A New Book by Kevin Gosschalk · Founder & CEO, Arkose Labs
From Bot Detection to Agent Trust
For a decade, the question was simple: bot or human? That era is over. This is the practitioner's playbook for the one that replaced it.
More than half of all internet traffic is now automated.Imperva 2025 Bad Bot Report
Time from initial access to active exploitation — collapsed from 8 hours in 2022.Google / Mandiant M-Trends 2026
The Agent Era
The bot era had one question: is this traffic automated? The agent era has three.
Who is the agent?
What is it trying to do?
Is your platform willing to authorize that action?
The Framework · Interactive
A cooperative agent that identifies itself. A quiet one working for a real user. An attacker using the same tools to deceive. Here are three live sessions. Which is which?
Session A
Session B
Session C
You couldn't tell — and neither can a detection stack. All three produce identical fingerprints. Detection sees automation; it can't see authorization. Without that distinction you're either blocking your customers or accepting your attackers. That gap is what this book closes.
You can't govern what you can't classify, and you can't classify what you haven't detected.
Detection was a prerequisite. Classification is the architecture. Authorization is the work.
60-Second Readiness Check
Check every statement that's true for your platform today.
What's Inside
What agents are, where they come from, and why all three populations produce identical signals.
How attackers assemble modular agents, and how the economics of fraud actually work.
The shift from detection to classification, the signal stack, and persistent device identity.
Managing the agents in the middle, and the architectural decisions leaders must make now.
18 chapters, a guest chapter from Paul Rockwell, and a conclusion — previewed below.
Table of Contents
Eighteen chapters, a guest chapter, and a conclusion — here's the whole map, one line each.
Preview all chapters ↓How automation evolved from crude cURL scripts into industrialized, human-like fraud over a decade.
Meet the internet's new user: an agent that transacts around the clock — and won't introduce itself.
The headless browsers running in the cloud, and why the real challenge is classification, not detection.
Agents on real user devices, where the old detection tells disappear and new ones take their place.
Three populations of agents, three different problems — and why they all produce identical signals.
Friction-based defense assumed attackers give up; agents with infinite patience break that assumption.
The danger isn't any single tool — it's how easily attackers snap open-source pieces together.
Why modern fraud begins at sign-up, and how fake accounts became the foundation of the fraud economy.
Why MFA is necessary but no longer sufficient once agents operate at machine speed.
A front-line view from the former VP & GM of Trust & Safety at Pinterest on where the adversary is heading.
Fraud is an economic problem: every attack happens when return exceeds cost — and stops when that inverts.
The defense begins by replacing “bot or human?” with a question about intent.
What it takes to classify agents across billions of sessions in real time — the signals and the architecture.
Why durable device identity is the anchor that defeats attackers who rely on a fresh start every session.
Detection tells you what's happening; enforcement decides whether it matters — and changes outcomes.
There's no silver bullet — so make the attacker's economics stop working.
The hardest problem isn't obvious fraud — it's the agents in the middle whose intent you can't yet determine.
A component-by-component audit of MFA, CAPTCHA, and WAFs — what holds up under agentic pressure and what doesn't.
The architectural and organizational decisions leaders must make now, before the agent internet fully arrives.
The bot era lasted a decade; the agent era is just beginning — and here's how to be ready for it.
The Category Shifted
In October 2025, Forrester renamed the category from “Bot Management” to “Bot and Agent Trust Management.”
“The decision is no longer ‘block or allow.’ It's ‘how much do I trust this agent, and what actions should that trust permit?’”Sandy Carielli, Forrester
Built for Practitioners
Security, fraud, and identity leaders responsible for consumer-facing platforms.
Free Copy · For Qualifying Leaders
The print run is limited. Complimentary copies are reserved for security, fraud, and identity leaders at consumer-facing platforms. Tell us about your role and we'll ship one your way.