When AI Traffic Surpasses Humans, How Do You Prove You're Human?

Foresight NewsPublished on 2026-06-11Last updated on 2026-06-11

Abstract

As AI-generated web traffic now surpasses human activity, the internet's foundational business models—built on human attention, browsing, and advertising—face severe disruption. AI agents crawl websites at immense scale without generating ad revenue, while AI summaries divert traffic from original content sites. In response, over 2.5 million sites are blocking AI crawlers, and protections like Cloudflare's "honeypot" traps have emerged, though advanced AI can bypass these. The collapse of traditional CAPTCHAs, which assumed machines were weaker than humans, has led to a shift toward behavioral biometrics for human verification. Companies like IBM and BioCatch now analyze unique human patterns—cursor movements, typing rhythms, keystroke dynamics, and even cognitive delays like the Stroop effect—to distinguish real users from bots. These biometric signatures are difficult to fake or alter, offering a new layer of security but raising significant privacy concerns. Two competing visions for a reliable human verification system are emerging. One, exemplified by Sam Altman’s World (formerly Worldcoin), uses centralized iris scanning to generate unique credentials, though it faces bans and criticism over unauthorized data collection. The other employs cryptographic zero-knowledge proofs, allowing users to prove they are human without revealing identity or biometric data, as advocated by Vitalik Buterin. However, decentralized approaches risk exploitation through identity renting i...


Author: Vaidik Mandloi

Translators: Luffy, Foresight News


Since its launch in late 2022, ChatGPT has given rise to a vast ecosystem of AI agents. Currently, the total network traffic generated by such programs has surpassed that of all human users worldwide. The online behavior of AI agents is fundamentally different from that of humans: they don't view ads, click on links, or shop online. They simply scrape data from the web to complete tasks and leave immediately afterward.


The internet's original architecture and business logic were built around human behavior and usage patterns. Yet today, the vast majority of web visits are not from real people, which troubles major websites. Currently, 2.5 million websites have begun blocking AI crawlers, leading to lawsuits involving platforms like Perplexity. Cloud service provider Cloudflare has even built "honeypot labyrinths"—pages filled with AI-generated, nonsensical text in an infinite loop—to trap data crawlers.


However, some advanced AI agents have already developed the ability to bypass such protective measures. Faced with this escalating human-machine confrontation, the industry is now focused on developing a more reliable human identity verification mechanism. This system needs to accurately determine whether the operator on the other side of the screen is a human: human operation involves hesitation, typing errors, and subtle, involuntary jitters in cursor movement, characteristic of the human nervous system. This article will analyze the causes behind this shift, the two main technical approaches, and the choices people will face: accepting centralized biometric surveillance or adopting cryptographic zero-knowledge proof technology for anonymous human verification.


AI Disrupts the Internet Business Model


The root cause of websites blocking AI programs is that AI simultaneously undermines the commercial foundation on which the internet depends from two ends. Traditional internet profit logic is built on user attention: when users visit pages and view ads, content publishers earn revenue. If an AI is tasked with online shopping, it will search through 5,000 websites at once, whereas a human typically browses only four or five pages.



AI reads much faster than humans, capable of completing cross-website price comparisons or even placing orders in minutes, without generating any ad views. This means websites bear server operating costs without earning any revenue.


Simultaneously, AI search continues to divert website traffic. After Google added AI-generated summaries at the top of search results, only 8% of users clicked through to the original webpages, leading to a direct 33% drop in traffic from Google to major content sites. Within just one year of launch, this feature reached over 1 billion monthly active users, with platform query volumes doubling every quarter since its inception.


Many likely remember the learning Q&A platform Chegg. It once dominated the homework help business by leveraging its search ranking advantage but has now officially shut down its Q&A section, attributing its demise to the impact of ChatGPT. Content creators are caught in a pincer attack: on one side, crawlers scrape their content indiscriminately; on the other, AI summaries intercept traffic before users even reach the websites.


The data disparity is even more staggering. For every site visit OpenAI's crawler brings to a partner website, it previously scrapes data from 400 pages; for Anthropic, this ratio is 38,000:1. These companies freely use publicly available web data to train their AI models and then use the finished products to siphon off traffic that originally belonged to the websites.


In any other industry, such predatory data collection would have sparked countless lawsuits, but in the AI field, these companies achieve trillion-dollar valuations.


Your Body is the New Password


For the past 25 years, the internet has primarily relied on CAPTCHAs to distinguish humans from machines. People were asked to identify traffic signs or input distorted characters. This mechanism worked because machines' image recognition capabilities were far inferior to humans' in the past.


Now the situation is completely reversed. OpenAI's agent programs score far higher than humans on Google's human verification system, accurately clicking interfaces and copying/pasting content; AI-generated photos can fool identity verification systems, and deepfake video calls have even been used by criminals to complete bank transfers. The foundational premise of traditional verification methods—that machines are weaker than humans—no longer holds.


The industry must now focus on areas where AI cannot yet replicate human traits. These are the behavioral characteristics exhibited when humans operate electronic devices—behavioral biometrics. Companies like IBM and BioCatch are developing related systems. This technology verifies identity not just at login but monitors user behavior throughout the session, collecting data on cursor movement speed, page scrolling patterns, typing rhythm, keystroke pressure, text deletion/correction habits, phone holding angle, etc. The phone's gyroscope continuously records this information.



The system can also recognize details like the user's dominant hand and finger swipe trajectories. IBM needs only eight usage data points to create a unique user behavior profile, which is then continuously compared against baseline data during subsequent use.


BioCatch's technology can even identify online fraud scenarios. When a victim verbally reads out account passwords following a scammer's phone instructions, their frantic, interrupted typing rhythm is precisely captured by the system. In just one year, the system helped 257 banks identify approximately 2 million money laundering accounts. The EU has also begun piloting gait recognition technology. Just three years into the era of AI agents, EU border personnel are already collecting data on people's walking patterns.




Related research also incorporates the Stroop Effect: when the word "blue" is written in green font, the human brain experiences conflict between word meaning and visual color, slowing reaction time, but AI remains unaffected. Research shows this cognitive interference directly manifests in typing behavior. Platforms may not even need specific tests; by analyzing keystroke rhythms alone, they can determine if the operator is human. Typing habits contain unique signatures of human brain information processing.


Previous web tracking primarily recorded user browsing, clicking, and purchasing behavior. Users could evade this by blocking cookies, using VPNs, or disabling location services. However, behavioral biometrics captures innate human characteristics: cursor movement style and typing rhythm are difficult to consciously alter.


Each person's behavioral traits are as unique as a fingerprint. Unlike passwords or keys, this biometric profile cannot be changed or reset. Once this technology becomes widespread, all major platforms will be forced to adopt it. With voice simulation already capable of deceiving in calls and deepfake video technology following closely, a crucial question emerges if this is our future: who will ultimately control this human data?


Who Will Control the Human Verification System?


The industry is currently split into two main factions, each exploring human identity verification solutions.


The first is Sam Altman's World (formerly Worldcoin). Users must approach a spherical iris scanning device. The device captures iris information and generates an encrypted credential, proving the user is a unique natural person. Currently, 18 million people across 160 countries have completed iris registration. In April 2026, World partnered with dating app Tinder, video conferencing platform Zoom, and e-signature service DocuSign for user verification. It also collaborated with Coinbase to launch the AgentKit tool, allowing users to bind their AI agents to their verified identity. Platforms can confirm a human is behind the agent without accessing personal information.



However, iris scanning technology has been explicitly banned in several countries. The core reason for this resistance is that the public is unclear about the risks of authorizing biometric data collection. An investigation by MIT Technology Review also found that World, without proper authorization, privately collected multiple human vital signs data beyond the iris, including heart rate and respiration.


The second category is based on cryptographic zero-knowledge proofs (ZKPs), allowing you to prove you are human without revealing your real identity, location, or appearance. Vitalik Buterin proposed this concept as early as 2023. He argued that if a decentralized human identity system cannot be built, the internet will ultimately move toward centralized identity control. If the authority to verify identity is held by corporations or governments, surveillance mechanisms will become embedded in the network's foundation.


Large-scale attempts at decentralized human identity systems have been made before but ultimately failed. Idena was one of the first blockchain projects championing "one person, one identity." Within just two years of launch, 40% of network accounts and 48% of rewards were controlled by 23 entities. Account operation teams in places like India and Russia hired ordinary people at wages under one dollar per hour to lend their identities, reaping profits up to 55 times higher. Researchers also found that even children's identities were used as puppet accounts.


Vitalik had anticipated such risks. He stated that for human verification systems, the lowest-cost attack isn't deepfakes or advanced hacking but paying people in low-income regions to rent out their identities. Any human verification system requires financial support: iris scanners and on-chain verification nodes need ongoing investment.


Yet once identity credentials gain economic value, a black market for identity lending emerges. In a world of stark wealth inequality, the capital-rich will inevitably dominate such markets.


"Forcing a one-person-one-vote rule in a system with actual economic incentives will ultimately repeat the failures of similar social experiments in the 20th century."


Objectively, both development paths have clear flaws. The centralized approach can achieve scale but places users' biometric data in the hands of corporations prone to over-collection—corporations that themselves profit from the current bot infestation. The cryptographic approach theoretically protects privacy but struggles to overcome real-world economic imbalances, leaving it vulnerable to exploitation by gray-market industries.


If forced to choose, I would still bet on the cryptographic approach. This is because behavioral biometrics and centralized iris scanning permanently record your bodily information, and the ownership of that data belongs to the entity that deploys the system. Once they have your data, you cannot delete or transfer it; it remains locked with the company that collected it.


Even knowing zero-knowledge proofs might be exploited, they are still worth developing because they confirm you are human without requiring more information. Conversely, abandoning this path means a future where every website we visit retains our behavioral data. Today, this centralized, surveillance-prone approach is being implemented far faster than the cryptographic alternative.

Trending Cryptos

Related Questions

QWhy are many websites starting to block AI crawlers, according to the article?

AWebsites are blocking AI crawlers because AI traffic undermines the core business model of the internet. AI agents don't view ads, click links, or make purchases like humans do. They scrape data for tasks without generating any revenue for the sites, which incur server costs. Furthermore, AI-generated summaries on search engines divert traffic away from the original content websites, depriving them of visits and potential ad revenue.

QWhat is the fundamental shift that has rendered traditional CAPTCHA systems ineffective?

AThe fundamental shift is that AI's capabilities have now surpassed humans in the tasks CAPTCHAs were designed for. The original premise—that machines are worse than humans at visual recognition—is no longer true. AI programs can now easily solve image-based puzzles, generate photos that fool verification systems, and even mimic human-like interactions in tests designed to distinguish humans from bots.

QWhat is 'behavioral biometrics' and why is it being developed for human verification?

ABehavioral biometrics is a technology that identifies humans by analyzing their unique physical interaction patterns with devices. It monitors characteristics like cursor movement speed, scrolling style, typing rhythm, keystroke pressure, text correction habits, and even phone tilt via gyroscope. It's being developed because these subconscious, body-based behaviors are currently difficult for AI to replicate accurately and consistently, making them a potential new frontier for distinguishing humans from machines.

QWhat are the two main competing approaches to human verification systems discussed in the article, and what is a key criticism of each?

AThe two main approaches are: 1) Centralized biometric systems like World (formerly Worldcoin), which uses iris scans to create a unique human credential. A key criticism is that it involves handing over sensitive, immutable biological data to corporations, raising major privacy and control concerns. 2) Cryptographic zero-knowledge proof systems, which allow anonymous proof of humanity. A key criticism is its vulnerability to real-world economic exploitation, where people in low-income areas might be paid to rent out their verified identities, allowing wealthier entities to amass credentials and control the system.

QWhat does the author ultimately favor as a solution, and what is the primary reason given?

AThe author ultimately favors the cryptographic zero-knowledge proof approach. The primary reason is that, despite its potential for being gamed, it protects user privacy by allowing proof of humanity without revealing identity or biometric data. The author argues that centralized biometric solutions permanently lock an individual's biological data with the collecting company, creating an inescapable system of surveillance, which is a greater long-term risk.

Related Reads

Why Zhang Yiming Spends 50% of His Time on Seed?

Why does Zhang Yiming devote 50% of his time to Seed, ByteDance's core AI research team, while the company’s high-profile AI products like Doubao appear less dominant in the current market? An analysis reveals that ByteDance, historically a leader in defining trends (e.g., TikTok, Toutiao), has not set major AI industry agendas in the first half of the year, instead following competitors in areas like Agent and productivity tools. ByteDance’s strategy diverges from peers like Tencent and Alibaba, who are integrating AI into holistic productivity systems. While Doubao is highly successful—with 382 million MAU and leading revenue—its very success may create inertia, focusing iterations on improving the AI assistant rather than pioneering disruptive new entry points like Agent-native desktops. Zhang Yiming’s deep investment in Seed, a team of 300+ top researchers from firms like Google DeepMind, signals a long-term bet on foundational model capabilities as the ultimate competitive moat, reminiscent of ByteDance's past wins through superior underlying tech (e.g., recommendation algorithms). However, in the fast-evolving AI era, superior foundational models risk being outpaced by rapid shifts in product-level interaction paradigms and user habits. Zhang is essentially applying his principle of "delayed gratification" to corporate strategy, gambling that Seed’s breakthroughs will eventually make it the indispensable infrastructure for all AI applications, regardless of which product leads the user interface. The core question remains: is the AI era a race for the best product or the most powerful underlying infrastructure? The answer will define ByteDance’s future position.

marsbit3m ago

Why Zhang Yiming Spends 50% of His Time on Seed?

marsbit3m ago

From 'Speculative Asset' to 'The Next Generation Financial Infrastructure', Crypto is Growing a New TradFi World

From "Speculative Asset" to "Next-Generation Financial Infrastructure": Crypto Is Evolving into a New TradFi World Looking back, the crypto industry has long focused on identifying the "next asset to pump." However, starting around 2026, several developments across different sectors began converging. Stablecoin market cap approached $300 billion, entering a global payments adoption phase. DTCC initiated its first live tokenized asset conversions, while prediction markets expanded into regulated exchanges and brokerages. Simultaneously, AI Agents began using stablecoins autonomously for payments. These seemingly disparate trends share a common thread: the issuance, custody, trading, payment, and settlement capabilities built by the crypto industry over the past decade are now opening to broader financial activities and machine-driven economies. This suggests crypto is maturing beyond a purely speculative market, building a foundational infrastructure layer beneath it. This simultaneous progress occurs because the core components of a new financial system—stablecoins as programmable money APIs, RWA tokenization for traditional assets, prediction markets for price discovery on future events, and AI Agents as new economic actors—have developed independently and are now beginning to interconnect. These elements form the building blocks of a next-generation financial infrastructure. This emerging infrastructure features multi-layered capabilities: 1) Asset issuance and tokenization for a wider range of assets. 2) 24/7 programmable payments and settlement, simplifying global transfers. 3) Continuous trading and price discovery, providing real-time market signals for both humans and software. 4) Advanced identity, permissions, and authorization systems suitable for institutions and AI. 5) Growing connections to real-world legal and regulatory frameworks, providing greater clarity for traditional participants. This shift is reflected in changing funding sources, with more revenue now coming from real-world business flows, an expanding set of participants (including corporate systems and autonomous agents), and more nuanced regulatory discussions focused on rules and boundaries rather than outright prohibition. However, significant challenges remain. Technical confirmation is not legal finality; liability and governance for AI-driven payments are unclear; fragmentation across networks persists; privacy solutions for institutions are needed; and the system currently lacks mature frameworks for credit, insurance, and complex risk management found in traditional finance. In conclusion, 2026 marks a pivotal point where several previously independent pieces of the crypto puzzle started to connect. While far from complete, it signifies crypto's crucial step towards becoming a low-friction, global execution layer for real assets, traditional institutions, and intelligent software, built beneath its vibrant speculative markets.

marsbit53m ago

From 'Speculative Asset' to 'The Next Generation Financial Infrastructure', Crypto is Growing a New TradFi World

marsbit53m ago

Supporters of Bitcoin BIP-110 Update Have Prepared a 'Last Resort' Plan If the Proposal Is Not Adopted: It Could Radically Change BTC's Value

Supporters of the BIP-110 update for Bitcoin have prepared a contingency plan in case the proposal is not adopted, a move that could radically alter BTC's value. Developer Chris Guida has adapted a proof-of-work code originally created by Luke Dashjr in 2017 for the current version of Bitcoin Knots. This adaptation is described as a last-resort measure to be activated if miners do not signal readiness for BIP-110. The proposal itself is a soft fork aimed at temporarily limiting the storage of arbitrary data in Bitcoin transactions. It introduces stricter limits on new transaction outputs, OP_RETURN fields, and witness data, with rules designed to expire after approximately one year. Guida stated this option needs to remain open if miners were to "conspire to betray Bitcoin." Should the contingency code be used, it could change Bitcoin's current mining algorithm. This change would likely prevent existing ASIC miners from generating blocks on the new chain, leading to a large-scale reorganization of the Bitcoin mining network. Luke Dashjr, another Bitcoin Knots developer, contributed to the code and expressed hope it would not be needed, but sees its existence as useful for a potential crisis. A supporter known as Mechanic argued that the mere possibility of a proof-of-work change could act as a deterrent, emphasizing that Bitcoin's rules should be set by participants and node operators, not miners. While miner signals are tracked for BIP-110 activation, data from the proposal's official tracking page indicates support remains limited.

cryptonews.ru4h ago

Supporters of Bitcoin BIP-110 Update Have Prepared a 'Last Resort' Plan If the Proposal Is Not Adopted: It Could Radically Change BTC's Value

cryptonews.ru4h ago

Why Did Bitcoin's Price Remain Stable and Not Fall Despite the Recent Major Hack? Here's the Secret

The article discusses why Bitcoin's price remained stable despite a recent $100 million hack targeting individual cold wallets, citing insights from experts on "The Wolf of All Streets" channel. Analysts attribute this resilience to significant institutional shifts in the crypto market. Key points include: 1. **Market Maturation:** The crypto market has transitioned from being dominated by individual retail holders to institutional investors. Most new capital now enters via regulated channels like spot ETFs and custodial services (e.g., Coinbase, Anchorage), making vulnerabilities in individual cold wallets less impactful. 2. **Institutional Dominance:** Control over price dynamics has shifted from miners and crypto exchanges to Wall Street and institutional capital. These large players operate with long-term strategies, viewing price corrections as buying opportunities rather than reasons for panic. 3. **Increased Resilience:** Institutional involvement has reduced market sensitivity to negative news. Sellers are largely exhausted, and remaining holders are steadfast. Major financial institutions (e.g., Morgan Stanley, Wells Fargo) are incorporating crypto assets into portfolios, with research teams recommending allocations of 1–6% to Bitcoin. 4. **Risk Perception:** Bitcoin's integration into traditional financial indices has lowered perceived risk among professionals and institutions, further stabilizing its price against isolated security breaches.

cryptonews.ru5h ago

Why Did Bitcoin's Price Remain Stable and Not Fall Despite the Recent Major Hack? Here's the Secret

cryptonews.ru5h ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of AI (AI) are presented below.

活动图片