Biometric Payment Systems in 2026: What Works and What Failed

Hand pressing a glowing fingerprint scanner on a tabletop device in a blue-lit futuristic interior

Biometric payments were supposed to be the obvious next step: pay with a fingerprint, a face or a palm, and never touch a card again. Two years on, the picture is more interesting than that. Some biometric payment methods have quietly become the default for billions of people. Others have been switched off entirely.

This article sets out where biometric payments actually stand in 2026 — what shipped, what stalled, what the security research says, and how the rules changed on both sides of the Atlantic.

Key Takeaways

  • Device-based biometric authentication won; in-store biometric checkout largely did not.
  • Amazon shut down Amazon One for retail in June 2026, citing limited customer adoption.
  • Passkeys are the mainstream form biometric payment authentication actually takes.
  • Mastercard and Visa have both committed to removing manual card numbers and one-time codes.
  • Injection and deepfake attacks — not fake fingerprints — are the live threat.
  • The EU AI Act’s high-risk deadline moved to December 2027; most 1:1 payment verification sits outside it anyway.
  • Illinois BIPA no longer supports per-scan damages, and that change applies retroactively.

What Biometric Payment Systems Actually Are

A biometric payment system confirms who you are using a physical or behavioural trait — a fingerprint, a face, an iris, a palm, a voice — instead of, or alongside, something you know. The trait replaces the password or PIN in the authentication step. It does not replace the card network, the account or the settlement rails underneath.

That distinction matters more than it sounds. Almost every biometric payment you make today is a local check on your own device that releases a cryptographic key or a payment token. The bank never receives your fingerprint. This is very different from a system that captures your face at a till and matches it against a central database, and the two have had very different fates.

The first model is now embedded in digital wallets and phone-based checkout used by hundreds of millions of people. The second — biometric identification at the point of sale — is the one that keeps running into cost, consent and adoption problems.

What Changed Between 2024 and 2026

Three shifts define the current state of fintech’s payment layer.

Amazon walked away from palm payments in retail. On 28 January 2026 Amazon announced it was discontinuing Amazon One for facility access and payment, with the service ending on 3 June 2026. Its stated reason was blunt: limited customer adoption. The shutdown covered palm scanning at more than 500 Whole Foods locations and Amazon’s own Go and Fresh stores in the US, and Amazon said associated customer data would be securely deleted. Patient check-in at existing healthcare sites is the only use that continues. When the company with the deepest pockets and the best store footprint in the category withdraws, that is a data point worth taking seriously.

Card networks moved their security story to passkeys and tokenisation. Mastercard committed in June 2024 to 100% e-commerce tokenisation in Europe by 2030 and to phasing out manual card entry, passwords and one-time codes; in March 2025 it extended the ambition to all markets. By June 2026 the company reported that three in five of its European e-commerce transactions were tokenised, with Click to Pay live in 32 European markets. Visa’s Payment Passkey follows the same logic on the authentication side.

In-store biometric checkout went quiet. Mastercard’s Biometric Checkout Program reached Europe in June 2024 through a Polish pilot with PayEye — across five stores. No expansion announcements have followed. The programme has not been cancelled, but it is not where the networks are spending their communication budget.

Types of Biometric Authentication Used in Payments

Several methods are in production, with genuinely different risk and cost profiles:

  • Fingerprint scanning: the workhorse. Cheap, fast, and already present on almost every phone, which is why it dominates.
  • Facial recognition: used for device unlock and 1:1 verification; the controversial cases are 1:many identification in public or retail space.
  • Voice recognition: mostly used in contact centres and telephone banking rather than at checkout.
  • Iris and palm recognition: accurate, but requires dedicated hardware — the economics that sank Amazon One.
  • Behavioural biometrics: typing rhythm, swipe patterns, device handling. Runs silently in the background as a fraud signal, which is where it does its best work.

Gloved hand reaching toward a glowing fingerprint on a blue circuit board ringed with currency symbols

The strongest signal of the last two years: methods riding on hardware people already own scale, and methods requiring merchants to buy new terminals mostly do not — a lesson visible across autonomous retail and phygital store formats.

Where Biometrics Genuinely Help

Stronger Authentication Than Shared Secrets

Passwords and one-time codes can be phished, reused and intercepted. A biometric check bound to a specific device cannot be handed over by a customer who has been talked into it on the phone. Visa reports that its Payment Passkey approach cuts fraud by around half compared with SMS one-time passcodes, based on its own network data. That is the core security argument, and it holds.

Fewer Abandoned Checkouts

Every extra authentication step costs conversions. Removing manual card entry and code retyping is worth real money to merchants: Mastercard reports that tokenised transactions lift approval rates, and that returning customers dominate its Click to Pay volume. This is the commercial reason the change is happening, more than security is.

Speed at the Point of Payment

A biometric check completes in under a second and needs no recall effort from the customer. Combined with mobile commerce habits and one-tap wallets, it removes most of the friction that used to sit between intent and purchase.

Who Is Actually Deploying This

Mastercard

Mastercard’s Payment Passkey Service launched first in India in August 2024 and has since reached Latin America and parts of Europe through payment processors. In Asia Pacific the company committed in November 2025 to password-free and number-free checkout by 2030, with full tokenisation in Singapore, Malaysia and Vietnam targeted for 2027.

Its in-store biometric work is more modest than the headlines suggest. The often-quoted Brazilian pilot with St Marche ran with 919 monthly active users and about 5,300 transactions; 76% of participants said they would recommend it. Encouraging, but a pilot, not a rollout.

Visa

Visa Payment Passkey is built on FIDO2. The credential lives on the customer’s device and a biometric or device PIN unlocks it. Visa points to roughly four billion FIDO-capable devices worldwide as the reason this can scale without new hardware. India was the first major market, starting with IDFC FIRST Bank and a long list of gateways and merchants.

Amazon

Amazon One is the cautionary tale. Palm recognition worked technically, but never attracted enough repeat use to justify the hardware, and the service was retired in June 2026.

The Real Risks in 2026

Injection and Deepfake Attacks

The threat model has moved. Attackers are no longer mainly trying to fool a sensor with a fake fingerprint; they are bypassing the sensor entirely and injecting synthetic video or images into the capture stream. iProov’s 2026 threat intelligence report, covering 2025 data, recorded a 741% rise in injection attacks on iOS across the year, with the sharpest increase in the second half. Gartner research cited in the same report found that 37% of cybersecurity leaders had encountered deepfakes on video calls.

This matters for a specific reason: ISO/IEC 30107-3:2023, the standard used to test presentation attack detection, covers spoofing at the sensor. Injection attacks sit outside its test scope. A vendor certified against it is not thereby protected against the attack class that is actually growing. If you are procuring biometric verification, ask about injection detection separately. The broader picture is covered in our overview of cybersecurity trends for businesses.

Data That Cannot Be Reissued

A stolen password is replaced in seconds. A stolen biometric template is a permanent problem, because you cannot be issued a new face. The mitigations that work in production are architectural rather than procedural: keep the template on the device in a secure element, never transmit the raw biometric, and use tokenisation so the card number is never exposed either. ISO/IEC 24745 sets out the requirements for biometric template protection — irreversibility, renewability and unlinkability — and is the right thing to hold a vendor to.

One countervailing trend is worth watching: analysts at Goode Intelligence have noted a shift toward server-side matching for higher-value transactions, which abandons the on-device protection that makes the consumer model safe. Centralised templates turn one breach into an unrecoverable one — a concern that also drives interest in decentralised identity models.

Cost, Accuracy and Consent

Dedicated hardware is expensive to buy, install and maintain across a store estate, accuracy varies by method and by population, and several jurisdictions now require a non-biometric alternative — which means running two systems instead of one. For most merchants, the phone in the customer’s pocket already solves the problem.

Passkeys: The Model That Won

How Passkeys Work

A passkey is a public/private key pair. The private key stays on your device; the service holds only the public key. When you pay, your device signs a challenge — but only after you unlock it with your fingerprint, face or device PIN. As the FIDO Alliance puts it, the biometric information stays on the device and is never sent to a remote server; the server only receives an assurance that the check succeeded.

The important nuance: the biometric is not the credential. It is the local gate that releases the credential. That single design decision removes the central biometric database that makes people nervous, and it is why this model scaled where retail face-matching did not.

Why It Beat In-Store Biometrics

Passkeys work with hardware that is already deployed, they resist phishing by construction, and they require no merchant investment. The adoption numbers reflect that. The FIDO Alliance’s 2026 World Passkey Day research, based on a Sapio survey of 11,000 consumers across ten countries, estimated around five billion passkeys in use, with 90% consumer awareness, 75% having enabled at least one, and 49% using them regularly where available. On the enterprise side, 68% of organisations reported deploying or planning passkeys for employee sign-in.
Tablet showing fingerprint scans, a padlock and a QR code against glowing fingerprint-and-keyhole graphics

Security Benefits in Practice

  • Nothing to phish: there is no shared secret to hand over, so the standard social-engineering script fails.
  • Nothing to breach centrally: a server compromise yields public keys, not credentials.
  • Higher approval rates: both Visa and Mastercard report better authorisation outcomes than code-based flows.
  • No new hardware: the deployment cost sits at close to zero for merchants.

Market Direction: Wallets, Tokens and Credit at Checkout

Biometric authentication rarely arrives on its own. It comes bundled with a wallet, a token and often a credit option.

Tokenisation is the quiet foundation. Replacing the card number with a randomly generated token means the real credentials never travel, which is what makes one-tap repeat purchases safe. Mastercard’s European progress — three in five e-commerce transactions tokenised as of mid-2026 — shows how far this has gone in a single region.

Buy now, pay later continues to sit alongside these flows rather than competing with them, and the same authentication layer serves both. Meanwhile open banking rails and embedded finance are pushing payment initiation into places that are not banks at all, from marketplaces to super apps. Biometric verification is the piece that makes those handoffs feel safe enough to use.

Adjacent areas — peer-to-peer lending, blockchain settlement, predictive analytics in finance — all rest on answering the same question first: is this person who they claim to be?

Regulation and Consumer Rights in 2026

European Union

The EU AI Act’s prohibitions and AI literacy obligations took effect on 2 February 2025, and general-purpose model rules followed on 2 August 2025. The high-risk deadline moved: Regulation (EU) 2026/1744, the digital omnibus on AI, entered into force on 27 July 2026 and pushed stand-alone Annex III high-risk obligations to 2 December 2027, with product-embedded systems following in August 2028.

For payments specifically, do not overstate the exposure. Annex III carves out AI systems used for biometric verification whose sole purpose is confirming that a person is who they claim to be. Most 1:1 payment authentication therefore falls outside the high-risk category — though GDPR still treats biometric data used for identification as a special category requiring an explicit legal basis. Teams working through this alongside other obligations may find our RegTech overview useful.

On payments law, PSD3 and the Payment Services Regulation reached provisional political agreement in late November 2025. Strong customer authentication survives, with clearer rules and more flexible risk-based exemptions rather than a new biometric mandate. Practical applicability is expected around 2028, so PSD2 remains the operative regime for now.

United States

The US picture reversed direction. Illinois amended BIPA through SB 2979, signed in August 2024, so that repeated collection of the same identifier from the same person by the same method counts as a single violation — removing the per-scan damages theory that drove the largest settlements. In 2026 the Seventh Circuit held that this change applies retroactively, which further narrows legacy exposure.

The risk has not gone away, though. Colorado’s biometric amendment took effect on 1 July 2025, treating biometric identifiers as sensitive data requiring consent, mandating deletion within 24 months and carrying penalties up to $20,000 per violation. Texas amended CUBI in June 2025 through its AI statute.

Asia and Beyond

China’s Measures for the Security Management of Facial Recognition Technology Applications took effect on 1 June 2025 and require that a non-facial alternative be available — a direct constraint on face-only checkout. India notified its DPDP Rules on 14 November 2025, with phased compliance. Businesses operating across regions should also factor in data localisation requirements, which determine where biometric templates may be stored at all.
Glowing shield with a fingerprint inside it standing before a domed government building at sunset

What to Do Now

For businesses, the practical guidance in 2026 is narrower than the hype suggests. Support passkeys and tokenised wallet payments — that is where the fraud reduction and the conversion gain sit, and it costs nothing in hardware. Be sceptical about buying biometric capture terminals unless you have a specific, measured queue or shrinkage problem that nothing cheaper solves.

If you do process biometric data directly, keep templates on the user’s device, insist on injection attack detection rather than presentation attack certification alone, offer a non-biometric alternative by default, and document your legal basis before deployment rather than after. The same discipline applies to biometric authentication inside the workplace, where the consent picture is more complicated because employees cannot freely refuse.

For consumers the calculus is straightforward. Device-based biometrics and passkeys are meaningfully safer than passwords and SMS codes, because the biometric never leaves your phone. Systems that upload your face or palm to someone else’s database deserve more scepticism, and in a growing number of jurisdictions you may decline them. Most people appear to have reached that conclusion already: a 2026 Aevi survey of UK and US adults found fewer than half trust companies to protect biometric data they hand over.

Conclusion

Biometric payments did arrive — just not in the form the 2024 forecasts described. The winner was the quiet version: a fingerprint or a face that unlocks a cryptographic key on a device you already own, invisible to the merchant and to the bank. The loud version, where you present your palm to a scanner in a shop, has been retired by its most committed backer.

The useful question for 2026 is no longer whether to adopt biometrics. It is which architecture you adopt, and whether the biometric ever leaves the customer’s hands. Get that right and the security and conversion benefits are real. Get it wrong and you are storing data you can never make safe again, under rules that are tightening in most of the markets that matter. Our wider look at cybersecurity fundamentals covers the controls that surround this decision.

Found this useful?

Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.

Add as Preferred Source

FAQ

What are biometric payment systems?

Biometric payment systems authenticate a transaction using a physical or behavioural trait — a fingerprint, face, iris, palm or voice — instead of a password or PIN. In almost all consumer deployments today, the check happens locally on your own device and releases a cryptographic key or a payment token; the merchant and the bank never receive the biometric itself. A smaller category of systems captures the trait at a terminal and matches it against a central database. The two models carry very different privacy and security profiles, and it is worth knowing which one you are being asked to use.

Are biometric payments more secure than passwords and PINs?

Device-based biometric authentication is meaningfully more secure, mainly because there is no shared secret to phish, reuse or intercept. Visa reports that its passkey-based flow roughly halves fraud compared with SMS one-time passcodes, based on its own network data. The caveat is that security depends on architecture rather than on the biometric itself. A system that keeps the template in a secure element on your phone is strong; one that uploads your face to a central database creates a permanent liability, because a compromised biometric cannot be reissued the way a password can.

What happened to Amazon One palm payments?

Amazon announced on 28 January 2026 that it was discontinuing Amazon One for facility access and payment, with the service ending on 3 June 2026. The company cited limited customer adoption and said associated customer data would be securely deleted after shutdown. The change removed palm payment from more than 500 Whole Foods locations and from Amazon’s own Go and Fresh stores in the US. Patient check-in at existing healthcare sites continues for now. It remains the clearest evidence available that dedicated in-store biometric hardware struggles to earn back its cost.

Is a payment passkey the same thing as a biometric payment?

Not quite, and the distinction matters. A passkey is a public/private key pair: the private key stays on your device and the service holds only the public key. Your fingerprint or face is the local gate that unlocks that key — it is not the credential and it is not transmitted. As the FIDO Alliance describes it, the biometric stays on the device and the server only receives an assurance that the check succeeded. So a passkey payment feels like a biometric payment to the user, but architecturally it avoids sending or storing biometric data anywhere outside your phone.

What is the main security threat to biometric payments in 2026?

Injection attacks, not fake fingerprints. Rather than fooling a sensor with a spoof, attackers bypass the sensor entirely and inject synthetic images or video into the capture stream, often using virtual cameras and generative tools. iProov’s 2026 threat report recorded a 741% rise in injection attacks on iOS across 2025. This creates a procurement trap: ISO/IEC 30107-3:2023 tests presentation attack detection at the sensor, so certification against it says nothing about injection resistance. Ask vendors about injection detection as a separate question.

Which laws govern biometric payment data in 2026?

In the EU, GDPR treats biometric data used for identification as a special category needing an explicit legal basis, while the AI Act adds obligations for certain biometric systems — though 1:1 verification to confirm someone is who they claim to be is carved out of the high-risk category, and the high-risk deadline moved to December 2027. In the US, rules are state-level: Illinois BIPA, Texas CUBI and Colorado’s biometric amendment, which took effect on 1 July 2025. China has required non-facial alternatives since June 2025, and India notified its DPDP Rules in November 2025.

Should my business invest in biometric checkout hardware?

For most merchants, no. The evidence from 2024 to 2026 is that dedicated biometric terminals are expensive to deploy and maintain and struggle to generate enough repeat use to justify the cost — Amazon retired its own palm system for exactly that reason. Supporting passkeys and tokenised wallet payments delivers the fraud reduction and the checkout-conversion gain at close to zero hardware cost, because the biometric hardware already sits in your customer’s pocket. Consider dedicated capture only where you have a specific, measured queue or shrinkage problem that nothing cheaper solves.

Author

  • Felix Römer

    Felix is the founder of SmartKeys.org, where he explores the future of work, SaaS innovation, and productivity strategies. With over 15 years of experience in e-commerce and digital marketing, he combines hands-on expertise with a passion for emerging technologies. Through SmartKeys, Felix shares actionable insights designed to help professionals and businesses work smarter, adapt to change, and stay ahead in a fast-moving digital world. Connect with him on LinkedIn