Biometrics

Cross-cuts: Life & FrontierAI & SoftwareCompute
last updated 2026-08-31
Assessmentdraft · unreviewed
Viability
4/5
Drivers
3/5
Novelty
2/5
Diffusion
3/5
Impact
3/5

TimingNow (0-2yr)·ReadFairly rated

Otoacoustic EmissionsOtoacoustic Emissio…The ear as a sensing siteThe ear as a sensin…Agent Identity (KYA)Agent Identity (KYA)Edge AIEdge AIBiometrics

Biometrics is the recognition of people from physical or behavioural traits, and the deployed reality in 2026 is that matching largely works while liveness, injection resilience and commercial capture do not.

Summary

Biometrics covers the recognition of individuals from physical and behavioural traits such as fingerprints, face, iris, voice and gait, and is increasingly the default replacement for passwords in device unlock, border control, national ID and financial account protection. A system has three layers that are usually confused with each other: a sensor and feature extractor that turns a body into a template or embedding; a comparison step that produces a match score; and a defence layer that decides whether the thing in front of the sensor is a live human at all, and whether the data reaching the comparison step actually came from that sensor.

The numbers that decide a biometric are operating-point numbers, not accuracy numbers. False accept rate (FAR) and false reject rate (FRR) trade against each other, and equal error rate (EER) is the point where they cross, which is almost never where a security product runs. The ear-acoustic literature is the clearest illustration: sub-1% EER coexists with roughly 22% FRR at a security-grade FAR of 0.1%, improved to about 14% by a dedicated methods paper, against a Face ID FAR of around one in a million 2022 Ear Acoustic Between Class Features. For the defence layer the equivalent metrics are BPCER (rejecting genuine users) and APCER (accepting attacks), plus a separate question of injection resilience, meaning whether an attacker can bypass the sensor entirely with a virtual camera, hooked system call or manipulated network traffic ref.

The live frontier is therefore not new sensing modalities but that defence layer. A US government evaluation run by the Maryland Test Facility for DHS Science and Technology tested six active and twelve passive liveness systems, and of the twelve passive systems exactly one met the APCER threshold; the report places presentation attack detection between document validation (poor) and face matching (substantially better) in the identity stack ref. Standards are following: ISO/IEC 30107-3:2023 covers presentation attacks only, CEN/TS 18099:2024 is the only published specification that proves injection resilience, ISO/IEC 25456 is in development, and ETSI EN 119 461 already mandates injection-attack testing with documented evidence ref.

Alongside this, exotic modalities keep being reintroduced as novel. Transient evoked otoacoustic emission identity, including the liveness-by-construction argument that you cannot replay a signal the cochlea must actively generate, was published as a University of Toronto thesis in 2014 with 99.44% identification and 0.02% EER on both-ear fusion 2014 Liu Earprint Teoae Biometrics Thesis, and again with proper verification metrics in 2021 2021 Earnet Teoae Biometric Embeddings. Anyone assessing a biometrics pitch should check the prior art, the operating point rather than the EER, and whether the claim covers injection as well as presentation attacks.

Viability (4/5)

The core recognition function works. The RIVR Phase 3 evaluation explicitly ranks face matching as substantially better than liveness detection, which in turn is better than document validation ref, and one vendor has issued over 475 million iris-based identity proofs to more than 18 million verified people across 160 countries ref. That is demonstrated field performance, not a lab result.

The defence layer is where viability breaks. Only one of twelve passive liveness systems met the APCER threshold in the only independent benchmark of deployed systems, and the best reported combination was 0.5% BPCER with 1.7% APCER at 2.3 seconds ref; that benchmark covers presentation attacks only and tests nothing about injection ref. A vendor can hold PAD certification and have zero injection resilience ref. Novel modalities are further back still: ear-canal acoustic authentication still rejects roughly one in seven legitimate users at FAR 0.1% after a paper written specifically to fix that 2022 Ear Acoustic Between Class Features. Score reflects a mature core with a measured, unsolved perimeter.

TLDR: Matching is close to solved and deployed at scale; the liveness and injection layers demonstrably are not.

Drivers (3/5)

Demand side: biometrics is displacing passwords as the preferred authentication approach across smartphones, border security, national ID and financial accounts, with the skills shortage explicit enough for NSF to fund a dedicated undergraduate research site at $450,000. Regulation is a harder driver than fraud narratives: ETSI EN 119 461 already mandates injection-attack testing across face-to-face, remote-assisted and unattended remote identification, and eIDAS 2.0 encourages privacy-enhancing technologies in the wallet ref, ref. The structural why-now on the attack side is that injection attacks are software and scale to thousands of simultaneous attempts, whereas presentation attacks require physical presence ref.

Supply and monetisation are the weak half. The best-capitalised, best-distributed proof-of-personhood vendor, valued at $2.5bn with Zoom, Tinder, DocuSign and Okta as named partners, restructured a roughly 500-person team on 8 June 2026 because revenue had not kept pace with hardware and compliance costs, and only introduced per-verification application fees in June 2026 ref. Fraud-side growth numbers driving the demand story are largely vendor-published and uncheckable, including a claimed 495% increase in deepfake identity fraud in 2026 and 740% growth in iOS injection attacks during 2025, ref.

TLDR: Regulatory mandates and software-scale fraud pull hard on demand; the leading vendor still cannot convert it into revenue.

Novelty (2/5)

Very little in these sources is new. Otoacoustic-emission identity and its entire security framing, including the liveness and anti-replay argument and the term ‘earprint’ itself, were published in 2014 with 0.02% EER on both-ear fusion 2014 Liu Earprint Teoae Biometrics Thesis, and restated with authentication metrics and an open-set claim in 2021 at 0.057% EER for the right ear and 99.92% fused identification accuracy 2021 Earnet Teoae Biometric Embeddings. The edge-compute story is also already met: an October 2025 system extracts a stable binary key from the ear canal on the earbud itself in 226 ms with no classifier, reporting 98.7% accuracy and FAR below 1% 2025 Earid Ear Canal Biometric Key Extraction. That fuzzy-commitment architecture is strictly better than storing embeddings, because there is no template to leak.

Where something is genuinely better than what came before, the margins are modest and well characterised. Bilateral ear fusion buys roughly a 3x error reduction over one ear, 0.39% EER against 1.31% 2022 Bilateral Ear Acoustic Authentication. Between-class features improve the security-grade operating point by 7.95 points of FRR 2022 Ear Acoustic Between Class Features. Meanwhile the privacy primitives that would differentiate a product have been commoditised by the platforms and the regulator: Google open-sourced its zero-knowledge-proof libraries under Apache 2.0, the EU shipped an open-source age-verification blueprint behind the app announced 15 April 2026, and ZKPassport covers over 120 countries free and open source ref. The defensible novelty left is injection-attack detection and its test methodology, which is early enough that the standard is still in development ref.

TLDR: The category is old, the exotic modalities are older than their pitches, and the privacy layer is being given away free.

Diffusion (3/5)

Diffusion is already deep in some segments and reversing in others. Identity verification is an observable $14-16bn market in 2026 across four independent houses, roughly 56% cloud-deployed and 32.7% BFSI by vertical, and iris-based proof-of-personhood reached 1,500 Orbs live in 23 countries with a US launch on 1 May 2026 ref. That is real distribution.

The adoption barriers are consent, cost and error rates. The number-two proof-of-personhood vendor, with over 8 million palm-based Human IDs, abandoned the category in February 2026 for a verifiable-credential network, while a $30m-funded competitor positions explicitly against ‘invasive biometric scans’ using passport NFC and zero-knowledge proofs instead ref. Hardware-based capture carries manufacturing, deployment and per-jurisdiction compliance costs that outran revenue at the category leader ref. For new modalities the barrier is arithmetic: no consumer product ships an authenticator that rejects one user in seven at a usable FAR ref, 2022 Ear Acoustic Between Class Features. Fragmented certification, with PAD certification not covering injection, adds procurement friction on top ref.

TLDR: Ubiquitous in device unlock and identity verification, but the biometric-first identity vendors are retreating from biometrics.

Impact (3/5)

The stakes are substantive: biometrics gates devices, facilities, borders, national identification and financial accounts, and the observable base market for identity verification is $14-16bn in 2026 with houses disagreeing only on growth, between 11.2% and 18.2% CAGR. Because liveness sits in the middle of the stack as the weakest measured link, spend concentrating there is a structurally coherent expectation rather than an assertion ref. Bot farms using real human workers to defeat anti-bot protections, now the subject of a $471,822 NSF award, give an additional reason why proving a live, unique human has economic value.

Value capture is the constraint on the score. Adjacent decentralised-identity forecasts are unusable, disagreeing 6.5x on the same year with CAGRs between 51% and 80%, while the one layer-specific number is small: zero-knowledge KYC at $83.6m in 2025 rising to $903.5m by 2032. Regulators and platforms are donating the privacy layer, making it a compliance expectation rather than a differentiator ref, and the leading biometric vendor’s layoffs are harder evidence than any forecast that the value is not yet reaching the people building the sensors ref.

TLDR: A real, measurable market with genuine security stakes, but the sources show value leaking to free primitives rather than accruing to vendors.

Timing Now (0-2yr)

There is nothing speculative about the timing of core biometrics. Face and iris matching are deployed at hundreds of millions of transactions, the US launch of the largest proof-of-personhood network was 1 May 2026, and the identity verification market is being measured rather than projected ref,. What is in motion over the next two years is the defence layer: CEN/TS 18099:2024 is published, ISO/IEC 25456 is in development with weighted attack-complexity levels expected, and the European Association for Biometrics is working on capture-environment vulnerability methodology and explainability requirements for deepfake and injection detection ref.

The exception is exotic modalities. Ear-canal and otoacoustic authentication have been in the literature since at least 2014 and still sit at security-grade operating points no consumer product would tolerate 2014 Liu Earprint Teoae Biometrics Thesis, 2022 Ear Acoustic Between Class Features. On the evidence here their timing is unclear rather than soon, and twelve years of published prior art without a shipped product is itself the signal.

TLDR: Deployment is already happening; the contested liveness and injection layer is being standardised and independently benchmarked right now.

Overrated or underrated? Fairly rated

Split the category and the picture is consistent. Biometric matching is fairly rated: it works, it is deployed, the independent benchmark says so, and the market for it is one of the few in this space where four forecasting houses agree on the base ref,. Injection attack detection is arguably underrated, because it is the only layer with a published operational standard, an ISO successor in development, an existing ETSI mandate and a structural argument for why attacks scale that does not depend on deepfake quality improving ref, ref.

Two things are clearly overrated. Biometric proof-of-personhood as a business: the leader has $2.5bn of valuation, 18 million verified humans and layoffs in the same year, and the number-two player left the category entirely ref, ref. And novel ear-based modalities: the liveness pitch, the name and the headline error rates are all prior art from 2014 and 2021, the edge-compute and template-privacy arguments were closed by an October 2025 paper, and the honest operating point is roughly 14% FRR at 0.1% FAR against Face ID’s four-orders-of-magnitude better FAR 2014 Liu Earprint Teoae Biometrics Thesis, 2025 Earid Ear Canal Biometric Key Extraction, 2022 Ear Acoustic Between Class Features. Treat any EER-only claim as a flattering operating point until FRR at FAR 0.1% is stated.

Prediction

By 31 December 2028, no ear-acoustic or otoacoustic authentication system will have been independently benchmarked (by a body such as the Maryland Test Facility or an iBeta-equivalent lab) at an FRR below 5% at FAR 0.1%.

Evidence base

Open questions


Assessment drafted 2026-08-31 from up to 16 KB sources using the technology-scorecard framework; scores are a draft read pending review.

Recent mentions

Related concepts

Frontier questions