A Harder Problem Than “Human or Bot”
The old binary, human good, bot bad, doesn’t map cleanly here. A legitimate AI agent can generate automated requests and complete transactions without a human clicking every button, which looks a lot like abuse from a platform’s perspective.
Platforms are left choosing between imperfect options: block automation and frustrate authorized users, loosen restrictions and enable abuse, or lean on heavy verification that requires documents many users don’t want to hand over. There’s no clean solution.
The framing gaining traction among some builders is that the real question often isn’t “who exactly is this person?” but “is there one real, unique human behind this agent?”, a narrower ask that needs less personal data.
Different Approaches to “Proof of Human”
Several projects are building proof-of-personhood infrastructure, from biometric verification to social-graph attestation to hardware-based credentials, each trading off convenience, privacy, and resistance to gaming at scale.
One prominent example is World, whose World ID protocol is described in its developer documentation as a privacy-preserving way to prove someone is real and unique online without sharing personal information. World says zero-knowledge proofs let a service confirm a valid World ID without revealing it or linking activity across apps.
World has extended this into the agent space through AgentKit, which lets verified users delegate their World ID to AI agents, letting an agent carry cryptographic proof of a human behind it. Built with Coinbase on the x402 payments protocol, it lets a website request proof of a unique human before granting an agent access. World has since expanded integrations to Browserbase, Exa, Okta, Shopify, and Vercel.
Whether this model becomes a standard, or one of several competing approaches, remains open, and will likely hinge on how broadly platforms adopt it over time.
What’s Still Unsettled
In theory, a working proof-of-human layer could cut fake accounts and abuse without routing every user through document-heavy KYC, while sparing users from handing over unnecessary personal information.
Realizing that promise, though, will take more than good design. Open questions include how these systems perform at scale, how they handle someone running multiple legitimate agents, and how quickly bad actors adapt once a method becomes widely deployed. Such schemes will need to prove they’re meaningfully harder to spoof than the checks they replace.
The broader shift still seems real: as agents take on more tasks for people, platforms will need some way to reason about accountability beyond “human” or “bot.” World’s approach is one strong candidate for how that gets built, alongside competing standards and ideas still to come.