There is a fundamental recognition that traditional passwords have become defenceless in today’s modern threat landscape. At a time when cybercrime has evolved into a highly efficient industry, legacy authentication methods are impacting enterprises’ ability to defend against the growing wave of AI-powered identity attacks. In fact, only 9% of organisations are actively prepared to do so.
With threat actors now using industrial-scale AI to automate phishing campaigns, credential-stuffing attacks and account takeovers at unprecedented speed and scale, the UK’s National Cyber Security Centre (NCSC) has issued clear guidance: wherever passkeys are possible, they should be used in place of passwords.
As AI continues to accelerate the sophistication and volume of identity-based attacks, adopting passwordless authentication has become an urgent priority for organisations looking to close their preparedness gap and maintain digital trust.
The hidden costs of passwords
To understand why we must move away from passwords, we must look at the friction they introduce to the enterprise. For years, identity security was treated as a back-office problem. Today, it sits at the absolute centre of customer experience and corporate revenue.
Passwords force a broken trade-off: making users create increasingly complex strings of characters results in severe password fatigue and, in many cases, account abandonment altogether.
Furthermore, public scepticism is at an all-time high. Research shows that 76% of Brits are genuinely worried about identity theft and fraud, yet only 17% fully trust the organisations managing their identity data. Passkeys directly resolve this trust deficit through cryptographic authentication. As private keys stay securely on the user’s local device and are never shared with a central server or application, there is no central database for hackers to breach.
With passkeys also cryptographically bound to a specific, verified domain name, they are inherently phishing-resistant, neutralising the human error that social engineering exploits.
Identity security beyond the human user
The case for passkeys extends beyond human convenience. As we navigate the explosive rise of agentic AI – autonomous digital proxies, personal shoppers and synthetic workflows executing transactions and querying databases on behalf of humans – security models must also evolve.
The introduction of AI into security completely shatters traditional authentication models. Passwords were fundamentally built for human brains to remember. An autonomous AI agent cannot “remember” a password without creating severe vulnerabilities, such as hardcoded credentials or shared session tokens that expose permanent risks. If an agent inherits over-privileged human credentials, a compromised or rogue process can exfiltrate sensitive data at machine speed – vastly outpacing the response time of a traditional Security Operations Center.
Passkeys and decentralised, cryptographic credentials offer the only viable path forward. By giving AI agents their own distinct, first-class machine identities with task-specific, time-bound permissions, enterprises can securely verify and audit machine-to-machine actions without exposing underlying human credentials.
Breaking down the barriers to passkey adoption
Despite the clear benefits, transitioning away from passwords presents real-world complexities. Passwords remain deeply embedded within legacy architectures, core IT systems and critical compliance infrastructure. Replacing them requires careful orchestration and many IT leaders fear that updating these systems will demand massive code rewrites and extensive specialist development resources.
This is where advanced identity orchestration becomes a critical business enabler. Modern, low-code or no-code identity platforms allow organisations to visually map, test and deploy sophisticated authentication journeys seamlessly. This abstraction layer enables businesses to introduce modern passwordless options like passkeys or biometric prompts progressively, without ripping and replacing underlying legacy systems or disrupting the active user workflow.
Simultaneously, the broader industry momentum is making this shift inevitable. Tech giants like Google and Amazon are rapidly positioning passkeys as their default authentication standard. Organisations that delay moving toward passwordless frameworks will be left defending a perimeter built for an entirely different era.
The next chapter in digital trust
Scaling an organisation successfully and securely, in a world dominated by automated threats can no longer depend on point-in-time authentication. Achieving true modern security requires an identity-first strategy that combines passkeys with robust identity orchestration, enabling enterprises to reduce user friction and protect both human and non-human identities.
The NCSC’s recommendation recognises this reality, prompting that the future of digital trust depends on moving beyond passwords altogether.
Alex Laurie
Alex Laurie is GTM CTO at Ping Identity. With over two decades in security and identity technology, Alex has worked with leading international organisations, government departments, and military and police forces.


