World ID expands its ‘proof of human’ vision for the AI era
As artificial intelligence agents become more sophisticated and pervasive online, the challenge of distinguishing real humans from synthetic entities has intensified. In response, World ID, a digital identity initiative co-founded by Sam Altman and Alex Blania, is advancing its mission to establish a verifiable “proof of human” standard for the internet. At its recent “Lift Off” event, the project unveiled a suite of new tools and integrations, including World ID 4.0, a mobile app, business and agent-focused versions, a Selfie Check verification method, and partnerships with Zoom and Okta.
The core idea behind World ID is to enable individuals to prove they are human without revealing personal information such as names, emails, or photos. This is achieved through iris-scanning technology developed by Tools for Humanity, the company behind the initiative. Using a device called the Orb, the system captures an image of a person’s iris and converts it into a unique cryptographic hash known as an IrisCode. This code is then checked against a global database using zero-knowledge proofs to confirm uniqueness without storing or transmitting the original biometric data.
According to Daniel Shorr, chief of staff to the CEO at Tools for Humanity, the vision is to re-engineer digital identity around privacy and security. “It’s a re-engineering of the stack around a very simple idea: Humans should have a right to exceptional privacy and security,” Shorr said at the event. He emphasized that the system is designed to prevent abuse, impersonation, fraud, and misinformation by ensuring that online interactions can be trusted as human-to-human or human-delegated-agent.
Since its launch, more than 18 million people across 160 countries have verified their humanness using the Orb, with over 450 million verifications recorded to date, according to company executives. The Orb uses multispectral sensors and infrared light to capture high-resolution iris images, which are processed on-device to generate the IrisCode. Original images are deleted by default, and the IrisCode is anonymized and fragmented across secure servers to reduce the risk of reverse engineering or data breaches.
New features in World ID 4.0 and expanding ecosystem
The latest version, World ID 4.0, introduces several technical upgrades aimed at improving scalability, security, and usability. These include key rotation, which detaches cryptographic keys from identity to prevent long-term tracking; multi-party entropy, which ensures that each interaction remains unlinkable; and finer credential controls, giving users more granular control over how their identity is used. Shorr explained that these updates make the protocol more resilient and adaptable to evolving threats in the AI era.
One of the most notable additions is the Selfie Check feature, which allows users to verify their identity using a facial selfie instead of the Orb device. While Shorr acknowledged that this method is not as robust as iris verification, he described it as “really, really compelling for specific use cases” where the highest level of assurance is not required. This flexibility aims to broaden adoption across different contexts, from low-risk logins to high-security transactions.
World ID also now includes agent delegation tools, which Shorr likened to a “power of attorney for your agent.” These tools allow verified humans to authorize AI agents to act on their behalf in digital environments, such as signing documents or making purchases, while maintaining accountability. As AI agents proliferate, Shorr said, the question becomes: “How do you make sure the right humans are in the loop?” He added, half-joking, that the goal is to avoid scenarios where autonomous systems operate without human oversight — referencing the fictional Skynet from the Terminator franchise as a cautionary extreme.
In line with its goal of broader integration, World ID announced partnerships with Okta and Zoom. Okta has introduced Human Principal, a verification method based on World ID that is now available in beta. This allows enterprises to confirm that users accessing their systems are verified humans, adding a layer of trust to identity and access management. Meanwhile, Zoom is integrating World ID to combat deepfakes in video calls. The system will match live video feeds with the Orb-verified ID stored on a user’s device, displaying a badge in the Zoom window to indicate that the participant has been verified as human — all without leaving the device or transmitting raw biometric data.
Criticism and concerns over privacy and centralization
Despite its ambitious goals, World ID has faced significant criticism from privacy advocates, technologists, and regulators. Detractors, including whistleblower Edward Snowden, have warned that collecting iris data — even in anonymized form — creates risks of misuse, unlawful surveillance, and function creep. Snowden has previously argued that biometric databases controlled by private entities pose inherent dangers to civil liberties, particularly in authoritarian regimes.
Other concerns center on the project’s reliance on a single private company, Tools for Humanity, which critics say creates a central point of failure and requires users to place blind trust in one entity. David Shipley of Beauceron Security argued that proof of being human should be treated as a public good, not a proprietary service. “This feels like a super-bad idea,” Shipley said of World ID. “While having a secure, verified digital ID as a service that can be trusted is much needed, it shouldn’t be delivered by a private sector entity. Private sector control of personhood feels Hollywood-style cyber dystopian.” He emphasized that such systems should be governed by public bodies accountable through democratic representation.
The initiative has also drawn scrutiny for its deployment in developing nations. In Kenya, the program gained widespread traction because users received Worldcoin (WLD) cryptocurrency in exchange for iris scans. Critics alleged this constituted inducement or bribery, particularly among economically vulnerable populations. Following public backlash and regulatory concerns, Kenya suspended the program. Similar actions have been taken in Brazil, Indonesia, Hong Kong, and Spain, where World ID operations have been banned or suspended over data privacy and consent issues.
Legal experts have raised questions about compliance with data protection laws such as the GDPR in Europe and similar frameworks elsewhere. Because irises are immutable — unlike passwords or even facial features that can change over time — a breach of iris data could have permanent consequences. Although World ID claims it does not store raw iris images and uses zero-knowledge proofs to protect privacy, skeptics argue that the long-term security of such systems remains unproven at scale.
Monetization model and future outlook
To sustain the network without compromising user privacy, World ID is exploring a monetization model based on fees paid by developers and services that request identity verification. Shorr explained that because the system is designed not to share or sell user data, traditional advertising-based models are not viable. Instead, the team looked to historical precedents and concluded that charging apps for access to verified human users is a sustainable approach. “We dug through the history books, and we came up with an inventively classic approach: Fees,” he said. Under this model, businesses would pay when they request World ID proof, ensuring that individuals are not monetized as data points.
The project continues to evolve, with ongoing work on improving accessibility, reducing Orb distribution costs, and expanding third-party audits. Tiago Sada, chief product officer at Tools for Humanity, highlighted the protocol’s open-source nature, regular security updates, and commitment to transparency as key strengths. He noted that the system uses multiple cryptographic primitives — including anonymized multi-party computation and zero-knowledge proofs — to protect users throughout the verification process.
As AI-generated content becomes increasingly indistinguishable from human-created material, the need for reliable proof of human presence online is likely to grow. Whether World ID can overcome its controversies and achieve widespread adoption as a trusted, privacy-preserving identity layer remains uncertain. For now, the initiative stands at the intersection of innovation and debate, offering a bold vision for digital identity in the age of AI — one that promises security and inclusivity, but demands rigorous scrutiny to ensure it does not compromise the very rights it seeks to protect.
Worth a look