I think ideally they'll combine multiple factors, or at least have the option to, so:
- Something you have: a phone doing public key cryptography over BLE or equivalent, or your RFID/NFC keycard as a backup (same as today)
- Something you are: your face, gait, or things like heart rate profile...