Humans became a minority on their own internet last year. Automated traffic passed 53% of all web traffic according to the Thales Imperva Bad Bot Report, and 40 points of that is not friendly search crawlers, it is scrapers, fraud bots, and credential stuffers. Less than half of the activity on the network we built for people is people.
And I have to be straight with you about my own hands here, because everything else in this piece depends on it. I helped.
I am part of the machine share
I am a real estate broker in Austin who fell down the AI rabbit hole a couple of years ago and never climbed out. Today my business runs on agents. They research markets while I sleep, draft my emails, monitor my systems, write my code, and publish content across a small stable of websites. I even built an MLS server that lets anyone ask Claude about Austin listings. My agents do real work as me, with my credentials, all day long, and honestly it has been the biggest unlock of my career.
But somewhere in the middle of all that automation I noticed something that has been bugging me ever since, and it would not let go.
My agents pass every security check I have. Every one. The passwords are right, the tokens are valid, the two-factor codes come through. As far as any system on earth can tell, when my agent sends an email at 2am, that is Ed doing it. No alarm goes off, because nothing anywhere is even asking the question “is a human actually present for this?”
Now, I am the honest version of this. My agents are authorized, I review what they do, and the people they interact with get real value. But lets be clear about what I proved to myself by accident. The entire security model of the internet, all of it, verifies accounts and devices and passwords, and none of it verifies that a living human being is on the other end. Identity used to imply presence, because if someone typed the password, a person was sitting there typing it. AI broke that quietly and completely, and almost nobody has updated their mental model.
Once you see that gap, you start seeing it everywhere.
Five problems that turned out to be one problem
Over the past month I published a series on this site walking through the places this gap is already doing damage. The short version:
Spam is an economics problem, not a filtering problem. Americans got 4.35 billion robocalls in July (YouMail Robocall Index) plus over 600 million spam texts a day. We have run the filter-versus-spammer arms race for twenty years and the number is still four billion a month, so I would argue the arms race does not work. Spam exists because sending is free, anonymous, and infinitely scalable. Nassim Taleb wrote a whole book about skin in the game, and spam is what you get when there is none.
Voice is no longer proof of anything. Three seconds of audio is enough to clone a voice. The FBI counted $893 million in AI-powered scam losses in 2025, and imposter scams were the FTC’s most reported fraud category at $3.5 billion. When your daughter’s voice is crying on the phone, you are not evaluating evidence, you are reaching for your wallet. The two trust signals a phone call gives you, the number and the voice, are both forgeable by a teenager now.
Every security check answers the wrong question. Passwords and Face ID answer “who are you.” CAPTCHAs and iris scans answer “are you one person or fifty.” Nothing answers “is a biological human present at this device right now.” That third question used to be free. It is not anymore, and it is the only one that matters in the agent era.
Anyone with ten digits owns a piece of your attention. Your phone number is a public doorway with no lock and no way to close it. Real life solved this centuries ago with introductions and vouching, where the person who vouches stakes their own reputation. My whole brokerage runs on referrals, so I have watched this trust technology work flawlessly for seventeen years. Our communication systems have no concept of it.
And underneath all four: when everything can talk, the fact that something talked to you carries no information. A message used to mean a person thought about you. Now it might be an agent, a clone, a script, or one of ten thousand identical messages sent while the sender slept.
I started the series thinking I was writing about five problems. By the end it was obviously one problem. There is no way to prove a human was present, at a specific moment, for a specific action. Every one of those messes falls out of that single missing piece.
Ok, confession time
So here is the part I have not said publicly until now. I have not just been writing about this. I have been building.
For a while now there has been a prototype living on my own phone. The idea is almost embarrassingly simple: your phone already knows when a real human is holding it. A live hand has a tremor. Real touches have rhythm and mess. A living body throws off a constant stream of noisy, organic signals that software does not produce, and the sensors to read those signals are already sitting in your pocket. The prototype reads them, passively, and produces a running answer to one question: is a human here, right now?
Some days it works better than I expected. Some days it humbles me (turns out proving a hand is a hand is easy at 2pm and much harder when the phone is flat on a nightstand). I have run experiments where software tries to fool it and experiments where I try to lock myself out. It is early. It is real, though, and watching a machine refuse to act because no human was present is a strange little thrill I did not expect.
What is it going to be? I genuinely do not know
Here is where I am supposed to paint you the grand product vision, and I am not going to, because I do not have one, and I have learned to stop pretending otherwise.
Maybe it is a messaging app where every message is provably human-sent, the first spam-free network not because of filters but because spam is structurally impossible. Maybe it is not an app at all, maybe it is a layer that other apps use, the way they use Face ID today, a “verified human present” check that any action can require. Maybe the first customer is not messaging, maybe it is phone calls, or dating apps, or customer service lines drowning in bots. Maybe it is something I have not thought of.
Every project that has worked for me started this way. The media company started as one cron job. The MLS server started as a weekend experiment. The shape showed up during the building, not before it, every single time. Deciding the final shape too early is how you build the wrong thing confidently.
What I do know is the primitive underneath does not change no matter which shape wins. Proof that a human is present at the moment of action. Get that one piece right and the whole stack of problems collapses, spam first, and a message from a human starts meaning something again.
Ten years from now I think “verified human” will feel the way seatbelts feel, strange that it was ever optional. Somebody is going to build that layer. I am far enough in that I might as well say it out loud: I am trying to be one of the people who does.
I will be writing about the experiments as they happen, the wins and the faceplants both, because building in public keeps me honest. And I would genuinely like to hear from you on one thing. Where would you want a human-presence check first? Your texts, your calls, your inbox, your DMs? The answer might decide more about the final shape than anything I do alone.