TL;DR: 71% of organisations are concerned about generative AI threats to business apps, while 62% report decreased customer acquisition due to cyberattacks, underscoring how fraud, bots, and AI-driven abuse are now hitting revenue and trust at the same time, according to Arkose Labs. The governance problem is no longer detection alone, but whether platform identity and abuse controls can keep pace with adversarial automation.
NHIMG editorial — what this means for AI and NHI governance
By the numbers:
- 71% are concerned about generative AI threats to business apps.
- 62% report decreased customer acquisition due to cyberattacks.
- 53% say it's too difficult to integrate AI-powered solutions.
Questions worth separating out
Q: How should platform teams reduce bot abuse without blocking legitimate users?
A: Use adaptive challenges and multi-signal risk scoring so friction increases only when behaviour looks adversarial.
Q: Why do bots and account takeover often need the same control stack?
A: Because they usually share the same abuse infrastructure, telemetry gaps, and decision points.
Q: What signals should security teams measure to spot platform abuse early?
A: Look for velocity anomalies, device inconsistency, repeated failed interactions, unusual geographic patterns, and mismatches between behavioural and technical fingerprints.
Practitioner guidance
- Instrument abuse decisions across the full customer journey Correlate registration, login, reset, and transaction telemetry so bot activity is measured as a chain of behaviours, not four unrelated alerts.
- Use adaptive friction for high-risk sessions Apply step-up verification only when combined signals indicate suspicious activity, and keep low-risk paths as seamless as possible for legitimate users.
- Review your signal model for evasion resistance Test whether a small change in device, network, or behaviour can bypass the current decisioning model, then strengthen the weakest inputs first.
What's in the full announcement
Arkose Labs' full page covers the operational detail this post intentionally leaves for the source:
- Product-specific breakdown of how Arkose Titan combines detection and mitigation across abuse scenarios
- Customer story examples that show how the platform was applied to account takeover, fake accounts, and SMS fraud
- The vendor's own explanation of its 225-plus signal decisioning model and adaptive challenge flow
- Commercial details, customer proof points, and platform packaging that implementation teams would need before evaluating a deployment
👉 Read Arkose Labs' analysis of bot abuse, AI threats, and platform trust →
AI agents and bot abuse: what should platform teams change now?
Explore further
Platform abuse is now an identity problem, not just a fraud problem. The article shows that fake accounts, account takeover, and AI-assisted abuse all converge on the same trust surface: whether a platform can reliably distinguish legitimate from adversarial automation. That puts consumer IAM, bot management, and fraud operations into the same decision chain. The implication is that identity programmes for digital platforms need to treat abuse resistance as part of access governance, not as an adjacent web-security function.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Only 44% of organisations have implemented policies to govern AI agents, even though 92% say governance is critical to enterprise security.
A question worth separating out:
Q: Who should own bot management when it affects customer trust and revenue?
A: Ownership should sit with a cross-functional team that can act across IAM, fraud, and platform security, because bot abuse affects all three. If one team owns only the tooling, the organisation can still fail on response, tuning, or business impact. Shared accountability is what turns detection into a measurable control.
👉 Read our full editorial: AI agents and bot abuse are stretching platform trust controls