International Security Journal hears exclusively from Ricardo Amper, CEO of Incode, who discussed Identity Management Day and the importance of “Proof of human.”
Identity has always been the foundation of security.
Every system, transaction and interaction ultimately depends on a simple premise: that we know who or what, is on the other side.
That premise has held for decades, supported by a mix of passwords, documents, devices and behavioural signals.
As artificial intelligence reshapes the digital landscape, that foundation is beginning to fracture.
Identity Management Day 2026 arrives at a moment when organisations are being forced to confront a fundamental shift.
It is no longer enough to verify who someone claims to be. Increasingly, the first and most critical question is whether they are human at all.
The concept of proof of human is emerging as a new baseline requirement, simply because it can no longer be assumed.
The rise of synthetic actors
Historically, digital identity systems have operated on the assumption that every account corresponds to a real person.
Fraud existed, but it was constrained by effort.
Creating fake identities required time, resources and, often, physical documentation.
AI removes that constraint entirely. Today, attackers can generate thousands of synthetic personas in minutes.
These are complete digital identities, with profile photos that pass visual inspection, voices that sound natural and behavioural patterns that mimic real users.
When combined with automation, these synthetic actors can operate continuously, engaging with platforms, building credibility and executing attacks with minimal human oversight.
The implications are significant.
Fraud is no longer limited by human capacity.
It becomes a question of infrastructure: how many synthetic identities can be deployed, how quickly they can adapt and how effectively they can blend into legitimate environments.
This is where proof of human becomes critical.
Before organisations can determine who a user is, they must establish whether that user is a person at all.
Human vs. identity: a critical distinction
At first glance, proving someone is human and identifying who they are may seem like two sides of the same coin.
In practice, they are fundamentally different problems.
Identity verification is about attribution.
It answers questions such as: is this individual who they claim to be? It is inherently linked to personal data, documents and, often, regulatory requirements.
Proof of human, by contrast, is about existence.
It confirms that there is a real, live person behind the interaction, rather than identifying exactly who that person is.
Conflating the two creates both security gaps and privacy risks.
If organisations rely solely on identity verification without first establishing humanness, they risk validating synthetic identities that appear legitimate.
Conversely, if proof of human is implemented through excessive data collection, it can erode privacy and create unnecessary exposure.
The challenge is to separate these layers while ensuring they work together.
Proof of human should act as a gatekeeper, filtering out artificial actors before identity verification is applied, while minimising reliance on static personal data.
The privacy paradox
As identity systems evolve, so too do the risks associated with getting them wrong.
One of the most significant is the privacy paradox: the more aggressively organisations attempt to verify identity, the greater the potential for overreach.
Traditional approaches often rely on collecting and storing sensitive personal information, from government-issued IDs to biometric data.
While effective, these methods can create centralised repositories that become attractive targets for attackers.
In the age of AI, this risk is amplified.
Synthetic identities can be used to probe systems and exploit verification processes, while legitimate users are asked to share more data than ever, often without clear visibility into how it is used or protected.
This creates a tension between security and privacy.
Organisations need stronger verification, but must avoid expanding their data footprint unnecessarily.
The answer lies in more intelligent approaches.
Rather than relying solely on static data, organisations should prioritise dynamic, context-driven signals such as liveness, device binding and behavioural analysis.
In this model, trust is built on continuous validation rather than data accumulation.
Deepfakes and the erosion of trust
The rise of AI-driven scams and deepfakes is accelerating this shift.
As synthetic media becomes more convincing, traditional trust signals are losing their reliability.
Email was the first domain where this erosion became apparent.
Now, the same dynamic is extending to voice and video.
A phone call that sounds like a colleague or a video message that looks like a senior executive feels inherently trustworthy because it mimics human presence.
However, this assumption is becoming increasingly dangerous.
In real-world fraud scenarios, deepfakes are being used as part of targeted attacks, from authorising transactions with synthetic voices to building long-term trust using AI-generated personas.
The effectiveness of these attacks lies in their ability to exploit human psychology.
People are conditioned to trust what they can see and hear. When those signals can be replicated convincingly, intuition becomes unreliable.
This is why proof of human is becoming so important, as it anchors trust in something more fundamental than appearance: verified human presence.
Why detection is not enough
Many current strategies for addressing deepfakes focus on detection, such as identifying artefacts or analysing inconsistencies.
While valuable, these approaches are inherently reactive.
Detection assumes fake content will remain imperfect.
As AI improves, those imperfections are becoming harder to identify and the gap between synthetic and real is narrowing rapidly.
More importantly, detection places the burden on the moment of interaction.
It requires decisions to be made in real time, often under pressure and with limited context.
A more resilient approach is to shift from detection to verification.
Instead of asking whether something looks fake, organisations should ensure that critical actions require independent confirmation of human presence and intent.
This might include multi-channel verification, embedded liveness checks or behavioural anomaly detection.
The goal is not to eliminate risk entirely, but to ensure that no single signal is sufficient to authorise action.
Redesigning identity for the AI era
The emergence of AI-driven threats is forcing a rethink of identity systems.
The traditional model, where identity is verified once and then trusted indefinitely, is no longer sufficient.
Instead, identity must become dynamic and continuous.
Trust should be established throughout the lifecycle of an interaction, supported by real-time risk assessment and adaptive authentication.
Proof of human plays a central role in this model, ensuring interactions are grounded in real human presence, while identity verification provides attribution where needed.
Importantly, this approach also supports better privacy outcomes.
By separating humanness from identity, organisations can reduce reliance on sensitive personal data and align with growing expectations around transparency and data minimisation.
A new baseline for trust
As we mark Identity Management Day, it is clear that the concept of identity is evolving.
Proof of human is not a replacement for identity verification, but a prerequisite. It ensures that systems designed to establish trust are not undermined by artificial actors before they even begin.
For organisations, the implications are both strategic and operational.
Security frameworks must evolve, verification processes must become continuous and trust must be actively maintained rather than assumed.
AI will continue to drive innovation and growth.
This will also equip adversaries with powerful tools.
In this environment, resilience depends on building systems that can distinguish not just between legitimate and fraudulent identities but between human and machine.
The future of identity is not just about knowing who is on the other side, it’s about knowing that someone is there at all.

