboarding checks to gain trusted access inside organisations.
IDC’s data suggests the organisations performing best are the ones that treat identity as a business control, not just an IT utility. Leaders verify far more of their trust flows, move earlier on passwordless technology and are more likely to unify identity platforms.
The report says 69% of leaders verify 75% to 100% of trust flows, compared with just 16% of laggards. Leaders also report adoption rates above 80% for biometrics with liveness, passkeys and digital credentials or wallets.
IDC also recommends practical steps: start with high-impact journeys such as account creation, privileged access and AI agent interactions; track verification coverage as a KPI; move beyond passwords; and build in AI guardrails such as delegated authorisation, explainability logs and data provenance.
The wider message is clear.
In an AI-shaped enterprise, identity is no longer a background system for logging in. It is becoming the control layer for every human, machine and agentic interaction. Organisations that still rely on static trust may discover too late that the real weakness was never at the perimeter. It was in everything that came after.
Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.