Every security check you passed today answered one of two questions, and neither one is the question that matters anymore. I know that sounds dramatic, but walk through it with me, because once you see the gap you cannot unsee it.
Question one is identity. Who are you? Passwords, Face ID, fingerprints, two-factor codes. All of it exists to prove this account belongs to this person. Question two is uniqueness. Are you one person or fifty? That is what CAPTCHAs were for, and it is what the iris-scanning orb projects are chasing, one human, one account, no duplicates.
But there is a third question, and as far as I can tell nobody is seriously asking it. Is a biological human present at this device, right now, at this moment? Not “does this account belong to a human.” Is one there.
Why the third question suddenly matters
For the entire history of computing, questions one and three were the same question. If someone typed the password, a human was sitting there typing it. Identity implied presence, so we never had to check for presence separately.
AI broke that. Broke it quietly, and completely.
I know because I did it to myself, on purpose. I run AI agents all day. They read email, draft replies, do research, update my systems, and they do it as me, with my credentials, while I am at a listing appointment or asleep. Every one of those actions passes every security check I have. The password is right, the tokens are valid, the account is mine. Identity checks out perfectly, and no human was present for any of it.
Now, my agents are authorized and I watch them like a hawk. But the person receiving an email from my company has no way to know whether I wrote it or my software did. And the same door I walked through on purpose is standing open for every scammer, bot farm, and account thief on the internet. Steal a credential and you do not just impersonate someone once, you can be them at scale, forever, without a single human in the loop.
The checks we have keep failing sideways
CAPTCHAs are the punchline here. The test designed to separate humans from machines is now solved by machines faster and more accurately than by actual humans, which means at this point a CAPTCHA mostly just proves you are patient. And identity checks, as we covered with voice cloning, verify things near the person rather than the person.
The reality is your phone already knows the answer to the third question. It knows the micro-tremor of a real hand holding it, the rhythm of real touches, the messy signals a living body gives off constantly and software does not. The hardware in your pocket collects almost everything you would need. Nobody has wired it up to answer the question.
So there is the problem I would put on the whiteboard. Build the check that proves a human is present at the moment of the action, make it passive so it costs the human nothing, and make it something a bot cannot fake by holding still. Get that right and questions one and two get a whole lot more meaningful too, right.
Next week, a different angle on the same disease: why anyone with ten digits gets a lifetime license to interrupt your life.