Iris-recognition, a biometric scan that maps the colored ring around the pupil for identity checks, drove spending toward $63 billion by 2035 as hospitals, airports, and data centers retire passwords for an eye scan, even as a 2026 arXiv paper warned the technology still misses novel spoofing attacks, attempts to fool scanners with printed photos, patterned contacts, or replayed video.
The story matters because every shift toward biometric login replaces forgettable passwords with permanent body data that, once stolen, owners cannot reset. This raises questions for healthcare, banks, and the airports already running iris-only entry.
HID Global laid out the shift in a 2026 healthcare brief, arguing the password era ends as hospitals embed credentials in mobile phones protected by fingerprint or face matches.
Wellstar Health System anchored the shift by handing 11,000 iPhones to clinicians, building secure access into a device they already carry rather than another login screen.
Healthcare sits at the front of a larger market shift that runs through banks, government IDs, and even consumer phones.
An iris-recognition market analysis by Precedence Research placed the segment at $12.5 billion in 2025.
Precedence projects the same segment will compound at 17.6% a year, riding government, banking, and consumer-electronics demand.
Government and defense buyers absorb 38% of iris-recognition spending today, with banks and consumer mobile electronics chasing close behind.
North America commands 35% of current spending, but Asia Pacific compounds at 18% a year, the fastest regional pace in the segment.
Wider adoption now drags scanners into spaces where false matches and stolen templates carry sharper consequences than a forgotten password.
The Critical Infrastructure Protection Association ranked iris biometrics as the second-most accurate identifier after DNA, with one UK study clocking the system at roughly 20 times the search speed of the next-fastest method.
Google deployed iris readers in 2006, and the technology now screens passengers across hundreds of airports worldwide, with research institutions like CERN running their own iris-only gates.
The Critical Infrastructure Protection Association adds that iris templates already sit inside corporate networks at Google, Microsoft, Apple, Cisco, Citi, and the New York Stock Exchange, broadening the records a single breach can compromise, CIPA reports.
Scaling the technology into hospitals adds a privacy wrinkle that less-sensitive sectors have not faced as sharply.
AccountableHQ's 2026 HIPAA brief classifies iris images and templates as electronic protected health information when hospitals capture them for care or billing, dragging them under the same federal privacy rules that govern medical records.
AccountableHQ notes that a leaked iris template, unlike a stolen password, sticks with the patient for life since the underlying eye never changes.
Even before the privacy debate matures, technical researchers warn that the scanners themselves still miss spoofing tricks.
A May 18, 2026, arXiv preprint by Rahul Anand and four colleagues found that iris presentation-attack detectors fail to generalize when researchers swap sensors, swap attack tools, or shift from near-infrared cameras to visible light, meaning a hospital scanner trained in one wing could fail to flag a patterned contact lens held up at a different entrance.
The authors warned that strong cross-dataset numbers do not prove a system can withstand novel real-world attacks, calling for detectors that focus on attack artifacts rather than the surface signature of each test set.
Hospitals, airports, and banks now stand between a market that doubles every five years and a generation of attacks that researchers admit current detectors cannot yet read.
Beyond the eye itself, vendors continue to layer irises with fingerprint, face, and PIN, betting that no single biometric, however accurate, deserves the keys to a hospital, a bank, or a power grid alone.
Industry groups expect passwordless authentication to become the default in finance, healthcare, and government by the end of 2026, even as academic researchers race to harden the eye against the next wave of spoofing.