Here is an uncomfortable question for anyone who still thinks of the internet as a human place: if a majority of the traffic hitting the world's websites is not human, who exactly is the web being built for?
According to Imperva's 2026 Bad Bot Report, automated traffic accounted for more than 53% of all web traffic in 2025, up from 51% the year before, while human activity fell to 47% and continues to decline. Malicious bots alone made up 37% of all internet traffic in 2024, and Imperva is explicit that this reflects a structural change in how the internet operates, not a short-term attack cycle. Businesses are no longer serving customers alone. They are serving machines.
Layer the fraud numbers on top and the picture darkens. The FBI's IC3 logged roughly $893 million in losses from complaints that referenced AI in 2025, the first year the agency tracked AI as its own category. Deloitte's Center for Financial Services projects that generative AI will push US fraud losses to $40 billion by 2027, up from $12.3 billion in 2023, a 32% compound annual growth rate. The single most instructive incident remains the engineering firm Arup, where a finance employee wired $25.6 million across 15 transfers after a video call in which every other participant, including the CFO, was a deepfake. The attack did not defeat a firewall. It defeated the human assumption that a face on a screen belongs to a person.
The Broken Binary
The internet's traditional response to abuse has always been a trade. Platforms could demand government IDs, phone numbers, selfies and behavioral surveillance, buying trust at the price of privacy. Or they could preserve anonymity and accept the bots, the Sybils and the synthetic personas.
Both ends of that trade are now failing simultaneously, and for the same underlying reason: generative AI attacks both sides of the ledger at once. Surveillance-heavy verification creates honeypots of personal data that leak with clockwork regularity, and the stolen data feeds the very fraud it was collected to prevent. Imperva recorded around 330,000 account-takeover incidents in December 2024, up from roughly 190,000 a year earlier, driven by credential stuffing against exactly the databases that "know your customer" regimes require. Anonymity-heavy platforms, meanwhile, are being hollowed out by machine traffic that humans can no longer distinguish from their own.
The scale of the synthetic supply side makes the point sharper. Estimated deepfake files online grew from 500,000 in 2023 to 8 million by 2025, an annual growth rate approaching 900%, fueled by open-source models and deepfake-as-a-service platforms. Voice is even cheaper: three seconds of audio is enough to clone a voice with 85% accuracy.
Why Detection Alone Cannot Win
The instinctive answer to synthetic content is better detection, and the numbers explain why that instinct fails. Humans spot deepfake videos less than 25% of the time, and an iProov study found only 0.1% of people can reliably identify AI-generated deepfakes at all. Automated detectors look better in the lab, reaching up to 96% accuracy in controlled conditions, then dropping 45 to 50 points in real-world use. Attackers have also moved below the camera entirely: iProov tracked a 2,665% surge in native virtual camera attacks and a 1,151% rise in injection attacks that feed manipulated video directly into verification software, bypassing camera hardware altogether.
Detection is a classifier fighting a generator, and the generator improves on the defender's feedback. That asymmetry is why the industry's center of gravity is shifting from detecting what is fake to certifying what is real. If you cannot reliably identify the synthetic majority, the alternative is to cryptographically attest the human minority.
What Privacy-Preserving Proof of Human Actually Means
The concept has an academic pedigree. In 2024, researchers from OpenAI, Microsoft, Harvard and other institutions published a paper on "personhood credentials," arguing that AI's growing indistinguishability from people online requires credentials that verify humanness and uniqueness while preserving anonymity. The design constraints are strict. A valid system must confirm three things: that a user is human, that the human is unique within the system, and that neither the verifier nor the platform learns who the human is.
The cryptographic workhorse is the zero-knowledge proof, which lets a user demonstrate that a statement is true, such as "I am over 18" or "I hold a valid passport," without revealing the underlying data. Around that core, a four-layer trust stack is taking shape:
-
Device attestation.Apple's Private Access Tokens and Cloudflare's Privacy Pass certify that a request comes from a legitimate device without identifying its owner. Useful against crude botnets, but a device proof is not a person proof, and one human can run many devices.
-
Document-anchored proofs.Systems that read the NFC chip in a passport or national ID and emit a zero-knowledge attestation. Google has integrated zero-knowledge proofs into Google Wallet for age assurance, and Self Protocol has built an entire network on this layer.
-
Biometric uniqueness.Iris or palm-based systems can convert biometric signals into encrypted representations designed to establish that one credential corresponds to one person. This approach can provide strong resistance to duplicate identities, but its success depends on careful implementation, informed consent, secure data handling and transparent technical safeguards.
-
Content provenance.C2PA-style standards that watermark what machines make. Provenance certifies the artifact; personhood certifies the actor. They are complements, not competitors, and mature trust infrastructure will run both.
Uniqueness is the hard part of the stack. Anyone can prove "a human exists somewhere behind this account." Proving "exactly one credential per human, and this is it" is where the specialist networks compete.
Proof of Human: In the New World of AI
World: hardware-anchored uniqueness. World, the network co-founded by Sam Altman and developed by Tools for Humanity, uses dedicated hardware to establish that a participant is a unique human. Its Orb captures an iris image, processes it into an encrypted representation and issues a World ID without requiring the user to provide a name, email address, phone number or social profile.
The network reports nearly 18 million verified participants, compared with approximately 12 million in mid-2025 and 6 million in September 2024. Pantera Capital, an investor in the project, has identified Orb Mini, a smaller verification device, as an important part of the network’s future distribution strategy.
What changed in 2026 is distribution. At its April Lift Off event, World announced integrations with Tinder, Zoom and Docusign, alongside Razer for gaming, Mythical Games for player economies, Okta and Vercel for enterprise, and a Concert Kit that reserves tickets for verified humans. Tinder's US expansion gives verified humans a profile badge, moving proof of human from crypto novelty to dating-app table stakes. The Zoom integration uses a three-way cryptographic match involving the Orb-verified image, a live device selfie and the on-screen video, offering a potential safeguard against the type of impersonation risk illustrated by the Arup incident. World has also extended the thesis into agentic commerce, releasing AgentKit, which lets merchant sites verify that a real human sits behind an AI shopping agent's purchases via the x402 payment protocol, and opening a waitlist for Human Principal, which will enable per-human rate limits for agent traffic and abuse-protected free tiers.
What to Watch: Five Signals for 2026-2027
1. Orb Mini and the road to 100 million. Pantera flags Orb Mini as the device intended to scale World past 100 million users. If distribution moves from dedicated hardware to smartphone-class devices, the enrollment bottleneck breaks.
2. Agent identity standards. The fastest-moving frontier is binding humans to their AI agents. World's AgentKit rides the x402 payment protocol, the Human Principal beta promises per-human rate limits for agent traffic, and Google is wiring Self verification into rate limits for its blockchain-aware AI tools. The standards that emerge for linking people to accountable AI agents could shape how the agentic web manages access, payments and abuse prevention.
3. EU AI Act enforcement. With deepfake transparency obligations binding from August 2026, the first enforcement actions will reveal whether regulators accept provenance labels alone or start expecting personhood signals in high-risk contexts like political content and financial communications.
4. Financial rails going mainstream. Mastercard's integration with Humanity Protocol is the template to track: if verified credentials start gating access to regulated financial products at scale, proof of human graduates from social-platform hygiene to financial infrastructure, with the compliance budgets that implies.
5. Interoperability and standards alignment. Watch for progress around portable proofs, W3C verifiable credentials and cross-platform acceptance. A significant milestone will be reached when credentials issued through one system can be recognized by applications built around another, reducing fragmentation for users and developers.
The Industry Ahead
The agentic web makes personhood more valuable not less, due to this as AI agents transact through many of the same interfaces as people, the commercially important question becomes not simply whether an action was automated, but whether an accountable human authorized it. Establishing that relationship between a person and an agent may become one of the category’s most important applications.
Further, privacy and accessibility will remain central design requirements. Systems must account for people who lack supported documents, nearby enrollment infrastructure or compatible devices. They must also address credential recovery, revocation, coercion and unauthorized transfer. Networks that build these protections into their products will be better positioned to earn long-term institutional and user trust.
Final Thoughts
The internet spent decades operating on the assumption that most participants were human. As automated activity becomes more capable and more difficult to distinguish from human behavior, that assumption can no longer serve as a reliable security model.
Proof-of-human infrastructure offers a possible alternative to requiring every platform to collect additional personal information. World and the wider proof-of-human ecosystem around personhood credentials are testing whether cryptography can establish trust while limiting unnecessary disclosure. The next stage will be determined by practical outcomes: ease of enrollment, platform adoption, measurable reductions in abuse, interoperability and the ability to maintain credible privacy protections at scale.
Vested Interest Disclosure: HackerNoon has reviewed the report for quality, but the claims herein belong to the author. #DYOR.