The AI Verification Tax

Humans are now a minority on the web. Proving that you are one of them is about to get more expensive.
The-ai-verifiction-tax-norm-murray-the-norm-report

In 2025, automated traffic crossed a threshold that most boardrooms have not registered: bots now account for 53 percent of global web traffic, up from 51 percent the year before, according to Imperva’s 2026 Bad Bot Report. Humans have become the minority user of the internet they built. This is not a cybersecurity footnote. It is the early signal of a structural shift in how digital trust infrastructure gets priced, governed, and owned. The verification systems designed to keep bad actors out are now taxing your customers, your employees, and your brand with friction that legitimate humans absorb and sophisticated bots increasingly evade. This article applies two established frameworks, the Red Queen effect from evolutionary biology and Akerlof’s Market for Lemons from economics, to explain why the arms race cannot be won by better captchas, and what forward-positioned executives are building instead: verified-trust infrastructure as a competitive asset rather than a compliance cost.

AI-by-norm-murray

Humans Are Now A Minority On The Web.

You are trying to log into a platform you use every day. Instead of the page loading, a grid of blurred images appears: seven animals, and an instruction to match the one with similar eating habits to a cow standing in a red field. Is that a horse or a mule? What does a pelican eat? You guess. You guess wrong. You start again.

This is not a story about a frustrated consumer. It is a story about you, most likely, sometime in the past month. Chief executives, board directors, and senior operators are burning the same seconds on the same broken puzzles as everyone else, because the systems built to distinguish humans from bots were never designed with dignity, speed, or seniority in mind. They were designed for a world where humans were the default and bots were the exception.

That world ended. The math flipped, and almost nobody in a leadership seat has updated their mental model to match.

These tests have a longer history than most executives realize, and the history matters because it shows how far the original purpose has drifted. The now-defunct search engine AltaVista introduced a rudimentary bot test in 1997. Early captchas served a genuine dual purpose: they blocked spam while crowdsourcing the digitization of scanned historical texts, asking a human to type a word an optical scanner could not read. The test created value even as it verified identity. Today’s version creates no value at all. It exists purely as a toll booth, a pure deadweight cost imposed on the legitimate user to slow down the illegitimate one, and it is failing at the one job it still has.

Cybersecurity firm Imperva has tracked global bot traffic for more than a decade. Its 2026 Bad Bot Report confirms what practitioners have suspected for two years: automated traffic now exceeds human traffic online, and the gap is widening, not closing.

The numbers are stark. Bots accounted for 53 percent of all web traffic in 2025, up from 51 percent in 2024. Of that share, 13 percentage points are “good” bots such as search crawlers and monitoring tools, while 40 percentage points are bad bots built to scrape data, commit fraud, or overwhelm infrastructure, a figure that has grown for seven consecutive years. Imperva also recorded a 12.5-fold year-over-year surge in AI-enabled bot attacks, with daily blocked attacks rising from roughly two million to twenty-five million.

Security firm HUMAN Security, tracking a different but overlapping slice of traffic, found automated requests now make up 57.5 percent of HTML web traffic against 42.5 percent from humans. The firm also logged a 7,851 percent year-over-year increase in traffic from AI agents and agentic browsers, tools that now browse, click, and transact on a user’s behalf. By April 2026, agentic browsers generated roughly three-quarters of all agentic traffic on the open web.

The Crossover: Bot Traffic Overtakes Human Traffic by Norm Murray - The Norm Report

Cloudflare, which runs anti-bot infrastructure for a large share of the commercial web, says it now performs 7.7 billion anti-bot checks daily, up from 2.1 billion in 2023. Researchers at the University of Zurich showed two years ago that machine learning systems could already solve 100 percent of Google’s reCAPTCHA challenges. The tests keep getting harder. The bots keep getting better faster.

Cloudflare has estimated that a single captcha takes an average of 32 seconds to complete, which means humanity collectively loses roughly 500 years of cumulative human time to these tests every single day. That estimate predates the current wave of AI-driven verification hardening, so treat it as a floor, not a ceiling. Translate that into enterprise terms: every additional verification step a company adds to checkout, login, or onboarding is a direct tax on the limited attention of its highest-intent customers, levied at the exact moment those customers are most ready to transact. No finance function models this cost, because it never appears as a line item. It appears instead as cart abandonment, support tickets, and churn that gets attributed to everything except its actual cause.

There is a name for what is happening, and it did not originate in a technology lab. Evolutionary biologist Leigh Van Valen coined the Red Queen effect in 1973, borrowing from the character in Lewis Carroll’s Through the Looking-Glass who tells Alice, “it takes all the running you can do, to keep in the same place.” Van Valen observed that species locked in an evolutionary arms race, predator and prey, host and parasite, must constantly adapt not to get ahead, but simply to avoid falling behind.

Digital verification is now a textbook Red Queen system. Every time a company hardens its captcha, deploys a new behavioral biometric, or adds a device-fingerprinting layer, it does not create lasting advantage. It buys months, sometimes weeks, before adversarial AI systems adapt. Professor Gene Tsudik of the University of California, Irvine, put it bluntly: “The entire captcha concept is ultimately a losing battle. It may seem like an arms race, but we, humans, already lost it.”

The strategic error most organizations make is treating verification as a technology procurement decision, owned by IT, measured on uptime and fraud-loss reduction. That framing misses the governance dimension entirely. A Red Queen race cannot be won by running faster on the same track. It can only be exited by changing the game, moving from adversarial detection toward verified-identity infrastructure that does not need to be re-won every quarter. Executives who keep funding better traps are financing a race they were told, by the researchers who study these systems, that they cannot win.

The second framework explains why this is now an economic problem, not just a technical one. In 1970, economist George Akerlof published “The Market for Lemons,” showing how asymmetric information, where sellers know more about product quality than buyers, can collapse an entire market. Buyers, unable to distinguish good cars from bad ones, discount their offers to protect against the “lemons.” Sellers of genuinely good cars exit the market rather than accept a discounted price. The market shrinks around its worst participants.

The web’s trust market is running the same collapse. Platforms cannot cheaply distinguish a genuine customer from a sophisticated bot or an AI agent acting on a human’s behalf. Their response is to raise friction for everyone: more verification steps, more login requirements, more identity checks. Reddit’s recent decision to require account logins to view older posts, explicitly framed as tightening automated access, is one small data point in a much larger pattern.

The cost of that friction does not fall evenly. Legitimate, time-pressed customers, often your highest-value ones, abandon the process. Sophisticated bad actors, backed by well-resourced automation, absorb the friction and route around it anyway. Disability advocacy groups have documented for years that captchas disproportionately lock out users with visual impairments, a compliance and reputational exposure that grows as verification steps multiply. The market for genuine human engagement is shrinking around its most defended edges, exactly as Akerlof’s model predicts, while the actors with the least legitimate purpose become the most persistent participants.

This is where psychology and economics meet. Every additional verification step is a small trust tax levied on the customer relationship. Boards that track customer acquisition cost and churn rarely trace the line back to a five-step identity check bolted on by a security team responding to a threat, not designing an experience.

A new market is forming around the answer to the question your captcha keeps asking badly: are you human? The global identity verification market is valued at approximately 15 to 16 billion dollars in 2026, with projections toward 50 billion dollars by 2034, driven by fraud growth, regulatory pressure, and the shift to digital-first commerce.

Tools for Humanity, the venture co-founded by OpenAI’s Sam Altman that built World ID on iris-scan biometrics, has pivoted its “proof of personhood” technology toward enterprise security, with reported collaborations including Zoom, Okta, and DocuSign. The pitch to enterprises is direct: in a world flooded with AI-generated identities and deepfake video, a high-assurance signal that a counterparty is human is becoming infrastructure, not a novelty.

This raises a governance question every board should be asking now, before a vendor answers it by default. Who owns the infrastructure that certifies your customers, your employees, and your counterparties as human? A principal-agent problem sits underneath the entire proof-of-human economy. The verification vendor’s incentive is to maximize checks, data collection, and lock-in. Your incentive is frictionless, trustworthy transactions. Those interests are not naturally aligned, and few procurement processes are currently built to notice the gap.

verification-tax-governance-matrix

Three implications follow directly from the data, and none of them are IT department problems.

First, brand trust is now downstream of verification design. A customer who fails a captcha twice does not blame the bot ecosystem. They blame you. Friction engineered by a security team in response to a threat model is experienced by the customer as a judgment about their legitimacy. That is a brand cost with no line item.

Second, workforce identity risk has moved from theoretical to operational. Deepfake video and voice cloning tools, trained on the same generative systems fueling bot traffic growth, are already being used to impersonate executives in vendor calls and interview processes. The same proof-of-human question your customers face at checkout, your recruitment and finance functions now face internally.

Third, and most consequential, early movers in verified-trust infrastructure are converting a defensive cost center into a competitive asset. Companies that get ahead of the proof-of-human economy, building verification that respects customer time while genuinely raising assurance, are positioned to win the trust of the shrinking pool of engaged, high-value human users identified above. Those still funding the Red Queen race on captchas alone are spending to stand still, while competitors spend to move.

A useful diagnostic question for any executive team: does your organization currently know what percentage of its own traffic, checkout attempts, and inbound leads are automated rather than human? Most do not. Imperva and HUMAN Security built entire product lines answering that question because so few internal teams could answer it themselves. Governance starts with measurement, and on this issue, most boards are flying blind on a metric that already exceeds fifty percent of their total traffic.

The organizations quietly getting this right share a pattern. They have moved ownership of verification strategy out of a pure security function and into a cross-functional group that includes the chief marketing officer, the chief financial officer, and increasingly, the chief trust or risk officer, a role that barely existed five years ago and is now appearing on public company org charts. They treat the proof-of-human question as a customer experience design problem with security constraints, not a security problem with a customer experience footnote. That reordering of priorities, small on paper, is the difference between a verification system that builds loyalty and one that quietly erodes it, transaction by frustrated transaction.

Humans are now a minority on the web. Proving that you are one of them is going to get harder, not easier, as agentic AI traffic compounds at triple-digit growth rates and identity verification hardens in response. The organizations that treat this as a governance and strategy question, not a helpdesk ticket, will define the next decade of digital trust. Those that do not will keep buying better traps for a race researchers have already told them cannot be won.

nStratagem works with executive teams navigating exactly this kind of structural shift, where psychology, economics, and governance collide faster than internal policy can keep up. If your organization is still treating verification as an IT line item rather than a trust strategy, that gap is worth closing before a competitor, or a regulator, closes it for you. Learn more at nstratagem.com.

Found this useful? Share on LinkedIn →

Stay Ahead of the AI Shift

New analyses delivered direct to your inbox. No noise. No newsletters. Just intelligence.

If something in this analysis is relevant to a decision you're facing - don't sit on it.

More From The Norm Report

The analysis published in The Norm Report is intended for senior executive and board-level audiences as strategic intelligence and editorial commentary. It does not constitute legal, financial, investment, compliance, or regulatory advice. Readers should seek independent professional counsel before making decisions based on any content published herein. Norm Murray nor nStratagem accept no liability for actions taken in reliance on this analysis.

© 2026 Norm Murray. All Rights Reserved. No part of this publication may be reproduced, distributed, or transmitted in any form without the prior written permission of the author.