惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
Y
Y Combinator Blog
M
MIT News - Artificial intelligence
The Cloudflare Blog
WordPress大学
WordPress大学
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 司徒正美
小众软件
小众软件
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
J
Java Code Geeks
云风的 BLOG
云风的 BLOG
C
Check Point Blog
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
V
V2EX
F
Fortinet All Blogs
B
Blog
大猫的无限游戏
大猫的无限游戏
N
Netflix TechBlog - Medium
B
Blog RSS Feed
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

PYMNTS.com

Treasury Calls for Programmable Financial Enforcement Across Crypto DeepSeek Seeks $20 Billion Valuation as Tech Giants Weigh Investment Google Accelerates Agentic AI Shift With New Enterprise Platform OpenAI Begins Briefing Governments on Cybersecurity Capabilities DeFi Security Suffers New Blow With $3 Million Volo Exploit Uninvited Users Access Anthropic’s Mythos AI Model Block and Uber Expand Partnership Across Several Global Markets OpenAI Pledges $1.5 Billion to PE Enterprise AI Project Podcast: Inside the $9 Billion DeFi Hack That’s Shaking Crypto’s Foundations Synchrony CFO Flags Momentum in Spending and Credit Banks Risk Slowing the Emerging Middle Market Firms Driving Growth Paysafe Expands Digital Wallet Availability Across 18 European Markets Bad Data Can Break Good AI in Payments 50% More Digital Shopping Days Put Parents at the Center of Retail’s Shift 65% Call Insurance Essential. Why Most Spending Isn’t So Clear-Cut Amazon Recasts Marketplace Fraud as a Broader Trust Problem Capital One’s Q1 Shifts Attention From Spending to Strategy Lawmakers Question JetBlue About Surveillance Pricing Allegations Small Businesses Stop Chasing Amazon on Delivery Speed Google Embeds AI Into Chrome for 3.5 Billion Users Adobe Plans Outcome-Based Pricing for New AI Product Suite UnitedHealth Spends $1.5 Billion on AI and Wants Double Back MiCA Forces Crypto Firms to Get Licensed or Get Out Prediction Market Kalshi Targets Crypto Perpetuals New York Sues Coinbase and Gemini Over Prediction Markets Amazon and Anthropic Deepen Ties With Investment and Hardware Pact Agentic B2B Is Here. Are Your Contracts and Invoices Ready? Apple Hardware Leader John Ternus to Succeed CEO Tim Cook The Web Is Gaslighting AI Agents and Nobody Can Tell OCC Enters the Interchange Fight and Raises the Stakes
Bots Are Turning Identity Verification Into a Full-Time Job
PYMNTS · 2026-04-24 · via PYMNTS.com

By  |  April 24, 2026

 | 

identity verify

In the early days of digital commerce, identity verification was a front-door exercise. It represented a necessary, but narrow, checkpoint designed to confirm that a customer was who they claimed to be.

But findings in “Identity at Scale: Where KYC/KYB Touchpoints Create (or Contain) Agent Risk,” a new report from PYMNTS Intelligence and Trulioo, reveal how that model has increasingly collapsed under the weight of sophisticated adversarial behavior and automated bots.

The bots aren’t coming for commerce, the report found. Because they’re already there inside the system. Across everything from logins to loan applications, automated agents are now probing, mimicking and exploiting identity workflows at scale. During high-value moments like lending, over 63% of firms surveyed reported agent-driven threats and adversarial bots.

The result is forcing a rethink of digital trust: not just knowing your customer or your business, but increasingly, knowing whether you’re dealing with a human at all.

Why Identity Is Becoming a System, Not a Checkpoint

For years, bots were treated as an externality to be filtered out at the edges of digital systems. They showed up in bursts: credential stuffing attacks, fake account creation, scripted checkout abuse. Firms built defenses accordingly, focusing on detection at key entry points like login or onboarding.

But what has changed is not simply the volume of automated activity, but its distribution and persistence across the entire operational stack. Identity verification, once concentrated at onboarding, now spans multiple workflows: authentication, transactions, fraud monitoring, vendor onboarding and lending. As these controls expand, so too does the surface area for automated agents to operate within them.

Advertisement: Scroll to Continue

The question is no longer how to block bots at the perimeter. It is how to govern a system in which non-human agents are persistent, adaptive and economically consequential.

As bots become more integrated into economic activity, a new layer of identity emerges that sits alongside traditional frameworks like know your customer (KYC) and know your business (KYB). Increasingly, firms must contend with what might be called know your agent (KYA): the ability to identify, classify and govern non-human actors.

Designing for this reality requires a different mindset. Instead of treating bots as anomalies, firms must assume their presence as a baseline condition. Systems must be built to accommodate a mix of actors, each with different characteristics, capabilities and risks.

This involves developing new forms of identity that capture not just who or what an entity is, but how it behaves over time. It means integrating signals across workflows to create a more holistic view of trust. And it requires establishing policies that define acceptable use, rather than relying solely on binary allow-or-block decisions.

Read the report: Identity at Scale: Where KYC/KYB Touchpoints Create (or Contain) Agent Risk

One of the more counterintuitive findings in the report is that the breadth of identity deployment often matters more than the sophistication of any single control. Firms that apply verification across a wider set of workflows (five or more) tend to experience less pressure from automated agents, fewer breakdowns and lower downstream costs.

When identity controls are embedded across multiple touchpoints, they reinforce one another, reducing the opportunities for agents to exploit gaps. Enforcement becomes more uniform, ownership clearer and signals more integrated.

The implication is that identity maturity is less about isolated excellence and more about systemic coherence. It is the difference between a series of checkpoints and a continuous control plane.

The challenge is not simply to keep bots out. It is to design systems that can operate effectively in their presence. In doing so, firms are not just defending against a threat. They are adapting to a new economic reality in which the question of who — or what — is on the other side of the interaction is more complex, and more consequential, than ever before.