Bojan Simic is the Cofounder and CEO of HYPR, a provider of passwordless MFA and identity assurance solutions.

getty
Identity verification has become a relentless requirement of digital life. Every time we open a bank account, access healthcare or log in to an enterprise system, we are asked to prove who we are. But as the cost of identity failure escalates, the threat model has shifted.
Simultaneously, the industry has spent years chasing seamless user experiences (UX). Verification has become lightning fast, nearly invisible and completely frictionless. But fast doesn't mean secure, and we’ve conflated a momentary check with continuous protection.
Unintended Consequences: Confusing The Process With The Outcome
The push toward seamless digital verification has delivered enormous benefits, but it has also introduced unintended consequences and blind spots. GenAI hasn't just introduced new threat vectors; it has industrialized existing ones, allowing adversaries to scale synthetic identities, deepfakes and automated replay attacks faster than legacy controls can adapt.
In response, identity verification has become synonymous with a particular user journey rather than the intended security outcome: absolute confidence that the user is who they claim to be.
Organizations have blurred the line between the technology they deploy and the goal they are trying to achieve. A passport scan doesn't verify an identity; it just verifies a document. A selfie doesn't establish trust on its own; it simply provides another piece of digital evidence. Over-indexing on the user experience has led us to confuse the means of verification with the end goal.
This distinction is critical because zero-trust architecture is only as strong as the initial identity proofing. You can enforce strict access controls downstream, but if an account was verified using a static, easily tricked document check, you are simply securing an impostor.
The critical metric isn't whether an identity check occurred; it’s how much assurance that check actually provides.
This doesn't mean every digital touchpoint requires maximum friction. True security requires a risk-based architecture where identity assurance matches the potential impact of getting the decision wrong. Instead of subjecting users to rigid, one-size-fits-all document scans, organizations must pivot toward contextual attestation, combining passive liveness, device-bound cryptographic signals and real-time risk intelligence to validate trust dynamically without creating unnecessary user friction.
Trust Changes Over Time
Most organizations treat identity verification as a static event at the start of a transaction. In reality, a legitimate account can be compromised seconds after authentication, making identity an ongoing assessment rather than a single point-in-time decision.
This risk is particularly acute during high-risk life cycle moments such as account recovery, self-service password resets and help desk interactions—the exact vectors attackers target to bypass primary MFA.
As user actions change and new risk signals emerge, verification controls must adapt dynamically. This fundamentally shifts the emphasis from completing a one-off verification step to maintaining continuous confidence across the entire identity life cycle. Organizations that build for holistic assurance rather than isolated features will be the ones equipped to adapt as threats evolve.
Ultimately, the question is no longer whether an identity was once verified. It's whether you have enough real-time confidence to trust it right now. In an era dominated by deepfakes and synthetic identities, that distinction will define the future of digital trust.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
>> Home