Every week, we pick the identity stories worth having on your radar – from new fraud tactics and emerging technologies to regulatory shifts and changes in how identity is verified and protected. Here’s our quick guide to what happened, why it matters, and what it could mean for the industry.
Last week, Malaysia began rolling out a more secure national ID, the UK expanded passkeys across a government login platform used by more than 23 million people, and AI agents moved another step closer to buying on consumers’ behalf. At the same time, a breach investigated in Spain showed the other side of agentic AI: attackers can use agents to automate multiple stages of an intrusion.
Here are four identity stories worth knowing as you start the week.
Malaysia rolls out a new national ID with 53 security features
Malaysia has begun issuing a new generation of its MyKad national identity card. The physical credential includes 53 security features, some of which will be introduced progressively. At the same time, the card’s QR code is redesigned to support digital verification and authentication without a live connection.
The system can also support live face matching against the holder’s photograph in Malaysia’s National Registration Department records. At least 24 million citizens are expected to receive the new identity cards.
Why it matters: The new MyKad illustrates how physical identity documents are evolving rather than simply being replaced by digital IDs. A modern credential can combine physical security features with cryptographic or machine-readable data and biometric checks against an authoritative source.
For organizations verifying these documents, this also means that checking only what is visible on the card becomes increasingly limiting. Strong identity verification will need to evaluate the available security features, machine-readable data, biometrics, and authoritative records together.
Read more: See how modern document authenticity checks combine multiple layers of evidence to determine whether an identity document presented online can be trusted.
GOV.UK One Login brings passkeys to more than 23 million users
The UK government is expanding passkey authentication for GOV.UK One Login, its access platform for more than 23 million users. More than 300,000 people adopted passkeys during the initial trial, and passkeys now account for nearly one in ten daily One Login sign-ins.
The government says signing in with a passkey can be up to 8 times faster than entering a username and password, followed by a 2-step verification code. Importantly, passkeys authenticate an already established account; they are separate from the identity checks used to establish who the person is in the first place.
Why it matters: Stronger authentication can shift where attackers look for weaker points.
While phishing-resistant passkeys make credential theft harder, enrollment and account recovery become more valuable targets. Fraudsters may try to establish an account under a false identity, bind an authenticator to the wrong person, or exploit a weaker fallback when the legitimate user loses access to a device.
That makes strong identity verification at onboarding and risk-sensitive re-verification during recovery increasingly important. Authentication can prove that the right credential is being used; identity verification still needs to establish who that credential belongs.
Read more: Explore identity lifecycle management and why identity controls need to extend beyond initial onboarding to authentication, recovery, re-verification, and other high-risk events.
AI agents are moving from shopping advice to actually making purchases
Mastercard is expanding its infrastructure for agentic commerce, as payment networks and technology companies prepare for AI agents to complete purchases on consumers’ behalf. Mastercard’s systems allow consumers to delegate purchases while setting conditions such as spending limits or approved merchants.
The broader payments industry is already working on the trust layer behind this model. EMVCo’s draft framework for agentic payments focuses, among other things, on establishing consumer intent and proving that a person actually delegated authority to an AI agent.
Why it matters: Once an AI agent can transact, businesses need to know more than whether the payment credential is valid. They need to establish who authorized the agent, what it was allowed to do, and whether the eventual transaction stayed within those limits.
Identity verification can become the starting point of that trust chain. First, it establishes the person behind the agent, then connects that identity to the authority they delegate and to the action performed. If something goes wrong, those links also need to be traceable.
Our take: Read why agentic commerce creates a new identity and authorization challenge – and how businesses can keep the chain from person to agent to transaction verifiable.
Spain investigates a data breach involving an AI agent
Spain’s data protection authority, AEPD, has received what it describes as its first personal data breach notification involving an AI agent apparently acting autonomously during a cyberattack.
According to the preliminary investigation, the attacker entered the system using valid credentials. An AI agent then appears to have performed several stages of the attack, including searching for vulnerabilities, modifying personal information, and accessing accounts. The investigation is still ongoing, and it is not yet known how the credentials were obtained or exactly how autonomous the agent was.
Why it matters: The case shows why the significance of AI agents in cybercrime may be less about inventing completely new attack techniques and more about compressing existing ones into faster, more automated workflows.
Once legitimate credentials are compromised, an agent can potentially move through systems, probe for weaknesses, and take actions much faster than a human attacker operating each step manually. That increases the importance of controls beyond login itself: contextual risk evaluation, monitoring after authentication, and stronger checks when behavior or transaction risk changes.
Our take: See what Spain’s AI-agent-linked breach tells us about identity security when attackers can automate actions after gaining access.
