GDC26: The Question Digital Identity Still Can’t Answer 

Illustration of Scott Jones hosting at the GDC26 - Closing the Digital Identity Verification Gap

Realeyes CPO Scott Jones spent last week at the GDC26 Summit in Geneva. The event ran September 1 to 3, 2026, at Palexpo. GDC (the Global Digital Collaboration initiative) is an invitation-only, standards-body-run event. Over 2,000 policymakers and technologists attend, from Apple and Google to the World Bank and the WHO. Their shared goal is building unified infrastructure for digital identity verification, something no single company or government can build alone.

Scott hosted a session on holder binding. Holder binding is the mechanism that ties a digital credential (a driving licence, a passport, an age token) back to the person actually holding it at the time of presentation. One line from that session, spoken by moderator David Kelts (Fractional Head of Digital ID / Trust Services at Decipher Identity), has stuck with the whole team since.

The Quote That Names the Gap

Kelts put it plainly:

David Kelts - Closing the Digital Identity Verification Gap

“The NIST work on mobile driver’s licences showed banks will accept a digital ID and still have to do the face matching themselves.

Nothing lets a verifier trust that the phone matched the holder to the credential.

The credential is now the strongest form of evidence NIST recognises, and digital onboarding stays blocked.”

Strip away the acronyms and the point is simple. A digital credential can prove what it says on paper. It can’t prove who’s holding the phone. So the bank, the exchange or the age-gated platform ends up doing the face match anyway. It happens on top of the credential check, not instead of it. That’s the friction everyone in digital identity verification claims to be solving, and almost nobody actually removes.

For banks, that gap is a design failure as much as a security one. Today they can’t simply declare a requirement: proof of a live human, at a given assurance level, refreshed within a given window. They can’t hand that requirement to a vendor and have it satisfied. Instead they end up building and managing their own biometric integration, just to do the face matching a credential was supposed to make unnecessary.

It’s also, not coincidentally, the exact problem VerifEye was built to close. Confirming that the person presenting the credential is a real, live, unique human takes seconds. It doesn’t need a document, a stored photo or a second verification step bolted on afterward.

Flowchart: A credential proves the document, not the human. VerifEye closes that gap before onboarding stalls.

The Next Gap Is Bigger, and It’s Already Forming

The holder binding problem doesn’t stop at documents. GDC26’s biggest theme, by volume of sessions, was agentic payments. Many players, from standards bodies to fintechs to big tech, are building the layer that lets an AI agent act with a person’s authority. Every one of them checks identity and intent once, at the moment a person delegates a task to their agent. From that point on, they trust the agent’s keys.

Nobody has answered a much simpler question. How does a bank, a merchant or a platform confirm a live human is still behind a high-stakes action, seconds before an agent executes it? It’s the same gap Kelts named for mobile driving licences, just moved one layer up the stack. That stack sits inside a market about to get very large, very quickly. Realeyes is already working through what that step-up-to-the-human moment should look like.

Our early thinking treats it less like a biometric checkpoint and more like a signature. It’s a discrete, signed confirmation that a real person authorized this specific action, tied to the exact mandate an agent is executing at that moment. Possessing the right keys proves an agent is authorized, but that’s no different from possessing someone’s password. It says nothing about whether a human is still behind it. What closes that gap is inherence: tying the key back to the specific person who delegated it. It’s not a standing assumption that whoever set up the account is still the one behind it. Put simply, the missing factor isn’t on the agent. It’s on the delegation. We’ll have more to share soon.

Realeyes continues to work with GDC-adjacent standards bodies on zero-knowledge proofs and personhood credentials and through its contribution to the W3C verifiable credentials working group.

Verify real humans. Without the friction.

VerifEye confirms users are real and unique in seconds. No documents, no stored data, no drop-off.

Company

One Face API, Native Mobile SDKs and a Cleaner Path to Verification 

VerifEye ships a unified Face API, restructured docs and native iOS/Android SDKs with demo apps a simpler path to human verification.

Company

Realeyes Chairs ZKP Task Force on Personhood Credentials 

See how Realeyes CPO Scott Jones is shaping the zero-knowledge proofs behind personhood credentials in digital identity.

Company

Realeyes is Helping Write the Standards Digital Identity is Built On

Realeyes is now contributing directly to the W3C standards that digital identity is built on. Here’s what that means and why it matters.