Volume 56
Volume 56 | April 24, 2026
🎙 Secured Podcast
Episode 11 | Like it or not AI is coming for access control
AI isn’t coming. It’s already here. Access control just hasn’t caught up yet.
Listen now.
West to East series | This week we are featuring:
Kyle Gordon and Tobin Richardson
✍🏻 Articles
Hailey Canady | The Security Industry Has a Branding Problem…
The security industry isn’t exactly “sexy”… but that might be exactly why it’s being overlooked.
Read below
Kabir Maiga | The Bouncer Has A Blacklight. The Door Doesn’t Need One.
Age verification still relies on human judgment and plastic cards. That’s starting to change in a much bigger way than most people realize.
Read below
Steve Van Till | Integration Goes to Zero
AI is about to change systems integration in a big way. What used to take teams and time could soon be done by anyone. Originally published here.
Read below
🚨 Breaking News
Breaking: dormakaba names Heather Torrey as Executive Vice President for the Americas.
Scroll down to go deeper ↓
![]()
Podcast | Secured: Episode 11
In this episode of Secured, Lee unpacks what AI entering access control really means beyond the headlines. He explores how it’s starting to impact integration, workflows, and decision-making, and why this shift could change where value is created across the industry. As things begin to move faster, he breaks down what’s real, what’s overhyped, and what people should actually be paying attention to right now. Listen now.

From West to East, the conversation doesn’t stop at the show floor. This podcast series brings together 45 voices from across the industry to share what’s actually top of mind right now. You can stream right from the Secured Youtube channel.
Kyle’s Episode: here, Tobin’s Episode: here

I’ll be honest, I didn’t even know this industry existed until not that long ago.
And I really don’t think I’m the only one.
That’s part of the problem.
The security industry is full of smart, experienced, talented people doing meaningful work. But if younger people don’t know the space exists, don’t understand why it matters, or don’t see themselves in it, then eventually that becomes a bigger issue than people want to admit.
Because no matter how strong the industry is today, life works the way life works. New generations have to keep coming in. They have to be taught what the people in this industry already know, but they also have to be allowed to bring something new with them. Their perspective matters too. How they communicate matters. What they pay attention to matters. What they find engaging, relevant, and worth caring about matters.
And right now, I think that is where the disconnect is.
This industry has a branding problem.
Not because the work isn’t important. It is.
Not because there isn’t opportunity. There absolutely is.
And not because the people in it aren’t impressive, because they are.
The issue is that it doesn’t present itself in a way that naturally pulls new people in.
The phrase “security industry” alone does not exactly sound exciting. It doesn’t sound eye-catching. It doesn’t sound like something a younger person is immediately going to want to explore. It sounds serious, maybe even important, but not necessarily interesting. And in a world where other industries are constantly marketing themselves as innovative, fast-moving, creative, and full of opportunity, security can feel quiet to the point of being invisible.
That matters more than people think.
Because once you actually get closer to this space, you realize how much it touches everyday life. It affects where we live, where we work, how we move, how we travel, how we feel, and how safe we are. It is everywhere. It just stays behind the scenes.
That is what makes it so important. It is also what makes it so easy to overlook.
I think the industry is in a weird phase right now where a lot of people are noticing the same problems, but no one is fully saying the quiet part out loud. There is this feeling that something big needs to happen before the rest will follow. But I don’t really think waiting is the answer.
I think the answer is being more proactive about change.
That means thinking more seriously about branding, storytelling, recruiting, and visibility. It means speaking to more than one type of audience. It means understanding that what has always worked may still work, but that doesn’t mean it will be enough to keep carrying the industry forward. If companies only market the same way, recruit the same way, and talk to the same people over and over again, then they are limiting how much room they have to grow.
And in an industry where everyone knows everyone, that matters.
Because yes, the security industry is huge. But it can also feel surprisingly small. And if the same voices keep speaking to the same circle, then the space will keep feeling smaller than it actually is.
Broadening the audience only helps. Reaching younger people only helps. Using newer tools, newer platforms, and more relevant ways of communicating only helps.
That doesn’t mean throwing away everything that already works. It just means recognizing that you cannot keep relying on the same methods forever if you want new attention, new talent, and new energy to come in.
And as someone from Gen Z, I think I can say that pretty honestly.
I’m not coming at this from a deeply technical background. I’m coming at it from the perspective of someone who is newer to the industry and can see, pretty clearly, why it might not be landing the way it needs to with younger people. I can also see how much potential it has if it were positioned differently.
Because once you do get into this world, you realize it is meaningful work. It matters. It is interesting. It is layered. It is evolving. There is so much more here than people on the outside would ever expect.
But they have to know that first.
And that’s where I think the industry still has work to do.
We need to make this space easier to understand, easier to talk about, and honestly, a little easier to market. We need to make it feel more relevant to people who have never been exposed to it. We need to make it more visible. More compelling. More appealing.
Not because the industry needs to become something it’s not, but because it needs to do a better job showing people what it already is.
Because if more people my age actually knew what was here, I really do think more of them would care.
And if we want this industry to keep growing, that matters.

Somewhere in America right now, a bouncer is looking at a plastic driver’s license under a blacklight, trying to decide if a 19-year-old is a 21-year-old. He’s right most of the time. He’s also the reason a gaming floor in Illinois, a dispensary in Colorado, or a sportsbook in New Jersey is one bad judgment call away from serious regulatory exposure.
This is how age verification mostly still works in 2026. Human judgment plus a plastic card. Not especially reliable, and everywhere.
Mobile driver’s licenses have changed this. Governments are issuing them as cryptographic, phone-based credentials defined by the ISO 18013-5 standard. They have a feature the plastic card never had. They can answer narrow questions.
An mDL can respond to “is this person over 21?” with a single boolean. No birthdate transmitted. No name. No photo. No document number. Just the fact the door actually needs.
That small capability unlocks something bigger. Identity-based access is the idea of making an access decision based on who a person verifiably is, rather than what token they happen to be carrying. The credential isn’t something the system issues. It’s something the person already has.
What regulated access is
Age verification at a gaming floor is one example of a bigger category. Regulated access is physical entry governed by legal compliance rather than employment. These are the doors that open not because an employer said so, but because a regulator said so.
Age-restricted environments: gaming floors, cannabis dispensaries, sportsbooks. Cleared-personnel zones: ITAR-controlled rooms, defense contractors, SCIFs. Regulated care spaces: medication rooms, pharmacy areas, clinical trial units. Controlled perimeters: airside access, port security.
These categories aren’t identical. Age verification at a gaming floor is essentially clipboard replacement, and mDL selective disclosure is close to a perfect fit. Cleared- personnel zones (defense, airside, port) already run sophisticated systems like PIV and TWIC. There, mDL looks more like an upgrade path. What they share is urgency driven by law rather than company policy.
The economics are inverted
You’re usually not adding identity alongside a working system. You’re replacing a clipboard, a visual ID check, or a legal exposure the general counsel already loses sleep over. The buyer isn’t negotiating a credential contract; they’re buying down regulatory risk. The ROI is immediate. Urgency comes from a regulatory deadline or a penalty already levied, not a budget cycle.
The buyer title changes too. It’s often a compliance officer, a general counsel, or an operations lead who’s personally accountable for a specific legal outcome. A conversation with different urgency and a different procurement path.
The technical fit is especially clean
Most compliance regimes require verification but penalize over-collection. Biometric privacy laws like Illinois BIPA put real teeth behind that principle. The older tooling is a visual ID check or a scanner that photographs the license. It either over-collects and creates breach risk, or under-verifies and creates compliance risk. mDL selective disclosure hits the narrow middle.
I build software that runs at the access control panel level. When a compliance-driven buyer shows up in an access control conversation, the driver isn’t “make life easier for our employees.” It’s “keep us from getting fined.” That changes the shape of the whole sale.
Why this matters
Regulated access is where some of the most interesting doors are starting to open. And the work done there will matter well beyond it.
When a hospital deploys mDL-based access in its medication rooms, the integration work and operational familiarity don’t stay in the pharmacy. They become the scaffolding for whatever that hospital does with identity-based access next. Same with a casino operator. Their age-verification deployment builds vendor relationships and operational expertise that carry over to whatever they do with identity next.
The bouncer with the blacklight isn’t going away tomorrow. But some of those doors are already opening to a cryptographic answer instead of a judgment call. The work it takes to build well for those doors is work the industry will need everywhere.

AI is about to radically restructure the multi-billion dollar systems integration business by changing the way software and hardware products can talk to each other. The reigning paradigm of bespoke integrations crafted by the software vendors themselves is about to end. Instead we will see agent-coded connectors that can be created by anyone, with minimal effort, and only rudimentary technical skills. This shift will give systems integrators and end users a massive expansion of choices for how they can use and interconnect the open systems of their choosing – or at least those with agent-friendly APIs.
Best of all: the cost of integration approaches zero.
The math is the problem
What makes this such a big deal is the raw math of connecting a large number of disparate products or endpoints in a multi-vendor ecosystem. Metcalfe’s Law famously observes that the number of connections between N nodes in a network is proportional to N2 ( N squared), which is to say that it gets very big very fast. In a network with 100 endpoints, for example, there are (100)2, or 10,000 possible interconnections. In a network of 1,000 endpoints, N2 equals 1 million. You can see where this is going.
The good news in Metcalfe's Law is that the utility of such networks or ecosystems also increases at the same rate – N2. That mathematical fact has been the basis of value creation in transportation systems, telecommunications networks, and the internet as a whole. A railroad system connecting thousands of producers and consumers was the infrastructure of the industrial revolution, and the computer network known as the internet with billions of users is what has given us the modern information economy….. To read full article, visit link.
đź‘€ As Seen in the PhySec Community this Week:
#security-research
|
|
​Industry Night at TSE returns for its second year on Tuesday, April 28 at 6:00 PM at The Botanist. Join us for an evening of connection and conversation with professionals from across the access control and security ecosystem. Attendance is capped at 120 guests, with food and drinks included, and a portion of proceeds supporting FAST. Sign up here to register .

ACS26, The Access Control Summit, is heading to New Zealand in 2026, hosted in collaboration with our city-host, Gallagher Security. Join us October 7–8, and sign up here to be notified first when registration goes live.
