Is your organisation ready for AI-driven identity threats? The data says no

There is a growing gap between how secure organisations think they are and how prepared they actually are for AI-driven identity threats. That is the central finding of an IDC white paper, sponsored by Ping Identity, which surveyed 794 organisations worldwide.

More than half of respondents said they believed they were ahead of their peers in establishing trusted digital identity, yet only 9% met IDC’s standard for “verified trust” leaders.

The report also found that 94% of leaders are already operating at scale, while 596% of starters remain stuck in pilot mode. For a market racing to deploy AI, that is an uncomfortable disconnect.

The problem is not the front door. 

It is everything that happens after the first login: password resets, privileged approvals, partner API calls, onboarding workflows and, increasingly, machine-led decisions.

IDC’s argument is that identity can no longer be treated as a one-time authentication event. Instead, organisations need what it calls verified trust: continuous assurance that every digital interaction, whether initiated by a person or an AI agent, is tied to an independently verified identity and remains trusted over time.

In practice, that means using contextual signals such as device posture, liveness-backed biometrics, behavior and real-time risk monitoring to decide whether access should still be trusted.

Timing matters

AI is already making identity abuse cheaper, faster and harder to detect.

Hong Kong authorities said in 2024 that police had recorded three deepfake-related fraud cases by the end of May that year, including one in which a victim was tricked through a fake video conference into authorising transfers worth about HK$200 million, and another involving nearly HK$4 million.

In a separate case, UK engineering firm Arup confirmed that fraudsters used AI-generated deepfakes in a scam that led to a $25 million loss. Microsoft, meanwhile, has warned that fake employees are slipping through remote hiring and onboarding checks to gain trusted access inside organisations.

IDC’s data suggests the organisations performing best are the ones that treat identity as a business control, not just an IT utility. Leaders verify far more of their trust flows, move earlier on passwordless technology and are more likely to unify identity platforms.

The report says 69% of leaders verify 75% to 100% of trust flows, compared with just 16% of laggards. Leaders also report adoption rates above 80% for biometrics with liveness, passkeys and digital credentials or wallets.

AI-Driven Identity Threats

Organisations that operationalized verified trust reported 51% higher customer registration conversion, 44% stronger compliance readiness, 43% lower fraud losses and 47% faster workforce onboarding.

Practical steps

IDC also recommends practical steps: start with high-impact journeys such as account creation, privileged access and AI agent interactions; track verification coverage as a KPI; move beyond passwords; and build in AI guardrails such as delegated authorisation, explainability logs and data provenance.

The wider message is clear. 

In an AI-shaped enterprise, identity is no longer a background system for logging in. It is becoming the control layer for every human, machine and agentic interaction. Organisations that still rely on static trust may discover too late that the real weakness was never at the perimeter. It was in everything that came after.

You might also be interested

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.