Skip to content

Proof of Human: Verified People Become the Scarce Resource Online

Once a bot passes for a person in text, image, and voice, "is this a real human?" can no longer be answered by inspection — only by protocol. That protocol becomes a valuable, contested, and dangerous new layer of the internet.

By Mehdi9 min read
Share
On this page

The scarce resource of the next internet is not attention, compute, or even trust in general. It is proof that there is a real, unique person behind an account. Once a bot can pass for a human in text, image, and voice — which for text it already does — the question "is this a real human?" stops being answerable by looking. It has to be established by protocol. My forecast, labeled plainly as a bet: verified humanity becomes a valuable, contested layer of the internet within a few years, and the design of that layer is one of the more consequential and least-discussed problems ahead. Because every system that can prove you are human is also a system that can watch you and lock you out.

Start with why inspection fails, precisely, because the precision is what makes this a protocol problem rather than a detection problem.

The moment inspection stops working

For most of the internet's life, "is this a person?" was answered by inspection. You read the comment, looked at the photo, heard the voice, and your own perception did the verification. It was cheap and it was usually right, because faking a human across those channels was expensive. A convincing fake profile took real human labor per account, which set a natural price floor on deception. Spam was crude because good fakes didn't scale.

That price floor is gone. A model now writes a comment indistinguishable from a thoughtful person's, generates a face that has never existed, and holds a voice conversation that passes for human on a phone call. The cost of a convincing fake human — per account, per hour — is collapsing toward the cost of inference. When the marginal cost of a plausible person approaches zero, inspection cannot separate the real from the synthetic, because inspection was only ever measuring the cost of the fake.

This is the mechanism behind what people loosely call "dead internet theory" — the idea, overstated as a description of today, that much of the web is already bots talking to bots. As a literal account of the present it's wrong; as a forecast of where the cost curves point, it names something real. If a synthetic participant is free and a real one is not, the synthetic ones dominate by sheer volume unless something external distinguishes them. Perception can't be that something anymore. Which leaves protocol: an out-of-band procedure that establishes personhood by evidence a bot can't cheaply produce.

Note what changed. We are not asking machines to be less capable so we can catch them — that's the CAPTCHA strategy, and it lost. We are asking for a positive credential of humanity, attached to the account, that survived some costly, hard-to-fake process. There are four families of such credentials, and each buys verification with a different currency.

Four ways to prove a human, and what each one costs

Verified identity (the KYC approach). Bind the account to a government-issued identity — passport, national ID, a bank that already did the check. This works. It is the most robust of the four because it inherits the state's investment in making identities hard to forge, and it's already deployed wherever "know your customer" law applies. The cost is paid in two currencies. First, pseudonymity dies: to prove you're human you reveal who you are, and the dissident, the whistleblower, and the person in an abusive situation lose the ability to speak without being named. Second, it centralizes power. Whoever operates the verification becomes a chokepoint that can deplatform, surveil, or be compelled by a government to do either. You've solved "is this a human" by making every human legible to an authority. For some contexts — banking, voting — that's acceptable. For the open internet, it's a different regime than the one we have.

Proof of personhood (uniqueness without identity). The clever ambition here is to prove two things while revealing a third: prove you are human and that you are unique — one person, one credential — without revealing who you are. Projects in this space, most visibly Worldcoin with its iris-scanning orbs, aim exactly at this: a token that says "one distinct person" and nothing more, ideally with zero-knowledge cryptography so the proof reveals no identity downstream. Done cleanly, it would defang most abuse, because uniqueness is what most abuse exploits — bot armies, sockpuppet rings, and vote manipulation are all one entity pretending to be many. Deny that and a huge class of attacks collapses while pseudonymity survives. The problem is that uniqueness is precisely the hard part. To guarantee one-person-one-credential you need something unique to the body, which pushes toward biometrics, which creates a permanent global registry of who exists and a biometric root that can never be revoked if it leaks. The cryptography can hide identity in daily use and still leave that enrollment root as a single, catastrophic point of failure and coercion. Promising, genuinely — and carrying a privacy risk shaped exactly like the problem it solves.

Reputation and web-of-trust. Skip credentials; accumulate a track record that is costly to fake. An account that has posted for years, is vouched for by other trusted accounts, and has staked something it would lose by misbehaving carries evidence no fresh bot can instantly manufacture. This is how trust worked before institutions — you trusted who your trusted contacts trusted — and it degrades gracefully, with no central authority and no biometric. Its weakness is symmetric to its strength: reputation takes time to build, so it can't verify a newcomer, and a patient adversary can farm aged, vouched accounts, which is already a black market. It raises the cost of fakery without setting a hard floor.

Costly-signal gating. Make participation expensive enough that running a million fake humans stops paying. A refundable deposit, a small stake, a fee, a scarce invite. This is the honest core of what proof-of-work and stake-based systems do: not prove humanity directly, but price out humanity's counterfeit at scale. It's simple and needs no identity, but it taxes the poor and the legitimate alongside the attacker, and a well-funded adversary just pays.

Approach Proves Preserves pseudonymity? Main cost
Verified identity (KYC) Who you are No Centralization, surveillance
Proof of personhood One unique human Partially (with ZK) Biometric root, exclusion
Reputation / web-of-trust A costly track record Yes Slow; farmable over time
Costly-signal gating Willingness to pay Yes Taxes the honest and the poor

None dominates. Each trades verification strength against some combination of privacy, inclusion, and centralization. That tradeoff is not an engineering detail to be optimized away later; it is the actual product decision.

Why this is the trust primitive of the agent era

Proof of human is not a content-moderation footnote. It's the foundational primitive underneath the whole coming economy of software agents, which is why it connects directly to the coming agent trust crisis. When agents act on your behalf — booking, negotiating, transacting, posting — every counterparty faces a new question before it engages: is there a human principal behind this agent, and is this the only agent that human authorized, or one of ten thousand? Agent-to-agent commerce cannot assume the other side is honest or even human. It needs a verifiable answer, and proof of personhood on the human root is where that answer bottoms out. An agent is trustworthy in part because a real, accountable, non-duplicated person stands behind it.

There's a deeper, epistemic layer too. Even setting agents aside, the flood of synthetic testimony breaks how we know things from what others tell us — the problem I worked through in testimony at scale. We form most of our beliefs by trusting sources, and that machinery quietly assumed the sources were people, or institutions staffed by people. When a source's humanity is unknown, the reasonable prior on any unverified claim drops, and proof of human becomes an epistemic filter, not just a security one — a way to know whose testimony to weight. That is a large shift in how trust flows across a network, and it's why verified humanity is contested: whoever controls the credential controls whose voice counts.

The dystopian edge is not a side effect

Here is the counterargument, in its most uncomfortable form rather than defused. Every proof-of-human system is also a surveillance system and an exclusion system, and the cure can be worse than the disease.

Surveillance, because a credential that proves you're human is, by construction, a persistent handle on you. Even a privacy-preserving one has an enrollment moment — a scan, a document, a vouching — where a body meets a database, and that root can be leaked, sold, or compelled. Build the infrastructure to verify humanity at internet scale and you have built the infrastructure to track it at internet scale; the same rails carry both, and which one runs is a policy choice made by whoever holds the root, not a property of the math.

Exclusion, because verification always has a population that fails it: no document, no supported device, a biometric that doesn't match, or a principled refusal to be enrolled. Those people don't stop existing — they get shunted to an unverified underclass whose speech is discounted and whose access is throttled. Identity infrastructure has historically fallen hardest on exactly the people with the least power to contest it. A two-tier internet — verified-human and everyone-else — is a plausible and grim output of solving this problem badly. And "badly" is the default, because the parties most eager to build the verification layer, large platforms and states, are precisely those who benefit from centralization and legibility.

That outcome isn't avoidable by wishing the whole project away. The demand for proof of human is real and rising; something will be built to meet it. The question is whether it's built by people who treat the privacy and exclusion costs as first-order, or by people who treat them as someone else's problem.

What to build, and what to watch

For builders, the shift is small to state and large to implement: treat "is this a human?" as a first-class, protocol-level question in your system, not an assumption baked into your UI. Decide explicitly what you need to know — humanity, uniqueness, or identity, which are three different things — and buy only the weakest one that solves your actual problem. If you need to stop bot armies, you need uniqueness, not identity; don't collect a passport to solve a sockpuppet problem. Weigh the privacy cost of every answer, because each bit of verification you demand is a bit of surveillance you're now responsible for, and a set of people you're now excluding. Prefer schemes that reveal less: zero-knowledge uniqueness over identity dumps, refundable stakes over collected documents, multiple independent verification paths over a single mandatory one.

For everyone else, the thing to watch is which family wins in which context — because it won't be one system. Watch whether the open internet gets a pseudonymous proof-of-personhood layer or collapses into KYC-for-everything by default, which is the lazy equilibrium. Watch who ends up holding the enrollment roots. Watch for the two-tier internet appearing not by decree but by a thousand platforms quietly deciding unverified accounts don't count.

The internet was built on the cheap, usually-correct assumption that the thing you were talking to was a person. That assumption is now false, and rebuilding it as an explicit, verifiable, deliberately-designed layer is unavoidable. Whether that layer protects people or catalogs them is still open — which is exactly why it deserves attention now, before the defaults harden into something we didn't choose.

Frequently asked questions

Isn't proof-of-humanity just CAPTCHA, which already exists and mostly works?
No, and the difference is the whole point. CAPTCHA tests a capability gap — it asks you to do something machines were bad at, like reading distorted text. That gap has closed: modern models solve the puzzles better than humans, and a paid solver farm handles the rest for a fraction of a cent. More importantly, CAPTCHA answers the wrong question. It asks 'is a human doing this action right now,' which a human-in-the-loop bot farm passes trivially. The hard question is 'is there a real, unique person behind this account over time,' and no per-action puzzle answers it. That requires binding an account to a persistent, costly-to-forge signal of personhood — a different and much harder protocol.
Does proof-of-personhood require biometrics like iris or face scanning?
It doesn't require them in principle, but the leading uniqueness systems reach for biometrics because uniqueness is the hard part. To prove you are one distinct person and not one person registering ten times, a system needs something unique to your body that can't be duplicated or shared. Biometrics are the obvious candidate, which is exactly where the risk concentrates: a biometric is a password you can never change, and a global uniqueness database is a permanent record of who exists. Cryptographic techniques like zero-knowledge proofs can hide who you are while still proving you are one enrolled person, but they don't remove the enrollment step where a body is scanned. The privacy question is not whether the proof reveals your identity downstream; it's who holds the enrollment root and what happens when it leaks or is compelled.
Won't verified-human systems just exclude people who can't or won't verify?
Yes, and that is the strongest objection, not a side effect. Every proof-of-human system is simultaneously an exclusion system: whoever lacks the document, the device, the biometric match, or the willingness to be enrolled is pushed to the unverified tier, where their speech counts for less and their access is throttled. Historically, identity infrastructure has fallen hardest on the stateless, the poor, and the dissident. A well-designed system minimizes what it demands and offers multiple independent paths to verification, but it cannot make the exclusion vanish — it can only choose who bears it. Builders should treat that distribution of harm as a design decision they own, not an externality.

Filed under Cross-Disciplinary Deep Essays. Where biology, computation, markets, and philosophy collide.

Essays like this, in your inbox.

Thoughtful essays. No spam. Unsubscribe anytime.

Cross-Disciplinary Deep Essays

"AGI by Year X" Is Unanswerable Until You Name the Definition

"Are we close to AGI?" is incoherent because AGI names at least four incompatible criteria that come apart in practice. Separate them and the timeline debate dissolves into concrete, checkable questions.

9 min read