
Create your personal agenda –check the favourite icon
This keynote address argues that a professionalized identity workforce is a critical and urgent necessity for U.S. national security. The speaker highlights that while identity is the foundation for countering every major threat—from border security and cyberattacks to insider threats and fraud—the thousands of government professionals performing this work lack unified standards, formal training, and a defined career path.
The address warns that without a formalized and interoperable identity workforce; the nation remains vulnerable to adversaries who exploit identity vulnerabilities with increasing sophistication. The proposed solution is to establish a professionalized corps of identity experts, modeled after cyber and intelligence career fields. This would involve creating a clear competency framework, a training and certification pipeline, and formal career tracks. The result would be a more resilient nation, capable of faster threat attribution, stronger fraud prevention, and enhanced public trust in a rapidly evolving digital world.
Historically, both cyber and identity security systems have been designed to react to known threats, rather than proactively prevent the next threat. But is this wise? Has that orientation actually worked? It would appear that cyber attacks, breaches, hacks, frauds and other identity-related problems have grown, seemingly unencumbered, despite a massive economic investment in systems claiming to mitigate them. In fact, it's the reactive nature of these systems that enables the next attack to go unnoticed until after the fact. The dogma that identity data and biometric data must be bound to devices, rather than to each other, might help device manufacturers sell future generations of devices, but it also forces the reactive nature of identity and cyber security. It’s the intentional separation of these attributes that enables the attacks that traditional architectures can only react to. In this presentation, Jay describes why a proactive system architecture, the proper binding between a verified identity, the human that identity describes, and the privileges that person is entitled to is the key to preventing the next cyber-identity attack.
AI agents are no longer just answering questions — they're acting on behalf of users, calling APIs, managing credentials, and interacting with authentication systems at scale. This shift introduces a new class of identity challenges: How do you authenticate an entity that acts autonomously but on behalf of a human? How do you scope its access without breaking the user experience?
You'll walk away with a practical framework of dos and don'ts for agentic access, including how to think about token scoping, consent delegation, session boundaries, and abuse prevention. Whether you're building AI-powered assistants or securing the identity layer they depend on, this talk will give you a grounded perspective on where agentic identity is headed and how to get it right.
This presentation will explore why the identity ecosystem must begin preparing now for the transition to post-quantum cryptography, even as full PQC adoption remains a work in progress. As the risk of “harvest now, decrypt later” grows, organizations need practical ways to strengthen identity security today while building toward a quantum-ready future. The session will focus on actions that can be taken now, including improving crypto agility, strengthening credentials and identity assurance, leveraging biometrics to reinforce trust in authentication and recovery processes, and securing key processes such as onboarding and account recovery. Attendees will leave with a clear view of practical steps to reduce risk and prepare for the transition ahead.
For more than a century, state and provincial driver licensing agencies have served as North America's de facto identity authorities — verifying identity, vetting source documents, and issuing the credential that more residents carry and more relying parties accept than any other form of ID. As digital identity moves from pilot to production, that role hasn't disappeared; it has simply gone mobile. This session will explore the idea that DMVs are not merely participants in the digital identity ecosystem, but its most credible foundation, and that the path to real-world interoperability runs through the standards DMVs helped build. Attendees will leave with a clearer understanding of why the DMV's expertise in identity verification is not easily replicated, why standards convergence — not standards proliferation — is the surest path to widespread digital ID acceptance, and what's at stake for issuers, relying parties, and the public.
Forfinancial services, the status of consumer identity is advanced but under stress. Banks and other financial institutions are no longer treating identity as only a login function. It now spansonboarding, KYC/CDD, fraud prevention, device binding, ongoing authentication, transaction risk, and recovery. Federal guidance expects financial institutions to use risk-based authentication and access controls, while the Federal Reserve’s more recent commentary shows that institutions are moving from physical-document-heavy onboarding toward more digital, layered, and signal-rich models that include device intelligence, biometrics, and multiple risk signals. So let’s talk about Customer On-Boarding - it’s already expensive to get them, and more complicated to authenticate them.
Law enforcement agencies have used tattoos for many years to assist in investigations. Historically, this has involved searching tattoo image databases using text descriptions of tattoos. However, the effectiveness of this method has been limited by the subjectivity of text-based descriptions. Recent advances in technology have enabled developers to leverage artificial intelligence (AI) to create automated, image-based tattoo search capabilities. Compared to traditional approaches that rely on subjective text descriptions, image-based searching provides a more objective means of retrieval. To determine whether these systems are fit for purpose, decision-makers will need to know their capabilities and limitations. NIST is running an evaluation program to assess the accuracy of tattoo recognition algorithms. This evaluation will measure the capability of these algorithms to detect tattoos in an image and to perform automated matching of different images of the same tattoo from the same subject over time. Thistalkwill present the state-of-the-art accuracy in image-based tattoo recognition and discuss current capabilities and limitations of the technology.
Sending a one-time passcode over SMS is practically synonymous with authentication. As consumers, we receive them every day; as business leaders, it's often the first security layer we implement.
But the gaps are becoming harder to ignore. SMS OTP doesn't fully protect against account takeover attacks, and SMS pumping fraud can quietly drive costs to astronomical levels.
So what's the answer? Layer in other communication channels? Abandon SMS entirely for newer technologies like Silent Network Authentication?
The reality isn't so cut and dry — the right approach depends on your customers, your risk profile, and the business outcomes you're trying to achieve. In this session, Telesign's Senior Solutions Engineer breaks down where SMS OTP still makes sense, where it doesn't, and how to build an authentication strategy that evolves with your users rather than against them. You'll leave with a practical framework for evaluating what "beyond SMS OTP" should actually look like for your business.
Explore the five shifts shaping KYC in 2026, from AI fraud and reusable identity to continuous trust and adaptive verification.
Critical infrastructure organizations face growing pressure to strengthen security while reducing friction for employees, contractors, and visitors. Traditional access cards and paper credentials are increasingly vulnerable to loss, duplication, and misuse—while manual verification slows operations and strains staff resources.
This session explores howID2 Passenables a modern, biometric approach to identity and access management for critical infrastructure environments. Attendees will learn how biometric credentials can enhance facility security, protect privacy, and improve operational efficiency—without disrupting existing access control systems or workflows.
Face recognition capability has improved massively over the last decade, benefitting from AI research in machine learning, deep neural networks, and computer vision. New capability has enabled more developers to offer an expanded and broad array of applications. Yet some problems remain, and the talk will describe seven areas where further technical advancements are needed. Additionally, the presentation will outline how current standardization activities and the recent expansion of NIST’s face recognition evaluations could improve capabilities in some of these areas.
With AI and Deepfakes as the main topic of discussion in fraud, paper still plays an integral role in how fraudsters perpetrate their schemes. In this presentation you will hear about the latest trends the U.S. Postal Inspection Service investigates and hear case studies on check fraud and lead list broker services.
The federal government loses between $233 billion and $521 billion annually to fraud and improper payments and the threat is accelerating. GAO reports that AI-enabled synthetic identities, deepfakes, and account takeover attacks are now the dominant attack vectors against benefits programs, grants, and citizen services. Yet many agencies still rely on legacy identity controls that were never designed to detect these modern threats.
This session explores how federal agencies can deploy modern identity verification to prevent fraud at critical moments: benefits enrollment, account creation, credential resets, and disbursement approval — before taxpayer dollars are compromised.
From buying a home to onboarding a new hire to authorizing an AI agent to act on your behalf, the gap between digital convenience and identity certainty is widening fast. In this session, Daniel Buchner, Director of Product, Digital Assets at Proof, and Kurt Ernst, Principal Product Manager for Risk and Fraud at Proof, trace the rise of the Identity Authorization Network across industries and government, expose what AI-generated deepfakes and synthetic identity fraud look like in the wild, and make the case that Digital ID isn't a compliance feature — it's the trust infrastructure the entire digital economy is being built on top of, whether we've planned for it or not. Leave with a cross-sector framework you can apply immediately and a clearer view of where identity risk is headed next.
For decades, identity resolution has focused almost exclusively on physiological markers: matching a face, a fingerprint, or an iris against a static database. But in today’s unconstrained environments—spanning real-time video networks, digital forensics, and tactical edge operations—biometrics alone are no longer sufficient. Static biometric records often lack critical context, and adversarial counter-measures or poor-quality captures can degrade matching confidence.
This presentation introduces Connected Intelligence, a paradigm shift that expands the definition of identity. We discuss how to resolve identities by unifying physiological biometrics with Events (spatial/temporal encounters), Objects (vehicles, license plates, weapons, and smuggled contraband), Attributes (scars, marks, tattoos, and age estimation), and Behaviors (patterns of life, association networks, and cross-channel digital links).
The Fraud Executive Orderreleased in March 2026signals a major shift in how digital identity is used to prevent fraud, requiring pre-payment identity verification, defining minimum verification standards, and expanding data sharing to detect fraudulent activity.
This session will explore how identity verification can be operationalized as a corecomponentof digital services, aligned to fraud risklevelsand integrated into broader fraud detection strategies. Through an interactive discussion, attendees will gain practical insight into strengthening digital identity ecosystems while balancing security, compliance, and user experience.
Participants will explore how to navigate these requirements across digital services, align identity verification to varying fraud risk levels, and balance security with user experience. Attendees will leave with a clearer understanding of the Executive Orders’s implications and practical considerations for strengthening fraud prevention strategies within their organizations.
Key Takeaways
The checkpoint model is broken at its foundation. Every credential that leaves the body can be stolen, replicated, or synthesized. Bio_Sole's hosted seminar introduces the autonomous alternative — where the biometric never leaves the device, identity is self-attested by the individual, and the environment receives proof, not data. Panellists examine how autonomous identity reshapes enterprise risk, clinical data integrity, and connected infrastructure. Not a better biometric. A different architecture.
The financial landscape is evolving fast — and so are the threats. As AI accelerates digital transformation across banking, fintech, and payments, financial institutions face a growing challenge: how do you embrace innovation without opening the door to fraud?
In this session, Vonage will explore how network-powered APIs are redefining the future of financial security — enabling institutions to stop fraud before it strikes, without sacrificing the seamless customer experiences that drive growth.
Key takeaways include:
Improvements in AI are enabling superior performance in automated biometric systems. However, these systems are also influencing human decision-makers in unexpected ways.
In face recognition, stronger algorithms can return doppelgängers that are difficult for reviewers to distinguish, potentially leading to false positives. At the same time, advances in generative AI are making biometric deepfakes more convincing, exposing security gaps and increasing fraud risk.
Across both areas, one thing is becoming clear: As AI takes on more work in biometric workflows, humans are often presented with more complex decisions. This dynamic can position humans a potential weak link in biometric system design.
This session presents SAIC’s perspective on this challenge and introduces an emerging approach to better integrate human and AI teaming to improve biometric outcomes. In the era of AI agents, this approach enables more informed, agentic AI.
In an increasingly digital and AI-powered world, two-Factor Authentication (2FA) has become critical for security-minded enterprises, but can often cause friction, impact user experience, and is vulnerable to social engineering attacks. CAMARA Network Powered Digital Solutions, developed by GSMA and the Linux Foundation, offers a seamless alternative with Number Verification and Silent Authentication. This technology enables secure, frictionless authentication directly through mobile network operators, eliminating the need for OTPs and reducing vulnerabilities.
This session highlights how Silent Authentication is transforming digital authentication, prioritizing both security and user experience.
As sophisticated fraud tactics like caller ID spoofing, network hijacking, and AI-driven voice cloning accelerate, enterprises can no longer rely on the origin of a phone call as proof of identity. There is a critical, yet often overlooked, distinction in modern telecommunications security: authenticating the call (verifying the device, network, or phone number) versus authenticating the caller (verifying the actual human speaking).
This presentation explores the dangerous security gaps created when businesses conflate these two concepts. Attendees will learn how threat actors exploit device-centric trust models and why shifting to human-centric authentication—leveraging advanced voice biometrics, behavioral analytics, and real-time identity verification—is essential for robust enterprise fraud defense. We will break down practical strategies for implementing seamless, secure voice authentication that protects the bottom line, reduces customer friction, and ensures that the voice on the line truly matches the identity on the account.
Key Takeaways:
In this fireside chat, attendees will learn how LAFC deploys next-generation technologies, such as biometrics, to revolutionize the fan experience. Drawing from World Cup ticketing insights and short-notice mega-events, the session explores the operational agility needed for modern venue management. Participants will also gain a sneak peek into 2028 Olympic preparations and discover how vendors and policymakers can collaborate to solve upcoming industry hurdles.
Account recovery is where security and customer experience come together. In this session, we'll share eBay's journey of rethinking account recovery through product, design, and customer research. We'll discuss key insights, design principles, and lessons learned while balancing security with a simpler, more intuitive recovery experience. Attendees will leave with practical ideas that can be applied to designing recovery experiences at any scale.
Identity tells us who someone is. As AI systems begin acting on governed information, the harder question is whether the requested action is authorized—and who has the authority to approve it. Drawing on cultural rights as a proof case, this presentation introduces machine authorization as the missing layer between identity, authorship, and accountable AI.
Create your personal agenda –check the favourite icon
The strongest identity evidence a credential service provider (CSP) can collect now lives in digital wallets.A CSP that accepts a mobile driver's license (mDL) or other digital credential for identity proofing becomes a wallet relying party with obligations under NIST SP 800-63-4. Kantara Initiative (kantarainitiative.org) is the nonprofit that operates the leading US accreditation program for assessing conformance to NIST's digital identity guidelines. This session previews the wallet-related requirements in Kantara's baseline certification criteria and how CSPs will be assessed when they accept credentials from digital wallets. Attendees will leave with a clear picture of what wallet acceptance requires under the new guidelines and how to prepare for assessment against Kantara's criteria. For government agencies and relying parties,the session offers a benchmark for vendor due diligence: what Kantara certification for wallet acceptance actually verifies, and what to demand from a CSP before trusting its wallet-based identity proofing.
Digital identity is quickly becoming the foundation for how people prove who they are — not just at a border, but across banking, government services, healthcare, and everyday digital life. As more of these interactions move to mobile-first, remote enrollment, the industry has gotten good at solving the pieces in isolation: capturing a face, capturing a fingerprint,validatinga document. But the moment thatactually determineswhether a digital identity can be trusted is the one nobody talks about enough — proving thatall ofthose pieces belong to the same person, securely, remotely, and without friction.
Most identity programs today rely on document validation and facial biometrics, which workreasonably wellfrom a smartphone. The harder problem is fingerprintcapture, andbinding it to the face in a manner thatisn’tawkward for the user, time-consuming, or dependent on costly hardware. Mobile touchless remote fingerprintcapturechanges that equation. But it introduces a challenge the industry hasn’t fully addressed: how do you guarantee that the fingerprint captured remotely actually belongs to the person whose face and documents you just verified? This is the “binding” problem — andit’sthe difference between a genuinely secure enrollment model and a vulnerability waiting to be exploited.
Identy.io’sbiometric binding architecture links face capture, document OCR, and touchless fingerprint collection into a single authenticated session. The face is real — independentlyvalidatedin DHS’s RIVR evaluation with zero attack acceptance across all attack classes. The fingerprints are real — ISO/IEC 30107-3 Level 2 certified byIdiapResearch Institute and Ingenium Biometrics. And they belong to each other, verifiably. Further, they are interoperable with legacy AFIS databases and watchlists, without requiring hardware replacement. No rip-and-replace. No new kiosks.
Agentic AI is reshaping the identity threat landscape. As autonomous agents grow more capable, the same technology driving innovation can automate fraud, exploit vulnerabilities, and interact with your applications as if it were a legitimate user. This session makes the case that visibility into agentic traffic is now a security imperative, and shows how organizations can detect, classify, and govern AI agents based on their behavior and intent. You'll leave with a practical framework for distinguishing malicious agents from legitimate ones and deciding what to allow, block, or challenge.
The proliferation of generative AI systems capable of synthesizing photorealistic humanlikenesses, voices, and performances has created a structural gap in the media andentertainment supply chain: the absence of a neutral, persistent, interoperable identifier for theIdentity resolution of notable talent at the center of these transactions. Without such infrastructure, consent cannot beverified at scale, provenance chains collapse under the weight of synthetic content, andenacted regulatory frameworks have no technical substrate against which compliance can bemeasured or enforced at machine-readable speed.
HAND founder Will Kreth will discuss howpersistent, interoperable, standards-aligned talent identifiers are themissing technical precondition for the consent-based rights frameworks now demanded bylegislation, labor agreements, and the broader creative economy.
The identity industry is racing to provision and authorize AI agents — but who holds the authority to revoke them mid-execution, and how is that authority enforced? This talk reframes "stopping a rogue agent" as an authorization-lifecycle problem and answers it with three production-tested patterns: circuit breakers that halt execution when anomaly thresholds are breached (the WHEN of revocation), dead man switches that revoke an agent's credentials at the IAM layer when heartbeat signals go silent (the HOW), and state machines that make an agent's identity lifecycle — provisioned, active, suspended, revoked — authoritative in the IAM layer rather than the agent's own code (the WHO). Attendees leave with implementable patterns for agent containment, plus the structured-testing methodology that surfaces failure modes like these before they reach production.
Since TSA's deployment of Credential Authentication Technology in identity screening, TSA has shifted its counterfeit detection strategies to alert resolution and partnerships for 1:many facial comparisons in the trusted traveler populations. The remaining gap in deterring and detecting fraud lies in improving the machine readability of the U.S. Driver's License.
In this session, we'll share PayPal's journey deploying Passkeys across our platforms, reaching millions of customers worldwide. If you're interested in passwordless authentication or planning your own passkey implementation, we'd love to see you there.
Each March SXSW takes over Austin, TX with no fence line, no pre-registration required, and no limit to the kinds of events. From star-studded red carpets and 4-story-tall vending machines to one-on-one mentor sessions and VR experiences, a unique event has unique credentialing demands. This talk will dive into the process of delivering a credentialing and access control system that equally serves a Music Festival, a Film Festival, and a Conference all while providing real-time analytics and event safety controls.