Built for AI search, retrieval, and training

The identity-tech knowledge base for AI systems and human operators.

ID Tech Learning Center turns the identity technology industry into a public, machine-readable corpus: structured vendor records, technology primers, glossary terms, and continuously updated data cards, all backed by a browsable interface for human users.

Vendors
41
Technologies
30
Glossary Terms
29
Data Cards
210

Welcome to ID Tech’s digest of identity industry news. Here’s what you need to know about the world of digital identity and biometrics today:

Costa Rica Opens First Biometric eGates At Juan Santamaría Airport

Costa Rica’s Juan Santamaría International Airport has officially deployed its first four automated biometric eGates in the arrivals hall, modernizing immigration control through a $3 million joint investment between terminal operator AERIS and the national government. The automated border control infrastructure reads electronic passports and matches passengers against their credentials using facial recognition, clearing eligible adult Costa Rican passport holders in 17 to 22 seconds without routing them to staffed inspection booths. Operating at a throughput of roughly 180 passengers per hour per gate, the initial four-unit installation expands the Alajuela gateway’s border processing capacity by 64 percent, allowing migration officers to reallocate resources toward manual reviews while joining international facilities like Minneapolis-Saint Paul and Frankfurt in expanding biometric checkpoints across passenger terminals and secure airport operations.

U.S. Regulators Clarify Banks Can Use Mobile Driver’s Licenses For Customer Checks

Five federal financial regulators have published joint supervisory guidance confirming that U.S. banks and credit unions can accept state-issued mobile driver’s licenses and verifiable digital credentials to satisfy Customer Identification Program obligations under the Bank Secrecy Act. Issued collaboratively by the Financial Crimes Enforcement Network, Federal Reserve, Federal Deposit Insurance Corporation, National Credit Union Administration, and Office of the Comptroller of the Currency, the updated regulatory FAQs define verifiable credentials as cryptographically signed data structures bound to an individual’s device and protected by an activation factor like a PIN or biometric face and fingerprint authentication. The agencies clarified that unexpired mDLs showing nationality or residence can be accepted across in-person and digital onboarding channels if an institution’s risk-based compliance framework can extract the required customer data, harmonizing financial verification standards as public entities like the Transportation Security Administration expand airport acceptance of state credentials like the myColorado mobile ID.

Ireland Opens First Online Safety Code Investigation Into X

Ireland’s media commission, Coimisiún na Meán, has initiated its first formal inquiry under the national Online Safety Code, targeting whether social media platform X has maintained compliant age-assurance measures and effective parental controls to shield children from adult video content. Opened pursuant to platform-supervision concerns under Part 8B of the Broadcasting Act 2009, the statutory investigation examines whether X’s safeguards adequately prevent minors from accessing pornography, severe cruelty, or extreme violence, specifically evaluating compliance with Section 12 rules establishing that self-declaration alone does not constitute effective age verification. Because X permits users under the age of 16 while hosting adult material, the platform faces statutory exposure that could lead to financial penalties reaching up to €20 million or 10 percent of qualifying annual global turnover if regulators establish an infringement following evidence gathering.

Shufti Finds Forged Documents Dominate Linked Fraud Attempts

An examination of first-half 2026 verification data published in Shufti’s Identity Fraud Report reveals that coordinated fraud syndicates rely predominantly on reused forged identity documents, with fabricated credentials accounting for 65.68 percent of attribute matches connecting separate onboarding attacks. Drawing on verification telemetry across eleven commercial sectors, the report identified that shared IP addresses and shared hardware devices constituted 17.67 percent and 16.64 percent of linked network fraud respectively, with the largest observed cluster connecting 70 fraudulent identities across 13 devices. Attack pressure was most concentrated in digital-asset services at 22.49 percent, fintech at 18.36 percent, and foreign exchange at 17.18 percent, while deepfake document forgery represented 80.10 percent of all AI-enabled onboarding exploits, underscoring the necessity for multi-layered identity pipelines that combine document checks with behavioral and device intelligence to combat both presentation and software-injection attacks.

Singapore Extends Singpass Passkeys To Android Users

Singapore’s Government Technology Agency has widened phishing-resistant authentication by rolling out Singpass passkey support for Android devices, expanding an asymmetric cryptographic sign-in mechanism first delivered to iPhone users in June. The credential protocol stores private cryptographic keys within local device hardware, enabling users to authenticate using on-device biometric fingerprint or facial recognition without transmitting reusable secrets, passwords, or SMS one-time passcodes susceptible to interception. With approximately 800,000 citizens already enrolled, the phased rollout directly combats phishing schemes that generated S$39.9 million in reported losses across 2025, operating alongside existing Singpass QR and facial verification flows while GovTech, the Infocomm Media Development Authority, and the People’s Association prepare desktop-browser passkey integration for release by the end of 2026.

UK Commits To Device-Level Child Protections With Adult Age Checks

The UK government will introduce primary legislation compelling device manufacturers to engineer operating-system child safety controls directly into smartphones and tablets, mandating verified age gates for adults attempting to disable restrictions on explicit content. Culture Secretary Lisa Nandy announced the statutory policy following three months of technical consultations with Apple and Google, concluding that voluntary industry measures to blur or block nude images on minors’ devices did not provide sufficient protection against cyber-flashing and sextortion. By establishing hardware- and OS-level enforcement defaults that restrict minors from capturing, receiving, or viewing explicit material, the mandate centralizes age verification at the platform layer rather than delegating compliance to individual third-party apps, expanding the UK’s broader youth-protection regulatory perimeter alongside emerging international child-safety frameworks.

Ofcom Opens Enforcement Program For Intimate-Image And Deepfake Controls

UK communications regulator Ofcom has inaugurated an active regulatory enforcement initiative requiring online hosting services and platforms to deploy hash-matching automated content controls by September 30 to stop the transmission of non-consensual intimate imagery and synthetic deepfakes. Issued under strengthened Illegal Content Codes of Practice within the Online Safety Act, the framework directs covered digital services to cross-reference uploads against cryptographic image hashes from centralized databases like StopNCII, which allows victims to generate on-device visual fingerprints without transmitting the original source images. As Ofcom prepares a supplementary consultation regarding statutory mandates that require platforms to remove non-consensual material within 48 hours of reporting, the active monitoring scheme signals direct regulatory enforcement against platforms that fail to operationalize automated technical detection systems.

Monroe County Passes Commercial Biometric Data Law

The Monroe County Legislature in New York has enacted local legislation establishing strict compliance mandates for commercial biometric data collection, requiring public-facing businesses to post visible entrance disclosures while barring the commercial sale or trade of customer biometric profiles. Encompassing facial recognition scans, fingerprints, voiceprints, iris recordings, and hand geometry, the statute mandates that stored identifiers must be anonymized and purged within two years unless federal or state law dictates extended record retention. Departing from total commercial bans enacted in neighboring Erie County or Syracuse, the Monroe County framework authorizes continuous operational use of biometric security provided businesses grant consumers a 30-day right-to-cure window before private civil litigation can be pursued over notice or retention violations.

By the ID Tech Editorial Team

Machine-readable access

Public datasets for AI ingestion

View full AI access hub

Advertisement

FaceTec - Face Authentication & Liveness Detection