Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agents and platform fraud: what does trust control need now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Sharing platforms are being targeted by bots, fake accounts, account-sharing fraud, and AI-assisted abuse, while 53% of platforms still lack personnel with AI and cybersecurity expertise, according to Incognia 2025. Trust controls now need to account for identity abuse, not just traffic filtering, because fraud prevention and governance are becoming the same problem.

NHIMG editorial — what this means for AI and NHI governance

By the numbers:

Questions worth separating out

Q: How should security teams reduce fake account abuse on sharing platforms?

A: Security teams should reduce fake account abuse by tightening identity proofing at sign-up, adding behavioural risk scoring, and challenging suspicious activity before high-value actions.

Q: Why does account sharing create more risk than a normal access violation?

A: Account sharing creates more risk because it breaks accountability.

Q: What do platform teams get wrong about bot detection?

A: Platform teams often treat bot detection as a perimeter problem, when the real issue is whether the platform can bind identity to trust at every step.

Practitioner guidance

  • Instrument the full account lifecycle Track registration, verification, recovery, login, and high-risk actions as one sequence so shared use and fake onboarding can be detected before payout or abuse.
  • Add trust scoring before sensitive actions Use risk signals such as device reputation, velocity, and behavioural anomalies to challenge or slow accounts before listings, transfers, or referrals are completed.
  • Separate enrolled identity from active actor Where account sharing is common, require stronger checks at the moment of action so the platform can tell whether the user performing the task is the user who enrolled.

What's in the full announcement

Arkose Labs' full analysis covers the operational detail this post intentionally leaves for the source:

  • Signal-level examples of how bot behaviour is distinguished from legitimate user traffic in platform environments
  • Operational detail on adaptive challenge design and how it changes attacker economics
  • Cross-industry intelligence on abuse patterns that helps teams tune decisioning models
  • Product-specific examples of how the platform applies detection and mitigation across account abuse scenarios

👉 Read Arkose Labs' analysis of bot, AI agent, and fraud risk in sharing platforms →

AI agents and platform fraud: what does trust control need now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Fraud prevention on sharing platforms is now an identity trust problem, not a traffic problem. Bots and fake accounts succeed when platforms can no longer distinguish valid credentials from valid intent. That means the control boundary has moved upstream into registration, recovery, and behavioural trust, where IAM, fraud, and abuse operations now overlap. Practitioners should treat identity assurance as part of the fraud stack, not a separate governance lane.

A few things that frame the scale:

  • 53% Of platforms lack personnel with AI and cybersecurity expertise, according to AI Agents: The New Attack Surface report.
  • A separate finding shows that 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems and revealing access credentials.

A question worth separating out:

Q: How should platform operators respond when account sharing is common?

A: Platform operators should treat account sharing as a governance and attribution issue, not only as a policy breach. They need controls that identify shared-use patterns, link actions to the active user, and surface when one account is being monetised by multiple people. That creates the evidence needed for enforcement, support, and fraud containment.

👉 Read our full editorial: AI agents and bot fraud are reshaping sharing platform trust



   
ReplyQuote
Share: