A regulatory first is worth noticing: the Central Bank of the UAE has mandated that banks phase out SMS and email one-time passcodes by March 2026, replacing them with risk-based multi-factor authentication built on facial biometrics, device tokens and national digital identity. It is the first outright regulatory retirement of the OTP, and it will not be the last.
Everyone knew, someone finally acted
The security industry has documented OTP weaknesses for a decade: SIM-swap takeovers, real-time phishing relays, malware that reads messages, and users trained to type codes wherever asked. PSD2's "possession" factor kept SMS alive in Europe on the argument that something imperfect beats passwords alone. The UAE has now made the opposite bet: at current fraud levels, imperfect is unaffordable.
What replaces it
The replacement stack is recognisable: biometrics bound to a verified identity, cryptographic device credentials, and step-up verification proportional to risk. The critical dependency is the first mile, binding the biometric to a real, government-proofed person, because authentication is only as strong as the enrolment behind it. That first mile is WeVerify's core: NFC chip verification with certified liveness, and reusable verified identity for instant step-up afterwards. When your regulator writes its own OTP obituary, the enrolment layer is what you will be inspected on.
