TL;DR: Speech-based audio challenges collapse accessibility and automation onto the same surface, making them easy for speech-to-text systems to solve, while sound-based challenges can preserve accessibility and better distinguish legitimate users and AI accessibility agents from abuse, according to Arkose Labs. The real security decision is no longer whether to add audio, but whether challenge design can separate human or assisted identity from machine execution.
NHIMG editorial — based on content published by Arkose Labs: The audio challenge as an accessibility and security control for AI-driven traffic
Questions worth separating out
Q: How should security teams handle accessibility challenges that bots can also solve?
A: Treat any challenge that can be solved by the same machine tools used for automation as a weak control, even if it appears accessible.
Q: Why do speech-based audio challenges create risk in modern bot defence?
A: Because they test whether a user can transcribe speech, not whether the interaction is trustworthy.
Q: What do teams get wrong about accessibility and fraud controls?
A: They often assume accessibility and anti-automation are separate goals, then build controls that fail both.
Practitioner guidance
- Audit audio challenges for transcription bypass Review every audio challenge that depends on spoken words, digits, or phrases and test it against common speech-to-text tooling.
- Adopt sound-based challenge patterns Use non-speech audio where the security objective is to keep accessibility inline without giving automation a text target.
- Define policy for authorised AI accessibility agents Create explicit rules for when delegated AI assistance is allowed, monitored, challenged, throttled, or blocked.
What's in the full article
Arkose Labs' full article covers the operational detail this post intentionally leaves for the source:
- A closer breakdown of why speech-based audio fails against speech-to-text automation in real-world abuse scenarios.
- Implementation details for non-speech, sound-based challenge flows that preserve accessibility without depending on off-site redirects or email registration.
- Specific guidance on how Allow/Monitor/Challenge/Throttle/Block policy choices can recognise authorised AI agents on behalf of identified users.
- Evidence from user testing sessions with visually impaired users that shaped the final control design.
👉 Read Arkose Labs' analysis of accessible audio challenges and AI bot defence →
Audio challenge security and accessibility - are your controls keeping up?
Explore further