Built for AI search, retrieval, and training

The identity-tech knowledge base for AI systems and human operators.

ID Tech Learning Center turns the identity technology industry into a public, machine-readable corpus: structured vendor records, technology primers, glossary terms, and continuously updated data cards, all backed by a browsable interface for human users.

Vendors
41
Technologies
30
Glossary Terms
29
Data Cards
210

Welcome to ID Tech’s digest of identity industry news. Here’s what you need to know about the world of digital identity and biometrics today:

Device Intelligence Is No Longer a Proxy for Identity Trust

Regula executive Henry Patishman argues that relying on device intelligence as an identity proxy creates an untenable security gap known as identity drift, where a familiar hardware environment remains intact while the actual actor controlling the session has changed. Driven by risks including remote zero-click exploits, banking malware like Brokewell, and autonomous AI agents susceptible to prompt injection, familiar device signals can no longer guarantee the live presence or identity of the legitimate user. Highlighting Regula research where only 5 percent of respondents ranked device signals as their most trusted identity evidence compared to 37 percent for biometrics, the analysis advocates for NIST SP 800-63A-4 aligned architectures that verify the human actor at critical inflection points through fresh biometric liveness, hardware-backed capture integrity checks, and auditable proofing logs rather than environmental familiarity.

New MyKad Holders Face Temporary MyDigital ID Registration Barrier

Malaysian citizens issued the newly redesigned physical MyKad national identity card are experiencing a temporary MyDigital ID registration barrier that prevents first-time online enrollment via the mobile app until software updates deploy on October 1. The disruption stems from structural alterations on the new card, which moved the embedded microchip to the back and shifted the citizen photograph from the right side to the left, causing mobile scanning failures during digital capture and commercial eKYC checks across partner banking applications. While existing digital certificate holders remain unaffected and National Registration Department records confirm older MyKad versions stay valid, new recipients requiring immediate first-time digital activation must bypass the mobile application and enroll in person at one of nearly 700 physical MyDigital ID kiosks equipped with facial biometric verification.

North Yorkshire Schedules First Live Facial Recognition Deployment

North Yorkshire Police will initiate the force’s first live facial recognition deployment on September 23 in York city center, using mobile vehicle-mounted cameras to scan public crowds against targeted operational watchlists. Authorized following data protection and scope reviews led by Deputy Mayor for Policing, Fire and Crime Jo Coles, the system converts faces in public transit corridors into biometric templates, triggering human officer assessments only when a mathematical similarity score passes predefined match thresholds. Biometric templates that fail to trigger watchlist matches will be deleted immediately, and the police department has committed to publishing formal deployment metrics within seven days alongside public oversight mechanisms to ensure the overt surveillance vehicles operate strictly within lawful, proportionate parameters.

Vanguard Biometrics Introduces Guided LiveScanID Fingerprint Software

Biometric software provider Vanguard Biometrics has officially launched guided LiveScanID fingerprint software, an operational capture platform engineered to streamline civil background checks, professional licensing, and employee screening for certified service providers. The software provides real-time visual feedback and workflow prompts during the physical capture appointment, minimizing operator error and rejected prints before applicants leave the facility while consolidating supporting identity documentation, acknowledgments, and enrollment logs into structured, cloud-based storage. By integrating client feedback directly into administrative routines and document workflows, the system targets routine identity verification providers seeking standardized recordkeeping without relying on disconnected local storage practices.

Interior Plans Clearview AI Access for Missing-Person and Trafficking Investigations

The U.S. Department of the Interior has issued a sole-source federal procurement notice to acquire Clearview AI investigative facial recognition accounts dedicated to the Bureau of Indian Affairs’ Office of Justice Services and its Missing and Murdered Unit. The proposed firm-fixed-price contract will supply six user accounts to federal investigators handling human trafficking, internet crimes against children, and an estimated 4,200 unresolved cases involving missing and murdered Indigenous persons. Operating alongside existing federal deployments across agencies like Immigration and Customs Enforcement, the platform compares case photos against publicly scraped web imagery to generate investigative leads, with competing vendors invited to submit capability statements ahead of formal contract finalization.

Tesla App Adds Passkey Setup for Account Sign-In

Automaker Tesla has introduced native passkey setup for iOS sign-in in version 4.61.0 of its mobile application, allowing vehicle owners to authenticate without passwords using Face ID, Touch ID, or their device passcodes. Managed within the profile settings under Security and Privacy, the deployment implements FIDO Alliance cryptographic standards, binding an asymmetric public key to Tesla’s authentication servers while keeping the corresponding private key safeguarded on the user’s Apple device. By anchoring access to on-device biometrics and phishing-resistant public-key cryptography, the rollout protects user accounts and linked vehicle functions against remote credential stuffing, session replay, and phishing attacks.

India Requires Aadhaar Biometric Checks for Regulated-Price LPG Refills

The Indian Ministry of Petroleum and Natural Gas has mandated Aadhaar biometric authentication for LPG refills at regulated retail prices beginning October 1, linking subsidized fuel distributions directly to the national digital identity registry. With 274.3 million domestic consumers (89.9 percent of the market) already verified by September 19 following an extensive outreach campaign, remaining customers must authenticate through distributor showrooms, delivery agent terminals, or official oil marketing apps like IndianOil ONE, HelloBPCL, and HP PAY. Consumers who decline or cannot complete biometric checks will be barred from subsidized rates, though suppliers permit them to purchase unsubsidized 5-kilogram or 10-kilogram cylinders at prevailing commercial market prices.

Toss and CGV Plan FacePay at Cinema Ticket and Concession Kiosks

South Korean financial technology company Toss and multiplex operator CJ CGV have signed an agreement to deploy FacePay facial recognition payments across self-service cinema ticketing and concession kiosks, beginning at CGV Yongsan I Park Mall in Seoul. The deployment integrates Toss Front camera units directly into CGV’s existing kiosk hardware, enabling registered users to purchase movie admissions and food concessions without physical credit cards, mobile wallets, or cash. Expanding Toss’s biometric payment footprint beyond convenience store chains like GS25, CU, and 7-Eleven—which helped the platform surpass one million users and 240,000 merchant locations—the cinema rollout incorporates active liveness detection and transaction monitoring to prevent presentation attacks at unstaffed point-of-sale terminals.

Gyeonggi Opens Employee Verification Portal to Counter Official-Impersonation Scams

South Korea’s Gyeonggi provincial government has launched a public employee verification portal against impersonation scams, providing businesses and residents with real-time tools to cross-reference individuals claiming to represent the provincial administration. Established after authorities logged 183 scam attempts from 2025 through September 2026 resulting in 351.7 million won in fraudulent procurement and advance-payment losses, the portal matches an official’s claimed name, department, phone number, and email address against live civil service personnel databases. To ensure security beyond digital record matching, the administration advises procurement targets and contractors to place direct confirmation calls to the validated telephone numbers before issuing goods, processing wire transfers, or executing contracts.

CrowdSec Traces Repository Leak to Former Employee’s Stolen GitHub Token

Open-source cybersecurity firm CrowdSec disclosed that an external threat actor leveraged a stolen GitHub OAuth token belonging to a former employee to clone approximately 170 private code repositories during a nine-minute breach on May 22. Originating from a broader supply-chain compromise targeting TanStack software packages, the stolen credential retained authorized repository access because the organization had intentionally left the departed employee’s account active to finalize project transitions. While codebases and build pipelines remained unaltered, the unauthorized repository clone exposed an AWS notification service token, 83 user emails, and legacy records associated with 51 prospective investors from 2020, prompting CrowdSec to revoke the credentials, implement workstation endpoint protection, and mandate strict credential rotation policies.

By the ID Tech Editorial Team

Machine-readable access

Public datasets for AI ingestion

View full AI access hub

Advertisement

FaceTec - Face Authentication & Liveness Detection