Home Artificial Intelligence The AI Identity Crisis – Unite.AI

The AI Identity Crisis – Unite.AI

by admin
The AI Identity Crisis – Unite.AI

This spring, Redwood Research gave an AI agent built on Claude Opus 4.7 a $5,000 stake, an internet connection and four days to make as much money as possible. Across four separate runs, the agent made nothing. Every attempt stalled at the same wall: a CAPTCHA and an identity check, the same KYC gauntlet a bot hits trying to open a bank account.

While that agent sat stuck at the front door, another population of agents was already moving real money through a different channel to bypass KYC. According to an independent Chainalysis count, the agents who found a workaround processed more than 100 million payments over Coinbase’s x402 protocol on the Base network by early 2026. All settled in stablecoins. None touched a bank. Both facts appear in the same reporting on the emerging agent economy

An AI agent cannot be the legal owner of a bank account. The system assumes a human behind every account, with KYC checks, legal identity and liability that attach to a named person. So the agents found a way to move money anyway, just not through the door built to check for a person.

More Machine Than Human

The operator behind a transaction is no longer reliably human, with 40% of enterprise applications projected to ship with task-specific AI agents by the end of this year, up from under 5% in 2025. On the consumer side, 45% of shoppers already turn to AI for part of a purchase, even as most still shop in physical stores. Another survey found that 95% of merchants already see AI agent traffic on their sites, while only 20% have product catalogs that a machine can actually read.

Within the enterprise, the ratio is even starker. A recent report found machine identities now outnumber human identities 109 to 1, up from 82 to 1 a year earlier, with 77% of organizations expecting that ratio to keep climbing. The same report found 99% of organizations have already adopted AI agents, and 40% of those agents already hold access to organizational data.

What a Session Actually Proves

None of this would matter if a login still meant what it used to mean. It doesn’t. A session that clears every existing signal, a real device, a clean IP address and a solved verification challenge increasingly proves nothing about who or what sits on the other end.

That is a narrower claim than it sounds, and a more useful one. Nobody is arguing that automation itself is illegitimate. A person’s own banking assistant, travel bot or procurement agent is a session too, and a growing share of genuine sessions will be exactly that kind of authorized proxy rather than a person typing directly. The infrastructure already makes that frictionless. Once a user authorizes an agent via MCP, the open standard that lets AI tools connect to a service and act on a user’s behalf, the agent can continue transacting under that authorization without a fresh human login each time. The official MCP registry listed more than 6,400 registered servers by February 2026, reaching that milestone in just over a year since the protocol’s 2024 release.

The problem is that today’s risk stack has no reliable way to distinguish an authorized proxy from an agent acting without authority at all, because both arrive with the same signals.

ID document checks and biometric selfie scans confirm that a document belongs to a person and that the person is alive. They do not confirm that genuine intent, or the digital history that a real identity accumulates, lies behind the transaction. Identity verification needs to shift from checking an appearance to confirming intent through continuity. A real person builds years of ordinary online behavior. An agent provisioned minutes before a transaction has no way to fake that. A session was always a proxy. It just used to be a reliable one.

The Blind Spot Nobody Priced In

Account takeover already exploits the gap between a session and a person, and it is where the shift first appears in loss data. A recent analysis of global account-takeover trends for 2026 found that financial accounts accounted for 32% of breaches, with session hijacking and multifactor fatigue attacks displacing brute-force login attempts as the preferred route in, precisely because a hijacked session inherits all the trust a genuine login earned. Global identity fraud topped $50 billion in 2025, according to the same analysis, with AI-driven attacks alone responsible for an estimated $40 billion in annual business losses.

That gap is structural, not incidental. A login check happens once at the front door, and everything that follows inherits its verdict. Nothing re-checks the ten minutes between a clean login and a fraudulent transfer. Closing it requires a discipline most fraud stacks don’t yet have: session monitoring, treating the full session as a continuous thread rather than a single gate. A remote-access tool switched on mid-checkout or a device fingerprint that changes after login raises the alarm that the original check never could.

Every control built to catch that gap was calibrated against a specific enemy: a human fraudster impersonating a genuine human. Behavioral biometrics learned to spot mouse movements too smooth to be human. Device intelligence learned to spot the fingerprint of a cloud device farm. Neither was built to answer a newer question. Not whether the session belongs to a fraudster, but whether it belongs to anyone at all.

The Question With No Name Yet

That question does not yet have an agreed-upon name in the industry, though it will need one before this year is out. Regulators are already circling it, banks are already being tested by it and the agents themselves are not waiting for either to catch up.

An industry that spent two decades learning to tell a real customer from a fake one is now being asked to tell a customer from a piece of software acting in nobody’s name at all. That is a harder problem than the one the current stack was built to solve, and pretending otherwise is the most expensive option on the table.

Source Link

Related Posts

Leave a Comment