Identity verification is moving beyond the moment an employee joins a company. Sumsub has launched Workforce Verification, a product designed to apply document checks, biometric liveness and other identity controls throughout the employee lifecycle, including at moments when risk changes.

The most significant part of the launch is not onboarding. Sumsub says the product can be used for step-up identity verification when a password is reset, privileges are escalated or a login appears suspicious. That reflects a broader security problem created by deepfakes, credential theft and AI-assisted social engineering: possession of a password, token or authenticated session does not necessarily prove who is behind it.

In the traditional enterprise identity model, a user proves who they are during enrolment and then repeatedly authenticates with credentials. That remains important, but high-risk workflows are increasingly creating demand for stronger forms of re-verification. The emerging model is closer to: verify the person, authenticate the credential, and re-prove identity when the risk of the action justifies it.

The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.

Sumsub describes the checks as deepfake-resistant. AI360 is deliberately not reproducing a numerical deepfake-performance figure here: Sumsub currently publishes inconsistent percentages across its own launch material and product page, and neither figure should be treated as an independent benchmark without a disclosed, comparable test methodology. The broader architectural point does not depend on the percentage.

That shift has implications beyond cyber security. Biometric verification raises questions about consent, retention, purpose limitation, data minimisation and supplier accountability. Those issues are especially important in jurisdictions with biometric privacy laws and in financial services, where identity controls must operate alongside fraud prevention, customer protection and regulatory obligations.

It also creates a useful distinction between credential assurance and human identity assurance. Multi-factor authentication can raise confidence that the user controls the required authentication factors, but it does not by itself prove the real-world identity of the person presenting them. Biometric or document-based re-verification aims to raise confidence that the person is who they claim to be. In some high-risk workflows, enterprises may increasingly want both.

The commercial race will be to make stronger verification usable enough that it can be inserted into sensitive workflows without creating unacceptable friction. The governance race will be to prove that the additional biometric data and verification steps are proportionate to the risk they are meant to reduce.


Conquered Your Data? - Now Combat Your AI
Souvik Choudhury, an AI and Data Governance Specialist at Fractal Analytics with a background spanning Infosys, HSBC and several startups, joins Stewart Tinson to unpack why data governance and AI governance can’t be treated as sequential problems, and why so many organisations discover the gap between them the hard way. Souvik argues that traditional data governance remains the foundation everything else is built on, and that AI agents amplify existing weaknesses rather than replacing the need for accountability, contextualisation and lineage. He walks through a real project example where an organisation believed it had solved data governance by using agents to generate column definitions, only to discover the definitions were pulled from generic internet knowledge rather than the organisation’s own policies, leaving a false sense of confidence behind a genuinely ungoverned dataset. The conversation covers where accountability actually sits when an autonomous agent makes a bad decision, why third-party models don’t dilute an organisation’s own responsibility for outcomes, and why Souvik pushes back on the idea that governance is an innovation-killing bureaucracy rather than the structural work that makes innovation possible in the first place. He also sets out a practical, staged approach to evaluating AI governance tooling rather than jumping straight to an enterprise platform, and offers a way to actually measure AI governance maturity using a weighted scoring model across multiple pillars. The discussion closes on an unexpected angle: the sustainability cost of AI infrastructure, and why Souvik believes environmental impact deserves a seat alongside profitability and productivity in any serious cost-benefit conversation about agentic AI.
Share this post
The link has been copied!