Behavioral biometrics is being asked to do too much

Visa recently announced an agreement to acquire BioCatch, one of the best-known behavioral biometrics vendors.

Timing is interesting. 

The deal lands at a moment where AI agents are making one of behavioral biometrics’ core inputs harder to interpret: whether interaction patterns reflect the person behind the account.

I think about identity differently. A session can tell you how someone is interacting in that moment, but true identity is established over time.

What matters is whether the person behind the account continues to behave in ways that are consistent with their real-world trajectory, even when the device, session, or interaction changes.

And when I say trajectory, I mean whether someone’s physical-world behavior continues to make sense based on what we’ve seen over time.

In my experience, looking at identity this way can give fraud teams broader coverage, fewer false positives, and a faster path to value than relying on session behavior alone.

Human behavior changes. Identity doesn't.

Behavioral biometrics works by comparing the way someone interacts today with the way they interacted before.

That sounds straightforward. In practice, human behavior changes constantly.

You type differently when you’re walking than when you’re sitting at a desk.

You may use one hand instead of two, or you might use your non-dominant hand.

A new phone can change the way you hold the device, swipe, or type.

None of that means your identity has changed.

The system still has to decide whether each variation is normal or whether it indicates fraud. That usually requires enough historical data to learn a baseline, followed by ongoing tuning as behavior changes.

Even then, legitimate changes can look suspicious.

That’s one reason behavioral biometrics can produce high false positive rates and add friction for customers who are doing nothing wrong.

It takes time and money

Behavioral biometric models need a lot of historical data before they can establish a useful baseline.

Then the tuning starts.

Different use cases may require separate models. Changes in user behavior, fraud tactics, or the app itself can force teams to fine-tune or retrain them.

I’ve seen what that looks like in practice. Here’s how it played out for a large bank:

Year 1: Millions spent collecting data, with no meaningful results yet.

Year 2: Millions more spent training models for each use case, still not live.

Year 3: Millions spent again, finally launched, performance still below expectations.

Year 4: Contract canceled.

They carried implementation costs and fraud losses for years before seeing any value.

Even when the technology catches some fraud, the economics can still be weak once you account for the upfront spend, slow deployment, and ongoing maintenance.

Some fraud problems are difficult to solve from a single session

Even a well-trained behavioral model is still only working with what happens inside the session.

That becomes a limitation across the customer lifecycle.

At account opening, there is no behavioral history yet.

When a customer changes devices, the interaction pattern may change even though the customer has not.

Fraud rings can also look like a collection of unrelated users because each account is evaluated separately.

Human-operated fraud creates a different problem. A real person may be typing, swiping, and navigating the account, so the interaction itself can look normal.

AI agents make this harder again. They can click, type, and navigate on a user’s behalf, which makes it harder to attribute the behavior in the session to the person behind the account.

These problems share the same limitation: the model is evaluating one interaction at a time, with limited context about the identity behind it.

Location provides the context a session cannot

Precise location intelligence looks beyond how someone interacts during a single session.

It combines multiple signals from the device and its surrounding environment to understand where the device is operating, whether the data has been manipulated, and whether that physical-world behavior is consistent with the person behind the account over time.

That gives fraud teams a more stable view of identity. The way someone types or swipes may change from one session to the next, while their real-world behavior remains consistent.

Let’s say a customer upgrades to a newer, larger phone.

Behavioral biometrics may see a sudden change in how they type, swipe, or hold the device. Compared with previous sessions, the interaction can look unfamiliar and may be treated as higher risk.

Precise location intelligence sees that the customer is still accessing the account from places that match their trajectory.

The interaction changed. The trajectory did not. That can support a low-risk decision.

The same logic applies after an app reinstall or factory reset.

Behavioral biometrics may need to rebuild confidence from new session behavior.

Precise location intelligence can still show that the person continues accessing the account from familiar places. The session may be new, but the location history is not.

Another example:

A newly created account may look normal inside its first session. There is no prior interaction history, so behavioral biometrics has little to compare it against.

Precise location intelligence can add context immediately. A genuinely new customer begins establishing a location history. A repeat fraudster may open another account from places already connected to suspicious activity.

The account may be new. The location behavior behind it may not be.

The same applies to an established account.

Behavioral biometrics may see normal typing and navigation.

Precise location intelligence could show that the account has suddenly appeared in places that do not match its established history.

That kind of discontinuity can indicate account takeover or a mule account handover.

Better fraud outcomes come from broader context

Precise location intelligence adds a layer of context that session behavior cannot.

In my experience, that changes the quality of the decision.

Legitimate changes, such as a new phone or an app reinstall, don’t automatically become suspicious when the person's location behavior remains consistent with their trajectory.

That can reduce false positives and the unnecessary friction that comes with them.

The same context can expose risk that looks normal inside a single session.

A new account may already be connected to locations associated with suspicious activity. An established account may suddenly break from its normal location history.

That gives fraud teams a better chance of catching activity that session behavior alone may miss.

Coverage also starts earlier. Precise location intelligence can provide useful context at account opening, before the user has built a long interaction history.

And because it doesn't depend on long periods of user-specific behavioral training, teams can reach useful decisions faster with less ongoing tuning.

I still see behavioral biometrics as a useful supporting signal for certain use cases.

But precise location intelligence provides a stronger foundation for identity because it evaluates behavior over time, not just behavior during a session.

Behavioral biometrics still has a role

I’m not arguing that fraud teams should throw behavioral biometrics away.

We use some behavioral biometric signals ourselves. But the problem is the expectation.

Behavioral biometrics is often sold as a stronger identity signal than it really is.

A session can tell you something about the interaction, but it cannot tell you the full story of the identity behind it.

Precise location intelligence fills in that missing context by looking beyond the session.

Fraud teams should keep behavioral biometrics where it works.

But identity decisions should be grounded in whether the person continues to behave consistently in the real world over time, not just whether today's interaction looks like yesterday's.

 

By clicking "Accept" or continuing to use this Website after this notice, you agree to our Terms of Use - including your rights, responsibilities, and how we handle disputes.