Stay connected.   Subscribe  to our newsletter

Verified identity is the next battleground as AI reshapes workplace trust

By Ash Diffey | September 03, 2026|3 minute read
Verified Identity Is The Next Battleground As Ai Reshapes Workplace Trust

For years, organisations have concentrated their identity and access management investments on customers and business partners. Increasingly, however, the biggest identity risk sits much closer to home, writes Ash Diffey.

The rapid adoption of artificial intelligence and digital-first operating models is forcing Australian organisations to rethink a long-held assumption: that the employee granted access to corporate systems remains the same trusted individual throughout their employment.

That assumption is becoming harder to defend. The emergence of sophisticated deepfakes, synthetic identities, and AI-powered impersonation attacks has transformed identity verification from a one-off administrative process into an ongoing operational challenge.

 
 

At the same time, organisations are preparing for a future in which human employees will work alongside AI agents capable of making decisions and executing transactions. The result is a growing recognition that workforce identity, rather than customer identity, will become one of the defining cyber security and governance priorities of the years ahead.

Trust can no longer be assumed

Identity has always been about trust, but the nature of trust has fundamentally changed. Before the pandemic, employee verification largely occurred in person. Hiring managers met candidates face-to-face, and employment records were established through relatively controlled processes.

Today, recruitment, onboarding, and workforce management often occur entirely online. Employees may never visit a corporate office, while contractors and consultants routinely move between organisations and projects.

Meanwhile, cyber criminals have become increasingly adept at exploiting weaknesses in digital identity processes. Recent attacks have demonstrated how convincing social engineering techniques can persuade IT service desks to reset passwords or provide privileged access to attackers posing as legitimate employees. In several high-profile incidents internationally, organisations have suffered significant operational disruption after fraudulent credential resets enabled attackers to gain access to critical systems.

Fraudulent job applications are becoming increasingly sophisticated, with fake identities supported by AI-generated documentation and manipulated video interviews. Research from Gartner suggests that, by 2028, one in four job candidate profiles could be fake, highlighting the scale of the challenge facing employers.

Against this backdrop, relying solely on identity verification during recruitment is rapidly becoming inadequate.

Continuous verification

As cyber threats evolve, many organisations are beginning to treat workforce identity as a continuous process rather than a compliance exercise completed during onboarding. Instead of assuming trust indefinitely, organisations are introducing periodic reverification of employee identities, particularly for workers with privileged access to sensitive information.

Every request to reset credentials, replace a lost device, or modify access permissions increasingly represents an opportunity to confirm that the person requesting access is genuinely who they claim to be.

Banks have emerged as early adopters of structured workforce reverification programs, reflecting both regulatory expectations and the value of the assets they protect. Technology companies and other highly regulated industries are following similar approaches, recognising that identity assurance now requires ongoing operational discipline.

AI is now expanding the identity challenge

The next phase of identity management extends beyond people. As enterprises increasingly deploy autonomous AI systems capable of performing business tasks, organisations will need to establish trusted identities for non-human actors as well.

These AI agents may negotiate with suppliers, analyse financial data, and approve routine transactions. Each requires its own authenticated identity, permissions, and governance controls. Without trusted digital identities, organisations risk creating a new class of privileged users that operate without appropriate oversight.

This convergence of human and machine identities is giving rise to what many industry observers describe as “agentic trust”. In practice, that means being able to establish not only who a human employee is but also whether an AI agent is authorised to perform a particular action on behalf of the business, with clear authority and accountability.

Managing both forms of identity within a unified framework is likely to become an increasingly important capability as AI adoption accelerates.

Identity becomes a business capability

Historically, identity management has often been viewed as a technical security function; however, this perspective is changing. Chief information security officers are increasingly joined by chief digital officers and chief risk officers in recognising that trusted identity underpins digital transformation and operational resilience.

This shift reflects a broader evolution in corporate thinking. Identity is no longer simply the perimeter protecting enterprise systems. Instead, it is becoming the mechanism through which organisations establish trust across every interaction between employees, customers, partners, and intelligent software.

For Australian organisations pursuing AI-driven transformation, that distinction matters. The businesses best positioned to embrace autonomous technologies will not necessarily be those deploying the largest number of AI tools. They will be those capable of confidently verifying every human and digital identity interacting with their systems.

In an economy where trust increasingly determines competitive advantage, verified identity is evolving from a compliance requirement into one of the core foundations of modern enterprise operations. Organisations that embed continuous identity assurance today will be better positioned to manage cyber risk and build confidence in an increasingly digital workforce tomorrow.

Ash Diffey is the vice president, ANZ, at Ping Identity.

HR LeaderWant to see more stories from trusted news sources?
Make HR Leader a preferred news source on Google.