6th July 2026, Reddit disclosed how they stepped up against spam exposure, along with cutting out inauthentic votes, manipulation, and whatnot. That's the biggest culture forum in the world.
Human verification of AI slop is a must now, given the telltale signs are getting blurred each passing day. Astroturfing and sock puppeting are now more common than ever. Brands and service businesses are investing millions to hire agency clusters from around the world for such multi-accounting.
Really feels scary to think that the comment, picture, or emotion you read, saw, or felt good about is getting seeded as some wider campaign/propaganda. Likes, comments, upvotes, etc engagement still ride to the top of the relevancy chart. But you'd be a fool if you base your complete faith on these cause these can now easily be fabricated.
Proof of personhood (PoP), while preserving anonymity, is building a system to solve this crisis, based on privacy-preserving credential elements and reverse AI engineering mechanisms. But the need to build something of that sort is now more emergent than ever.
Why a convincing crowd no longer proves demand
A bad bot study published this year found that above 53% of total internet traffic in 2025 is automated, which was 51% two years back. Totally segregated bots account for 40% of human traffic, while real humans account for 47%, but the crazy thing is that the data here is observational, not systematically tallied.
Another study in August 2025 was targeted specifically at X content and found that 44.5% of it feels automated, with 70% of these posts having the same lingo, the same kind of hashtags, and the same snippets and word count per sentence. Haha, crazy, right? But wait, there's more.
Considered reluctantly…AI can be misused and prove costly for companies. A famous example of this is how, in 2024, an employee from the famous engineering company Arup got scammed by video and voice deepfakes of senior employees posing as real colleagues and wired HK$200 million (about 25.6 million USD) to the scammers. Hefty, isn't it?
Such payment frauds can happen even more easily as newer and better models with more contextual ability are being launched. Heck, they may even acquire verified badges and pose as real human accounts, but there is no telling unless there is a verification protocol established.
AI vs human verification technologies: what can they prove?
Why do harder CAPTCHAs still fall short?
In a USENIX Security 2023 study, 1,400 people were given about 14,000 CAPTCHAs. Similarly, when given to bots, the results came out very surprising. 85–100%, versus 50–85% for humans. Plus, for image recaptures, bots took 17.5 seconds versus 18 seconds for humans.
General-purpose agents and backtracking, as per Open CaptchaWorld’s research, are still nascent. Comparisons of AI vs human verification technologies need that context. Sites nowadays look out for browser/device fingerprints, dwell time on site, and many other signals to tell bots from real humans. But with specific anti-detect browsers and software available in the market, grading profiles on whether they are really human or not is still very hard.
Anyone can get an anti-detection browser and couple it with a static residential/mobile proxy to impersonate a real user using a real IP with fabricated signal elements. Boom, they can run multiple accounts impersonating anyone from any place in the world, even when their original IP is flagged and banned.
The difference between normal KYC and PoP check
One is authenticating someone's civil identity. The other one is whether it's an automated system or a human. A proper one-person, one-account credential storage means associating KYC with biometrics, Gmail, geolocation, time-to-time passkey update requests, and finally adding a writing-style scan as well. A higher proof-of-personhood check might also include restricting the account geographically or tracking its region-specific engagement history.
NFT.eu’s guide to on-chain reputation without KYC explores a related distinction: an account’s history supplies evidence about its behaviour. Uniqueness asks how many such accounts one person controls.
How private human verification works
Biometric deduplication fails because sites can't force people to accept their cookies. Anyone can choose their data to be stored locally instead of the server or cloud. Performing one-to-one authentication becomes very hard for growing sites like, say, Reddit or X, and biometric resemblance across people makes one-to-many matching unreliable.
Five requirements for usable personhood credentials
1. Enrolment must resist forgery
Checks must move beyond CAPTCHA. According to the World's Orb whitepaper…hardware metrics, liveness, and ID/biometrics combinations provide unique identifier elements.
The higher the quality of the sensor and decoder, the more accurate the output is cause that hardware root of trust is paired with a changing biological element (like an iris pattern) that verifies the same person logging in every time from the same configuration. Add to that the periodic updates requirement and security moves to a much larger scale.
Still one established identity doesn’t equate to them always being present.
2. Duplicate checks must protect biometrics
Secure multi-party computation (SMPC) uses separate operators to compare protected data in the same time frame. This allows splitting biometric info into secret shares to analyze and reveal close inferences with previous records. Security still depends on the protocol’s assumptions about collusion and compromised systems.
3. Recovery must preserve existing limits
Another one of the reasons why regular update notifications are mandatory regarding account recovery is to help users who might lose their device access. Having a key rotation would help them restore access on the server side. The server can manage triggering of new keys and blocking out the old keys. This makes credential management much easier by relying on a single source of login/logout signal.
A lost phone must not mean permanent exclusion. Account recovery and key rotation need to restore control while retiring compromised access. For quota-based services, recovery must also preserve previous usage; otherwise, replacing a key becomes a way to claim again. World’s private proof of human paper discusses recovering access without issuing another independent credential.
4. Duplicate markers need narrow scopes
Zero-knowledge proofs can verify authentication claims without revealing any personal or restricted info. This happens via a nullifier, which creates a poll for any specific activity. This poll, or any different marker attribute for the activity, is restricted to one action, one marker only, which helps with proof checking while keeping the previous method of checking a one-time-use only.
Cookies, payment records, or reused wallet addresses can still connect activity. NFT.eu’s programmable privacy explainer provides further background on controlling disclosure.
For daily basis login/logouts, the marker should tally the day along with the service, and the backend system should keep a record. Otherwise, more than one request can pass before any of the markers is put to use.
5. Agent access needs limits
Imagine there's a website that gives every person a free ticket, and you ask the AI assistant of that site to book it for you. Two things are happening here:
- The assistant is working for you, the person.
- You haven't claimed the ticket yourself or via another agent.
Agent delegation playbooks define how AI assistants can help you with recurring tasks like this, and you can use multiple agents for multiple tasks with one user at the backend. However, the control of each and every AI agent's subtasks is not authenticated by you, which is a permission blockage. The website, hence, must deliberately control how much spending, transactions, or permission each agent can have if the real human is unavailable to permit it.
Examples of this would be online shopping agents doing large purchases or site MCP connectors connected to some LLM to act as an AI agent to do the shopping and transaction for you.
Where counting people changes platform rules
One user can make multiple fake accounts to gain more engagement, power, or spread propaganda. This is popularly referred to as a Sybil attack, and proper human verification can cut out such manipulated spam tactics, helping areas like:
- public decisions, so that every vote or petition is valuable
- product launches or complaint tickets, where targeted launches, targeted complaints, or user onboarding can't be fabricated
- shared benefit access, where free offers and limited access can't be overutilized.
None prevents a verified person from lying, reselling tickets or directing harmful software. NFT.eu’s coverage of AI agents finding blockchain vulnerabilities is relevant here: human backing cannot substitute for security controls.
Who gets left out when verification becomes compulsory?
World ID report published recently noted how nearly 18 million people from 160 countries have authenticated digital identities, although countries like Spain, Germany, Brazil, Kenya, the Philippines, and Thailand had some data-hoarding concerns and hence were opt-outs.
But the crux of the matter is there should be more than one way to prove somebody is human. Error rates and rejection checks should follow along with periodic reset strategies so that if somebody gets blocked from the platform, they can reclaim it. For well-connected and reputed people, that can also consider social proof checking for cross-platform validation.
But such can't always be the case for every app or platform, as the amount of money involved greatly matters. For the big platforms, stronger check-ins would do, but for the platforms starting or navigating the scene, they might depend on manual mail support or voting powers, whatever. Everyone should be given the right to share their part online.
Which brings me to the fact that a lot of the platforms that are functional right now are more platform-rule-aligned rather than personhood-aligned.
Reddit, for example, doesn't disclose why they explicitly take actions regarding shadowbanning or banning people. OpenAI doesn't disclose why they won't output certain images or certain answers. Frustrated users simply mean a lost one, which can snowball into a greater loss of trust and faith in the platforms' jurisdictional capability.