惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
MongoDB | Blog
MongoDB | Blog
Martin Fowler
Martin Fowler
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
B
Blog
U
Unit 42
B
Blog RSS Feed
D
DataBreaches.Net
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
腾讯CDC
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
博客园 - 聂微东
MyScale Blog
MyScale Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
Engineering at Meta
Engineering at Meta

PYMNTS.com

Crypto Payments Are Back. Will Merchants Actually Care This Time? B2B’s New Battlefield Is Everything Before the Button Amazon Targets the GLP-1 Gap Big Pharma Left Open LendingClub Signals Expanded Capabilities With Happen Bank Rebrand Congress Moves to Give FinTechs Direct Fed Payment Access Microsoft Tests Mythos to Identify and Mitigate Vulnerabilities United Airlines Hikes Fares as Fuel Costs Surge OpenAI Images 2.0 Is a Real Leap With a Real Price Tag Morgan Stanley Says Gaming Could Score $22 Billion With AI FTC Shuts Down Alleged Healthcare Fraud Scheme Sam’s Club Offers eCommerce Shoppers Hour-or-Less Deliveries FinTechs Cut Staff as AI and Margins Redefine Growth JPMorganChase Extends Critical Industries Investment Program to Continental Europe OpenAI Lands $75 Million Investment From Robinhood Ventures House Bill Would Reduce Small Lenders’ Reporting Requirements Coinbase Lists tGBP to Expand Locally-Denominated Stablecoin Access BNY Names New Head for Payments/Trade Client Platform KnowBe4 Automates Global Cash Flow Via Flywire Partnership Treasury Calls for Programmable Financial Enforcement Across Crypto DeepSeek Seeks $20 Billion Valuation as Tech Giants Weigh Investment Google Accelerates Agentic AI Shift With New Enterprise Platform OpenAI Begins Briefing Governments on Cybersecurity Capabilities DeFi Security Suffers New Blow With $3 Million Volo Exploit Uninvited Users Access Anthropic’s Mythos AI Model Block and Uber Expand Partnership Across Several Global Markets OpenAI Pledges $1.5 Billion to PE Enterprise AI Project Podcast: Inside the $9 Billion DeFi Hack That’s Shaking Crypto’s Foundations Synchrony CFO Flags Momentum in Spending and Credit Banks Risk Slowing the Emerging Middle Market Firms Driving Growth Paysafe Expands Digital Wallet Availability Across 18 European Markets
Bots Are Turning Identity Verification Into a Full-Time Job
PYMNTS · 2026-04-24 · via PYMNTS.com

By  |  April 24, 2026

 | 

identity verify

In the early days of digital commerce, identity verification was a front-door exercise. It represented a necessary, but narrow, checkpoint designed to confirm that a customer was who they claimed to be.

But findings in “Identity at Scale: Where KYC/KYB Touchpoints Create (or Contain) Agent Risk,” a new report from PYMNTS Intelligence and Trulioo, reveal how that model has increasingly collapsed under the weight of sophisticated adversarial behavior and automated bots.

The bots aren’t coming for commerce, the report found. Because they’re already there inside the system. Across everything from logins to loan applications, automated agents are now probing, mimicking and exploiting identity workflows at scale. During high-value moments like lending, over 63% of firms surveyed reported agent-driven threats and adversarial bots.

The result is forcing a rethink of digital trust: not just knowing your customer or your business, but increasingly, knowing whether you’re dealing with a human at all.

Why Identity Is Becoming a System, Not a Checkpoint

For years, bots were treated as an externality to be filtered out at the edges of digital systems. They showed up in bursts: credential stuffing attacks, fake account creation, scripted checkout abuse. Firms built defenses accordingly, focusing on detection at key entry points like login or onboarding.

But what has changed is not simply the volume of automated activity, but its distribution and persistence across the entire operational stack. Identity verification, once concentrated at onboarding, now spans multiple workflows: authentication, transactions, fraud monitoring, vendor onboarding and lending. As these controls expand, so too does the surface area for automated agents to operate within them.

Advertisement: Scroll to Continue

The question is no longer how to block bots at the perimeter. It is how to govern a system in which non-human agents are persistent, adaptive and economically consequential.

As bots become more integrated into economic activity, a new layer of identity emerges that sits alongside traditional frameworks like know your customer (KYC) and know your business (KYB). Increasingly, firms must contend with what might be called know your agent (KYA): the ability to identify, classify and govern non-human actors.

Designing for this reality requires a different mindset. Instead of treating bots as anomalies, firms must assume their presence as a baseline condition. Systems must be built to accommodate a mix of actors, each with different characteristics, capabilities and risks.

This involves developing new forms of identity that capture not just who or what an entity is, but how it behaves over time. It means integrating signals across workflows to create a more holistic view of trust. And it requires establishing policies that define acceptable use, rather than relying solely on binary allow-or-block decisions.

Read the report: Identity at Scale: Where KYC/KYB Touchpoints Create (or Contain) Agent Risk

One of the more counterintuitive findings in the report is that the breadth of identity deployment often matters more than the sophistication of any single control. Firms that apply verification across a wider set of workflows (five or more) tend to experience less pressure from automated agents, fewer breakdowns and lower downstream costs.

When identity controls are embedded across multiple touchpoints, they reinforce one another, reducing the opportunities for agents to exploit gaps. Enforcement becomes more uniform, ownership clearer and signals more integrated.

The implication is that identity maturity is less about isolated excellence and more about systemic coherence. It is the difference between a series of checkpoints and a continuous control plane.

The challenge is not simply to keep bots out. It is to design systems that can operate effectively in their presence. In doing so, firms are not just defending against a threat. They are adapting to a new economic reality in which the question of who — or what — is on the other side of the interaction is more complex, and more consequential, than ever before.