AI Is Changing Cybersecurity. Identity Is Becoming the Trust Layer.
For years, cybersecurity asked a relatively simple question:
Who are you?
Then we began asking a better question:
Can you prove it?
Artificial intelligence is forcing us to ask a much harder one:
Can we continue to trust that you are who, or what, you claim to be throughout the interaction?
That distinction may define the next generation of identity security.
I was reminded of this recently while reading Abnormal AI's Every Attack Has an Identity, a collection of perspectives from security leaders examining AI, impersonation, insider threats, non-human identities and post-authentication security. Its central premise is compelling: much of today's attack surface ultimately collapses into a question of identity.
I agree.
But I believe the implications go even further.
As AI changes who and what participates in digital transactions, identity is rapidly becoming the trust layer connecting people, devices, applications and autonomous agents.
And that means we may need to rethink what we mean by authentication itself.
Authentication is getting stronger. The problem is moving.
The cybersecurity industry has invested enormously in authentication.
MFA, passwordless authentication, biometrics, passkeys, risk-based authentication and increasingly sophisticated IAM platforms have made it much more difficult to simply walk through the digital front door with a stolen password.
That progress matters.
But attackers adapt.
Verizon's 2025 Data Breach Investigations Report found that compromised credentials were used as the initial access vector in 22% of the breaches it analyzed. CrowdStrike reported that 81% of hands-on-keyboard intrusions observed in its 2025 threat-hunting research were malware-free.
Think about what that means.
Increasingly, the attacker doesn't necessarily need to break the system.
The attacker needs to look sufficiently like someone the system already trusts.
That can mean stealing credentials. It can mean social engineering a help desk. It can mean stealing an authenticated session. It can mean acquiring an OAuth token. Increasingly, it can also mean impersonating a human convincingly enough that another human grants access.
CrowdStrike documented a 442% increase in voice-phishing activity between the first and second halves of 2024 as adversaries increasingly incorporated AI-enabled deception into social engineering.
The attack surface is shifting from breaking technology to counterfeiting trust.

And that is an identity problem.
A successful login is not the same thing as continuous trust
One of the most important observations in Abnormal's report concerns what happens after authentication.
Organizations have become quite good at guarding the front door. But once someone gets through that door, many security architectures continue to place considerable trust in the credential, token or authenticated session that follows.
That creates an important distinction.
Authentication tells us that sufficient evidence was presented at a particular moment to grant access.
It does not necessarily tell us that every action occurring afterward should continue to inherit that trust.
Consider a stolen session token.
The credential may be valid.
The session may be active.
Every permission check may pass.
The security system can therefore behave exactly as designed while the person using the identity is no longer the person the organization intended to trust. Abnormal describes precisely this post-authentication problem in its analysis.
SpyCloud's 2026 Identity Exposure Report illustrates the scale of this emerging attack surface. Its recaptured identity dataset contained 8.6 billion stolen session cookies, along with 18.1 million exposed API keys and machine credentials.
That should cause us to reconsider a fundamental assumption.
Perhaps authentication should not be viewed as an event.
Perhaps it should be viewed as the beginning of a trust relationship.

AI makes that distinction much more important
Now add artificial intelligence.
AI adoption is moving far faster than the governance structures intended to manage it.
ISACA's 2026 AI Pulse Poll, drawing responses from more than 3,400 digital-trust professionals, found that 90% believe employees are using AI within their organizations, while only 38% say their organizations have a formal, comprehensive AI policy.
IBM found an equally significant security gap. Among organizations that experienced an AI-related security incident, 97% lacked proper AI access controls. IBM also found that 63% of surveyed organizations lacked AI governance policies, while organizations with extensive shadow AI experienced breach costs approximately $670,000 higher than those with little or no shadow AI.

Employees are already giving AI tools access to information, applications and workflows.
But this is only the beginning.
The next phase is not simply employees using AI.
It is AI acting on their behalf.
Welcome to the age of the non-human identity
Traditional identity architecture was largely designed around a simple assumption:
There is a person somewhere at the end of an access decision.
An employee requests access. A manager approves it. A credential is issued. Permissions are assigned. Eventually, the employee changes roles or leaves and those permissions are modified or revoked.
That model becomes considerably more complicated when the actor is an AI agent.
Abnormal's report identifies this problem directly. Service accounts, API keys and autonomous agents can possess credentials and permissions without a human actively participating in each transaction.
An AI agent might someday negotiate a purchase.
Another may access financial information.
Another might initiate a payment.
Another could interact with a customer's agent.
Another could access healthcare information or participate in decisions involving highly sensitive data.
Suddenly the identity question becomes much larger.
Who authorized this agent?
Whom does it represent?
What is it permitted to do?
For how long?
How does another system verify its authority?
What happens when its behavior changes?
And how do we revoke trust when that trust is no longer warranted?
These aren't merely AI questions.
They are identity questions.

From Authentication to Verification to Continuous Trust
I believe we are moving through three important stages in digital identity.
Authentication asks:
Can you demonstrate that you are entitled to enter?
Verification asks:
Can we establish with sufficient confidence who or what is participating in this interaction?
Continuous Trust asks:
Does the evidence available throughout this interaction continue to justify the trust we originally granted?
Those are very different questions.
And increasingly, cybersecurity will need to answer all three.
This does not mean authentication becomes less important.
Quite the opposite.
Strong authentication remains one of the foundations upon which digital trust is established. Passwordless technologies can remove vulnerable shared secrets. Biometrics can strengthen the relationship between credentials and individuals. Multi-factor and phishing-resistant authentication can dramatically raise the cost of impersonation.
But the objective should no longer be merely to authenticate entry.
The objective should be to establish and maintain Verifiable Identity.
That distinction becomes especially important as human and machine identities begin interacting with one another at enormous scale.
AI will need identity just as humans do
Imagine a digital transaction several years from now.
A human authorizes an AI agent.
That agent communicates with another organization's AI agent.
One agent accesses an application.
Another invokes an API.
A third validates information.
A fourth executes a transaction.
Where, exactly, is the traditional login?
More importantly:
Where is trust established?
The answer cannot simply be at the beginning.
Trust will need to travel with the transaction.
Systems will need ways to establish that an identity, human or non-human, is legitimate; that it possesses the authority it claims; that its permissions remain appropriate; and that the evidence supporting that trust remains valid throughout the interaction.
This is why I believe Verifiable Identity will become the cornerstone of Digital Trust.

The future of identity will not simply be about proving that someone knows a secret.
It will increasingly be about establishing trustworthy relationships between humans, machines and autonomous systems.
The Human Side of Digital Trust
There is a danger in discussing AI, machine identities, behavioral analytics and Zero Trust that we make cybersecurity sound increasingly complicated.
The objective should be exactly the opposite.
Technology should quietly serve humanity.
People should not have to become cybersecurity experts simply to participate safely in the digital world.
The best identity systems should reduce friction for legitimate users while making impersonation increasingly difficult.
Put another way:
Trust should be effortless for honest people and extraordinarily difficult to counterfeit.
That principle becomes even more important as AI becomes embedded in everyday life.
We will increasingly delegate activities to intelligent systems. Those systems will communicate with other systems. Decisions that once required direct human interaction may occur autonomously and at machine speed.
But underneath all of that sophistication remains a remarkably simple question:
Who, or what, am I trusting?
If we cannot answer that question with confidence, every security control that follows rests upon uncertain ground.
AI may be changing cybersecurity faster than any technology we have encountered in decades.
But AI is also making something else increasingly clear:
Identity is no longer simply the front door to the digital world.
Identity is becoming its trust layer.






Comments