惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
NISL@THU
NISL@THU
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
SecWiki News
SecWiki News
Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
Schneier on Security
Schneier on Security
V
Vulnerabilities – Threatpost
C
CXSECURITY Database RSS Feed - CXSecurity.com
V
Visual Studio Blog
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
T
True Tiger Recordings
F
Full Disclosure
Martin Fowler
Martin Fowler
D
Docker
Stack Overflow Blog
Stack Overflow Blog
Security Latest
Security Latest
A
About on SuperTechFans
雷峰网
雷峰网
Know Your Adversary
Know Your Adversary
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Hacker News: Ask HN
Hacker News: Ask HN
B
Blog
V
V2EX - 技术
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google DeepMind News
Google DeepMind News
S
Security Archives - TechRepublic
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
Malwarebytes
Malwarebytes
C
Check Point Blog
美团技术团队
P
Privacy International News Feed
Recorded Future
Recorded Future
博客园 - 司徒正美
T
The Blog of Author Tim Ferriss
L
LangChain Blog
Project Zero
Project Zero
P
Proofpoint News Feed
有赞技术团队
有赞技术团队
P
Proofpoint News Feed
Scott Helme
Scott Helme
C
CERT Recently Published Vulnerability Notes
云风的 BLOG
云风的 BLOG
T
ThreatConnect
F
Fox-IT International blog

Forbes - Innovation

‘Spider-Noir’ Just Set A Marvel Rotten Tomatoes Audience Score Record Stop Treating Your Next Contact Center Migration Like A Project How Gemini Omni From Google Turns AI Video Into A Living Asset Smart Homes Won’t Scale Until The Privacy Problem Is Fixed SSL Breaks The Sound Barrier With Its Affordable SSL 1 Audio Interface The Boys’ Chace Crawford Pitched A Deep Spinoff That Sounds Great Scribe Or Operator? The AI Architecture Question Most Professional Services Firms Are Getting Wrong Samsung Details Its Full 2026 TV Range—Including Prices Cyber Vigilance In An Era Of AI ‘The Pitt’ Star Addresses Reported Feud With Noah Wyle The Operational Gap That's Stalling Autonomous Networking Elderly Trauma Often Causes Rapid Decline. How Adult Children Can Help New Info On ‘Destiny 2’ Alarm Bells, Marathon’s Role And ‘Destiny Infinity’ Pitch Xiaomi 17T, 17T Pro Bring ‘Leica Live Moments’ And Large Batteries Xiaomi 17T Series Brings Bigger Batteries And More Leica Magic WWDC 2026 Apple To Unveil iPhone Updates Including New Siri — How To Watch How AI Fits Into Luxury Retail: Enhancing High-Touch Personal Service How AI Has Changed The Way I Think Why AI Is Redistributing Power In Healthcare The Next Just-In-Time? How Agentic AI Is Rewiring The Factory How Do Crocodiles Drown Animals Twice Their Size? A Herpetologist Explains Telling Friend From Fraud In The Agentic AI Economy Nuclear Is Surging. The Real Question Is Timing Oura Ring 5, Claimed To Be World’s Smallest Smart Ring, Comes With Up To $100 Price Hike Why The Smartest Deal Teams Are Keeping AI Inside The Deal Room With ‘Trans Duets,’ Singer Makes Music, And Peace, With His Former Self AI Is Not A Bubble, But Real Transformation Comes With Growing Pains A Steel Revolution: Game-Changer For The Climate And Energy Crises A Leader’s Guide To Identifying High-Value AI Opportunities From Raw Data To Smarter Decisions: Decision Intelligence Best Practices Why The Next Era Of Biomanufacturing Will Be Won By Intelligence The New CTO Mandate: Steer The Promise Of Enterprise AI Toward Reality How AI Can End Recessions As We Know Them AI Will Accelerate IT Services—Quality Engineering Will Decide Who Can Keep Up How The RedMagic 11S Pro Smartphone Stands Out In A Crowded Market The Real Cost Of Enterprise AI Hallucinations City Lights Are Lengthening The North American Mosquito Season Before Removing Friction, Ask What It Protects TikTok And Cannes Push Vertical Drama Toward The Mainstream Pennsylvania Seeks Injunction Against AI Maker Whose Chatbot Brazenly Claims To Be A Psychiatrist Licensed To Practice Medicine TP-Link’s First Wi-Fi 8 Router Is Designed For Real-World Reliability The Important Healthcare Model Most People Have Never Heard Of Fans Already Have A Cool Theory About The Protagonist For ‘Dragon Quest XII’ Why WorkBuddy Going Global Marks A Reversal In The AI Agent Race AI Giants Bet Billions On The Most Expensive Job In Enterprise At-Home Care Devices May Make Pediatric Emergencies Easier To Deal With AI Spurs A Cultural Shift In A 1,000-Developer Insurance Company Today’s NYT Mini Hints And Answers For Thursday, May 28 Today’s NYT Strands Hints, Spangram, Answers For Thursday, May 28 (Ketchup Or Mustard?) These Fish Robots Will Eat Seawater To Harvest U.S. Critical Minerals Increased Funding Is Making At-Home Hospital Care A Reality Today’s Wordle #1804 Hints And Answer For Thursday, May 28 NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, May 28 4 ‘Weird’ Rituals Of Truly In-Love Couples, By A Psychologist Meet The Doctor-Turned-Entrepreneur Using AI To Save Lives The Ebola Epidemic Is Spreading Samsung Galaxy S26 Ultra Buyers: The Wait Has Finally Paid Off Netflix’s New Duffer Brothers Series ‘The Boroughs’ Starts Strong, Fizzles Out Robinhood Lets You Use AI To Trade Your Portfolio And Make Purchases Ferrari’s Controversial EV Likely To Advance Despite Launch Wobble Today’s NYT Connections Answers Explained For Thursday, May 28 Quordle Hints Today: Thursday, May 28 Clues And Answers Today’s NYT Connections Hints And Answers For Thursday, May 28 80+ Chambers Of Commerce Sound Alarm On STEM Talent Exodus, R&D Funding Tough Outlook For New North America Trade Agreement As Deadline Nears How To Connect Digital Transformation To Organizational Purpose Sony Reveals Full Details Of Its New True RGB TV Range—Including Prices Enterprise AI Has A Readiness Problem, Not A Model Problem Health Groups Launch ‘One Nation, Overcharged’ Campaign As Affordability Grips U.S. How To Build In Regulated Industries Without Killing Innovation Honor Watch 6 Plus Sets A New Wearable Standard With 1,000mAh Battery Sony Bravia 9 II True RGB TV First Impressions ​Why AI Delivery Can’t Wait For Tech Sovereignty ​ Your AI Budget Is Going To The Wrong Place ‘Off Campus’ Just Broke A Viewership Record On Amazon Prime Video Plugable’s Latest Thunderbolt 5 Dock Supports Dual HDMI 2.1 Screens Why Your Digital Transformation Is Already Obsolete: The Rise Of The Augmented Intelligent Enterprise (Part 1) Prompt After Prompt: AI Doesn’t Need More Instructions; It Needs Feedback Loops Why Delaying Zero Trust Can Be Financially Irresponsible Apple iPhone 18 Pro Will Debut ‘Game-Changer’ Satellite Upgrade, Report Says How Forward-Thinking Organizations Are Innovating Around Transport Policing Why Fast Follow-Ups Outperform Bigger Marketing Budgets The Highest Metacritic-Scored Game Of 2026 Has Just Arrived The Illusion Of Control: Why Dashboards Are Failing Legal And Operations Teams O2 Satellite Unlocks Potentially Life-Saving Feature Of iPhones A ‘Destiny 2’ Vs. ‘Marathon’ Civil War Is Heating Up, Frustrating Many Googlebook: Google Unifies Android And ChromeOS For AI-Powered Laptops Gen Z, AI And The Future Of Stakeholder Trust In The Impact Sector AI's Turning Point: Why Control Is Now The Competitive Edge ‘Dragon Quest’ Celebrates Its 40th Anniversary By Revealing ‘Dragon Quest XII’ The ‘Backrooms’ Rotten Tomatoes Review Score Has Arrived The Hidden Layer Every Healthcare AI Solution Is Missing Your AI Is Making Million-Dollar Decisions Based On Data Nobody Understands ‘The Witcher 3’ Reveals ‘Songs Of The Past’ Expansion 11 Years After Release Intelligence For Beings Who Can't Tell You What They Feel I Nailed a Robotaxi Forecast In 2013. Here’s Why Elon Keeps Blowing It Rewiring Omnicom’s Operating Model For AI At Scale From Supplier Scorecards To Predictive Intelligence: How AI Is Transforming Procurement Performance Exclusive: GoodRx Launches Companion Subscription As Insurance Add-On The Last Byte: The DRAM Shortage Auto Industry Never Saw Coming
Why Security Teams Should Shift From Bot Detection To Bot Diplomacy
Kaustubh Pha · 2026-05-28 · via Forbes - Innovation

Kaustubh Phatak is a seasoned product leader at AWS, driving strategy, execution, and GTM for cloud services serving global enterprises.

getty

​Six months ago, I wrote about the AI bots crisis facing publishers: Traffic is plummeting, unauthorized scraping is surging and the industry is scrambling to protect its assets.

The problem of increasing bots hasn't been solved since then, but it has been inverted.

Last month, I watched a major retailer's security team block an AI agent that was trying to complete a legitimate purchase on behalf of a customer. Their bot-detection system worked perfectly. It identified non-human traffic and shut it down.

But should it have? The "bot" was a paying customer's personal shopping agent, authorized and authenticated, attempting to do exactly what the customer asked.

Bot traffic now exceeds human traffic on the internet, crossing 51% in 2025 according to Imperva's annual report. Many of these bots are legitimate and useful, but our entire security apparatus still operates on a binary model: human or threat. We've built a multi-billion-dollar industry around a question that's no longer the right one to ask.​

Why The Binary Model Is Broken

​​For two decades, bot management meant one thing: detection. Identify the non-human traffic, challenge it, block it. CAPTCHAs, behavioral analysis, device fingerprinting and the entire toolkit assumes that identifying automation is synonymous with identifying threats.​

Today's AI agents, however, are authorized representatives carrying credentials, budgets and user intent. Customer's travel agents can query airline APIs to book a flight. A procurement agent can negotiate pricing across three vendor portals simultaneously.

Yet most security teams have no category between "verified human" and "blocked bot," meaning legitimate automation can get caught in detection systems designed for a different era. At the same time, sophisticated threats are learning to mimic the behavioral patterns of authorized agents.​​

​From Detection To Diplomacy​

To solve this, security teams ​will need to shift philosophically from focusing on detection to focusing on diplomacy.

Think about how international relations work. Countries don't ask "Is this person foreign?" and block all foreigners. They verify identity, check credentials, confirm intent and grant scoped access. Diplomats get different permissions than tourists. Business travelers get different access than refugees.​

Historically, bot detection has focused on the yes/no question: "Is this a bot?"

Today, security teams should be asking a more nuanced question: "Is this bot authorized to do what it's asking?"​​​

Three Embassies, No Common Language

Frameworks to address the evolving roles of bots are emerging, and there are mainly three competing approaches​.

The first approach treats agent identity as an extension of API authentication. Google's Agent-to-Agent (A2A) protocol, Anthropic's Model Context Protocol (MCP) and Cloudflare's Web Bot Authentication framework all define how agents identify themselves to services. The biggest concern is that they do it incompatibly. Currently, the major "passport offices" don't recognize each other's documents.

The second approach pushes identity into DNS, the internet's existing trust layer. If every legitimate agent has a verifiable identity record at the DNS level, services can check credentials the same way browsers check SSL certificates today. The idea is that no new protocol would be required, only an extension of infrastructure that already handles billions of lookups daily.

The third approach skips identity entirely and focuses on economic signals. If an agent is willing to pay for access (through micropayments, token deposits or computational proof-of-work), that economic commitment itself becomes the trust signal. You don't need to know who the agent is if you know it has skin in the game.​

Each approach has backers with deep pockets. The NIST has also launched a formal collaboration on agent identity standards in February.

Only time will tell how this will play out, but if you're a CTO or CISO, here's the practical reality: Your current bot management stack will need to account for legitimate bots in the near future. Here are three shifts to make now:

1. Create a third traffic category. Your systems likely classify traffic as "human" or "bot." Add "authorized agent" as a distinct category with its own policies, rate limits and access scopes. This can be the difference between blocking a customer's purchasing agent and completing a sale.

• 2. Invest in identity verification over behavioral detection. Behavioral analysis tells you what something is. Identity verification tells you who sent it and why. As AI agents become indistinguishable from humans in their browsing patterns (and they will, within months), identity will become more durable than behavioral detection.

• 3. Design for protocol plurality. Don't bet on a single agent identity standard winning. Build abstraction layers that can verify A2A Agent Cards, MCP credentials and DNS-based identity records. ​

The Publisher Update​

​Here's what most people miss: Up until this point, the conversation focused almost entirely on agents that read: content access, web scraping, information retrieval.

But as agents begin to act by booking flights, executing trades, signing contracts and deploying infrastructure, every one of those transactions requires trust. Not the "prove you're human" kind, but the "prove you're authorized, scoped, and accountable" kind.​ ​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?