
Someone in Germany let an A.I. agent make a purchase. Their phone approved it with a fingerprint. Technically, it worked perfectly. Visa is now rolling out these passkeys, letting your face or fingerprint replace passwords at checkout. That's genuinely good news. Stolen passwords and intercepted text codes drain billions from ordinary people every year. Passkeys close that hole. But there's a quieter problem. A passkey proves it's you. It doesn't prove you meant to buy what the A.I. just decided to buy.
According to Biometric Update, Visa completed a live test where an A.I. agent bought something and a passkey approved it. Nearly half of American shoppers already use A.I. for some shopping task.
The chargeback rules that protect you were written for a human pressing the button. Not software spending money at 2 a.m. while you sleep. Your phone proves it's you. Nothing yet proves it's what you meant.
Speaking of your face saying yes without you knowing, another camera may already be watching for it.
You walk into a grocery store, grab a cart, head for the produce. A camera above the door already scanned your face and checked it against a shoplifter database. You never saw a sign. You never agreed. A Québec privacy watchdog just ruled on exactly this. A grocery chain ran facial recognition across ten stores. The regulator didn't just ask if it worked. It asked something harder. Did you actually need to scan every customer's face?
According to Ogletree Deakins, the chain had to prove less invasive options failed, delete your face data when there's no match, and cap the pilot at ten stores. Consent is still blocked on appeal.
These systems make mistakes. And they make more of them on people of color. Being wrongly flagged as a thief isn't abstract. It's humiliating, and it's led to wrongful confrontations. A small sign near the door is not the same as someone asking you.
But whether it's a store camera or your bank, they all trust one thing. A face that matches.
Somewhere, right now, a fraudster is skipping the camera entirely. They don't sit down and get scanned. They slip a fake video straight into the data pipeline. The system never sees a real face. It sees a perfect file, and it says yes with total confidence. A ninety-nine percent match on a deepfake gives you ninety-nine percent confidence in a lie. The matching score only asks one question. Do these two faces look alike? It has no idea if the face was ever real.
According to Biometric Update, these injection attacks jumped more than eleven times in a single year. And Deloitte projects generative A.I. fraud could cost up to forty billion dollars by twenty twenty-seven.
Real verification asks three things. Was the person live? Is it the right person? And can you trust how the image was captured? A face match is the label on the package. It tells you nothing about what's inside.
Three stories, one thread. Every system today is brilliant at proving it's you. Your passkey, the store camera, the match score. But none of them prove the thing that actually matters. Did you mean to do this? Was the face even real? Identity is solved. Intent is the gap everyone's racing to close. Links to every story and today's podcast deep-dives are in the description. See you next time.