Modern digital identification systems reliably confirm a user’s identity.
Mobile ID, Smart ID, banking authentication, and cryptographic signatures answer the question: who performs the action.
However, they do not answer another critical question: does the action correspond to the user’s behavioral intention?
At the moment a transaction is confirmed, the system sees:
- valid authorization
- a verified device
- a legitimate session
However, the system cannot determine whether the action corresponds to the user’s habitual behavior.
This is where a vulnerability emerges — between action and intention.