As AI agents become harder to distinguish from people, identity checks are reaching their limits. Could proof of personhood offer a more private solution?
I'm not a robot. ...or am I?
Automated systems generated more than 53% of measured web traffic in 2025, overtaking human traffic. That does not mean half the people you encounter online are bots, as the figure includes crawlers, scanners, scripts and other machine activity. But it does reveal a structural change. The internet is increasingly being navigated, queried and acted upon by software as well as people.
And when that software is designed to behave like a person, the distinction becomes much harder to see. You cannot know from the words alone whether this article was written by a person, an AI system, or some combination of the two.
So what are AI agents? Why are they becoming difficult to distinguish from human users? And what can digital services prove without forcing everyone to surrender their identity?

AI agents are software systems that can observe an environment, select actions, use tools, and work towards a goal with varying degrees of autonomy. They may plan several steps, evaluate results, and adjust what they do next.
That does not mean every agent is handed a goal and left to operate independently. In practice, agents work within human-defined permissions, tool constraints, approval steps, and safety boundaries. The useful distinction is not that traditional software follows instructions while agents do not; it is that agents can decide which permitted action to take next as conditions change.
Imagine you want to book a holiday. An agent could search flight and hotel sites, compare options against your preferences, coordinate over email and, if explicitly authorized, complete a booking and payment. To do this, it uses familiar software building blocks: APIs, browsers, network access, stored context and permissioned access to accounts or payments. Multiple agents can also divide work, exchange information and adapt to one another's actions.
This is not inherently a bad development. Agents are already used to detect fraud, support compliance workflows and handle customer requests. Now, as the cost of deploying them falls, they are being integrated into browsers, search systems and enterprise software, allowing automated systems to interact with digital services at a scale no individual person could match.
The uncomfortable part is that legitimate and malicious agents can use the same interfaces. A holiday planner and an attack tool may both browse pages, call APIs, submit forms, and complete transactions. They are not necessarily technically identical, but their requests can look equally valid at the surface. The challenge is therefore shifting in complexity because digital services increasingly need to understand not only whether an interaction is automated, but what the automation is authorized to do, whose interests it serves, and whether it is operating at a deceptive scale.
Imperva reports that blocked AI-enabled bot attacks increased 12.5-fold in a year, from a daily average of 2 million to 25 million incidents. Attack volume matters, but the more significant change is what increasingly capable and inexpensive automation can do.
Consider synthetic identity fraud. Unlike conventional identity theft, which impersonates an existing person, a synthetic identity combines real and fabricated information: perhaps a legitimate identification number alongside a false name, an AI-generated face, and a manufactured history. The resulting persona may not correspond to any single victim, making attribution and recovery unusually difficult.
Generative tools can reduce the cost of producing realistic profile images, fraudulent documents, and supporting digital histories. Automation can then test those identities against verification systems, record why they fail, and refine subsequent attempts. The capabilities are familiar: gather information, use tools, assess an outcome, and try again. But the key point is that the objective is different.
Some attackers also use injection attacks to replace a device's live camera feed with manipulated or synthetic footage. Where liveness and device-integrity controls are weak, this can undermine biometric checks intended to verify that a real person is present, and the scale is already substantial. In the final quarter of 2024, Meta reported taking action against 1.4 billion fake accounts and estimated that fake accounts represented around 3% of Facebook's monthly active users. Generative AI does not create the problem, but it can make convincing profiles, images, text, and interaction patterns cheaper to produce and operate at scale.

Distinguishing people from automated systems is not a new problem. CAPTCHAs were built around a simple assumption: present a task that is easy for a person but difficult for software. We have all clicked traffic lights, identified bicycles, or decoded distorted text, but in today's world the assumption is weakening.
In one controlled study, ETH Zurich researchers built a system that solved every reCAPTCHA v2 image challenge it encountered. Their result does not prove that every CAPTCHA can always be bypassed, but it demonstrates how little security can be inferred from completing a task that modern computer-vision systems also perform well. To put it bluntly, the robots are becoming very good at proving they are not robots.
The same study found evidence that browser cookies and history influence reCAPTCHA's risk assessment. This illustrates a broader point that modern anti-bot systems rarely rely on a puzzle alone and instead combine device, network, and behavioral signals. Attackers respond by imitating those signals, creating an arms race that becomes increasingly costly and meddling for legitimate users.
What about identity checks? Electronic know-your-customer processes typically compare a user with a government-issued document, often alongside a selfie, video, or liveness check. Banks, exchanges and other regulated services use these systems to establish identity and meet obligations such as anti-money-laundering and sanctions controls. These systems are also targeted by organized services that sell forged documents, manipulated video feeds, and other methods for bypassing verification. While AI can increase the speed and quality of those attacks, the underlying contest between verification and evasion predates generative AI.
Biometrics provide another signal: a face, fingerprint, iris, or behavioral characteristic that is difficult to reproduce exactly. But biometrics carry a different risk from passwords because a compromised password can be replaced; a compromised biometric characteristic cannot.
The risk depends heavily on system design, and some services store biometric templates or derived data centrally, creating attractive targets, while others keep data on the user's device or use cryptographic techniques intended to minimize disclosure. Biometrics are therefore not automatically unsafe, but they demand stronger answers about collection, storage, retention, recovery and consent.
CAPTCHAs, identity documents and biometrics answer different questions, and none is a complete defense against deceptive automation. Moreover, the solutions we built for yesterday's internet are just not holding up against the challenges we now face with the increased usage and access of agentic AI. But, perhaps, the real problem is not the tools we use, but rather what question we're trying to answer.
Many online verification systems make a costly assumption: to prove that you are a person, you must prove which person you are. A service may receive your name, document, face, date of birth, and address even when it needs only a much more limited amount of information. Even technically robust identity checks can be the wrong tool for the task, as they can exclude people and disclose far more information than a service might need.
Firstly, identity is often the wrong question because identity requirements can exclude people. Only 35% of children under five in Sub-Saharan Africa have a birth certificate, while around half of Syrian refugees in Jordan reportedly hold no UNHCR identity card. A digital front door built entirely around government documents will deny access to many of the people least able to deal with another barrier.
Biometric systems do not automatically resolve that problem because error rates can vary across demographic groups, and enrollment or recognition can be difficult for some people due to disability, age, injury, equipment, or environment. A system that recognizes only documented and easily scanned people is not universally accessible.
The second reason identity is often the wrong question is that identity checks can over-disclose. Why should a service learn a person's name, date of birth, nationality, and address when it needs only to know that the user is eligible, unique, or above a certain age? Each additional copy of an identity record creates another system that must be secured, governed, and eventually deleted. Too often, users disclose maximum personal data to answer a narrow question.
For many digital services, the better question is not "Who are you?" but "Are you a recognized, unique person who is eligible to perform this action?" That is a narrower question than identity, although it is not the only question every service will ever need to answer. This is the idea behind personhood credentials: digital credentials that allow someone to demonstrate personhood to an online service without disclosing their civil identity.
A useful system needs at least two important properties:
One person, one valid credential within the system. The enrolment process should make it difficult for the same person to obtain multiple simultaneous credentials. This can limit some forms of deception at scale: generating a thousand profiles is easy, but acquiring a thousand independent personhood credentials should not be. The guarantee is only as strong as enrolment, recovery, revocation and resistance to credential sharing or coercion.
Unlinkable pseudonymity. A person should be able to use a different pseudonym or alias in each context, preventing services from automatically correlating their activity. Strong designs aim to preserve this property even when verifiers compare data, although implementation details, metadata, and the trust model still matter. In practical terms, a person could prove eligibility to several services without presenting the same reusable identifier to each one, and the main appeal is that the same primitive can improve both privacy and abuse resistance.
A service gains a signal that an action is associated with a recognized personhood, while the user does not have to reveal a name or a globally reusable identity. In this setup, privacy and security do not have to sit on opposite sides of the trade-off.
What Proof Of Personhood Does Not Prove
A personhood credential does not prove that a person personally typed every word, clicked every button, or completed every task. A verified person can still use an AI agent, automate their account, lend access to someone else, or act maliciously.
Personhood is therefore not the same as bot detection, nor is it the same as identity verification. Its main value is narrower: it can make it harder for one actor to present themselves as many independent people. Services still need separate controls for authorization, behavior, fraud, content provenance, and rate limits.
Researchers and companies are exploring many ways to distinguish people, agents, and automated abuse, and while some experiments use content rendered differently for humans and machines, others test live gestures or device signals intended to demonstrate that a person is present. These approaches may be useful in particular settings, but they remain part of an arms race and challenge that depends on what today's model cannot see or imitate may weaken as models and attack tools improve.
Other projects address uniqueness directly. World, formerly Worldcoin, uses specialized Orb hardware to capture iris and facial images and issue a World ID. It has faced regulatory restrictions and investigations in several jurisdictions concerning biometric data, consent, and data protection.
World says its current design keeps captured images in personal custody on the user's device and stores no central database of biometrics. A credible comparison should examine the current architecture rather than reduce the project to its earliest implementation or most critical headlines.
The bigger risk remains. If personhood becomes a widely required entry ticket, the systems that control enrolment, recovery, revocation and acceptable use gain significant power. A technically private proof can still depend on a narrow set of issuers, hardware operators or governance bodies.
The engineering question is therefore not only where data is stored, but who can recognize a person, who can exclude them, how mistakes are corrected, and whether people have meaningful alternatives.
The challenge is harder than it first appears, and we need personhood systems that minimize identity disclosure, resist duplicate enrolment, support recovery, reduce exclusion and avoid concentrating control in a single gatekeeper. Decentralization can certainly help to distribute trust, but it does not remove the need to define who attests personhood and how that process is governed.
One part of this problem has long been recognized across peer-to-peer systems and is particularly familiar within Web3: the Sybil attack. One actor creates many identities or accounts to gain advantage in a system that treats them as independent participants. That can distort rankings, repeatedly claim the same entitlement, manipulate reputation, or overwhelm peer-to-peer mechanisms.
But a Sybil attack is not simply "a group of malicious validators", and it is not identical to all bot activity because the defining issue is that one underlying actor can cheaply appear as many. Proof of personhood is relevant where a system genuinely wants participation or access to be limited per person.
This distinction also matters for forms of Web3 governance that aim to reflect community participation rather than just token ownership on its own. Wherever accounts are treated as independent voices, one actor controlling many of them can create a false impression of wide support. Different communities use different safeguards against this, but the underlying challenge remains the same: how can a system recognize genuine participation without requiring everyone to reveal their identity?
Personhood is more directly useful for mechanisms that are intentionally person-based: one-per-person distributions, personhood-gated capacity, reputation, community polling, rate limits, or access to scarce resources, and Polkadot's proof-of-personhood work is designed around that narrower primitive: allowing someone to prove that they belong to a recognized set of people without revealing which person they are.
One approach being explored begins with an in-app video interaction after which the user's personhood is registered in a membership ring on People Chain. This isn't intended to be the only possible route to getting personhood, and Polkadot's wider approach separates the method used to recognize a person from the privacy-preserving infrastructure they use afterward, which allows different verification and attestation protocols to be developed over time.
Once a person has joined an appropriate membership ring, Ring-VRF cryptography allows them to prove that membership without identifying themselves. Products can receive a context-specific alias rather than the underlying verification data or identity record. The same person therefore appears under different aliases in different products, reducing the ability to correlate their activity across different services.
That does not mean every interaction is human-authored, nor does it remove every trust assumption from enrolment. It provides a reusable, privacy-preserving personhood signal that products can apply where uniqueness matters, without asking users to hand each product a passport, civil identity or biometric record.
How the membership ring, Ring-VRF proofs, aliases and runtime components work deserves its own article. In the next post, Guillaume will take us under the hood of Polkadot's proof of personhood.
Until then, stay skeptical and stay curious because the next stranger you meet online may be a person, an agent, or a person using an agent. The more useful question may be what the system actually needs them to prove.
The code is open source, and the work is ongoing. Start here: