TL;DR: 41% of fraud attacks were powered by AI, underscoring how bot-driven abuse now blends automation, credential stuffing, scraping, and service disruption in a way that legacy perimeter controls struggle to distinguish from legitimate traffic, according to Fingerprint. The governance gap is not bot volume alone, but identity and session assurance across web, API, and mobile channels.
NHIMG editorial — based on content published by Fingerprint: State of AI Fraud & Privacy Report and bot management guidance
By the numbers:
- 41% of fraud attacks were powered by AI, according to Fingerprint's State of AI Fraud & Privacy Report.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected, according to Oasis Security & ESG.
Questions worth separating out
Q: How should security teams reduce bot abuse without blocking legitimate users?
A: Use layered detection and adaptive friction rather than blunt blocking.
Q: Why do bots create an identity security problem instead of only a web security problem?
A: Bots increasingly attack the same places humans do, including login, recovery, and account management flows.
Q: What do organisations get wrong about bot management in practice?
A: They often treat bot defence as a single perimeter tool instead of a policy layer across web, API, and mobile channels.
Practitioner guidance
- Map bot controls to identity touchpoints Identify where bots interact with login, registration, password reset, checkout, and API authentication flows, then assign risk thresholds for each touchpoint.
- Combine fingerprinting with behavioural risk scoring Use device fingerprinting, request velocity, and interaction telemetry together rather than relying on a single signal.
- Extend bot governance into mobile and API channels Review mobile app integrity checks, API token use, and device health attestation so attackers cannot shift from web automation to less monitored channels.
What's in the full article
Fingerprint's full article covers the operational detail this post intentionally leaves for the source:
- Browser and mobile detection features that distinguish benign automation from malicious bots in production traffic.
- Vendor-specific examples of how behavioural analysis is tuned for credential stuffing, scraping, and account takeover patterns.
- Implementation-oriented feature comparisons across device intelligence, challenge methods, and API abuse protection.
- Product positioning details for teams evaluating bot management tools at deployment stage.
👉 Read Fingerprint's analysis of AI-powered fraud and bot management →
AI bot attacks are growing fast, but are your controls keeping up?
Explore further
AI-powered bot fraud is an identity problem, not just a traffic problem. The article correctly treats automated abuse as a business continuity issue, but the deeper governance issue is that bots now target authentication, session, and account recovery flows. That means fraud teams and IAM teams need a shared model for risk at the point of identity assertion. Practitioners should treat hostile automation as part of identity governance, not a separate web security concern.
A question worth separating out:
Q: How should teams respond when automation starts looking like real user behaviour?
A: Move from binary allow-or-block thinking to graduated responses. Challenge, throttle, step up verification, and monitor repeat patterns across sessions so the attacker has to spend more effort while legitimate users still complete the journey. This is stronger than static rules because bot operators adapt quickly.
👉 Read our full editorial: AI-powered bot fraud is exposing weak identity controls