A New Book by Kevin Gosschalk · Founder & CEO, Arkose Labs

After Bots

From Bot Detection to Agent Trust

For a decade, the question was simple: bot or human? That era is over. This is the practitioner's playbook for the one that replaced it.

More than half of all internet traffic is now automated.Imperva 2025 Bad Bot Report

22seconds

Time from initial access to active exploitation — collapsed from 8 hours in 2022.Google / Mandiant M-Trends 2026

The Agent Era

The question just changed

The bot era had one question: is this traffic automated? The agent era has three.

01

Who is the agent?

02

What is it trying to do?

03

Is your platform willing to authorize that action?

The Framework · Interactive

Three populations. One set of signals.

A cooperative agent that identifies itself. A quiet one working for a real user. An attacker using the same tools to deceive. Here are three live sessions. Which is which?

Session A

  • Headless Chromium
  • Datacenter IP · cloud
  • Scripted mouse path
  • Sub-100ms action loop
?

Session B

  • Headless Chromium
  • Datacenter IP · cloud
  • Scripted mouse path
  • Sub-100ms action loop
?

Session C

  • Headless Chromium
  • Datacenter IP · cloud
  • Scripted mouse path
  • Sub-100ms action loop
?
Reveal the answer

You couldn't tell — and neither can a detection stack. All three produce identical fingerprints. Detection sees automation; it can't see authorization. Without that distinction you're either blocking your customers or accepting your attackers. That gap is what this book closes.

You can't govern what you can't classify, and you can't classify what you haven't detected.

Detection was a prerequisite. Classification is the architecture. Authorization is the work.

60-Second Readiness Check

Is your stack built for a binary world?

Check every statement that's true for your platform today.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Check the boxes above to see where your program stands.

What's Inside

The full arc of the problem

Part One

The New Internet

What agents are, where they come from, and why all three populations produce identical signals.

Part Two

The Attack Surface

How attackers assemble modular agents, and how the economics of fraud actually work.

Part Three

The Defense

The shift from detection to classification, the signal stack, and persistent device identity.

Part Four

Governance

Managing the agents in the middle, and the architectural decisions leaders must make now.

18 chapters, a guest chapter from Paul Rockwell, and a conclusion — previewed below.

Table of Contents

Preview every chapter

Eighteen chapters, a guest chapter, and a conclusion — here's the whole map, one line each.

Preview all chapters ↓
01

A Brief History of Automation

How automation evolved from crude cURL scripts into industrialized, human-like fraud over a decade.

02

The New Internet

Meet the internet's new user: an agent that transacts around the clock — and won't introduce itself.

03

Cloud Agents

The headless browsers running in the cloud, and why the real challenge is classification, not detection.

04

Local Agents

Agents on real user devices, where the old detection tells disappear and new ones take their place.

05

Why Everything Looks the Same

Three populations of agents, three different problems — and why they all produce identical signals.

06

Infinite Willpower

Friction-based defense assumed attackers give up; agents with infinite patience break that assumption.

07

The Assembly Problem

The danger isn't any single tool — it's how easily attackers snap open-source pieces together.

08

Generated Identities at Scale

Why modern fraud begins at sign-up, and how fake accounts became the foundation of the fraud economy.

09

Credential Theft and MFA Bypass

Why MFA is necessary but no longer sufficient once agents operate at machine speed.

Guest Chapter: Paul Rockwell

A front-line view from the former VP & GM of Trust & Safety at Pinterest on where the adversary is heading.

10

The Fraud Economics Model

Fraud is an economic problem: every attack happens when return exceeds cost — and stops when that inverts.

11

The Question Has Changed

The defense begins by replacing “bot or human?” with a question about intent.

12

Classification at Scale

What it takes to classify agents across billions of sessions in real time — the signals and the architecture.

13

Persistent Device Identity

Why durable device identity is the anchor that defeats attackers who rely on a fresh start every session.

14

Enforcement vs. Detection

Detection tells you what's happening; enforcement decides whether it matters — and changes outcomes.

15

Breaking the Fraud Business Model

There's no silver bullet — so make the attacker's economics stop working.

16

Managing the Gray Area & the Disclosure Problem

The hardest problem isn't obvious fraud — it's the agents in the middle whose intent you can't yet determine.

17

What Agentic AI Does to Your Existing Stack

A component-by-component audit of MFA, CAPTCHA, and WAFs — what holds up under agentic pressure and what doesn't.

18

Building for What Comes Next

The architectural and organizational decisions leaders must make now, before the agent internet fully arrives.

Conclusion

The bot era lasted a decade; the agent era is just beginning — and here's how to be ready for it.

The Category Shifted

In October 2025, Forrester renamed the category from “Bot Management” to “Bot and Agent Trust Management.”

“The decision is no longer ‘block or allow.’ It's ‘how much do I trust this agent, and what actions should that trust permit?’”Sandy Carielli, Forrester

Built for Practitioners

Who this book is for

Security, fraud, and identity leaders responsible for consumer-facing platforms.

CISOsCIOsHeads of IdentityFraud & Risk LeadersIdentity Architects

Meet the Author

Kevin Gosschalk

Kevin is the founder and CEO of Arkose Labs, where he has spent over a decade on the defender side of online abuse — protecting some of the largest consumer platforms on the internet across billions of sessions and hundreds of millions of consumers. He has watched the same attack patterns evolve from scripted bots into agentic systems that reason, plan, and adapt. After Bots is his first book.

Free Copy · For Qualifying Leaders

Request a free copy

The print run is limited. Complimentary copies are reserved for security, fraud, and identity leaders at consumer-facing platforms. Tell us about your role and we'll ship one your way.

We prioritize fulfillment to fraud, identity, and security leaders at consumer platforms. Prefer not to wait? Buy it on Amazon →

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thanks — if you qualify, we'll be in touch to ship your copy of After Bots.