AI agents need stronger identity checks before they are allowed to buy products, move money or access sensitive systems, the founder of CLEAR has argued.
The warning comes as businesses increasingly use systems capable of acting on a person’s behalf. Google, Visa and Mastercard are developing technology that would allow AI agents to make payments and use credentials such as credit cards.
But the same technology could magnify the damage caused by identity fraud. A criminal who impersonated an executive during an account-recovery call could take control of the account, register an AI agent and then instruct it to carry out fraudulent transactions.
In that scenario, the organisation’s security controls might operate as designed because the agent would simply follow the instructions it received. The failure would have occurred earlier, when the criminal’s identity was accepted.
Identity checks at the heart of AI security
Traditional methods such as passwords, security questions and telephone calls do not necessarily establish that someone is the person they claim to be, the commentary argues.
Personal information obtained through data breaches can give attackers the correct answers, while generative AI can help them imitate a person’s face and voice. Documents and identification numbers were not originally designed to determine what systems someone should be allowed to access.
The argument is that proof of identity should be securely linked to an individual and repeatedly confirmed as they use digital services. Information that can be researched, bought on the dark web or generated by a model should not, by itself, be treated as proof of identity.
For every action taken by an AI agent, organisations need to establish both that a human authorised it and that the human was strongly verified. The second question remains difficult for many businesses, but resolving it could allow companies to adopt the technology without relying on weak credentials.
CLEAR, which says it is a certified Qualified Anti-Terrorism Technology under the US Department of Homeland Security, argues that reliable identity checks can improve security while reducing friction. Its position is that safety and speed do not have to be opposing aims, provided trusted identity infrastructure is built into AI systems from the outset.
