I spent an afternoon this week in Bloomberg's TV studio talking with Scott M. Lawrence, Chief Product Officer of Verizon Business, about a question that's been sitting under the surface of every fraud conversation in financial services: what happens to authentication once anyone can fake a voice, a face, a video call?
The honest answer is uncomfortable. Deepfakes and voice clones can now forge almost anything you show or say. A six-digit code texted to your phone was never built to survive that.
The problem with convenience
SMS OTP was designed for convenience in the 1990s, not security for the AGI era. It's been vulnerable to interception and SIM swaps for years — AI-powered social engineering just gave attackers a faster way in. The FBI reports over $20B in annual fraud losses, and industry estimates put the real number at 5-10x higher once you account for what goes unreported. That gap is exactly where deepfakes and voice clones are doing the most damage right now.
None of this is a reason for alarm. It's a reason to look at what's already sitting in almost everyone's pocket, unused.
The key you already have
Here's the part that doesn't get said enough: the fix isn't hypothetical, and it doesn't require new hardware, new apps, or new behavior. Every phone already has a private cryptographic key embedded in its SIM card, sitting inside a secure element. Carriers have quietly distributed more than 5 billion of them.
That's 5 billion dormant hardware security modules, already deployed, doing nothing.
When you authenticate with that key, your device proves it holds it — without ever revealing it. No code to type, no code to phish, and a SIM swap breaks the chain instead of hiding inside it. It's recognition, not interrogation: the system confirms who you are instead of asking you to prove it over and over.
Building it with the carriers
Together with AT&T, T-Mobile, and Verizon, we're turning that dormant key into a login. This is a coalition project, not a Glide project — the trust infrastructure for the AGI era only works if the tech, telco, and finance side build it together, and it doesn't work at all without the carriers opening up access to keys they already control.
Thanks to Shawn Hakl and the team at AT&T, Dennis Wukovits and the team at Verizon Business, and Anup Chathoth and the team at T-Mobile DevEdge for getting us here. Same coalition, same infrastructure, now proving itself with real institutions.
What this looks like in practice
We're wrapping up the first pilots with some of the biggest fintechs and financial institutions in the U.S., taking out friction and fraud in the same motion. Fewer dropped logins because there's no code that fails to arrive. Fewer fraudulent ones because there's no code to intercept in the first place. It's the same key, finally doing what it was always capable of.
For financial services specifically, this is the trade every fraud and IT team has been told doesn't exist: reduce account-takeover and transaction fraud while removing a friction point that was costing them logins and conversions anyway.
The window is closing
We have roughly 12-18 months before AI-powered fraud outpaces the defenses most companies are running today. The infrastructure to get ahead of it already exists — the carrier APIs are opening now. The teams that activate it early get a real advantage in trust and conversion. The ones that wait face a much harder retrofit later.
For the record: lipstick was offered at the Bloomberg studio. I turned it down.




.webp)
