A re-cap of the IBIA-moderated panel at Identiverse 2026—why the identity technology industry can’t afford to stand on the sidelines during the lawmaking process
By Robert Tappan, Executive Director, International Biometrics + Identity Association
At Identiverse 2026, held earlier this summer in Las Vegas, I had the privilege of moderating a session on why the biometrics and identity technology industry must be more fully engaged as a participant in the lawmaking process, rather than just being a passive spectator and watching it unfold. The stakes for our industry are high.
Our panel was entitled “If You’re Not at the Table, You’re on the Menu: The Importance of Engagement to the Identity Technologies Industry in the Lawmaking Process”, and I was joined on the stage by three executives and government affairs professionals from the industry:
- Brian Krause, Chief Revenue Officer of Aware, Inc., a publicly traded, Boston-area biometrics and identity product company serving U.S. government customers at virtually every level, as well as commercial customers globally;
- Arielle Thomas, Senior Manager of Government Relations at NEC Corporation of America, a multinational ICT company with a deep biometrics portfolio across the span of federal government and defense, the enterprise, and air travel and transport; and
- Hadley Sosnoff, Partner and Co-Founder of the bipartisan government relations firm Emergent Strategies.
Our discussion was less a policy briefing and more of a stark warning to the industry, as the panel’s title made vividly clear: lawmakers and regulators are zeroing-in on the identity industry, whether or not they choose to engage in the process—and most of the people and companies building all of these great technologies, by and large, still don’t see the connection between the two. We also focused heavily on how proposed new legislation and regulations will impact our industry.
Here are some of the key takeaways from our discussion:
The industry doesn’t realize how much policy and law already applies to it. Many of the companies in our audience will face, or be impacted by, legislation covering artificial intelligence, data privacy, biometrics, and digital identity—in some cases, all four at once. Yet, too many of them have not made the connection between these laws (and new ones on the horizon) and their own businesses.
The consequences are not hypothetical. For example, Congress considered a proposal last year that would have sharply curtailed the ability of the Transportation Security Administration (TSA) to use biometrics in screening passengers, which would have created serious difficulties not just for the agency, but for the airports, airlines, and travelers that depend on those processes. When you add the steady stream of facial recognition headlines involving major commercial deployments, coupled with news media coverage about the politically-charged environment around current immigration enforcement, a change in control of the House of Representatives after the upcoming election just two-and-a-half months from now could bring renewed legislative pressure and scrutiny as soon as next year.
That’s why I believe that companies need to start showing up today in the rooms and legislative offices where these decisions will be made, highlighting our industry’s commitment to the responsible use of the technologies—including safeguards, privacy protections, and operational realities under which they already operate.
Lawmakers need to legislate outcomes and standards, not technologies. One of the most practical pieces of advice to come out of the session—and one I make regularly in meetings on Capitol Hill—was that policy should be built around the outcome, not around the technology itself. There is a well-worn cliché in technology circles that it’s never really a “technology” problem, because nearly anything is achievable. However, writing a specific technical answer into a statute freezes a moment in time and forecloses better solutions that inevitably emerge later. Instead, policymakers should define the desired outcome (e.g. secure and quick passenger boarding), then let the private sector and government work together to determine what solution is best and realistically achievable.
The corollary to this is to lean harder on standards. The United States has a genuine structural advantage in the National Institute of Standards and Technology (NIST), whose testing and evaluation work underpins the global credibility of the biometrics industry. Investing further in that work, and using standards (rather than technology mandates) as the backbone of policy, offers a path that keeps guardrails around compliance, safety, and data privacy without dictating how a given outcome must be achieved.
AI policy has narrowed from “comprehensive” to “high-risk use cases”. The initial wave of legislative and regulatory proposals around artificial intelligence (AI), at both the federal and state level, tried to oversee essentially everything developers and deployers touched. However, the center of gravity has moved to use-case- and risk-based approaches, focusing on high-risk applications (like facial recognition and access to government services) and on frontier models. California pivoted in that direction and the Great American AI Act reflects the same instinct at the federal level.
Within that framework, our panelists identified two technology design and implementation features as essential: the time-tested and proven “human in the loop” approach (which needs no defense with an identity audience) and an effective “kill switch”. If a system is being used or goes outside its intended purpose, or is attempting to override human review, there should be a fail-safe mechanism to stop it.
Poorly-designed regulation can endanger security. Knowledge-based authentication (KBA), now largely obsolete, is one major area where regulation unintentionally weakens security or increases fraud risk. Research cited by my fellow panelists suggests that fraudsters are roughly twice as likely as the legitimate accountholder to answer KBA questions correctly because the real person forgets while the answers circulate through breaches, data aggregators, and AI-driven scraping. Mandating KBA-based policies forces organizations to adopt an expensive, low-utility control that checks a compliance box while making them more vulnerable.
In a similar vein, the panel argued that it’s time to revisit SMS one-time passcode requirements, which are still in place in certain U.S. industries and use-cases, even as other countries move to prohibit them.
Illinois’ Biometric Information Privacy Act (BIPA) is a cautionary tale, but is still spreading. The Biometric Information Privacy Act (BIPA) that Illinois enacted in 2008 governs how companies collect, use, and share biometric data in that state. While IBIA and our member companies broadly share its noble intent—that biometric data should be protected, BIPA, in practice, has produced adverse outcomes that other states should study very carefully before following suit.
As an example, BIPA has generated enormously costly and sometimes frivolous litigation and has led some companies to simply avoid operating in Illinois where and when they can. The lesson for legislators is that the goal should be legislation that protects biometric data and citizens, not legislation that becomes a vehicle for extracting money from companies through the legal system for an inadvertent, unwitting or unforeseen violation.
That lesson is becoming increasingly urgent, because BIPA-style bills are being introduced elsewhere around the country. Massachusetts is among the states where copycat versions of the law have cropped up. What is an Illinois compliance problem today may not stay one.
This brings up a larger point raised in our discussion—the need for a comprehensive, 50-state federal approach to protecting data privacy. Enacted at the federal level, national legislation would pre-empt a crazy-quilt “patchwork” of approaches that individual states have implemented (or have contemplated passing) in the absence of a uniform, nationwide law. A federal law would eliminate confusing individual state laws that vary by jurisdiction and are onerous to businesses trying to comply with them on a state-by-state basis.
Where things currently stand for the biometrics and identity industry on the federal front:
In Washington, biometrics and digital identity bills rarely move as standalone legislation; instead, they usually get folded into AI and privacy packages. Recent standalone bills on biometrics in housing access and law enforcement use of biometric data, largely introduced by Democrats, have not advanced. And the Improving Digital Identity Act, which would convene federal stakeholders and build collaboration across federal, state, local, and tribal governments, has been introduced in previous Congresses without moving to passage.
With regard to AI, Congress has been looking to work on a comprehensive AI bill but has thus far largely deferred to the Administration, whose priorities include exporting American AI stacks, expanding data centers and domestic compute, and, most consequentially for the biometrics and identity industry, preempting state AI laws. As drafted at the time of the panel, the Great American AI Act would have imposed a three-year preemption of state AI laws; that provision has since been amended as the legislation has evolved. The framework would also increase oversight of frontier models, expand research investment and public-private partnerships, and stand up a third-party audit body. Short of legislation, several other levers exist to achieve this outcome, including Commerce Department review of state laws for burdensomeness, pending Department of Justice litigation, and conditioning federal funding.
In the near-term, states are where the industry will actually face regulation first. This, to me, was the most urgent point of our entire discussion. More than 15 states introduced comprehensive AI bills last year. Few advanced and several that did drew high-profile gubernatorial vetoes on innovation grounds. The pattern this year is narrower: Colorado’s AI Act was tamped down toward algorithmic discrimination in access to government services, Connecticut enacted its own AI law, and California took a frontier-model approach.
Narrower doesn’t mean irrelevant, though. State law is where identity companies, their deployers, and their customers will feel direct impact first—through impact assessments, disclosure requirements, and obligations to document how systems were developed. Legislators keep reintroducing these bills even when they fail. And absent a federal preemption regime that actually holds, companies in the biometrics and identity space will be regulated by this eventually, in the absence of comprehensive federal laws.
Meanwhile, state privacy bills continue to move—the state patchwork of policies and regulations continues to grow, and BIPA copycats continue to appear in other statehouses. Federal policy absorbs most of the attention, but the near-term regulatory reality is being written in state capitals across the country, for now, while Washington remains in limbo.
Conclusion
Among the four perspectives represented on our panel, one of the main points of agreement was that policymakers are now shaping the future of identity, fraud prevention, and authentication. With a few exceptions, most lawmakers are not steeped in these technologies and don’t yet know what they don’t know, and correcting that is not someone else’s job. It’s ours.
That’s the message I and my fellow panelists want to leave with our industry: We need to engage early, and often. NOW is the time when we need to educate policymakers on outcomes and standards rather than simply defending technologies. We need to point to the real-world consequences of well-intentioned mandates that enshrine today’s technologies that quickly become yesterday’s outdated ones. We need to conduct our legislative educational and advocacy through our companies, our employees, our customers, and associations like IBIA and other partners in this space.
At IBIA, this is the work we do every day on behalf of the biometrics and identity community, and our efforts only get stronger when more companies in our industry join the effort.
If your company is not yet an IBIA member, I invite you and your company to join us. Our Members both support and help shape the Association’s advocacy work, including comment filings, Congressional engagement and legislative testimony, and coalition efforts. For more information on IBIA membership, visit https://ibia.org/membership/.