
On July 22nd, representatives from two FIDO Alliance board and FIDO Japan WG members, RSA and Mercari, met in Tokyo to discuss the next critical frontier: Enterprise passkey adoption. The hour-long conversation was organized to surface key challenges and opportunities in scaling passkeys across the enterprise, with a particular focus on phishing-resistant authentication and emerging AI-related use cases.

Leaders from RSA—including Field CTO Ingo Schubert and SE Manager Mohamed Zohny—sat down with FIDO Japan WG Co-Vice Chair and Mercari CISO, Naohisa Ichihara. The primary goal of this dialogue was to share global insights and explore how the industry can accelerate the implementation of passkeys in enterprise environments across Japan and beyond.
The Consumer Baseline: A Resounding Success
The consumer validation of passkeys in Japan is significant. Mercari, a leading C2C marketplace, boasts approximately 23 million monthly active users, with nearly 13 million accounts already utilizing passkeys. This bold approach to passwordless authentication has yielded a significantly higher sign-in success rate compared to traditional SMS OTPs.
Furthermore, in Japan’s financial sector, large-scale phishing attacks targeting securities firms in 2025 prompted the Financial Services Agency (FSA) to issue stringent supervisory guidelines that same year. As a result, financial institutions are facing strong regulatory pressure to adopt phishing-resistant authentication, accelerating the industry’s transition toward more secure authentication methods.


However, translating this consumer success to the enterprise domain presents unique technical and operational challenges that the industry must address collectively.
The “Synced Passkey” Dilemma
While cloud-synced passkeys are highly effective for consumer convenience, they introduce unique security challenges in a corporate environment. The dialogue highlighted the enterprise concern of passing credential control to third-party sync frameworks, where corporate credentials might inadvertently spread to unmanaged devices—such as a personal family tablet.

For robust enterprise security, organizations require granular policy controls that can enforce “Device-Bound” keys for specific corporate personas, ensuring authentication remains strictly within the managed corporate perimeter.
Securing the Identity Lifecycle and Defeating Fraud
No matter how cryptographically secure an authentication method is, it remains vulnerable if the surrounding workflows are weak. Attackers are increasingly bypassing MFA by utilizing social engineering tactics against IT help desks—a method notably used in recent high-profile breaches.

The transition to passwordless authentication serves as a vital trigger for enterprises to rebuild their identity infrastructure end-to-end. The discussion emphasized that securing the entire authenticator lifecycle—from strict employee KYC (Know Your Customer/Employee) during onboarding to robust, automated, yet highly secure account recovery processes—is non-negotiable for achieving true zero-trust.
AI Agents: Defining the New Trust Boundary
As the industry enters the Agentic AI era, a new operational challenge arises: how can autonomous AI agents securely authenticate and execute actions on behalf of humans?

Naohisa Ichihara emphasized the growing importance of secure delegation to AI in B2B operations, where finance teams are increasingly entrusting AI agents with tasks such as corporate bank transfers and procurement processes.
. Simply handing raw FIDO credentials to an AI breaks the chain of accountability. To address this, the industry is turning to protocols like the Agent Payments Protocol (AP2)—originally developed by Google and donated to the FIDO Alliance in April 2026 to ensure open, platform-agnostic governance—paired with Verifiable Intent to safely map human authorization to AI actions.
Furthermore, the discussion touched upon the necessity for the security industry to utilize deterministic AI models rather than black-box systems, ensuring that every automated security decision can be fully explained and audited to maintain enterprise trust.
Resilience and Cloud Independence
Looking ahead, particularly driven by European resilience regulations like DORA, there is a growing global demand for cloud-independent identity infrastructure. Enterprises managing critical infrastructure need assurances that their authentication systems will remain operational even during severe cloud outages or geopolitical crises. The industry is increasingly recognizing the need for on-premise FIDO solutions that ensure operational resilience and strict data sovereignty.

Conclusion
Transitioning to passkeys is not simply about swapping out a login method; it is a strategic catalyst for enterprises to fundamentally re-evaluate their access management architectures. By continuously sharing insights and collaborating within groups like the FIDO Japan WG, member companies are paving the way for a more secure, passwordless enterprise future globally.
