When AI Traffic Surpasses Humans, How Do You Prove You're Human?

marsbitPublished on 2026-06-12Last updated on 2026-06-12

Abstract

With AI-generated web traffic surpassing human activity, websites face a crisis as AI agents bypass ads, avoid clicks, and scrape data without generating revenue. This disrupts the ad-based internet economy, diverting traffic and reducing site visits. In response, sites are blocking AI crawlers and deploying traps like Cloudflare's "honeypot" pages. Traditional CAPTCHAs are now ineffective against advanced AI. The focus has shifted to behavioral biometrics—analyzing unique human patterns such as cursor movement, typing rhythm, and keystroke dynamics. Companies like IBM and BioCatch use this data to distinguish humans from bots, even detecting fraud through behavioral inconsistencies. Two competing approaches aim to verify human identity centrally. Sam Altman’s World (formerly Worldcoin) uses iris scanning to create unique credentials, though it faces privacy concerns and regulatory bans. Alternatively, cryptographic zero-knowledge proofs offer anonymous verification without revealing personal data, championed by Vitalik Buterin to avoid centralized surveillance. However, both systems have flaws. Centralized solutions risk biometric data misuse, while decentralized models may be exploited through identity rental markets in economically unequal regions. Despite challenges, the author favors cryptographic methods for preserving privacy over pervasive behavioral monitoring that permanently captures and controls personal biometric data.

Author: Vaidik Mandloi

Compiled by: Luffy, Foresight News

Since its launch at the end of 2022, ChatGPT has spawned a vast ecosystem of AI agents. Currently, the total web traffic generated by such programs has surpassed that of all human users worldwide. The online behavior of AI agents is fundamentally different from humans: they don't view ads, click on links, or shop online; they simply crawl web data to complete tasks and leave once finished.

The internet's original architecture and business logic were built around human behavior and usage patterns. Yet today, the vast majority of web visits are not from real people, a situation that deeply troubles many websites. Currently, 2.5 million websites have begun blocking AI crawlers, with platforms like Perplexity getting embroiled in related lawsuits. Cloud service provider Cloudflare has even built "honeypot mazes," using AI-generated nonsensical text to create infinite-loop pages designed to trap various data crawlers.

However, some advanced AI agents have already developed the ability to bypass such protective measures. In the face of escalating human-machine conflict, the industry is now focusing on developing a more reliable human identity verification mechanism. This system needs to accurately identify whether the operator behind the screen is human: real human operators exhibit hesitation, typing errors, and cursor movements with the subtle tremors unique to the human nervous system. This article will analyze the causes behind this transformation, the two mainstream technological solutions, and the choices people will face: either accept centralized biometric monitoring or adopt encrypted zero-knowledge proof technology for anonymous human verification.

AI Disrupts the Internet's Business Model

The root cause of websites blocking AI programs lies in AI undermining the commercial foundation of the internet from both ends. The profitability of the traditional internet is built on user attention: users visit pages, view ads, and content publishers earn revenue. If an AI handles shopping, it might search 5,000 websites at once, whereas an ordinary person typically browses only four or five pages.

AI reads far faster than humans, capable of comparing prices across the entire web and even placing orders directly within minutes, a process that generates no ad views. This means websites bear server costs without earning any revenue.

Simultaneously, AI search is continuously diverting website traffic. After Google added AI-generated summaries at the top of search results, only 8% of users clicked through to the original webpages, leading to a direct 33% drop in referral traffic for major content sites from Google. Within just a year of its launch, this feature's monthly active users exceeded 1 billion, and platform retrieval volume has doubled every quarter since its debut.

Surely everyone remembers Chegg, the study help platform. It originally operated a homework Q&A business relying on strong search rankings, but has now officially shut down its Q&A section, attributing its demise to the impact of ChatGPT. Content creators are caught in a double bind: crawlers scrape content on one side, while AI summaries intercept traffic before users even reach the website.

The data gap is even more staggering. For every referral visit OpenAI's crawler brings to a partner website, it previously scrapes data from 400 pages; for Anthropic, this ratio reaches 38,000:1. These companies use publicly available data across the web to train AI models for free, then use the finished products to divert traffic that originally belonged to the websites.

In any other industry, such predatory data collection would have sparked countless lawsuits, yet in the AI field, these companies secure valuations in the trillions.

Your Body is the New Password

For the past 25 years, the internet has primarily relied on CAPTCHAs to distinguish humans from machines. People needed to identify traffic signs or input distorted characters. This mechanism worked because machines' image recognition capabilities were far inferior to humans in the past.

Now the situation is completely reversed. OpenAI's agent operations score far higher than humans in Google's human verification system simulations, capable of accurately clicking interfaces and copying/pasting content; AI-generated photos can fool identity verification systems, and deepfake video calls have even been used by criminals to complete bank transfers. The design premise of traditional verification methods—that machines are weaker than humans—no longer holds.

The industry is now forced to focus on areas where AI still struggles to replicate human capabilities: the physical behavioral characteristics displayed when humans operate electronic devices, also known as behavioral biometrics. Companies like IBM and BioCatch are developing related systems. This technology not only verifies identity at login but also monitors user behavior throughout the session, collecting data on cursor movement speed, page scrolling patterns, typing rhythm, keystroke pressure, text editing habits, and even phone holding angles, with the phone's gyroscope recording relevant information throughout.

The system can also recognize details like the user's dominant hand and finger sliding trajectory. IBM needs to collect usage data just eight times to establish a unique user behavioral profile, which is then continuously compared against benchmark data for every subsequent operation.

BioCatch's technology can even identify online scam scenarios. When a victim reads out account passwords following a scammer's phone instructions, the panicked and disjointed typing rhythm is precisely captured by the system. Within just one year, the system helped 257 banks identify approximately 2 million money laundering accounts. The EU has also begun piloting gait recognition technology. Just three years into the era of AI agents, EU border personnel are already collecting data on people's walking gaits.

Related research also incorporates the Stroop effect: when the word "blue" is written in green font, the human brain experiences conflict between word meaning and visual color, significantly slowing reaction time, but AI remains unaffected. Research finds this cognitive interference is directly reflected in typing behavior. Platforms may not even need specific test questions; based on keystroke rhythm alone, they can judge whether the operator is human. Human typing habits contain unique characteristics of brain information processing.

Previous web tracking mainly recorded user browsing, clicking, and consumption behaviors. Users could evade this by blocking cookies, using VPNs, or turning off location services. But behavioral biometrics collects instinctive human characteristics: cursor movement patterns and typing rhythms are difficult to consciously alter.

Each person's behavioral characteristics are as unique as fingerprints. Unlike passwords or keys, this biometric profile cannot be changed or reset. Once this technology becomes widespread, major platforms will be forced to adapt. Voice simulation technology can already deceive in phone calls, and video deepfake technology is following closely. If this is the future, the core question emerges: Who will ultimately control this human data?

Who Controls the Human Verification System?

Currently, the industry is divided into two main camps exploring human identity verification solutions.

The first is Sam Altman's World (formerly Worldcoin). Users need to approach a spherical iris-scanning device. The device collects iris information and generates an encrypted credential to prove the user is a unique natural person. Currently, 18 million people across 160 countries have completed iris registration. In April 2026, World formed user verification partnerships with dating app Tinder, video conferencing platform Zoom, and e-signature service DocuSign. It also collaborated with Coinbase to launch the AgentKit tool, allowing users to link their AI agents to their verified identity. Platforms can confirm a human is behind the agent without leaking personal information.

However, iris scanning technology has been explicitly banned by multiple countries. The core reason for this resistance is that the public is unclear about the potential risks of authorizing biometric data collection. An investigation by MIT Technology Review also found that World, without valid authorization, privately collected multiple human vital signs data like heart rate and respiration in addition to iris data.

The second category is zero-knowledge proof based on encryption technology, which allows you to prove you are human without revealing your real identity, location, or appearance. Vitalik Buterin proposed this concept as early as 2023. He argued that if a decentralized human identity system cannot be built, the internet will ultimately move toward centralized identity control. Once identity verification authority is held by companies or governments, surveillance mechanisms will become embedded in the network's foundation.

Decentralized human identity systems have seen large-scale implementation attempts before, but ultimately failed. Idena was among the first blockchain projects promoting "one person, one identity." Within just two years of launch, 40% of network accounts and 48% of rewards were controlled by 23 institutions. Account operation teams in places like India and Russia hired ordinary people to lend their identities for less than a dollar per hour, profiting up to 55 times. Researchers also found that even children's identities were used as puppet accounts.

Vitalik had anticipated such risks earlier. He stated that for human identity verification systems, the lowest-cost attack method is not deepfakes or advanced hacking, but paying people in low-income regions to lend their personal identities. Any human identity verification system requires financial support: iris-scanning devices and on-chain verification nodes need continuous investment.

Yet once identity credentials gain economic value, a black market for identity lending inevitably emerges. In a world of stark wealth inequality, the capital-strong will always control such markets.

"Forcing a one-person-one-vote rule in a system with actual economic incentives will only repeat the failures of 20th-century social experiments."

Objectively, both development paths have clear flaws. Centralized solutions can achieve scale but involve users' biometric data being stored by companies prone to over-collection, companies that themselves benefit from the current bot proliferation. The encryption route theoretically protects privacy but struggles to escape real-world economic imbalances, ultimately being exploited by gray-market industries.

If forced to choose, I'd still bet on the encryption solution. Because behavioral biometrics and centralized iris scanning permanently record your bodily information, and the ownership of this information belongs to whoever deploys the system. Once they have your data, you cannot delete or transfer it; this data is locked with the company that collected it.

Even knowing zero-knowledge proofs might be exploited, they are still worth developing, as this proof can confirm you are human without revealing more information. Conversely, abandoning this path means in the future, every website we visit will retain our physical behavioral data. Currently, this centralized surveillance-based solution is being implemented far faster than the encryption technology route.

Trending Cryptos

Related Questions

QAccording to the article, what is the fundamental reason why many websites are banning AI crawlers?

AThe fundamental reason is that AI disrupts the core business model of the internet. AI traffic generates zero advertising revenue for websites while incurring server costs, and AI search summaries divert human traffic away from the original content sources, leaving websites with no financial return for their content.

QWhat technology is the industry shifting towards to distinguish humans from AI, and what does it measure?

AThe industry is shifting towards behavioral biometrics. It measures unique, subconscious human physical behaviors during device interaction, such as cursor movement speed/patterns, typing rhythm/errors, scrolling style, key pressure, phone tilt, and even gait. These are difficult for AI to perfectly replicate.

QWhat are the two main approaches to human verification discussed in the article, and what are their key challenges?

A1. Centralized biometric systems (e.g., Worldcoin's iris scanning): The key challenge is user privacy and centralized control of sensitive, immutable biological data by corporations or governments. 2. Cryptographic zero-knowledge proof systems: The key challenge is economic attacks, where people in low-income regions can be paid to rent out their verified identities, undermining the 'one-person-one-identity' principle.

QHow does the article describe the impact of AI search summaries on website traffic?

AThe impact is severe. Google's AI overview feature has led to only 8% of users clicking through to the original websites, resulting in a 33% drop in referral traffic from Google to content sites. This creates a 'traffic interception' problem where AI provides answers before users visit the source.

QWhat example does the article give to illustrate the cognitive difference between humans and AI that can be used for verification?

AIt cites the Stroop effect. When a word like 'blue' is written in green ink, a human's brain experiences conflict, slowing their reaction time and affecting their typing rhythm. An AI, which processes text and color separately, shows no such delay. This cognitive dissonance manifests in typing behavior and can be used for passive verification.

Related Reads

New Fire Research Institute: Inflation May Become a Stubborn Problem, Can Cryptocurrencies Achieve Independent Performance in the Short Term?

New Fire Research Institute argues that despite the recent U.S. June CPI decline to 3.5% year-on-year—primarily driven by energy—core goods inflation remains persistent, with core PCE likely showing slight growth. Federal Reserve Chairman Wash has emphasized the Fed's independence and a "zero tolerance" stance on inflation, suggesting a continued hawkish posture that will pressure risk assets, especially if energy prices rise again. Concurrently, the semiconductor memory sector faces structural pressures, as seen in significant sell-offs for Micron and SK Hynix. High leverage in markets like South Korea is triggering deleveraging, amplifying volatility. Investors are also questioning the sustainability of AI-related capital expenditures. In contrast, the crypto market showed relative stability last week, with BTC and ETH gaining slightly. Positive developments include a shift to net inflows for U.S. Bitcoin spot ETFs, a narrowing Coinbase discount, and strong activity on the Robinhood Chain ecosystem. The potential advancement of the U.S. CLARITY Act provides a policy catalyst. Overall, the probability of an independent crypto bull run in the short term is low, given overarching macro pressures. However, fundamentals are improving with ETF inflows and robust on-chain activity, providing solid support. Technically, BTC and ETH show strong support at key moving averages. New Fire Research maintains that Bitcoin around $60,000 represents a high-value allocation zone, with limited downside risk near current levels. The true bull market catalyst awaits a confirmed market bottom combined with a macro policy shift and legislative progress.

marsbit20m ago

New Fire Research Institute: Inflation May Become a Stubborn Problem, Can Cryptocurrencies Achieve Independent Performance in the Short Term?

marsbit20m ago

Base Under Pressure

**Title: The Pressure Mounts for Base** Base, the Ethereum Layer 2 scaling solution backed by Coinbase, is facing significant pressure and public scrutiny from its leadership following the launch of Robinhood Chain. Base co-founder Jesse Pollak recently acknowledged strategic missteps, admitting that the chain's past focus on social and creator tokens (e.g., through Farcaster, Zora) failed to deliver sustainable adoption. He has refocused on core infrastructure, handing leadership of the Base App back to Coinbase's Cobie. While Base remains a top L2 contender alongside OP Mainnet and Arbitrum, and boasts the highest TVL (nearly $12B), its weaknesses are being highlighted by the new competitor. Key criticisms include its slow progress on decentralization. Base has faced issues with its single sequencer causing block production halts, and L2BEAT is reportedly considering downgrading its decentralization rating from Stage 1 to Stage 0. This contrasts sharply with the rapid initial success of Robinhood Chain, whose DEX quickly entered the top five by volume. The leadership styles of the parent companies are also being compared: Robinhood's CEO actively engages with new projects, while a recent incident where Coinbase's Brian Armstrong briefly changed his profile picture—sparking and then crashing a related meme token—drew community ire and mockery. Pollak stated Base is working with Coinbase on tokenized stocks backed 1:1 by real equity, differentiating it from Robinhood's derivatives model. However, the article argues that Base's most urgent task is to address its long-standing technical and trust issues. With more traditional finance players likely to emulate Robinhood's path, Base must use this competitive pressure to solidify its position as long-term financial infrastructure.

Foresight News37m ago

Base Under Pressure

Foresight News37m ago

White House Concession Removes Ethical Hurdle, Clarity Act Races Against Final Window Before Recess?

On July 21st, industry sources reported that the Trump administration has agreed to include an ethics provision in the "Clarity Act" (Digital Asset Market Clarity Act of 2025). This concession addresses the long-standing conflict-of-interest concerns regarding government officials and the crypto industry, potentially removing the final major obstacle to the bill's progress. Additionally, Patrick Witt, the executive director of the White House's Digital Asset Advisory Committee, confirmed he will remain in his role to help finalize the bill, alleviating previous concerns about his potential departure. The Clarity Act aims to establish a unified federal regulatory framework for the U.S. digital asset market. Its core objective is to resolve regulatory ambiguity by defining different types of digital assets (digital commodities, investment contract assets, and permitted payment stablecoins) and clarifying the respective oversight roles of the SEC and CFTC. This would end the long-running jurisdictional dispute between the two agencies and provide clearer compliance paths for the industry. With the ethics issue moving toward resolution, the most urgent challenge now is time. The U.S. Congress is set to begin its August recess in mid-August, leaving only a few working weeks to finalize the text and advance the bill through the Senate. Industry advocates, like the Blockchain Association's Kristin Smith, stress that this is a critical moment. If negotiations conclude successfully in the coming weeks, the Clarity Act could pass a key hurdle before the recess; otherwise, it may face significant delays. If enacted, the Clarity Act could mark a historic turning point in crypto regulation. By providing a clearer and more predictable legal framework, it aims to reduce uncertainty for businesses, developers, and traditional financial institutions looking to enter the digital asset space, potentially setting a global benchmark for market structure regulation.

Odaily星球日报42m ago

White House Concession Removes Ethical Hurdle, Clarity Act Races Against Final Window Before Recess?

Odaily星球日报42m ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of AI (AI) are presented below.

活动图片