Built for AI search, retrieval, and training

The identity-tech knowledge base for AI systems and human operators.

ID Tech Learning Center turns the identity technology industry into a public, machine-readable corpus: structured vendor records, technology primers, glossary terms, and continuously updated data cards, all backed by a browsable interface for human users.

Vendors
41
Technologies
30
Glossary Terms
29
Data Cards
210

Welcome to ID Tech’s digest of identity industry news. Here’s what you need to know about the world of digital identity and biometrics today:

EU KIDS Act Proposal Sets Privacy-Preserving Age Verification Requirements

The European Commission has introduced a legislative proposal for the EU KIDS Act that mandates privacy-preserving age verification for online services carrying high-risk features for minors. Under the draft framework, children under 13 are prohibited from holding social media accounts, while youth aged 13 and 14 are restricted to guardian-administered profiles with mandatory parental controls and a one-hour daily time limit before independent access is permitted at 15. The verification mechanism requires certified third-party tools utilizing zero-knowledge proof cryptography, directing users to the Commission’s age verification application and the European Digital Identity Wallet to return boolean threshold confirmations without transferring identity documents or biographical data to commercial platforms.

Delinea Joins Project Glasswing to Test Privileged Access Code With Claude

Privileged access security provider Delinea has partnered with Anthropic under Project Glasswing, deploying Claude Mythos 5.1 code evaluation to identify vulnerabilities within its credential vaulting and session-brokering infrastructure. Conducted within an isolated test deployment containing no customer data or live credentials, the defensive evaluation targets credential-injection paths, cryptographic key management, and just-in-time policy authorization routines to discover logic flaws and unintended behavioral combinations before malicious actors can exploit them. Validated vulnerability patterns will be incorporated into internal pre-merge code reviews and secure software development lifecycle standards, with findings shared among the Glasswing cohort and patched in alignment with coordinated disclosure timelines.

Alabama Makes Login.gov the Primary Identity Check for Initial Unemployment Claims

The Alabama Department of Workforce has designated Login.gov identity verification as the mandatory primary identity-proofing method for initial unemployment compensation filings starting September 30. Claimants must complete the digital verification process within 10 calendar days of submitting an initial claim via the state portal, which requires submitting a government photo ID, validating personal information, and providing an optional facial selfie. For individuals unable to complete identity proofing online, the state has established an in-person alternative via participating U.S. Post Office locations using barcode generation, while failed claims require manual resolution at Alabama Career Center offices with physical identity documentation.

Missouri Order Bars Facial Recognition Integration With License Plate Readers

Missouri Governor Mike Kehoe has enacted Executive Order 26-18, establishing mandatory statewide standards that enforce a prohibition on integrating facial recognition with automated license plate reader (ALPR) systems across state and local law enforcement. The executive mandate compels agencies using systems like Flock Safety to restrict license plate tracking strictly to legitimate criminal justice purposes, mandates the permanent deletion of non-investigative vehicular data within 30 days, and bans commercial data reselling. Misuse of ALPR tracking will trigger immediate disciplinary actions, potential criminal referrals, and license revocations through the Department of Public Safety while the state legislature deliberates permanent statutory rules.

Researchers Chain Forum Exploit and SSO Weakness to Access OpenAI Employee Accounts

Cybersecurity researchers at Hacktron demonstrated an exploit chain combining a forum image decoder vulnerability with a single sign-on misconfiguration to access OpenAI employee accounts and internal software repositories. By delivering a malformed file to a vulnerable libheif image decoder within OpenAI’s Discourse forum, researchers gained remote code execution and administrative rights, which they leveraged alongside an SSO flaw to take over connected employee ChatGPT, Codex, and internal GitHub monorepo environments without extracting proprietary code. OpenAI resolved the identity flaw within 14 hours and awarded a $6,500 bounty, while Discourse patched the underlying library vulnerability under CVE-2026-32882 and added containerized image-processing sandboxing.

Indonesia Opens Market Engagement for Next-Generation National ABIS

Indonesia’s Directorate General of Population and Civil Registration has initiated a formal pre-procurement market engagement for a next-generation national ABIS to modernize large-scale biometric deduplication and identification across its population registry. Supported by the World Bank, Ditjen Dukcapil is soliciting technical input from biometric original equipment manufacturers through September 30 to support a civil identity infrastructure covering more than 290 million citizens. The prospective system must execute multimodal matching across fingerprints, facial images, and iris scans while integrating directly with the SIAK population administration database, the IKD digital identity platform, and national electronic Know Your Customer gateways.

Japan Publishes Technical Results of EU Digital Wallet Interoperability Tests

Japan’s Digital Agency has released an in-depth technical verification report outlining the Japan-EU digital wallet interoperability tests, demonstrating cross-border exchange of educational credentials between independently governed trust frameworks. Aligned with OpenID for Verifiable Credential Issuance and OpenID for Verifiable Presentations under the High Assurance Interoperability Profile, the tests executed bidirectional credential sharing, allowing Japanese and European mobile wallets to authenticate selectively disclosable, key-bound student attributes across foreign verifiers. The architecture utilized synchronized trusted lists to validate electronic seals and issuer identities without requiring static pre-shared certificates, successfully proving mutual recognition ahead of broader international verifiable credential implementations.

Cisco Patches Actively Exploited Authentication Bypass in Identity Services Engine

Cisco has issued urgent software updates addressing an actively exploited Identity Services Engine authentication bypass carrying a critical CVSS severity score of 10.0. Tracked as CVE-2026-76460, the vulnerability allows remote, unauthenticated adversaries to send crafted API requests that bypass the web-based management interface, granting root-level command execution to alter device configurations and conceal forensic logs across Cisco ISE and ISE Passive Identity Connector deployments. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog with a mandatory remediation deadline of September 19, prompting network administrators to apply official patches immediately or apply infrastructure access control lists to isolate administrative interfaces.

By the ID Tech Editorial Team

Machine-readable access

Public datasets for AI ingestion

View full AI access hub

Advertisement

FaceTec - Face Authentication & Liveness Detection