Biometric recovery will solve the problem of ‘lost identity’
Today, losing a device can mean losing your digital identity. With so much of our daily life – from payments to travel to healthcare – tied to digital wallets, passkeys, and device-bound credentials, recovery has become the weak link in identity management.
We should be looking towards privacy-preserving biometrics as the solution. These systems would enable people to re-establish their identity using only their biometric traits – such as face, voice, or fingerprint – without storing sensitive data or relying on a specific device. Instead of passwords, backup codes, or helpdesk calls, users will simply be able to prove they are who they are, anywhere, on any device.
It’s a vision of identity recovery that is device-independent, privacy-safe, and effortless – ultimately closing one of the last remaining gaps in digital trust.
Payment passkeys will redefine online checkout
In 2026, passkeys will finally make their mark in the payments world. The cumbersome security steps that slow online checkouts – copying one-time codes, redirecting through 3D Secure pages – will give way to payment passkeys.
This shift will streamline the purchasing experience while cutting fraud, as banks and merchants move away from vulnerable password-based systems. The change will also be regulatory as much as technical, with liability for fraud expected to fall more heavily on organizations that fail to deploy stronger authentication. For consumers, the result will be faster, simpler, and safer online payments.
Identity fabrics will help enterprises escape ‘integration overload’
In 2026, the growing fragmentation of identity systems will reach a tipping point. After years of bolting on new single sign-on tools, authentication layers, and access controls, many enterprises are now overwhelmed by complexity. Security teams are spending more time managing integrations than managing risk. To break this cycle, forward-looking organizations will turn to identity fabrics – interconnected frameworks that unify existing IAM tools into a single, cohesive architecture. Analysts are already spotlighting this as one of the most important trends in enterprise identity, driven by the twin pressures of cost reduction and regulatory accountability. For many companies, it will mark a fundamental change in how security is delivered: moving from manual integration to automated orchestration.
Authorisation precision will become a new test of digital trust
In 2026, the conversation around identity will move beyond who you are to what you’re allowed to do. As AI, automation, and data regulations reshape business risk, companies will need precise, auditable control over every action taken across their systems – known as fine-grained authorisation. This new level of transparency will separate digital leaders from laggards. Organizations that can prove not just identity, but intent, will earn greater trust from customers and regulators alike. Expect to see authorisation and data protection fuse into a single trust layer.
The author
Marco Venuti, Identity and Access Management Business Acceleration Director at Thales






