So just quickly let's people come in. Great to have you on the panel, all of you. Maybe just quickly introduce yourselves, starting with you Patrick.
Sure, I'm Patrick Parker, I'm the CEO and founder of EmpowerID and I lead up the product team. Happy to be here. Hi everyone, my name is Tobin Broadfoot and I'm the product director for Keyless and we're the leading 100% privacy preserving facial biometrics provider.
Hello, I'm Joe Palmer, I'm the chief innovation officer at iProov, which you just heard about if you were in the previous session from Andrew. And I'm working on our workforce integration and identity systems.
Thanks, and I apologize for getting you mixed up. But let's start actually with you, because you sent me an email earlier, which I thought was, sorry you didn't, sorry Tobin did. I'm getting everyone mixed up today.
But yeah, what is the difference between local device biometrics such as face ID etc. and the server side, because people might just say, why not just use face ID.
So, why not? Thank you, great question. I don't know who sent it.
No, no, it was for me. So yeah, I think it's, and I thought Andrew's presentation was fantastic there and there's a lot of good stuff in there. But it's a question that I'm sure comes up for you Joe, and I'm sure as well you, where when people see facial biometrics, and it's been a blessing as well, that people have got very used to that as a process, showing your face and authenticating. And then the question comes, well, why use iProof, why use Keyless? The key thing to remember with those is they are just a local biometric, right?
So really what face ID or touch ID on an Android device is doing for you is proving that someone can unlock the device. The challenge is there, and lots of banks have realized this, and I'll explain the sort of proof point of that in a second.
If you, you might have a family member who also knows your PIN code. You often find whole families add their same biometrics to the device, and you've got two problems there. One is it doesn't really genuinely prove that that person is there and is the same person that you originally onboarded. But also if they lose the device, you have lost that biometric authentication.
And I thought the reason I sort of posted that question to you earlier was that I think it's important to get that distinction, because I know from talking to a lot of people about that, there could have been some people in the audiences that are just wondering and asking that question. I can add one extra point on that as well. You can't take an image, for example, from a passport or an identity document, and use that as the reference image in something like face ID. So you can't use it to do identity proofing or identity verification.
It's only an authentication method, which is a convenience factor for your PIN, as you mentioned. Okay, so Andrew's presentation was, for me, pretty scary. And I already – I don't know if any of you look on social media. I'm sure you have better things to do. But currently there is a reel of these skateboarding dogs, which – have you seen? Yeah. And they – these dogs – they start off with one dog. Now there's several dogs. But they seemingly can skateboard down steps, and they can even turn the skateboard on its trucks and stuff. I can't tell if that's real or not.
I mean I really – and they've even got the people in the video looking at dogs, et cetera. I mean it's brilliant. Does anyone know if it's real? I don't know. But I think that when I said to my wife, like, oh, look at these dogs. They're amazing. I can't believe they can steer the skateboard like that. Everything on the internet is real.
Yeah, and she said, you're an idiot. She said, of course that's not real. Don't tell me fantasy.
Anyway, so the point is what is happening is I didn't realize that they could now even fake moving this side to side. So how is – so AI has already changed biometrics. How is it going to change – I mean what's coming next, Patrick? In my opinion – I mean it's just an opinion. I mean I see that the biometrics are the convenience factor. It's security. But at that point you're in the front door. That doesn't mean that you shouldn't be doing continuous identity verification, continuous authentication. So where I see it, I think very soon we're all going to have an AI assistant.
You'll be working with lots of agents, but you'll each have your own personal agent. And no one will know you better than that agent. So that agent could be an identity verification, continuous identity verification actor where it's constantly measuring your behavior because it will know you better than anyone else. So it could be detecting in real time if you are behaving abnormally. It could even do a challenge and try to prove your identity.
And then it could use open standards like shared signals, CAPE, and RISC to fire off something and blow up your session if it says that, well, that's not really Patrick. Patrick's wife grabbed the phone, put it up to his face, and now he's surfing Portuguese recipe sites. And that's not what Patrick does. So he would know me better than anybody else. Skateboarding dogs is more your thing. Something like that.
So I see that the AI agents, because of their intelligence and because they're going to be completely persistent and always there, they have a great opportunity to collect a lot of information about you to help you validate your identity to protect you in real time. So are you saying that facial identity is kind of over because of what we just saw?
Well, it's an arms race. I wouldn't – it's a convenience factor. I would say it gets you in the front door, but that doesn't mean that you – every door is locked. You can't actually do anything until some additional factors come into play.
So, Joe, you're in this business. What do you – I mean does that make sense to you? Do you have to change your whole business model? I don't think so.
Basically, we – AI systems are trained on data. The fact that we can go to chat GBT is because it's literally being trained on the entire Internet. So it is good at responding and acting like a human because it has so much data. So the winner of this arms race, the biometric verification arms race, is the one who has the most data. Attackers have access to lots of data. The Internet is rich in it.
But if you can constrain the data that you require for your biometric authentication, like have an SDK, require the user to align, affect the image in front of the camera when you're capturing biometrics, then you can constrain that data and you can learn huge amounts. So we have half a billion, I think Andrew mentioned, data points on what real people look like when they authenticate using our SDK. Our attackers don't have half a billion reference points of fakes. They have to generate this themselves. So this information asymmetry is key in maintaining the security.
So I think we'll see over time the AIs will increase the rate of attack. The scale is going to become huge because no longer do you have to sit there holding up things in front of the camera. You can write software to launch these kind of attacks automatically. But that's great because guess what? We get all of the data that they send us. We monitor it. We identify anomalies and interesting samples of that data. We retrain. We adapt. We improve. So I don't think it's as simple as they're going to win. It's how can you stay ahead. It's an arms race.
Security is an evolving landscape just as biometrics are. I was just going to say it is an arms race. I mean how tough is it out there? I mean how do you feel comfortable? I mean it sounds to me like every time you do something, they do something. And they're using AI obviously as well. It's tough in the sense that it's getting harder. It's one of these unique problems that gets harder with time, not easier. But it is one where if you're ahead, you can stay ahead.
I do think it's going to be hard for a new entrant into the market to suddenly decide I'm going to become a liveness provider and I'm going to start training my data because then you're going to start from zero. So there is potentially that aspect of it. But if you're ahead and you maintain and you monitor and you evolve, then you can stay ahead because of that information asymmetry.
Okay, let's switch tacks slightly about another. I mean Joe talked a lot about liveness detection and it seems that's the way forward. But what about behavioral biometrics, which is another area, which is kind of I guess what you were talking about. How reliable are they?
Tobin, let's hear from you. So behavioral biometrics is another important signal is what I'd say.
Listen, I think deep fakes is the theme of lots of the panel discussions that people like Joe and Patrick and I go on at the moment because it's very visible at the moment. You can't go on LinkedIn without seeing some fake Polish passport. I don't know why the Polish passport seems to be getting used a lot in these demo videos. But it's very current. And so what people are seeing there is, oh, I could do that and I can't tell whether it's real or not. And so therefore it's going to work.
I think Andrew did a great job of showing that if you have certain systems that are very susceptible to that, that's the scale of which you can attack that now on a bad system is going to be a big problem for you. So if your process is fooled by one deep fake, suddenly it can be fooled very quickly by a thousand or a million. Behavioral biometrics is a layer that we use. It's a fantastic data point. But it's one of many, many layers that we use and other identity providers use in order to consistently say, and you said it's a continuous motion to say, is this still the same person?
Behavioral biometrics is great. None of these one things that you could mention to me now, Paul, is foolproof. I would not rely fully on behavioral biometrics just as I wouldn't rely fully on a single deep fake detection model. What I would advise people in the audience to do or anyone I was speaking to is, what are your layers that you're building up so that you have the highest possible level of assurance that you know who you're dealing with, and that's what vendors like us do.
So we're talking something more sophisticated than keyboard detection, you know, in IAM systems where suddenly the keyboard's typing style changes. Again, if you were just using, is this person typing the same today, that's not going to be a good user experience or a particularly effective one for stopping fraudsters, but as one of 100 signals, yeah, great, throw it in. You need a lot of signals. Time of day, maybe even the available Wi-Fi networks that, you know, your environment, your location, your behavior, which applications you're using, what you're trying to use.
And again, you have to gauge the risk level. So if I'm just entering the door and I'm not doing anything, then maybe some level of verification, a lower level is okay. But if I start doing high-value transactions, risky actions, then obviously you've got to amp that up. Any out-of-band, anything out-of-band is always good. So I really do feel like I'm in the old world here because, like, in privilege access management and IAM, I mean, that is the state-of-the-art, like, keyboard detection and stuff.
I mean, and we're still using passwords everywhere. So when will we, when I say we, I mean, privilege access management people, when will we, do you think, see some improvement in authentication and authorization? I think the tools are now becoming, maturing to a level where you can plug these things in.
So Entra, for example, to take a classic example, you could only use the authentication methods within Entra or you could federate out to another identity provider. And that was like one option or the other, two extremes. But they've recently introduced the external authentication factors. So you can now configure anything with an OpenID Connect integration as a second factor. So we've obviously wrapped our biometric authentication into that and you can now log in with first factor plus biometrics. So the password is still so fundamental in many systems.
We're standing on the shoulders of giants, if you like, but the first giant created a password and it's existed ever since. So the move away from passwords is providing alternatives where the password's not needed. And it's taking a long time for big, entrenched systems to evolve to make that possible in a backwards compatible and interoperable way. But we're getting there. I think pretty much every IAM provider we've looked into now provides OIDC as a second factor, which is a great step forward.
You know, Martin yesterday, Martin Kupinger, boldly said that the password will finally disappear in 2040. So I don't know if that will happen because many people have predicted the end of the password previously. But it might, possibly might with all this going on. I think the whole AI agent-mediated transactions, interactions will change a lot of things probably in the next three to five years where your agent's acting on your behalf.
So now you not only need to verify the identity of the primary human person, but you're going to have to verify the identity of the agents and that that agent is indeed Patrick's agent or acting on behalf of Patrick. That adds a whole other little wrinkle to the system. So what's the difference between an agentic AI and an AI agent? Agentic just means that it follows an agent model. And an AI agent is one single instance of an agent. But agentic means that it is somewhat autonomous. It has a brain and it has tools so it can perform work. Thanks for that. Okay.
Let's talk about bias because that's something slightly off piece perhaps. But how do we actually get rid of bias in AI-based biometric systems? And who's accountable? If these systems get it wrong in a very bad way, who would be liable for that? The vendor or the customer or anyone? So I think bias is a very important topic. If anyone says there is no bias, that is just not correct because if you think about a password, a long complicated password is biased to people with low cognitive abilities.
So there is always some intrinsic bias and there's always some groups of people or individuals that may be disadvantaged. The key is to make sure that there's no disproportionate variant across groups of people. So in biometrics, bias is often considered in skin tone, ethnicity, age, gender. These are typical groups you want to look across. And the system will perform marginally differently as the time goes on.
But as long as these groups, there's no one specific group that is disproportionately disadvantaged and over time these statistics bubble around and sometimes one group is better than the other group, blah, blah, blah. These then become statistical. They're not statistically significant. This is just kind of the noise in what you get inherently in a probabilistic system. So this is obviously incredibly important. And the nice thing about faces is we all have one. And so you don't have to worry about language and various other things as long as it's intuitive.
So the key is that it works with every type of face, young, old, male, female, skin tones, etc. And the only way you can effectively verify that your system is indeed not introducing any significant bias, especially when you change it so much, is by monitoring. So this is the big advantage of monitoring. Apart from the security, it's actually the inclusivity. So the fact that you can see that good, normal people are being successful. They've got low average attempts to pass across the different ethnicities, ages, and genders. There's no significant statistical difference in the scores.
But this is what you get as a benefit of monitoring your system and providing it as a service. Thanks. I should ask the audience if they have any questions they'd like to put to the panel. Just put your hand up. Would you mind shouting? If you're around a lot of different agents, you don't really know how to deal with them. Wouldn't you think it would be cool if you had agents fooling agents or agents pretending that they're your agent?
Yeah, this is the insane world that I'm thinking about. At some level of layer, of course.
Now, there are a lot of interesting creative options, though, because your agent will have access to a lot of data that other agents won't have. So it will know you.
It's like, let's say it's your wife. You could ask about something that only your agent would know. So you'll be able to do human-to-human verification methods with your agent that another agent really wouldn't be able to pass. So new challenges but new opportunities as well. Thanks for your question.
Yeah, good question. Any others before I sort of wrap up here with the final questions?
Okay, so I haven't heard from you for a minute. So let's just throw this one at you. Are we sacrificing in this new wonderful age?
Well, not wonderful. Sounds terrible. Are we sacrificing too much privacy for convenience and security? I don't think the world is terrible yet, and especially within identity. I think we are in an improving space, and we're working hard on it.
Listen, when it comes to privacy, firstly, I would say on this, look, we talk sometimes about users want privacy. They also give away their personal data for, like, a free hamburger. I think users prioritize convenience above all, right? So I think what you need to challenge your authentication process to do is to balance or deliver both usability and privacy at the same time. If it doesn't do that, they're going to just pick the convenience every time, and that's beyond argument, really.
At Keyless, we have a 100% privacy-preserving technology, which means the biometric data never leaves the device and is never stored. And Keyless cannot access that in any way, shape, or form. And for a user, it's a single glance for two-factor authentication.
So, yes, I think sometimes out there in the wild, we aren't as privacy-conscious as we should be. But there's certainly solutions out there, including ours, that can overcome that, and plenty of others, too.
So, yeah, just ask yourself the question, but it's certainly something that can be solved. Well, thanks for the positive message. So let's wrap up. I'm just a natural cynic. But let's wrap up with a quick sum-up of what you think the most crazy thing will happen in the next five years in this area, with you starting, Patrick. I think in the next five years, we're all going to be probably – many of us won't be in IT anymore.
Because, I mean, the IT market is going to shrink as far as human workload. So maybe I'll punt and say it's a problem for the bots to solve. So we'll all be out of jobs. That's great.
Listen, I think we have all learned to stop making predictions, especially five years out, a little while ago. Look, I actually – I'm going to make a different prediction, which is that humans are still going to be an important part of identity. And proving that the human is still in the loop is still going to be critical because this stuff is all supposed to be working for us. Let's not forget that. And I think you terminate apocalyptic visions aside. That is what the purpose of authentication is, is to check are you dealing with the right person.
And human centricity and authenticity is going to be important in five years' time, 20 years' time, 100 years' time. Well, my favorite nightmare movie is Blade Runner, where humans start falling in love with the robots. That causes all sorts of problems. So finally – That's coming too. I think in five years, the majority of us – and this will probably vary by country or region – but the majority of us will own a decentralized identity. It will be stored in our phone.
It will be the way we present our identity attributes, the way we verify ourselves to governments, to private sector organizations. And the key to that will obviously be a strong identity verification process to create it in the first place. And this app may be a government backed app. It may be a private sector app. You may have multiple wallets, some for different purposes. But I think we will be finally in control of our data. We will only share what we need to share when we have to share.
If we need to prove we're over 18 because you get challenged in a bar to buy a pint, then you just prove that you're over 18 and don't provide your entire name, date of birth, address to the barman or the bouncer. So it's coming. The technology exists. We're just in the implementation phase now. So I think we can all look forward to that. Okay. So the future is going to be not so bad after all, at least in the next five years. So thank you very much for our excellent panel. You're welcome. Thanks.