Early-bird Discount
expires in
Register Now

Blog

Identity for Everyone: What Humans and Their AI Agents Need from the Systems We Build

Blog Post

Identity for Everyone: What Humans and Their AI Agents Need from the Systems We Build

Mirela Ciobanu
Jul 10, 2026

This guest post reflects the views of the author and does not necessarily represent the views of KuppingerCole Analysts. It is provided for informational purposes only and should not be interpreted as independent research, analysis, endorsement, or advisory services by KuppingerCole Analysts.

Ray Kurzweil once wrote about how the human brain reveals itself in layers. He explained that you do not need to understand the physics of a semiconductor to describe what a computer does, because a whole machine built from billions of transistors can be summarised in a handful of pages once you rise to the right level of abstraction. The same is true of the brain. A single neuron is astonishingly complex, yet a pattern recognition circuit made of millions of neurons can often be described more simply than the neuron itself. Put simply, the higher you climb, the clearer things become, as long as the foundation beneath you is sound.

I kept returning to that idea throughout the European Identity and Cloud Conference (EIC) in Berlin this May. Identity, in every conversation I had, behaved exactly like Kurzweil's neurons and transistors.

Get the foundational layer right and everything you build on top of it becomes simpler, more durable and more inclusive. Get it wrong, and every subsequent layer inherits the flaw.

Starting With the Basics

Before we can talk sensibly about digital identity, we need to talk about human identity. Not the technical kind, the human kind. It begins with a birth certificate and follows a person through school, work, healthcare, banking, pensions and, eventually, death. It should make no distinction based on where someone was born, what they look like or what they are able to do physically or cognitively. That is the layer everything else sits on.

Once that foundation is solid, the digital layer becomes a natural extension rather than a separate problem to solve. We already have most of the technical tools required. What we lack is agreement on how to assemble them into something people can actually use without thinking too hard about it. Events like EIC exist precisely for that reason: to bring the people who build standards, write policy and design products into the same room so that identity can move from an abstract concept to something consumable.

Making Identity Consumable

Consumers do not wake up wanting a digital identity wallet. They want easier travel, safer banking, faster onboarding and protection from fraud. As John Erik Setsaas, Principal Advisor and Founder at Setsaas Trust Advisory, put it during his session, people do not really care about digital identity. They simply expect to be recognised.

That single observation captures a shift taking place across the whole industry. The conversation is moving away from technical vocabulary such as credentials, wallets and protocols, and towards outcomes: less friction, more trust, portability across borders and resilience in a crisis. Whether it is a European wallet that lets citizens book a hotel or prove a qualification without oversharing personal data, or a system that helps a refugee prove who they are after losing every physical document, the goal is the same. Identity has to disappear into the background of everyday life for it to succeed.

Identity as a Business Capability, Not Just a Security Problem

One of the most striking conversations I had at EIC was with Eve Maler, founder of Venn Factory and author of Mastering Digital Identity: From Risk to Revenue. Her central argument is that most CEOs barely think about digital identity until something goes catastrophically wrong, and by then it is far too late to treat it as a footnote.

Eve believes identity should be understood as a business enabler rather than a purely technical function. When identity sits solely within a security team, the metrics tend to focus on risk reduction while overlooking customer experience, revenue growth, and broader business value. She described four jobs that identity actually does: protecting people and transactions, personalising customer experience, enabling payments and commercial interactions, and giving people convenience and control over their own digital lives. Most organisations, in her experience, invest heavily in the first and neglect the other three.

Treating identity as a product rather than a project changes the conversation entirely. It creates accountability for delivering value to customers and to the business, not just for closing security gaps.

Nishant Kaushik, CTO of the FIDO Alliance, made a related point from a different angle. Trust, he told me, is built when technology simply works the way people expect it to. It needs to be easy, reliable, fair and available exactly when someone needs it. When it fails, the damage goes well beyond a security incident. It erodes customer confidence and brand reputation. Standards, interoperability and genuine user choice are what allow that reliability to scale beyond a single company or a single market.

Trust Must Work for Everyone

Dr Angelika Steinacker, who works as an enterprise IAM consultant and serves as DACH ambassador for Women in Identity, offered one of the most important reminders of the conference: a digital identity solution that does not work for everyone does not work.

Inclusion means a system remains usable regardless of age, skin colour, disability or cognitive impairment. Women in Identity has spent roughly five years researching this, moving from identifying where exclusion happens, to listening to people who have experienced it, to quantifying its economic cost in collaboration with the London School of Economics. That research produced a striking finding. When people cannot access services because an identity system fails them, participation in the digital economy falls, and that ultimately affects productivity and GDP. Inclusion, in other words, is not only a social responsibility. It is a measurable economic one.

Angelika was equally direct about why progress remains slow. Identity systems are often designed and tested by fairly homogeneous teams, who naturally build for people whose backgrounds resemble their own. Retrofitting inclusion after launch is far more expensive and far less effective than building it in from day one. As she puts it, diversity is not an end product. It is an entire development process.

Preparing for a World After Classical Cryptography

Not every threat to identity is about who gets left out. Some of it is about what happens to the data we generate today, years from now. Dr Michael B Jones walked me through the quantum question in stark terms. Within a decade or so, quantum computers are likely to be capable of breaking the classical public key cryptography that underpins most of today's digital identity infrastructure. Nobody can say precisely when, and that uncertainty is exactly why organisations struggle to justify acting now.

The risk is already live in a practical sense, through what is known as store now, decrypt later. Well resourced attackers can capture encrypted traffic today with no ability to read it, and simply wait for the computing power to catch up. For sectors such as finance, healthcare and government, information that is sensitive today will often still be sensitive in fifteen or twenty years.

Mike's message to executives was refreshingly simple. You do not need to understand Shor's algorithm to understand the business risk. Migration takes years, uncertainty is not a reason to delay, and organisations handling long lived sensitive data should be planning now rather than waiting for a definitive deadline. He was equally clear that quantum computing is not only a threat. The same power that endangers today's encryption could unlock breakthroughs in drug discovery, materials science, and personalised medicine. It is worth remembering, as he pointed out, that standards like OpenID Connect, now used every time someone signs in with Google or Apple, were born from informal conversations in a hotel lobby at an early EIC event. Progress in this field has always depended on practitioners choosing to collaborate rather than work in isolation.

What Happens to Our Identity After We Die

A theme that surprised me by how little attention it usually receives was raised by Dean H Saxe, co-author of the OpenID Foundation whitepaper The Unfinished Digital Estate: Culture, Law and Technology After Death. Managing a person's digital estate, from email accounts to cloud storage to banking logins, remains extremely difficult for individuals, families, businesses and governments alike.

Dean pointed out that death creates a significant window for fraud. In the UK, for example, pension payments can continue to be collected by family members if the authorities are not informed of a death promptly. The challenge is designing mechanisms that release access only after a genuine trigger event, whether that is death, incapacity or a legal guardianship order, without creating a gap that a fraudster can exploit in the meantime. An executor might need access to specific accounts, but that does not mean they should be able to log into a password manager and move money out of an investment account.

These questions are shaped as much by culture, religion and inheritance law as by technology. In some countries families manage almost everything after a death. In others, only a formally appointed executor has any authority at all. That is precisely why Dean argues for open, extensible standards, so that different legal and cultural models can coexist rather than being forced into a single global template.

The New Layer: Identity for AI Agents

Every single conversation I had eventually arrived at the same unresolved question. What happens to identity once AI agents start acting on our behalf?

Eve Maler described AI agents as a fundamentally different identity challenge from the non human identities organisations have managed for years, such as service accounts or IoT devices. Agents introduce delegation, autonomy and accountability across chains of people, agents and sub agents that existing identity approaches were never designed to handle. Her phrase for the underlying problem was memorable: AI is the balloon payment on technical debt. Organisations have spent years compensating for weak identity foundations with manual human processes. AI will expose those weaknesses at scale, all at once.

Angelika Steinacker is approaching the same problem from a governance angle, working on a paper that asks what purpose and intent actually mean for an autonomous agent, how an organisation defines an agent's identity, and how it verifies at runtime that an agent has not drifted from the mandate it was given. She compares the shift to the relationship between quantum mechanics and classical physics. It is not simply a harder version of the same problem. It is a different space that may need entirely new foundations, arriving faster than the industry has had time to properly define the problem it is solving.

Dean Saxe extended the question into the digital estate itself. If an agent has standing authority to make payments or manage investments on someone's behalf, what happens when that person dies? An agent's mandate might depend on a condition as simple as the account holder being alive, yet reliably detecting that a condition has stopped being true, and revoking authority accordingly, is still an open problem.

Even the future of Europe's own digital identity wallet is entangled with this question. John Erik Setsaas told me the EUDI Wallet is expected to go live by the end of 2026, although some member states will miss that deadline, and getting ordinary citizens to actually use it may prove to be the harder task. Consumers already carry Apple Wallet or Google Wallet, and many are more comfortable sharing data with large technology companies than with their own governments, which makes the value of a new wallet a communication challenge as much as a technical one. John also raised a question I had not previously considered: will AI agents eventually need their own wallets, distinct from the humans who authorise them? Nobody at EIC had a settled answer.

Building Foundations That Last

If there was a single thread running through every interview, it was this. Whatever we build for identity now, whether for humans or for the agents acting on their behalf, needs to be built on a foundation solid enough to support everything that comes after it, in the same way Kurzweil's simple equations only work because the physics beneath them was understood first.

That means inclusion designed in from the start rather than patched on afterwards. It means treating identity as a business capability with real accountability, not a security checkbox. It means preparing for cryptographic threats years before they arrive, and thinking through what happens to a person's digital life, and their agents' authority, long after they are gone. Above all, it means recognising that AI agents are not simply another category of user to slot into existing systems. They may require us to rethink identity from first principles, in much the same way that understanding the brain required scientists to move beyond the chemistry of a single synapse.

The technology to do most of this already exists. What EIC 2026 made clear is that the harder work now lies in agreeing on the standards, the governance and the incentives needed to put it all together, before the pace of AI adoption outruns our ability to do so responsibly.

About the author

Mirela Ciobanu is Lead Editor Banking and Fintech at The Paypers, focusing on following the latest trends and developments in fraud, cybersecurity, and technology (generative AI, blockchain analytics, data, etc.). Topics related to compliance, risk management, and balancing those with a great user experience play an important role in her expertise.

Mirela is particularly passionate about the importance of having interoperable digital identity solutions that help not only to secure payments but also transactions in other areas of life (travel, health, education). She is a strong advocate for online data privacy and protection. As a skilled writer, she strives to deliver accurate and informative insights to her readers, always in pursuit of the most compelling version of the truth. To share more ideas and get inspired, connect with Mirela on LinkedIn or reach out via email at mirelac@thepaypers.com


The Paypers
Mirela Ciobanu is Lead Editor Banking and Fintech at The Paypers, focusing on following the latest trends and developments in fraud, cybersecurity, and technology (generative AI, blockchain analytics, data, etc.). Topics related to compliance, risk management, and balancing those with a great user experience play an important role in her expertise. Mirela is particularly passionate about the importance of having interoperable digital identity solutions that help not only to secure payments but also transactions in other areas of life (travel, health, education). She is a strong advocate for online data privacy and protection. As a skilled writer, she strives to deliver accurate and informative insights to her readers, always in pursuit of the most compelling version of the truth. 
Almost Ready for EIC 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.