OUR RESPONSE
Published August 2026
Yesterday, more than 100 leading technology and cybersecurity companies called for collective action to address the growing impact of AI on cybersecurity.
A key point in that letter stood out to us: as autonomous agents become more capable, their identities must be traceable and accountable.
We agree. But we believe the challenge goes one step further.
The question is no longer simply: is this traffic human or automated?
It's now: is this agent authorized to do what it is trying to do, and is there a link between a known human and this agent?
This distinction will become increasingly important as legitimate AI agents conduct more commerce, research, transactions and other activity on behalf of people and businesses. Simply blocking automated traffic is no longer a viable answer. Equally, authentication does not mean trust. So, assuming an agent is valid because it presented a known credential is courting potential fraud disaster.
Organizations will now need to understand:
- Who is the agent?
- What is it trying to do?
- What is its reputation and connection to a known customer?
- Is it authorized to take that action?
This requires the ability to classify agents, understand their intent and enforce policies based on the activity they are attempting to perform.
For nearly a decade, Arkose Labs has helped the world's largest digital businesses distinguish legitimate users from increasingly sophisticated automated attackers. As the internet continues its torrid evolution from bots to autonomous agents, we believe that the same fundamental problem is evolving. And as attacks become faster, cheaper, and potentially more effective, the best mitigation is an equally capable adversary in the fight.
The next generation of cyber defense will not simply determine whether something is automated.
It must determine whether it should be allowed to act!