Deepfakes, AI Agents, and the Collapse of Traditional Identity Security
The Business of CybersecurityMay 27, 2026
34
00:26:5324.62 MB

Deepfakes, AI Agents, and the Collapse of Traditional Identity Security

How do you defend trust in a world where AI can imitate voices, generate highly convincing phishing attacks, and automate fraud at a scale humans can barely keep up with?

In this episode of Business of Cybersecurity, I sit down with Mary Ann Miller from Prove to discuss how AI is reshaping fraud, identity, and cybersecurity in ways many organizations are still struggling to understand fully. With decades of experience across banking, fintech, and fraud prevention, Mary Ann brings a unique perspective on the growing collision between customer experience, digital identity, and AI-driven attacks.

We explore how cybercriminals are using contextual AI-powered phishing campaigns that feel increasingly believable, why account takeover attacks are evolving into AI-assisted operations, and what happens when human intuition is no longer enough to identify deepfakes and manipulated content online. Mary Ann explains why the traditional idea of identity verification at login is beginning to break down, especially as one-time passwords and legacy authentication methods become easier to exploit.

The conversation also examines the rise of “continuous identity,” in which organizations must continually evaluate trust signals across the customer journey rather than relying on a single authentication event. Mary Ann shares why many organizations are investing heavily in AI innovation while simultaneously lacking the controls needed to defend themselves against AI-driven fraud. We also discuss how non-human identities, AI agents, and automated interactions are introducing new risks that many businesses are still unprepared for.

There is also a fascinating discussion around how AI has quietly powered fraud detection systems for decades, from early neural networks monitoring payment anomalies to today’s far more advanced machine learning systems. But as organizations race to introduce AI-powered customer experiences, Mary Ann warns that customer trust and adoption cannot be taken for granted. She shares the example of Walmart reportedly seeing a major drop in conversions during an AI-driven commerce experiment, highlighting how businesses are still learning where AI genuinely improves experiences and where it creates friction.

Mary Ann also offers practical advice for boards and security leaders on how to proactively test their defenses through fraud red-team exercises, why organizations need to recognize AI-generated attack patterns earlier, and how businesses can rethink identity in a world where both humans and machines participate in digital interactions.

If you care about the future of trust, authentication, fraud prevention, and cybersecurity in the AI era, this conversation offers a valuable look at the challenges already unfolding behind the scenes.

Useful Links

Visit our Sponsors

Check out the Nordlayer Browser

[00:00:00] - [Speaker 0]
A big thank you to Denodo for helping me make more than 60 monthly interviews possible across the Tech Talks network. And as businesses move from GenAI to Agentic AI, trusted data becomes everything. Everything from GenAI to Agentic AI, Denodo is helping organizations build intelligent, secure, and scalable AI solutions with data access, governance, and explainable results. So build AI that you can trust and do it with Denodo. And you can learn more by simply visiting denodo.com.

[00:00:43] - [Speaker 0]
What if the person logging in to your bank account isn't a person at all? Not a hacker in a hoodie, not someone halfway across the world guessing your password, but an AI system that knows just enough about you, your habits, your bank, and even the exact moment that your bank updates its website, all in a way to sound completely convincing. And here's the incredibly uncomfortable part. Most of us would still trust it, and today's conversation sits right at the center of that tension between trust and deception. Because while businesses are racing to adopt AI, the very thing that holds everything together, which is identity, this is something that's starting to crack under the pressure.

[00:01:33] - [Speaker 0]
So joining me today is someone who has spent decades right in the middle of this world. Her name's Mary Anne Miller, and she's a fraud and cybercrime executive adviser and VP of client experience at a company called Prove. And she is someone that has advised banks, fintechs, and global institutions, And she's seen firsthand how fraud has evolved long before most of us even knew it existed. And from her time, everything from PayPal and Lloyd's banking group through to her work with the Federal Reserve, Mary Anne brings a perspective that cuts through the hype and gets into exactly what is happening right now in front of us and behind the scenes. So today, we're gonna talk about something that impacts every single one of us.

[00:02:21] - [Speaker 0]
That is whether we realize it or not, and why identity can no longer be treated as a one time checkpoint, and why your login might be the last secure moment in your entire digital journey. So if you've ever assumed that once you're logged in, you're safe, this conversation might just change how you think about trust online. But enough scene setting for me. Let me introduce you to my guest now. So a massive thank you for joining me on the podcast today.

[00:02:52] - [Speaker 0]
For everyone listening, hearing about you for the first time, can you tell them a little about who you are and what you do?

[00:02:58] - [Speaker 1]
Hi, Neil. It's great to be here with you and your audience, and I'm Maryann Miller. I'm the VP of customer experience at Proof, but also I'm a fraud and cybercrime executive advisor. So I've held leadership roles globally. And I've worked in a combination of different leadership roles, expanding banking, FinTech, and also technology companies that supply good risk controls to the market.

[00:03:30] - [Speaker 1]
And I'm here today to talk about lots of topics that you and I wanna cover.

[00:03:37] - [Speaker 0]
So much I wanna talk with you about as well because I think you have a somewhat of a unique vantage point because you've spent years at the intersection of fraud, identity, identity, financial systems, etcetera. And I'm curious now as we talk about all things AI, when you look at how AI is changing the threat landscape today, what genuinely feels different this time around compared to the previous waves of cyber risk that you've seen throughout your career?

[00:04:04] - [Speaker 1]
Yeah. It's that's a great question. And, know, Neil, there really is, what I call a step change occurring when it comes to AI infused attacks. You know, when we think about the cybercrime landscape, let's just use one example. A clear example is what I call AI infused phishing attacks.

[00:04:28] - [Speaker 1]
So what we're seeing is the bad actors are able to have more contextual phishing. So for example, my bank actually is updating their website. And the phishing message actually says, you know, we're XYZ Bank. We're updating their website. We need you to click on this link to update your account for this.

[00:04:54] - [Speaker 1]
And I've already received as a consumer, as a bank customer, an alert from the bank that they are updating their website. So it's not just it's the bank trying to reach out. It's actually, I'm going to pretend like I'm the bank and I'm going to actually have information about that bank to be able to convince you that this is a real fish. So we're seeing that. So the more contextual phishing, But not only contextual, but we're actually seeing it at scale.

[00:05:26] - [Speaker 1]
So there's many more customers being touched at one point. And we're actually seeing it go across the industry. Recently here in The US, this will be an interesting use case. We saw a spike. It was a day in February when a lot of mid tier banks suddenly put a security banner on top of their websites.

[00:05:49] - [Speaker 1]
And security banners are also indications that their customers are being influenced by or being attacked by these phishing text messages or emails. And not only does the security banners go up, but we saw some, websites actually shut down their their, access to their customers temporarily, till they could recover from that attack.

[00:06:17] - [Speaker 0]
Another shocking statistic I found before coming on here is that the the data out there shows that humans can only actually detect things like deepfakes for around 40% of the time. So shockingly low stat there. So what does what do you think that tells us about the future of trust online, especially when we're reaching a point where human intuition is is no longer a reliable security layer? And even just scrolling down our social media feeds, we see so much AI and fake stuff there. What do you think this means?

[00:06:47] - [Speaker 0]
Where is it taking us?

[00:06:49] - [Speaker 1]
Oh, yeah, this this is so much manipulation going on. As we know, you know, with this AI, you know, around all kinds of communication. What's interesting is, recently I saw a statistic, I don't know if you're familiar with Liminal, but they're an organization that really focuses on identity. And they focus on all things human and non human in their reporting. And they did a survey and it was real interesting.

[00:07:16] - [Speaker 1]
I think there's a little bit of what I call false sense of security. You know, they said 94% say they govern non human interactions, 94% of organizations, which I found high.

[00:07:31] - [Speaker 0]
But

[00:07:32] - [Speaker 1]
60% of those respondents said that they cite compliance risks from unauthorized agent access. So these are, you know, AI agents or AI techs, or even AI legitimate AI that's trying to, you know, access their organization. But this is the most important statistic is 10% don't have a mature nonhuman identity management strategy. So, you know, if you, you know, are allowing AI to occur, but you don't or you're not ready, you don't have a strategy and a framework in place, that really puts you in a vulnerable position and then and and what I call non ready position.

[00:08:17] - [Speaker 0]
And I think for years, identity has been treated as almost a a checkpoint at login. But what's breaking in that model right now? And and why are organizations still holding on to something that clearly no longer reflects how digital behavior works? So much has changed, hasn't it?

[00:08:33] - [Speaker 1]
It has. And, you know, login is, the welcome mat. It's when the customer comes into your organization, their account, they, you know, expect, you know, a good customer experience. We have the breakdown of one time passwords, and all of the attacks around OTPs when it comes to, you know, SMS forwarding. We have SMS, you know, takeover in those accounts when the actual OTP is SIM swapped.

[00:09:10] - [Speaker 1]
We have, you know, porting events that occur as well. So the actual mechanism that a lot of businesses in general, financial institutions and businesses use to really answer the question, is Maryann Miller, or is Neil at the other end of that interaction? And that's the question they're trying to answer. And that's starting to break down. And when you look at login, a lot of the bad actors, you know, there'll be a new device that'll enter the ecosystem.

[00:09:44] - [Speaker 1]
And during that event, that new device needs to be authenticated. You know, it could be the customer. The customer, we all get new devices or we have multiple devices, but there's a breakdown around how that is established, both combining the identity and authentication process. So it really, really, it's really forcing the industry globally to look at fresh eyes around A, how do we bind the correct identity to a new login, or an unrecognized login? And how do we authenticate that login?

[00:10:26] - [Speaker 0]
And one of the things I love about you and your work that you're doing here is you would talk about identity as something that evolves over time rather than a single moment. So can you just walk me through what continuous identity actually look like in practice inside a typical organization?

[00:10:43] - [Speaker 1]
Yeah. Continuous identity is really identity doesn't have it doesn't happen at one point in time. There's always, you know, you're welcome mat, again, whether, you know, it's a new account that you're onboarding a new customer. There's, you know, of course, depending on the type of organization or type of regulations that your organization is bound to, there's going to be specific KYC, KYC, know your business, know your customer requirements, even compliance requirements. But I find that those compliance requirements are not even good enough.

[00:11:23] - [Speaker 1]
You know, they're guardrails, they're guidance. But it's really incumbent upon us to actually look at identity from a new way of looking at how do we tokenize identity? How do we look at identity to really answer that question? Is Marian on the other end of that event? To establish that identity, especially in a call center, especially in a digital interaction, especially in a mobile interaction.

[00:11:52] - [Speaker 1]
And then once that's established, ongoing those logins, those registration events, those recovery events, those are all what I call identity risk moments. And that's all part of what I call the continuous identity landscape. Now, there's always a reason to be able to check-in to say, do I recognize Mary Anne on the other end of that event? Is she still on the other end of that event? Or is this an AI agent?

[00:12:20] - [Speaker 1]
Or is this a nefarious actor coming in? And, that's really important for all of us in the industry to take a fresh look at that.

[00:12:30] - [Speaker 0]
And I think another one of the most striking things that we're seeing right now is, yes, many organizations will proudly say that they are investing heavily in AI. Yet a large percentage of those same organizations will also admit that they have no real defense strategy against AI driven fraud. So there's a clear disconnect there. But where are you seeing that disconnect happening between awareness and adoption and actual action against some of the threats?

[00:12:57] - [Speaker 1]
That's a I really like this perspective because, you know, we mentioned it earlier, Neil, but this is, again, I'll go back to Liminal and some of their statistics. Recently, they said 68% of organizations that they lack the identity controls for AI systems and agents. So, you know, any genetic interactions. And this is the most alarming, that of the organizations that they surveyed, and I think this number has probably gone up. This was survey in 20 at the end of twenty twenty five.

[00:13:31] - [Speaker 1]
That 19% of all account takeovers have some kind of agenic AI involvement driver. So they're seeing that we're already looking at nonhuman drivers for account takeover. And that is going to be climbing in 2026.

[00:13:52] - [Speaker 0]
And I think there's always been a tension between reducing fraud and maintaining that smooth customer experience that we all almost expect a standard now. So I'm curious. How do you advise companies to maybe re rethink that balance without introducing more friction for legitimate users? Because it is a tough balancing act sometimes, isn't it?

[00:14:13] - [Speaker 1]
Yeah. And it's real interesting. I like to look at when I look at AI, both perspectives, how AI is being used to create a better customer experience, and how AI is being used for fraud prevention and for cybersecurity risks. And in this, what's interesting, Neil, is what's not always talked about too much is that AI classically has been used in fraud prevention for decades. If you think about it, every time we swipe our card, there's generally And I worked for a company out of San Diego, California that developed the first neural networks.

[00:14:53] - [Speaker 1]
And this was back in the late nineties. And this was a pattern recognition software that looked at anomalies for credit card or credit card and debit card transactions. And we've all had that phone call from our bank to say, is this you using your card? You know, this isn't normal activity. So that was early versions of AI, early versions of neural networks.

[00:15:18] - [Speaker 1]
Again, more elementary than what we have today. Fast forward to 2026. Today, of course, AI is driving cars, AI is, you know, driving commerce, we're seeing a lot of adoption of AI across all kinds of use cases. What I do think what, you know, let's talk about a little bit around business. We're going to see, in fact, I just read this, there's actually a gentleman out of The UK who has a site called FinTech Brain Food, I think it's called his name, Simon Taylor.

[00:15:50] - [Speaker 1]
And he just posted over the weekend that was interesting where, you know, there's a lot of discussion around AI commerce, egenic commerce, but Walmart just that, you know, they launched an egenic experience, but they saw a 66% drop in conversion. So that was alarming to Walmart, because you were trying to use AI for the customer experience, but yet customers are not looking at that as something that's really helpful to them. So I think what we're going to see is we're going to see a lot of stops and starts around AI enablement. And we're going to see companies that say, wait a minute, we have to build this for the customer with the customer in mind, you know, otherwise they're not going to adopt to it. They're gonna go back to the old ways to interacting.

[00:16:40] - [Speaker 1]
So I think we're going to see delays and stops and starts, some lessons learned. On the fraud and risk side, I think we're going to see more advanced adoption of AI. There's companies out there developing risk tools, using more AI, machine learning, fraud detection, you know, to actually complement the early use cases of of AI. So, there's going to be some real interesting days for all of us in the fraud risk and cybersecurity world.

[00:17:10] - [Speaker 0]
So many great examples there, and I love that stat around Walmart as well. And I'm curious from everything else that you're seeing across multiple industries, where are attackers having the most success right now? Is it still at the front door during onboarding, or is real risk happening later in the customer journey? Where where are you seeing any trends around where these attacks are happening?

[00:17:33] - [Speaker 1]
Yeah. I think it depends. Of course, there's different types of trends in different countries all over the world. Yeah. But, certainly, I I a consistent message I hear globally is definitely at the front door, you know, opening up an account.

[00:17:48] - [Speaker 1]
But more importantly, account takeover. Account takeover, you know, it was a term established. And in fact, I think, you know, as we talked about earlier, account takeover is morphing. It's morphing to automated attacks. I think we're going to start to see new fraud classifications of account takeover to say AI infused account takeover rather than human infused account takeover.

[00:18:16] - [Speaker 1]
So I think that account takeover authentication, as we talked about with some of the attacks around a one time passwords, that's where we're still seeing a lot of risk globally. In fact, there are some countries that have just recently made statements that they're no longer going to accept a one time password as the authenticator for login. So those countries are moving to new technologies like we have at Proof to actually authenticate and log into your account with with more modern ways of looking at that.

[00:18:59] - [Speaker 0]
And one of the things I always try and do on this podcast is give everyone listening a valuable takeaway. So if you have the attention of any boardroom anywhere in the world just for five minutes, what what would you tell them that needs to change immediately and and how they think about identity, risk, and trust in this AI first world that we find ourselves in? Any any particular advice or message that you'd really want to deliver to those people?

[00:19:25] - [Speaker 1]
Absolutely. I would I would take a step back. There's routines in cybersecurity we call pen testing. But there's also what we call fraud red team testing. And that's something that I think you take a step back so you can do your risk assessments and do an AI fraud red team testing control against all of your organization, your logins, your account openings, your recovery, all of your password resets.

[00:20:01] - [Speaker 1]
Make sure that you're looking at, can I answer these questions? Can I recognize an AI fused attack? If I see a spike in my IVR suddenly, is that customers calling in or is that an AI infused attack? If I see a spike, you know, an anomaly at a different recovery, password reset, are these AI infused attacks? And a lot of organizations, a, don't know how to recognize that, and b, don't have the right defenses built in to to have those controls.

[00:20:35] - [Speaker 1]
So don't wait for those spikes. Actually do these proactive fraud red team testings. There's companies that will provide that for you. And then that way, you can actually start to form your strategy and start to put those controls in place.

[00:20:51] - [Speaker 0]
And, of course, you work at Prove, which is trusted by over 1,500 plus leading companies in helping them reduce fraud and improve customer experiences, ultimately helping them enable their customers to prove their identities. And if you can share with me about what you do at Prove and and what makes Prove a little bit different from other solutions that business leaders might be using?

[00:21:12] - [Speaker 1]
So at Proof, we're looking at the future of identity. We're taking care of organizations of all sizes, whether they're banking, whether they're gaming, whether they're crypto, whether they're, you know, marketplace accounts, we're protecting healthcare, we're protecting all kinds of interactions across the industry today. But we also take seriously that we know investment and innovation for the future is really important. So at Proof, we're always looking forward, we're always looking at innovation, what we can do to really support our customers going into the future.

[00:21:50] - [Speaker 0]
I think that's a great moment to end on. And for anyone listening, wanting to dig a little bit deeper on anything we talked about today, they want to connect with you, your team, find out more information about Prove. Where would you like me to point everyone listening and I'll post links to everything?

[00:22:04] - [Speaker 1]
Yes. Our website's very, very informative. So if you go to www.prove.com, you can certainly find information there. Certainly, in the media, we have press releases, we have blogs, we have lots of information out there, white papers. And so there's lots of information that all, organizations can take a look at.

[00:22:26] - [Speaker 0]
Awesome. Well, I will include links to everything that you mentioned there, including your LinkedIn. And there was a a great section on the proof website of all the blogs that you've written as well. There's some great information there. So I'll pop a link to that too.

[00:22:38] - [Speaker 0]
So for everyone listening, please go check those links out. Let me know what your thoughts, how it might work for you, the challenges that you're having. But more than anything, Mary Anne, thank you for shining a light on this topic today. Really appreciate your time.

[00:22:50] - [Speaker 1]
Thank you, Neil. This has been fun.

[00:22:54] - [Speaker 0]
Wow. So where does all this leave us? Because if there's one thing that really stayed with me from this conversation, it is that fraud isn't waiting at the front door anymore. It's sitting inside quietly watching and waiting for the moment when trust has gone unchecked for a little too long. That's the moment that changes everything.

[00:23:15] - [Speaker 0]
And for years, many organizations, yep, they've treated identity like another box to tick. Verify once, move on, job done. But as Mary Anne made clear today, that model belongs to a very different era, a slower Internet, a simpler threat landscape, a time before AI could mimic behavior, scale attacks, and blur the lines between humans and machines. But now, fast forward to 2026, trust has a shelf life. And if it isn't being continuously reevaluated, it does start to drift.

[00:23:51] - [Speaker 0]
So what I found interesting today is that it isn't just a security problem. It is a business wide problem. Because the same systems that are meant to protect customers can also frustrate them. It can slow them down or even push them away entirely if they're not designed with real human behavior in mind. So it seems from the outside looking in that every company now is walking a very fine line.

[00:24:17] - [Speaker 0]
They need to reduce fraud without adding friction. They need to strengthen security without breaking the experience. And this is where this idea of continuous identity starts to feel much less like a technical upgrade and more like a complete rethink of how digital trust works. So if you wanna explore this further, I'll add links to Mary Anne, her work, and everything happening at Prove in the show notes. But as always, you've heard from me.

[00:24:46] - [Speaker 0]
You've heard from my guests. I wanna hear your take. This is a dialogue, not a monologue. That's why I record these episodes. So have a think.

[00:24:54] - [Speaker 0]
Are we heading towards a future where we trust machines to verify us more than we trust ourselves, or are we sleepwalking into a world where identity can become the weakest link in everything that we do online? And how are you managing these new set of challenges? Let me know your thoughts. Go to techtalksnetwork.com. We'll continue this conversation.

[00:25:15] - [Speaker 0]
A quick thank you to NordLayer for supporting the podcast and helping me make these daily conversations possible. And if you are listening and you're responsible for security or IT, you will know the reality. The reality that most of your risk now sits inside SaaS apps and browser activity. That gap is exactly what NordLayer is addressing with its new business browser. So instead of bolting security on from the outside, it builds it directly into the browser itself.

[00:25:49] - [Speaker 0]
This means you can control access, monitor activity, enforce policies, and reduce shadow IT all from one single place. And most importantly, it does it without adding deployment headaches or complex onboarding. You get things like browser based data loss prevention, SaaS access control, and zero trust browsing, but delivered in a way that your team can actually use. So if you've been trying to simplify your stack while improving visibility, please check it out at nordlayer.com/browser. And as for me, I'll also return again real soon with another guest with lots to talk and think about.

[00:26:32] - [Speaker 0]
I'll meet you here. Same time, same place. We'll do it all again, but that's it for now.