Agent Classification Is Now a Security Requirement

By Kevin Gosschalk, Founder and CEO, Arkose Labs [ Join Cybersecurity Insiders ]

The most dangerous traffic on your network now looks exactly like your best customers. Over the past few years, the threat landscape has shifted from conventional bot attacks to agentic AI operating at machine scale. The agents helping your users today and the ones attacking your platform use the same technology. Attackers assemble fraud operations from off-the-shelf tools and run them through the same automated browsers and device environments your legitimate users touch every day.

While consumers want agents to book flights, compare offers, and handle routine tasks, attackers leverage agents to create fake accounts, run credential stuffing, and automate fraud. On your network, most agentic AI traffic looks the same: headless browsers, cloud infrastructure, proxy networks, and AI frameworks powering both personal assistants and adversarial bots.

This is the shift from the bot era. If traffic looked automated, treating it as hostile was usually the right call. Today, automation is no longer a reliable proxy for malicious intent. Detection can still spot bots, it can’t tell you whether an AI agent is authorized or malicious.

The Three Populations of Agentic Traffic

Each population behaves differently and needs different handling:

  1. Self-disclosing good agents. Verified crawlers, partner integrations, and cooperating platforms that identify themselves through IP ranges, signed headers, API keys, or emerging disclosure standards.
  2. Non-disclosing good agents. AI assistants, agentic browsers, and local agents acting on behalf of real users. Most have no reliable way to identify themselves, and no incentive to self-identify.
  3. Malicious adversaries. Account takeover campaigns, fake account factories, scraping fleets, payment fraud operations, and coordinated swarms running at machine scale.

When platforms default to blocking all automation, legitimate agent builders learn the same lesson attackers learned years ago: blend in or get shut out. Blocking all bots now means blocking customers’ agents as well, and it teaches adversaries to hide inside the same traffic.

Traditional Friction Doesn’t Work Any More

For most of the bot management era, defense strategy rested on a simple assumption about human psychology: make it hard enough and the attacker gives up. But agents don’t get frustrated or tired.

CAPTCHA, OTP, KYC, and liveness checks all assumed bots would fail or humans would give up. Modern AI models solve more of those challenges, and agent pipelines cut human labor out of the loop. A one-second delay repeated one million times is significant if someone is paying for those seconds, but it’s irrelevant to an agent running unattended on cheap cloud infrastructure.

Some friction still holds, such as time, physical presence, and earned reputation. Safeguards such as multi-day withdrawal holds, in-branch identity checks, and reputation ladders can’t be compressed. However, you can’t put a multi-day hold on checkout or send every password reset to a call center. 

Economics Is Where Defense Still Works

For years, the biggest cost in fraud operations was labor: human workers solving CAPTCHAs, running device farms, moving through flows manually, and handling edge cases.

Agents collapse that cost line. Not to zero, but enough that attack campaigns can scale further for the same budget, with one person and an agent fleet doing work that used to require a team. If every automated session incurs a cost, you charge legitimate agents and their users alongside attackers. If only sessions classified as high-risk incur a cost, you concentrate pressure where it belongs.

Proof-of-work, AI-resistant challenges, multi-step verification, forced human involvement, and rate shaping all work best when they’re applied selectively. You won’t win by making the whole internet harder to use. You’ll win by making abuse too expensive to scale.

From Detection to Classification

Detection still matters, but it’s an input, not an answer. Classification draws on four kinds of signals:

  • Known good signatures. Published IP ranges, signed headers, API keys, verified user agents, disclosure protocols.
  • Behavioral cohorts. For unidentified traffic, patterns matter: timing, navigation, mouse behavior, challenge responses, device inconsistencies, IP context, and similarity across sessions.
  • Business logic. Check whether the session behavior lines up with activity your business expects to see.
  • Challenge response. When classification is uncertain, the challenge is a probe. Legitimate agents solve correctly or back off. Malicious agents retry, rotate identities, test bypasses, or fail in patterns that look like solver services.

Turning Classification into Policy

Most organizations already have a policy for humans (serve them) and a policy for obvious bots (stop them). To make classification actionable, those policies need clear enforcement modes. Enforcement usually takes five forms:

  • Allow
  • Monitor
  • Challenge
  • Throttle
  • Block

Policy must be set by endpoint. Login, new account creation, payment flows, and device identification should not all use the same agent policies. Where you sit on the policy spectrum should be a deliberate decision, informed by classification data and reviewed as agent traffic changes.

Intent Matters More Than Identity

Classification isn’t just about who the agent is; it’s about what it’s doing and how that behavior changes over time. Identity alone solves the easiest case. A signed request tells you who the agent claims to be, not whether or how that agent is authorized to act on your platform. That’s the core problem with non-human identities in security: knowing what an agent is tells you nothing about whether it’s doing what it should..

Disclosure standards help manage self-disclosing agents. Agents that won’t identify and those that can’t are the ones that turn agentic AI security solutions into a classification and enforcement problem.

Putting Agent Policy in Place

Here are a few moves security leaders should consider making now.

  • Build a classification stack that combines device signals, behavioral signals, business logic, and challenge response.
  • Use graduated enforcement: Allow, Monitor, Challenge, Throttle, Block.
  • Support disclosure standards, but don’t base strategy on disclosure alone.
  • Track trust over time and revoke it when behavior drifts.

A growing share of fraud and abuse work will sit here: governing agent traffic by classification instead of treating all automation the same. The agents attacking your platform will keep looking like your best customers, and that gap won’t close on its own. It will only widen as agentic AI gets cheaper and more capable.

Security teams that build classification into their agent strategy now will be making informed decisions about who gets access to what. The rest will find out the hard way.

 

 

Join our LinkedIn group Information Security Community!

No posts to display