By Tech Innovators

September 2026

For decades, the password has been the internet's front door.

Email accounts, banking platforms, social networks, enterprise systems and shopping apps have all depended on the same basic idea:

You know something that someone else does not.

That system worked reasonably well when digital identity was simpler.

Artificial intelligence is making that assumption increasingly fragile.

A badly written phishing email once contained obvious warning signs: strange grammar, awkward formatting or an implausible request.

Generative AI can remove many of those weaknesses.

Attackers can produce polished messages in seconds, imitate writing styles, translate scams into multiple languages and potentially combine stolen personal information with synthetic audio or video.

India's cyber-security authorities are already warning about the shift.

CERT-In has highlighted AI-generated phishing and impersonation attacks, multilingual social engineering, automated reconnaissance and increasingly sophisticated attack workflows as emerging risks.

The problem is therefore becoming bigger than choosing a stronger password.

The internet may need a different way to prove that you are actually you.

And that transition has already begun.


The Password Was Never a Particularly Good Security System

Think about what users are routinely told to do.

Create a long password.

Include numbers.

Add symbols.

Do not reuse it.

Do not write it down.

Change it if it leaks.

Create another one for every service.

Then remember all of them.

The predictable result is password reuse.

People choose memorable passwords because the human brain was never designed to maintain dozens of random cryptographic secrets.

That creates an opportunity for attackers.

If credentials stolen from one service are reused elsewhere, attackers can attempt those combinations against other accounts.

Phishing attacks create another weakness.

A fake website can look almost identical to a legitimate login page.

If the victim types a password into it, the attacker doesn't need to defeat the encryption protecting the real service.

The victim has simply handed over the secret.

Multi-factor authentication made this harder.

But even MFA has weaknesses depending on how it is implemented.

One-time passwords can still be socially engineered from victims. Attackers can create fake login flows designed to capture credentials and authentication codes. SIM-related attacks can target phone-based authentication.

The fundamental problem remains:

Traditional authentication frequently asks humans to recognise whether something is trustworthy.

AI is becoming very good at manufacturing things that look trustworthy.


Enter the Passkey

Passkeys attempt to remove the password from the equation.

Instead of proving identity by sending a secret that you remember, passkeys rely on public-key cryptography.

When a passkey is created, the user's device generates a cryptographic key pair.

One part—the public key—can be stored by the service.

The other—the private key—remains protected by the user's device or credential provider.

When the user signs in, the service sends a challenge.

The device proves possession of the corresponding private key without sending that private key to the website.

The user can typically approve the authentication using the same mechanism already used to unlock a device, such as a fingerprint, face recognition or device PIN.

There is no password to type.

And critically, there is no reusable password for a phishing site to steal.


Why Passkeys Are Harder to Phish

Imagine receiving a convincing email:

Your account has been temporarily restricted. Verify immediately.

The link leads to a fake login page that perfectly imitates the real company.

With password authentication, the attacker wants you to enter your credentials.

With passkeys, authentication is cryptographically associated with the legitimate website or application.

A credential created for one legitimate service cannot simply be replayed against an attacker's lookalike domain.

That changes the economics of phishing.

The attacker can still deceive a person.

But stealing a screenshot of a login page or convincing someone to type a password becomes far less useful when there is no password to type.

This is one reason the technology industry is increasingly moving toward passwordless authentication.


Passkeys Are No Longer an Experiment

The transition has already reached substantial scale.

According to the FIDO Alliance's State of Passkeys 2026 research, approximately 5 billion passkeys are now in active use globally.

Its consumer study surveyed 11,000 adults across ten markets—including India.

Around 90% of respondents were familiar with passkeys, while 75% had enabled them on at least some accounts.

The enterprise transition is happening too.

FIDO reported that 68% of surveyed organisations were deploying, piloting or rolling out passkeys for employee authentication.

That doesn't mean passwords disappear tomorrow.

Legacy systems are enormous.

Banks, government portals, universities, businesses and consumer applications cannot replace authentication infrastructure overnight.

But the direction is increasingly clear.

The password is moving from being the default identity mechanism toward becoming one option among stronger cryptographic alternatives.


Then AI Changed the Threat Model

The rise of passkeys would be important even without artificial intelligence.

AI makes the transition more urgent.

India's CERT-In has warned that advanced AI systems can potentially assist attackers with:

  • automated reconnaissance,
  • credential harvesting,
  • attack-path discovery,
  • multilingual phishing,
  • impersonation,
  • vulnerability exploitation,
  • and multi-stage cyberattack orchestration.

This doesn't mean AI has suddenly made every hacker unstoppable.

It means certain activities that once required more time, skill or manpower can increasingly be automated.

A criminal no longer necessarily has to manually write hundreds of different scam messages.

AI can personalise them.

It can translate them.

It can alter tone.

It can generate fake documents.

And increasingly, it can imitate people.


When the Attacker Sounds Like Your Boss

Consider a finance employee receiving a WhatsApp message from a senior executive.

The profile looks correct.

The language sounds familiar.

The message says a payment needs to be processed urgently.

That scenario is no longer hypothetical.

In August 2026, India's Indian Cyber Crime Coordination Centre warned businesses and finance professionals about a “Boss Scam” campaign involving compromised WhatsApp accounts and malicious files.

I4C said attackers were targeting company directors, CFOs, chartered accountants and finance teams.

Compromised accounts belonging to senior executives could then be used to instruct employees to transfer money.

I4C said more than 58,000 potential victims had been alerted during the preceding 30 days.

Now add generative AI to that attack model.

A compromised text account is dangerous.

A convincing synthetic voice can make the request feel even more authentic.

A realistic video can potentially make verification harder still.

This is where cybersecurity starts colliding with a deeper problem:

What happens when seeing and hearing are no longer sufficient proof of identity?


Deepfakes Turn Trust Into an Attack Surface

Deepfakes were initially treated largely as a misinformation problem.

They are increasingly becoming a cybersecurity problem.

A synthetic video can impersonate a public figure.

A cloned voice can impersonate a family member.

A generated image can support a fake identity.

A convincing video call could potentially reinforce a fraudulent financial request.

India has begun responding.

In February 2026, the government strengthened the Information Technology Rules to address synthetically generated information, including deepfakes and other AI-generated content.

The framework introduced stronger requirements around identifying permissible synthetic content, including labelling and metadata requirements.

Government disclosures also show growing institutional focus on deepfake detection and AI-related cyber harms.

But regulation can only address part of the problem.

Technology must also evolve.


Authentication Is Moving From “What Do You Know?” to “What Can You Prove?”

The history of digital authentication can be simplified into three stages.

Stage 1: Something You Know

Passwords.

PINs.

Security questions.

Stage 2: Something You Have or Are

A phone.

A security key.

A fingerprint.

A face.

Stage 3: Cryptographic Proof

The device proves possession of a cryptographic credential associated with the legitimate service.

Passkeys belong largely to this third transition.

And that matters because cryptography does not care how convincing a fake email looks.

A perfect deepfake cannot mathematically recreate a private cryptographic key simply because it resembles its owner.

That doesn't make identity systems invulnerable.

Attackers can shift toward account recovery, compromised devices, malicious applications, social engineering and weaknesses elsewhere in the identity lifecycle.

Security never becomes “finished.”

The attack surface moves.


India Is an Especially Important Test Case

Few countries have digitised everyday economic life at India's scale.

Banking, digital payments, government services, commerce, communication and identity increasingly depend on digital infrastructure.

That creates enormous efficiency.

It also makes identity security strategically important.

India's cybercrime response infrastructure is already dealing with the scale of the problem.

The Ministry of Home Affairs reported in July 2026 that its Citizen Financial Cyber Fraud Reporting and Management System had helped save more than ₹11,158 crore across over 32.8 lakh complaints since the system was launched.

The government operates the 1930 cybercrime helpline alongside the National Cyber Crime Reporting Portal for reporting cyber incidents.

Those figures demonstrate something important:

Cybersecurity is no longer merely an IT department issue.

It is consumer infrastructure.


But Passkeys Will Not Solve Everything

It would be tempting to declare:

Passwords are dead. Problem solved.

Reality is more complicated.

Authentication systems have recovery mechanisms.

Users lose devices.

People change phones.

Cloud accounts themselves can be compromised.

Businesses operate old software.

Some users share devices.

Others have limited digital literacy.

Attackers adapt.

If stealing the password becomes difficult, criminals may increasingly attack the recovery process.

They may impersonate users to customer-support teams.

They may trick victims into approving malicious actions.

They may compromise devices before authentication occurs.

And AI could help automate some of those attacks too.

The security challenge therefore isn't simply replacing one login box.

It is rebuilding the identity lifecycle around stronger assumptions.


The Next Authentication Battle: Proving Intent

There is an even bigger challenge coming.

Today, authentication usually answers:

Is this really the person who owns the account?

Tomorrow, it may also need to answer:

Did that person actually intend to perform this action?

Consider AI agents.

A user may authorise an AI system to read email, book travel, purchase products, manage documents, access enterprise software or eventually initiate financial workflows.

Authentication then becomes more complicated.

The system may need to distinguish between the human, the device, the AI agent and the specific actions the human authorised the agent to perform.

This could create an entirely new identity layer for the internet.

Instead of merely proving who logged in, systems may need cryptographically verifiable permissions defining what an AI agent is allowed to do, for how long and under what conditions.

The authentication problem is therefore about to expand beyond humans.


The Passwordless Future Will Not Arrive Overnight

Passwords have survived decades of predictions about their death.

They will probably survive for years more.

But survival is different from dominance.

Passkeys are now operating at global scale.

Major technology platforms support them.

Enterprises are experimenting with them.

Meanwhile, AI is increasing the sophistication and scalability of phishing, impersonation and social-engineering attacks.

Those two trends are moving toward each other.

One makes traditional identity verification harder.

The other attempts to remove one of its weakest components.

The result may be one of the most important transitions in consumer cybersecurity since the invention of the password itself.

For India, the stakes are particularly high.

As more of the country's economic and public infrastructure becomes digital, authentication becomes more than a login problem.

It becomes trust infrastructure.

And in an internet where AI can imitate your writing, your photograph and increasingly even your voice, the future of identity may depend less on whether a system recognises you—

and more on whether it can cryptographically prove that you are there.


In 30 Seconds

The shift: Passkeys are beginning to replace passwords with cryptographic authentication.

The scale: FIDO Alliance says roughly 5 billion passkeys are already in active use globally.

The threat: CERT-In is warning about AI-assisted phishing, impersonation and automated cyberattacks.

The India factor: India's massive digital economy makes secure authentication increasingly critical infrastructure.

What's next: AI agents could create a new authentication problem—proving not only identity, but what actions a human actually authorised an AI system to perform.


Sources

FIDO Alliance — The State of Passkeys 2026: Global Consumer and Workforce Report

Indian Computer Emergency Response Team (CERT-In) — advisories on advanced AI cyber capabilities and AI-assisted threats

Indian Cyber Crime Coordination Centre / Ministry of Home Affairs — cyber-fraud response and Boss Scam advisory

Ministry of Electronics & Information Technology, Government of India — regulatory framework addressing AI-generated deepfakes

Google India — security foundations for India's agentic AI ecosystem