Item 1A. Risk Factors 6
Item 1B. Unresolved Staff Comments 22
Item 1C. Cybersecurity 22
Item 2. Properties 24
Item 3. Legal Proceedings 24
Item 4. Mine Safety Disclosures 24
PART II
Item 6. Reserved 29
Item 7A. Quantitative and Qualitative Disclosures About Market Risk 38
Item 8. Financial Statements and Supplementary Data 38
Item 9A. Controls and Procedures 38
Item 9B. Other Information 38
Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspection 38
PART III
Item 10. Directors, Executive Officers and Corporate Governance 39
Item 11. Executive Compensation 45
Item 14. Principal Accounting Fees and Services 56
PART IV
Item 15. Exhibits and Financial Statement Schedules 57
SIGNATURES 60
i
FORWARD-LOOKING
STATEMENTS
Certain
statements discussed in Item 1 (Business), Item 1A (Risk Factors), Item 3 (Legal Proceedings), Item 7 (Management’s Discussion
and Analysis of Financial Condition and Results of Operations), Item 7A (Quantitative and Qualitative Disclosures About Market Risk)
and elsewhere in this Annual Report on Form 10-K as well as in other materials and oral statements that the Company releases from time
to time to the public constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform
Act of 1995. Such forward-looking statements concerning management’s expectations, strategic objectives, business prospects, anticipated
economic performance and financial condition and other similar matters involve significant known and unknown risks, uncertainties and
other important factors that could cause the actual results, performance or achievements of results to differ materially from any future
results, performance or achievements discussed or implied by such forward-looking statements. Such risks, uncertainties and other important
factors are discussed in Item 1A (Risk Factors) and Item 7 Management’s Discussion and Analysis of Financial Condition and Results
of Operations. In addition, these statements constitute the Company’s cautionary statements under the Private Securities Litigation
Reform Act of 1995. It should be understood that it is not possible to predict or identify all such factors. Consequently, the following
should not be considered to be a complete discussion of all potential risks or uncertainties. The words “anticipate,” “estimate,”
“expect,” “project,” “intend,” “believe,” “plan,” “target,” “forecast”
and similar expressions are intended to identify forward-looking statements. Forward-looking statements speak only as of the date of
the document in which they are made. The Company disclaims any obligation or undertaking to provide any updates or revisions to any forward-looking
statement to reflect any change in the Company’s expectations or any change in events, conditions or circumstances on which the
forward-looking statement is based. It is advisable, however, to consult any further disclosures the Company makes on related subjects
in its Quarterly Reports on Form 10-Q and Current Reports on Form 8-K filed with the Securities and Exchange Commission.
ii
PART
I
Item
1. Business
Overview
authID Inc. (the “Company”) ensures enterprises “Know
Who’s Behind the Device”TM for every customer or employee login and transaction, through its easy-to-integrate,
patented, biometric identity platform. authID powers biometric identity proofing, biometric authentication, and account recovery with
a fast, accurate, user-friendly experience. With our PrivacyKeyTM solution, authID provides highly accurate biometric authentication
while storing no biometric data. authID’s goal is to stop fraud at onboarding, blocks deepfakes, prevents account takeover, and
eliminates password risks and costs, through the faster, frictionless, and most accurate user identity experience demanded by today’s
digital ecosystem.
Our
Platform
Our
cloud-based platform was developed with internally developed software as well as acquired and licensed technology and provides the following
core services:
● Biometric Identity Verification – ProofTM
● Biometric Identity Authentication - VerifiedTM
● PrivacyKeyTM Privacy Preserving Biometrics
● Identity Exchange (IDX) Platform
● authID Mandate Agentic AI Security
Biometric
Identity Verification - Proof
Biometric
identity verification establishes the trusted identity of a user based on a variety of ground truth sources, including government-issued
identity documents such as national IDs, driver’s licenses and passports or electronic machine-readable travel documents (or eMRTDs).
Our VerifiedTM platform detects presentation attack and spoofing threats, evaluates the authenticity of security features
present on a government-issued identity document, and biometrically matches the reference picture of the document with a live user’s
selfie (a photograph that the user has taken of themselves). Usually occurring at account opening or onboarding, identity verification
ensures that the enterprise knows that the person interacting with the enterprise is who they say they are, in real time. authID’s
ProofTM identity verification product eliminates the need for costly and less accurate face-to-face, in-person ID checks and
instead provides a verified identity in seconds. Additionally, authID’s PrivacyKeyTM technology enables customers to
perform biometric verification through the use of Public/Private Keys that is performed without storing any biometric data, which ensures
individual data privacy. In a digital, online world of increasing fraud and security threats, Proof speeds up onboarding and offers our
customers confidence in the identities of consumers, employees or third-party vendors.
Biometric
Identity Authentication - Verified
Biometric
identity authentication provides any organization with a secure, convenient solution to validate that an individual is the verified account
owner for various purposes including passwordless login and performing specific transactions, or functions. The authID Verified product
allows users to confirm their identity with their facial biometric by simply taking a selfie on a mobile phone or device of their choosing
(as opposed to dedicated hardware). The solution includes a patented audit trail created for each transaction, containing the digitally
signed transaction details, with proof of identity authentication and consent. Verified allows users to recover, via a facial biometric,
account access that is lost or blocked due to expired credentials, lockouts, lost or stolen devices, or compromised accounts. Because
the account owner’s root of trust is established in the cloud, recovery is independent of any device or hardware. In this way,
account recovery is instant, portable, and does not require the presence of or access to a previously provisioned device in order to
secure access from a different device.
1
PrivacyKey
Privacy Preserving Biometrics
authID’s
PrivacyKey solution provides biometric authentication without the requirement to store any biometric or derivative of biometric data.
The technology transforms biometric verification into Public/Private Key cryptography whereby the facial image of the person is converted
into an elliptical public/private key pair where only the public key is stored and the private key only exists during authentication
and is deleted immediately after. The solution is compliant to the ISO30136 Privacy Biometric standard and provides a False Match Rate
accuracy of 1:1 Billion at a False Rejection Rate of 0.3%, as confirmed by independent tests conducted by the Commonwealth Scientific
and Industrial Research Organization (“CSRIO”).
Identity
Exchange (IDXTM) Platform
authID’s
Identity Exchange (IDX) is a next-generation platform purpose-built to allow authorized personnel to create or claim a central credential
that can be leveraged across multiple subsidiaries of a large enterprise, simplifying and securing the management of workforce identities
across distributed workforces that include employees, contractors, vendors, and other third parties. IDX modernizes identity management
with centrally-managed, biometric-bound, passwordless, interoperable and reusable credentials that stop phishing attacks, ensuring only
verified users can access sensitive systems and data. IDX is the first enterprise platform built on the Accountable Digital Identity
Association (ADI Association) specification, ensuring it is aligned with global interoperability and data sovereignty standards as well
as privacy regulations.
authID
Mandate - Agentic AI Security Framework
authID
Mandate is a framework for biometrically binding human sponsors to the AI agents they launched, ensuring that agentic activity is governed
by the user’s own scope, while also providing an immutable audit trail of that sponsorship. This provides a level of governance
far beyond machine IDs, or vulnerable tokens that are otherwise the basis for most agentic deployment of auditability.
Key
Customer Benefits
Our
solutions allow our enterprise customers to:
2
Corporate
Information
The
Company was incorporated in the State of Delaware on September 21, 2011. Our corporate headquarters is a virtual address located at 1580
North Logan Street, Suite 660, Unit 51767, Denver, CO 80203 and our main phone number is (516) 274-8700. Our website address is www.authid.ai.
The information contained on, or that can be accessed through, our website is not incorporated by reference into this Form 10-K and you
should not consider information on our website to be part of this Form 10-K.
Global
Market Opportunity
The
momentum towards a digital economy in recent years, accompanied by a massive growth in cyberattacks, fraud, and account takeovers fueled
by Artificial Intelligence are driving the demand for more streamlined and more secure identity verification and authentication. The
World Economic Forum estimates digitally enabled platform business models will drive 70% of new economic value created over the next
ten years. Yet vast amounts of data have been compromised, and ransomware attacks have cost businesses hundreds of millions in remediation
costs, lost revenue and brand equity. Passwords and device authentication alone no longer provide the security needed to fight today’s
rampant cyber-attacks and account takeover schemes.
According to Statista, cybercrime costs in the
United States alone are projected to increase to approximately $900 billion in 2026 and are projected to grow to over $3.4 trillion in
2030 (Statista: Annual Cost of Cybercrime in the U.S. 2017-2030). In the 2025 Verizon Data Breach Investigation Report, 78% of 3,300
financial data breaches studied involved external actors, while 74% of all breaches were attributed to some form of social engineering,
stolen credentials, or human error. Verizon also found that Business Email Compromise (BEC) attacks now represent more than 50% of social
engineering incidents, having almost doubled in recent years. Further it is predicted that Artificial Intelligence (AI) will almost certainly
increase the volume and heighten the impact of cyberattacks.
Financial
services, ecommerce, the sharing economy, and healthcare businesses, among other industry verticals, are confronted by the challenges
of identifying their customers, patients and beneficiaries with ease and certainty in the digital world. Organizations across all sectors
need to control access to their data and applications by their employees. Governments around the world are enacting new data privacy
regulations and pushing for stronger authentication methods in commerce, which impose a “call to action” for many of these
entities.
These
factors have created a hyper-growth market for the identity verification and authentication industry as well as increased buyer demand
for integrated identity platforms that can provide a range of identity solutions to address the full authentication lifecycle to govern
the user journey. The Global Biometric Technology Market is estimated to reach a market size of over $50 billion by 2025, increasing
at a 20% CAGR to reach over $150 billion by 2030 (Grand View Research, Biometric Technology Market Size, Share & Trends Analysis
Report, 2023 - 2030).
Growth
Strategy
We
orient our business strategy and invest for future growth by focusing on the following key priorities:
3
Sales
and Marketing
authID
provides its software as a service (SaaS) platform based on a subscription and usage-based model, with fees per transaction, enrolled
or active users.
We
sell our platform primarily through our direct sales team, which consists of inside sales and field sales professionals based in the
United States. To power our efforts, we have built a team of subject matter experts in the identity space, and applied a regimented sales
execution strategy, allowing us to win against competitors with comparable products but a sub-optimal approach to the market. We also
use a lead generation service and digital marketing in order to carefully target potential customers and provide qualified leads for
our sales representatives to develop.
We
also work with partners such as cybersecurity and financial technology providers who provide our services to their customers through
OEM or reseller arrangements and allow us to broaden our customer reach.
Competition
The
market for our service offerings is highly competitive and rapidly evolving. We face competition from a broad range of providers with
solutions across the identity management lifecycle, including:
● New entrants seeking to develop and market competing technologies.
4
It
is also possible that, as the digital identity market continues to grow and evolve, larger companies with significant resources may increase
their presence in the market and develop competing solutions through internal efforts or partnerships with existing players.
Due
to our ability to serve both identity verification and authentication needs, as well as the tendency for enterprises to acquire multiple
digital identity solutions, we can and often do co-exist with competing products within our customer base.
Research
and Development
Our
research and development team is responsible for the design, development, testing and quality of our platform as well as any new technologies,
features, integrations and improvements. The team includes specialists in software engineering, user experience, quality assurance, product
management, infrastructure, and technical writing. Our employees are located primarily in the United States, with additional employees
and sub-contractors based in Europe, India and Latin America. We intend to continue to invest in our technology to strengthen and expand
our platform to stay ahead of our competition and meet the evolving needs of our current and prospective customers.
Intellectual
Property
We
rely on a combination of patents, trademarks, copyrights, trade secrets and contractual provisions to protect our proprietary technology.
For example, we enter into confidentiality and invention assignment agreements with our employees, consultants and other third parties,
and control access to software, services, documentation and other proprietary information. We believe the duration of our patents is
adequate relative to the expected lives of our service offerings. We also purchase or license technology that we incorporate into our
products or services. While it may be necessary in the future to seek or renew licenses relating to various aspects of our products,
we believe, based upon past experience and industry practice, such licenses generally could be obtained on commercially reasonable terms.
Governmental
Regulations
Due
to the security applications and biometric technology associated with the Company’s products and platforms, the activities and
operations of the Company are subject to license restrictions and other regulations, such as (without limitation) export controls and
other security regulation by government agencies. Expansion of the Company’s activities in areas such as financial services may
require government licensing in different jurisdictions and may subject it to additional regulation and oversight.
Data
protection legislation in various US States and foreign countries in which the Company does business require it to comply with additional
disclosure and consent requirements with regard to the collection, storage and use of personal information of individuals in those States
and countries, as well as register its databases with governmental authorities in those countries. Several US states have adopted or
are considering adopting a Biometric Information Privacy Act, or BIPA modelled on the Illinois statute, which governs the collection,
processing, storage and distribution of biometric information such as facial biometric templates and fingerprints. Several of these new
statutes give individuals rights of action to sue violators, which have resulted in several class action lawsuits. These regulations
could have a significant impact on our business.
Human
Capital
As
of December 31, 2025, the Company had a total of 46 employees who are located in the United States, Latvia and Colombia as well as outsourced
service providers. There are 30 employees in the United States who provide overall Company strategic, business and technological leadership,
as well as engineering and customer support. Employees in the U.S. and Latvia receive health benefits on a cost-sharing basis and employees
in Colombia are provided the respective Government required benefits.
Subsidiaries
Currently, the Company has four U.S. subsidiaries:
Innovation in Motion Inc., Fin Holdings, Inc., ID Solutions Inc. and authID Gaming Inc. The Company had one subsidiary in Colombia: MultiPay
S.A.S. which was dissolved as of August 2, 2024. The Company has one subsidiary in the United Kingdom: authID Enterprises Limited (formerly
Ipsidy Enterprises Limited). The Company is the sole shareholder of all its subsidiaries.
5
Available
Information
Our
Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and any amendment to these reports are filed with the SEC. Such
reports and other information filed by us with the SEC are available free of charge on our website at investors.authid.ai as soon
as reasonably practicable after we electronically file such material with, or furnish it to, the SEC. The SEC maintains an internet site
that contains reports, proxy and information statements and other information regarding issuers that file electronically with the SEC
at www.sec.gov. The information contained on the websites referenced in this Form 10-K is not incorporated by reference into this
filing.
Recent
Developments
None.
Item
1A. Risk Factors
Summary
of Risk Factors The following summarizes the principal factors that make an investment in our company speculative or risky, all of which
are more fully described in the Risk Factors section below. This summary should be read in conjunction with the Risk Factors section
and should not be relied upon as an exhaustive summary of the material risks facing our business. The following factors could result
in harm to our business, reputation, revenue, financial results, and prospects, among other impacts:
● We depend upon key personnel and need additional personnel.
● We may have to seek business through a competitive bidding process.
● We rely in part on third-party software to develop and provide our solutions.
6
● We do not anticipate paying any cash dividends in the foreseeable future.
7
We
have a history of losses and we may not be able to achieve profitability going forward.
We have an accumulated deficit of approximately
$191.7 million as of December 31, 2025 and incurred an operating loss of approximately $17.9 million for the year ended December 31, 2025.
We have had net losses in most of our quarters since our inception. We expect that we will continue to incur net losses in 2026. We may
incur losses in the future for a number of reasons, including the other risks described in this report, and we may encounter unforeseen
expenses, difficulties, complications, delays and other unknown events. Accordingly, we may not be able to achieve or maintain profitability.
Our management is developing plans and executing certain programs to alleviate the negative trends and conditions described above, however
there is no guarantee that such plans will be successfully implemented. Our ability to curtail our operating losses or generate a profit
may be further impacted by the fact that our business plan is largely unproven. There is no assurance that even if we successfully implement
our business plan, that we will be able to curtail our losses. If we incur significant additional operating losses, our stock price may
decline, perhaps significantly and the Company will need to raise substantial additional capital in order to be able to continue to operate,
which will dilute the existing stockholders and such dilution may be significant. Additional capital may not be available on terms acceptable
to the Company, or at all. As there can be no assurance that the Company will be able to achieve positive cash flows (become cash flow
positive) and raise sufficient capital to maintain operations, there is substantial doubt about the Company’s ability to continue
as a going concern.
We
have yet to achieve positive cash flow and, given our projected funding needs, our ability to generate positive cash flow is uncertain.
We
have had negative cash flow from operating activities of approximately $15.0 million and approximately $11.6 million for the years ended
December 31, 2025 and 2024, respectively. We anticipate that we will continue to have negative cash flows from operating activities through
at least the next 12 months as we expect to incur increased research and development, sales and marketing, and general and administrative
expenses. Our business will require significant amounts of working capital to support our growth, particularly as we seek to introduce
our new offered products. An inability to generate positive cash flow from operations may adversely affect our ability to raise needed
capital for our business on reasonable terms, if at all. It may also diminish supplier or customer willingness to enter into transactions
with us, and have other adverse effects that may impact our long-term viability. There can be no assurance we will achieve positive cash
flows in the foreseeable future.
We
need access to additional financing, which may not be available to us on acceptable terms, or at all. If we cannot access additional
financing when we need it and on acceptable terms, our business, prospects, financial condition, operating results and ability to continue
as a going concern will be adversely affected. As a result of these factors, there is substantial doubt about the Company’s ability
to continue as a going concern.
Our
growth-oriented business plan to offer products to our customers will require continued capital investment. Our research and development
activities will also require continued investment. We raised approximately $11.4 million and $10.0 million net proceeds after expenses
in 2025 and 2024, respectively, through equity and debt financing at varying terms.
Our
limited operating history makes it difficult for us to evaluate our future business prospects and make decisions based on those estimates
of our future performance.
We
have a limited operating history and have generated limited revenue. As we look to further expand our existing products it is difficult,
if not impossible, to forecast our future results based upon our historical data. Because of the uncertainties related to our lack of
historical operations, we may be hindered in our ability to anticipate and timely adapt to increases or decreases in revenues or expenses.
If we make poor budgetary decisions as a result of unreliable historical data, we could be less profitable or incur additional losses,
which may result in a decline in our stock price.
There
can be no assurance that we will successfully commercialize our products that are currently in development or were recently launched,
or that our existing products will sustain market acceptance.
There
is no assurance that we will ever successfully commercialize our platform and related solutions or that we will experience market reception
for our products in development or increased market reception for our existing products. There is no guarantee that we will be able to
successfully implement our new products utilizing the internally developed and licensed technology and products. There is no assurance
that our existing or new products or solutions will achieve and sustain market acceptance. Further, there can be no guarantee that we
will not lose business to our existing or potential new competitors.
8
If
our technology and solutions are not adopted and used by customer organizations, we will not be able to grow our business and our operations
will be negatively affected.
Our
ability to grow depends on whether organizations of various types and sizes adopt our technology and solutions as part of their business
processes. If these organizations do not adopt our technology, we may not be able to increase revenues, penetrate some of the new markets
we are targeting, or we may lose some of our existing customer base.
In
order for us to achieve our growth objectives, our identity verification and authentication technologies and solutions must be adapted
to and adopted in a variety of areas including, among others, computer and online systems access control, and identity verification for
onboarding new workforce members or consumers and for transaction authentication purposes.
We
cannot accurately predict the future growth rate, if any, or the ultimate size of these markets, or our penetration of these markets.
The growth of the market for our products and services depends on a number of factors such as the cost, performance and reliability of
our products and services compared to the products and services of our competitors, customer perception of the benefits of our products
and solutions, public perception of the intrusiveness of these solutions and the manner in which organizations use the information collected,
customer satisfaction with our products and services and marketing efforts and publicity for our products and services. Our products
and services may not adequately address market requirements and may not gain wide market acceptance. If our solutions or our products
and services do not gain wide market acceptance, our business and our financial results will suffer.
We
depend upon key personnel and need additional personnel.
On
March 23, 2023, Rhoniel A. Daguro was appointed as our Chief Executive Officer. Our success depends on the continued services of Mr.
Daguro and of certain other members of the current management team. Our executive team is incentivized in part by stock compensation
grants that align the interests of investors with the executive team and certain executives have employment retention agreements. The
loss of key management, engineering employees or third-party contractors could have a material and adverse effect on our business operations.
Additionally, the success of our operations will largely depend upon our ability to successfully attract and maintain competent and qualified
key management personnel. As with any company with limited resources, there can be no guarantee that we will be able to attract such
individuals or that the presence of such individuals will necessarily translate into profitability for our company. If we are successful
in attracting and retaining such individuals, it is likely that our payroll costs and related expenses will increase significantly and
that there will be additional dilution to existing stockholders as a result of equity incentives that may need to be issued to such management
personnel. Our inability to attract and retain key personnel may materially and adversely affect our business operations. Any failure
by our management to effectively anticipate, implement, and manage personnel required to sustain our growth would have a material adverse
effect on our business, financial condition, and results of operations.
Government
regulation, specifically that relating to data privacy protection could negatively impact the business.
We
do not have or require any approval from government authorities or agencies in order to operate our regular business and operations.
However, data protection legislation in various countries in which the Company or its customers do business may require it to register
its databases with governmental authorities in those countries and to comply with additional disclosure and consent requirements with
regard to the collection, storage and use of personal information of individuals in those countries. To the extent that our contracts
are with Governmental or regulated entities, the relevant government authorities will need to approve us as a supplier and the terms
of those contracts. However, it is possible that any proposed expansion to our business and operations in the future would require government
approvals. Due to the security applications and biometric technology associated with our products and platforms the activities and operations
of our company are or could become subject to license restrictions and other regulations, such as (without limitation) export controls
and other security regulation by government agencies. As indicated in, “We are exposed to risks in operating in foreign markets”below,
the imposition of sanctions on particular countries, entities or individuals would prevent us from doing business with such countries,
entities or individuals. If our existing and proposed products become subject to licensing, export control and other regulations, we
may incur increased costs necessary to comply with existing and newly adopted or amended laws and regulations or penalties for any failure
to comply. Our operations could be adversely affected, directly or indirectly, by existing or future laws and regulations (and amendments
thereto) relating to our business or industry.
9
Some
states in the United States have adopted legislation governing the collection, use of, and storage of biometric information and other
states are considering such legislation. Specifically, several states are considering adopting a Biometric Information Privacy Act, or
BIPA modelled on the Illinois statute, which governs the collection, processing, storage and distribution of biometric information such
as facial biometric templates and fingerprints. Several of these new statutes give individuals rights of action to sue violators, which
have resulted in a number of class action lawsuits. The widespread adoption of such legislation could result in restrictions on our current
or proposed business activities, or we may incur increased costs to comply with such regulations.
We
are required to comply with stringent, complex, and evolving laws, rules, regulations, and standards in many jurisdictions, as well as
contractual obligations, relating to cybersecurity and data privacy. Our compliance efforts are complicated by the fact that these requirements
and obligations may be subject to uncertain or inconsistent interpretations and enforcement, and may conflict among various jurisdictions.
Any failure or perceived failure by us to comply with applicable laws, rules, regulations, standards, certifications, or contractual
obligations, or any compromise of security that results in unauthorized access to, or unauthorized loss, destruction, use, modification,
acquisition, disclosure, release, or transfer of personal information, may result in outcomes such as: requirements to modify or cease
certain operations or practices; the expenditure of substantial costs, time, and other resources; proceedings or actions against us;
legal liability; governmental investigations; enforcement actions; claims; fines; judgments; awards; penalties; sanctions; and potentially
costly litigation (including class actions).
The
market for our products is characterized by changing technology, requirements, standards and products, is impacted by the growing use
of AI technologies and we may be adversely affected if we do not respond promptly and effectively to these changes.
The
market for our identity verification and authentication products is characterized by evolving technologies, changing industry standards,
changing political and regulatory environments, frequent new product introductions and rapid changes in customer requirements. The introduction
of products embodying new technologies and the emergence of new industry standards and practices can render existing products obsolete
and unmarketable. In addition, cyberattack attempts are increasing in number, magnitude, and technical sophistication, and we expect
emerging technologies to contribute to the increasing sophistication of attacks and to lead to new threats. For example, threat actors
are leveraging emerging artificial intelligence (or, AI) technologies to develop new hacking tools and attack vectors, generate deep
fake images, exploit vulnerabilities, obscure their activities, and increase the difficulty of threat attribution. The use of AI by bad
actors can increase both the sophistication and ease of production and therefore proliferation of these new threats. Our future success
will depend on our ability to enhance our existing products and to develop, or acquire and introduce, on a timely and cost-effective
basis, new products and product features that counter these AI threats, keep pace with technological developments and emerging industry
standards and address the increasingly sophisticated needs of our customers. In the future:
If
we are unable to respond promptly and effectively to new cybersecurity threats and attacks, changing technologies and market requirements,
we will be unable to compete effectively in the future.
10
There
can be no assurance that we will successfully identify new product opportunities and develop and bring new products to market in a timely
manner, or that the products and technologies developed by others will not render our products or technologies obsolete or noncompetitive.
The failure of our new product development efforts could have a material adverse effect on our business, results of operations and future
growth.
Issues
relating to the development and use of AI, including generative AI, in our offerings may result in reputational harm, liability and adverse
financial results.
Social,
ethical and operational issues relating to the use of AI, including generative AI, in our offerings may result in reputational harm,
liability and additional costs. We are incorporating AI technologies, developed by third parties, into our offerings. If our AI development,
deployment, data privacy and product disclosures, or governance is ineffective or inadequate, it may result in incidents that impair
the public acceptance of our AI solutions, or cause harm to individuals, customers or society, or result in our offerings not working
as intended or producing unexpected outcomes.
Jurisdictions
around the world are developing and passing new regulations that apply specifically to the use of AI. For example, the EU AI Act was
adopted in 2024 and will be implemented in phases through 2030, and other jurisdictions are considering similarly focused legislation.
These regulations and the evolving AI regulatory environment may, among other impacts, result in inconsistencies among AI regulations
and frameworks across jurisdictions, increase our compliance, governance and research and development costs, increase our exposure to
claims related to our AI models and increase liability related to the use of AI by our customers or users that are beyond our control.
There can be no guarantee that future AI regulations, or customer requirements relating to AI will not adversely impact us or conflict
with our approach to AI, including affecting our ability to make our offerings available without costly changes, delaying or halting
development of our offerings, requiring us to change our development practices, go to market strategies and indemnity protections and
subjecting us to additional compliance requirements, regulatory action, competitive harm, reputational harm and legal liability. To the
extent we rely on third-party AI technologies in our products, services and solutions, we will face risks inherent in how those technologies
and their AI models have been developed and deployed.
Uncertainty
around new and evolving AI uses may require significant, additional investment. We may in the future experience, challenges accessing
AI models, datasets or hardware. Developing, testing and deploying AI systems and countermeasures to AI threats outlined above, may also
increase the cost of our offerings, including due to the nature of the computing costs.
We
have in the past entered into and may seek in the future to enter into contracts with governments, as well as state and local governmental
agencies and municipalities, which subjects us to certain risks associated with such types of contracts.
Most
contracts with governments or with state or local agencies or municipalities, or Governmental Contracts, are awarded through a competitive
bidding process, and some of the business that we expect to seek in the future will likely be subject to a competitive bidding process
(See “We may have to seek business through a competitive bidding process” below).
We
may not be afforded the opportunity in the future to bid on contracts that are held by other companies and are scheduled to expire, if
the governments, or the applicable state or local agency or municipality determines to extend the existing contract. If we are unable
to win new contract awards or retain those contracts, if any, that we are awarded over any extended period, our business, prospects,
financial condition and results of operations will be adversely affected.
In
addition, Governmental Contracts subject us to risks associated with public budgetary restrictions and uncertainties, actual contracts
that are less than awarded contract amounts, the requirement for posting a performance bond and the related cost and cancellation at
any time at the option of the governmental agency. Any failure to comply with the terms of any Governmental Contracts could result in
substantial civil and criminal fines and penalties, as well as suspension from future contracts for a significant period of time, any
of which could adversely affect our business by requiring us to pay significant fines and penalties or prevent us from earning revenues
from Governmental Contracts during the suspension period.
11
Additionally,
we are subject to the U.S. Foreign Corrupt Practices Act, or the FCPA, and other laws in the United States and elsewhere that prohibit
improper payments or offers of payments to United States’, or foreign governments and their officials and political parties for
the purpose of obtaining or retaining business. Our activities in the United States and elsewhere create the risk of unauthorized payments
or offers of payments by one of our employees, contractors or customers that could be in violation of various laws, including the FCPA,
even though these parties are not always subject to our control. We have implemented safeguards to discourage these practices by our
employees, consultants and customers. However, our existing safeguards and any future improvements may prove to be less than effective,
and our employees, contractors or customers may engage in conduct for which we might be held responsible. Violations of the FCPA or similar
laws may result in severe criminal or civil sanctions and we may be subject to other liabilities, which could adversely affect our business,
financial condition and results of operations.
Governments
may be in a position to obtain greater rights with respect to our intellectual property than we would grant to other entities. Governmental
agencies also have the power, based on financial difficulties or investigations of their contractors, to deem contractors unsuitable
for new contract awards. Because we will engage in the government contracting business, we will be subject to additional regulatory and
legal compliance requirements, as well as audits, and may be subject to investigation, by governmental entities. Compliance with such
additional regulatory requirements is likely to result in additional operational costs in performing such Governmental Contracts which
may impact on our profitability. Failure to comply with the terms of any Governmental Contract could result in substantial civil and
criminal fines and penalties, as well as suspension from future contracts for a significant period of time, any of which could adversely
affect our business by requiring us to pay fines and penalties and prohibiting us from earning revenues from Governmental Contracts during
the suspension period.
Furthermore,
governmental programs can experience delays or cancellation of funding and suspension of appropriations has occurred, for example the
partial United States government shutdown in October - November 2025 and current congressional uncertainty over the debt ceiling which
could lead to a further shutdown, which can be unpredictable; this may make it difficult to forecast our revenues on a quarter-by-quarter
basis.
We
may have to seek business through a competitive bidding process.
Competitive
bidding, whether for contracts with governments or with private enterprises, presents a number of risks, including:
If
we are unable to win particular contracts that are awarded through the competitive bidding process, we will incur expenses associated
with such competitive bidding and may not be able to operate in the market for the products and services that are provided under those
contracts for a number of years.
We
rely in part on third-party software to develop and provide our solutions.
We
rely in part on software licensed from third parties to develop and offer some of our solutions. Any loss of the right to use any such
software or other intellectual property required for the development and maintenance of our solutions, or any defects or other issues
with such software could result in problems or delays in the provision of our solutions until equivalent technology is either developed
by us, or, if available from others, is identified, obtained, and integrated, which could harm our business.
12
We
depend upon a small number of large sales with contractual commitments ranging from $500,000 to $2,000,000, which take longer to close
and may result in a concentration of business and unpredictable quarterly revenue.
We derive a substantial portion of our revenues
from a small number of sales with large contractual commitments ranging from $500,000 to $2,000,000. We have changed the product set of
the business and have developed a new range of SaaS based products and solutions, which are in a lower price range and intended to generate
recurring revenue from a large number of customers. We have at the same time changed our marketing focus to target major enterprises,
which involve a longer sales cycle but if we are successful in securing contracts with multi-million dollar contractual commitments with
such enterprises, we believe that such contracts will generate substantial, sustainable revenue growth. At the same time, we are also
focusing our efforts in expanding our channel partner relationships, in the expectation that these will bring additional sales that will
be quicker and easier to close. We are still endeavoring to enter into multi-year contracts for our new products with minimum commitments
ranging in price and we may, or may not, be successful in achieving such sales. If we are successful in securing the major contractual
commitments that we are targeting, that may result in concentration of our business amongst a small number of customers, the loss of any
one of which could have significant adverse effects on our revenue and financial situation. Additionally, the longer sales and implementation
cycle of major enterprises may delay the recognition of revenue and adversely affect our results of operations in the meantime. Some of
our large contractual commitments are from enterprises, which are at an early stage of business development and the ramp in their business
and processing volumes may be unpredictable. Accordingly, our quarterly results are difficult to predict because we cannot predict in
which quarter, if any, substantial sales (whether measured in commitment volumes, or number of contracts) will occur in a given year,
nor when (if at all), or at what rate the ramp in sales of new products will occur. As a result, we believe that quarter-to-quarter comparisons
of our sales are not a good indication of our future performance. In some future quarters, our sales may be below the expectations of
securities analysts and investors, in which case the market price of our Common Stock may decrease significantly.
Our
efforts to expand our international operations are subject to a number of risks, any of which could adversely reduce our future international
sales and increase our losses.
Most
of our revenues historically to date are attributable to sales and business operations in jurisdictions other than the United States.
Although we are now focusing our efforts in generating more United States based revenues, we continue to pursue international sales,
in particular in Asia and Europe. Our international operations could be subject to a number of risks, any of which could adversely affect
our future international sales and operating results, including:
● local Data Privacy and other regulations;
● trade restrictions;
● import duties and tariffs;
● export regulations or restrictions including sanctions;
● uncertain political, regulatory and economic developments;
● labor and social unrest;
● inability to protect our intellectual property rights;
● highly aggressive competitors;
● currency issues, including currency exchange risk;
13
● difficulties in staffing, managing and supporting foreign operations;
● longer payment cycles;
● increased collection risks;
● impact of the Coronavirus or other pandemics; and
● impact of wars and terrorism
Negative
developments in any of these areas in one or more countries could result in a reduction in demand for our products, the cancellation
or delay of orders already placed, difficulty in collecting receivables, and a higher cost of doing business, any of which could adversely
affect our business, results of operations or financial condition.
We
are exposed to risks in operating in foreign markets, which may make operating in those markets difficult and thereby force us to curtail
our business operations.
In
conducting our business in foreign countries, we are subject to political, economic, legal, operational and other risks that are inherent
in operating in other countries. Risks inherent to operating in other countries range from difficulties in settling transactions in emerging
markets to possible nationalization, expropriation, price controls and other restrictive governmental actions. We also face the risk
that exchange controls or similar restrictions imposed by foreign governmental authorities may restrict our ability to convert local
currency received or held by us in their countries into U.S. dollars or other currencies, or to take those dollars or other currencies
out of those countries.
It
is possible that countries in which we do or intend to do business, or companies and their principals become subject to sanctions under
U.S. law. This would prevent us from doing business with those countries or with those entities or individuals. We could be exposed to
fines and penalties in the event of breach any applicable sanctions legislation or orders. In addition, we might be required to suspend
or terminate existing contracts in order to comply with such sanctions, legislation or orders, which would adversely impact our future
revenues and cash flows.
Cyber-attacks,
breaches of network or information technology security, presentation attacks, natural disasters, pandemics, or terrorist attacks could
have an adverse effect on our business.
Cyberattacks
or other breaches of network or information technology (IT) security, natural disasters, pandemics such as Covid-19, terrorist acts or
acts of war may cause equipment failures or disrupt our systems and operations. We may be subject to attempts to breach the security
of our networks and IT infrastructure through cyber-attack, presentation attacks to biometric data capture systems, including deep fakes
and other threats developed by use of AI driven technologies, malware, computer viruses and other means of unauthorized access. While
we regularly review our security policies, protocols, controls and systems to determine their effectiveness for detection and prevention
of such attacks, and to make improvements and fix any known vulnerabilities where necessary, new means and methods for such attacks are
constantly being developed by bad actors, facilitated by the easy access to generative AI and we may not become aware of such new attacks
or vulnerabilities prior to being subject to such an attack. There is no guarantee that we can prevent all such attacks, even if we become
aware of their potential. While we maintain insurance coverage for some of these events, the potential liabilities associated with these
events could exceed the insurance coverage we maintain. A failure to protect the privacy of customer and employee confidential data against
breaches of network or IT security could result in damage to our reputation. To date, we have not been subject to cyberattacks or other
cyber incidents that we are aware of which, individually or in the aggregate, resulted in a material impact to our operations or financial
condition.
For
us to further penetrate the marketplace, the marketplace must be confident that we provide effective security protection for governmental
and other secured identification documents and other personally identifiable information or protected personal information, or PII. Although
we are not aware that we have experienced any act of sabotage or unauthorized access by a third party of our software or technology to
date, if an actual or perceived breach of security occurs in our internal systems or those of our customers, regardless of whether we
caused the breach, it could adversely affect the market’s perception of our products and services. This could cause us to lose
customers, resellers, alliance partners or other business partners, thereby causing our revenues to decline. If we or our customers were
to experience a breach of our internal systems, our business could be severely harmed by adversely affecting the market’s perception
of our products and services.
14
Most
recently, we have considered the impact of pandemics (e.g. COVID-19) on our overall operations. The impact of any disease which may give
rise to a pandemic in the United States and worldwide are unknown, and the widespread growth in infections, or travel restrictions, quarantines
or site closures imposed as a result of disease, among other things, may impact the ability of our employees, sub-contractors, or our
customers’ employees and sub-contractors to attend places of work, to meet with potential customers, or undertake implementations
at our customer’s locations. In addition, such a disease could lead to disruptions in our supply chain, causing shortages or unavailability
of software updates, or necessary equipment. Any of these outcomes could have a material adverse effect on our business, financial condition,
results of operations, and cash flows.
Acquisitions
present many risks that could have a material adverse effect on our business and results of operations.
In
the past we have closed acquisitions of various companies. We may also pursue select acquisitions in the future. The success of our future
growth strategy will depend on our ability to integrate our existing operations, together with any future acquisition of which none are
planned at this date. Integrating the operations of our existing business with any future acquisitions, including anticipated cost savings
and additional revenue opportunities, involves a number of challenges. The failure to meet these integration challenges could seriously
harm our results of operations and the market price of our shares may decline as a result. Realizing the benefits of any future acquisition
will depend in part on the integration of intellectual property, products, operations, personnel and sales force and the completion of