Passkeys are one of the most important advances in authentication: phishing-resistant, passwordless, and significantly harder to steal or replay than passwords and OTPs.
But passkeys also carry an assumption that deserves a closer look: when a relying party receives evidence of user presence or user verification, what does that actually prove?
As AI agents begin interacting directly with banking applications, successful authentication may no longer tell you whether a human is operating the session, whether an agent is acting on the customer's behalf, or whether the assumptions behind an authentication control still hold.
For banks that rely on passkeys for authentication, step-up, or strong customer authentication, this raises important questions for security, fraud, identity, and compliance teams.
Transmit Security CEO and Co-founder Mickey Boodaei will demonstrate the issue live, explain what WebAuthn does, and does not, prove, and outline how financial institutions should rethink authentication and agent visibility as autonomous software becomes a new actor in their digital channels.