Realeyes CPO Scott Jones spent last week at the GDC26 Summit in Geneva. The event ran September 1 to 3, 2026, at Palexpo. GDC (the Global Digital Collaboration initiative) is an invitation-only, standards-body-run event. Over 2,000 policymakers and technologists attend, from Apple and Google to the World Bank and the WHO. Their shared goal is building unified infrastructure for digital identity verification, something no single company or government can build alone.
Scott hosted a session on holder binding. Holder binding is the mechanism that ties a digital credential (a driving licence, a passport, an age token) back to the person actually holding it at the time of presentation. One line from that session, spoken by moderator David Kelts (Fractional Head of Digital ID / Trust Services at Decipher Identity), has stuck with the whole team since.
The Quote That Names the Gap
Kelts put it plainly:
“The NIST work on mobile driver’s licences showed banks will accept a digital ID and still have to do the face matching themselves.
Nothing lets a verifier trust that the phone matched the holder to the credential.
The credential is now the strongest form of evidence NIST recognises, and digital onboarding stays blocked.”
Strip away the acronyms and the point is simple. A digital credential can prove what it says on paper. It can’t prove who’s holding the phone. So the bank, the exchange or the age-gated platform ends up doing the face match anyway. It happens on top of the credential check, not instead of it. That’s the friction everyone in digital identity verification claims to be solving, and almost nobody actually removes.
For banks, that gap is a design failure as much as a security one. Today they can’t simply declare a requirement: proof of a live human, at a given assurance level, refreshed within a given window. They can’t hand that requirement to a vendor and have it satisfied. Instead they end up building and managing their own biometric integration, just to do the face matching a credential was supposed to make unnecessary.
It’s also, not coincidentally, the exact problem VerifEye was built to close. Confirming that the person presenting the credential is a real, live, unique human takes seconds. It doesn’t need a document, a stored photo or a second verification step bolted on afterward.
Flowchart: A credential proves the document, not the human. VerifEye closes that gap before onboarding stalls.
The Next Gap Is Bigger, and It’s Already Forming
The holder binding problem doesn’t stop at documents. GDC26’s biggest theme, by volume of sessions, was agentic payments. Many players, from standards bodies to fintechs to big tech, are building the layer that lets an AI agent act with a person’s authority. Every one of them checks identity and intent once, at the moment a person delegates a task to their agent. From that point on, they trust the agent’s keys.
Nobody has answered a much simpler question. How does a bank, a merchant or a platform confirm a live human is still behind a high-stakes action, seconds before an agent executes it? It’s the same gap Kelts named for mobile driving licences, just moved one layer up the stack. That stack sits inside a market about to get very large, very quickly. Realeyes is already working through what that step-up-to-the-human moment should look like.
Our early thinking treats it less like a biometric checkpoint and more like a signature. It’s a discrete, signed confirmation that a real person authorized this specific action, tied to the exact mandate an agent is executing at that moment. Possessing the right keys proves an agent is authorized, but that’s no different from possessing someone’s password. It says nothing about whether a human is still behind it. What closes that gap is inherence: tying the key back to the specific person who delegated it. It’s not a standing assumption that whoever set up the account is still the one behind it. Put simply, the missing factor isn’t on the agent. It’s on the delegation. We’ll have more to share soon.
Realeyes continues to work with GDC-adjacent standards bodies on zero-knowledge proofs and personhood credentials and through its contribution to the W3C verifiable credentials working group.