DEV Community

Cover image for Someone Else Pays for Your AI Access
Daniel Nwaneri
Daniel Nwaneri Subscriber

Posted on • Edited on

Someone Else Pays for Your AI Access

Biometric harvesting in low-income nations

you probably didn't think about this when you signed up.

you entered your card details, verified your phone number, maybe uploaded a government ID and took a selfie. friction. annoying. you moved on.

somewhere in cambodia or kenya, someone did the same thing. except they weren't signing up for claude. they were being paid — under $30 — to complete a verification step on behalf of someone they'll never meet, for a service they'll never use, in a supply chain they don't fully understand.

their face is now in a database they didn't choose. it will be used again. not for claude.


every time anthropic tightens access to protect its models, the evasion doesn't stop. it migrates.

geoblocking produced vpn services. phone verification produced sms farms. credit card requirements produced stolen card networks. biometric kyc — live selfies, government id matching — produced agents traveling to lower-income countries to recruit real people willing to complete in-person verification for cash.

the controls and the evasions are a paired system. you can't have one without the other. and the cost of the evasion doesn't stay where the models are. it moves to wherever people are poor enough to trade their biometric data for $30.


the fable shutdown made this visible in a new way.

on june 12, 2026, anthropic disabled fable 5 and mythos 5 for every customer worldwide — not because of an outage, not because of a flaw they found, but because the us government issued an export control directive at 5:21pm Anthropic's official statement and there was no way to segment foreign nationals from us persons in real time. so they turned it off for everyone.

gabriel attal compared it to iran blockading the strait of hormuz AI Frontiers Media. brussels talked. developers in san francisco talked about reliability. nobody talked about cambodia.


the transfer station economy — documented in may 2026 by oxford researcher zilan qian ChinaTalk, May 5 2026 — has been running this supply chain in public for years. github. taobao. telegram. chinese developers accessing claude at 10% of official price through api proxies that sit between them and anthropic's infrastructure.

the three ways the price gets that low:

first, account arbitrage — bulk-registered free credits, unused quotas, carved-up max plans.

second, model swapping — you pay for opus, you get haiku, sometimes you get glm. you can't verify which model answered you.

third, the logs. every prompt, every response, every tool call, every reasoning trace sitting on a proxy operator's server. for a developer using claude code, that's your repository context, your engineering decisions, your verified correct outputs. the markup business is customer acquisition. the logs are the margin.

but the third meal isn't just data extraction. the upstream supply chain that keeps the proxy pool running needs verified accounts. verified accounts need identities. identities increasingly need biometrics. and biometrics, when ai deepfakes get good enough to detect, need real humans.

so agents go to cambodia. agents go to kenya. they find people willing to complete verification for under $30. those faces enter a database. that database doesn't stay in the claude access supply chain.

the chinese developer paying 10% for tokens didn't order this. they're trying to build something with the same tools everyone else has, priced out by geography the same way a developer in lagos is priced out by latency and infrastructure. neither of them sees the person whose face just got harvested in cambodia. neither of them chose the system that makes that harvesting profitable. they're both downstream of a fight they didn't start, between parties who will never absorb the cost themselves.


the worldcoin black market documented this pattern before anyone was paying attention. iris scans harvested in cambodia and kenya, sold for under $30. the same infrastructure. the same geography. the same people absorbing costs they didn't choose.

this isn't new. content moderators in kenya process trauma for platforms they'll never use. data labelers in colombia annotate images for models trained in san francisco. the biometric harvesting is the same supply chain, one layer deeper.

a face verified to bypass anthropic's kyc today can be resold to open a fraudulent bank account tomorrow. it can generate a deepfake. it can be used for blackmail. the original subject in the global south bears the legal and reputational consequences of a transaction that had nothing to do with them.


i build in port harcourt. every api call i make crosses an ocean and costs latency i can't engineer away. i wrote about that recently — the physics problem nobody warned you about.

this is the other side of that piece.

the infrastructure gap isn't just latency. it's who absorbs the externalities of the access war. when two parties fight over who gets to use a model, a third party — somewhere with weaker institutions, fewer legal protections, and more financial pressure to say yes to $30 — pays the cost neither of the original parties wanted to carry.

that's not a side effect.


the controls will keep tightening. fable has been offline for seventeen days. mythos was partially restored on june 27 — only for critical infrastructure organizations the us government specifically approved. general users, developers, international subscribers are still waiting. gpt-5.6 is next in line for the same review process. each new restriction produces a new evasion layer, and each evasion layer reaches further down the economic ladder to find humans willing to be part of the supply chain for cash.

the people performing outrage about ai access — in brussels, in san francisco, in policy papers — are arguing about the front of the supply chain. nobody is arguing about the back.

someone else is paying for your claude access. you won't read about them in the policy papers.


AI helped me research, structure, and edit this piece. The arguments, the examples, and the opinions are mine. So is whatever's wrong with them.

Top comments (66)

Collapse
 
sylwia-lask profile image
Sylwia Laskowska

You’re absolutely right, Daniel. This feels like yet another chapter of the same story.

I'm not even talking about things like wealthy countries exporting their waste to poorer ones. Now we're seeing another level of inequality emerging, this time around access to AI.

I'm really glad you're writing about it, because I don't think enough people are talking about these consequences yet.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

the waste comparison is the right one and it's sharper than people want to admit.

wealthy countries have exported the physical cost of consumption for decades — landfills, e-waste, emissions. what's new here isn't the pattern, it's that the export is now happening to something nobody thought could be exported: identity. a face, a fingerprint, a thing that's supposed to be the one thing that stays yours no matter where you are.

That's what makes this chapter different from the ones before it. you can clean up a landfill eventually. you can't un-harvest a biometric...

Collapse
 
unitbuilds profile image
UnitBuilds

It's down to the same line it's always been, rich exploits poor, so rich gets richer, poor gets poorer and the divide grows. But you cant tell someone on the breadline to decline the $30, they need it, more than you need the food in your fridge. And it's not just identify in terms of biometrics, @dannwaneri hasnt even touched on hardware identity theft. Which comes in 2 forms, shadow proxy networks (malware that proxies traffic through your residential gateway) and physical theft and repurposing (the new one, surprisingly). You buy a windows 11 laptop, it has secure boot. You log in, it signs the hardware to your microsoft account. You're officially liable for anything that laptop does in the wild, because you're the authorized owner of it and it's linked to your name, even if it's formatted, until you go through the mile-long process of logging in to your microsoft account and removing the device from your list of owned devices. A small little detail they dont tell you when they say it's 'for your data security'.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, "a system built on accountability, not morality" . That's the thesis. write that sentence on a wall somewhere. the cow-versus-murder sentencing line makes it impossible to argue the system is broken by accident. it's calibrated. it just isn't calibrated to protect people.

The hardware identity theft angle changes the scope of what we're writing. I was building a piece about biometric liability. you just showed me the same mechanism exists at the device layer — secure boot binding ownership to an account that survives a format, survives resale, survives the original owner having no idea their hardware identity is still theirs in the eyes of Microsoft. that's not a follow-up section. that might be the better second half of the piece.

I don't want to paraphrase this anymore. send me what you're comfortable having attributed to you directly . The pensioner story, the cow sentencing line, the secure boot mechanism and I'll build the piece around your material with you credited as co-author, not cited. this is yours as much as mine at this point.

Thread Thread
 
unitbuilds profile image
UnitBuilds

Feel free to use whatever you like. The internet is a place where once your opinion is voiced, it's public record, so before I write anything, I make sure I'm comfortable taking accountability for every word. So feel free to quote as much as you like, you'll have no objections from me

Collapse
 
laxmansubadi profile image
laxman Subedi

From Bug Reports to GitHub Analysis—Everything in One Place.


GitHub Repo
Error Logs
Screenshots
From Bug Reports to GitHub Analysis—Everything in One Place.
bugdetect.com

Collapse
 
laxmansubadi profile image
laxman Subedi

hii. mam I recently launched an AI tool that solves real developer problems by helping with code analysis, debugging, and productivity. Excited to keep improving it based on user feedback. bug bugdetectai.con

Collapse
 
laxmansubadi profile image
laxman Subedi

From Bug Reports to GitHub Analysis—Everything in One Place.

l
GitHub Repo
Error Logs
Screenshots
From Bug Reports to GitHub Analysis—Everything in One Place.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

this piece closes out a month that started with @pascal_cescato_692b7a8a20's "1%" story and ran through a long thread with @sylwia-lask about access inequality. pascal wrote the 2029 fiction. sylwia kept asking what happens to the people priced out at the frontier. this is the answer neither of those conversations had room for — the supply chain underneath the access war, and who actually pays for it.

Collapse
 
pascal_cescato_692b7a8a20 profile image
Pascal CESCATO

This is the piece that makes 1% look comfortable.
Jensen gets to stand at a window. The person in Cambodia trading their face for $30 doesn't get a window, or a name in the story, or a line in anyone's postmortem. The fiction had the luxury of ending on an unfinished thought. This doesn't get that luxury — the cost already landed, on someone who never agreed to carry it.
"Nobody is arguing about the back" is the sentence that should follow every access control headline from now on.
Glad you went here. This was the conversation underneath the conversation.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

"The fiction had the luxury of ending on an unfinished thought" is the line I'll keep.

That's the actual difference between writing forward from 2026 and writing backward from 2029 . you get to leave a thought open. the person in Cambodia doesn't get that. the cost already landed.

this was always the conversation underneath the conversation. glad we found it.

Thread Thread
 
pascal_cescato_692b7a8a20 profile image
Pascal CESCATO

Writing backward lets you choose where the silence falls. Writing forward, you don't get to choose — the silence is just whoever didn't make it into the policy paper.
Good month.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

good month, Pascal. wouldn't have written this one without it....

Thread Thread
 
pascal_cescato_692b7a8a20 profile image
Pascal CESCATO

Wouldn't have read it the same way without yours either.

Collapse
 
unitbuilds profile image
UnitBuilds

Especially scary when you consider personal liability. That person who got paid $30 doesnt know it, but if their account gets used maliciously, they're held liable for it. The rush on restrictions and legislations to control ethical AI usage has severe caveats, because the best they can do at the moment is tie the task to the account.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, That's the gap the piece didn't name and it's the worse version of the problem. the $30 isn't the cost. the liability sitting on an account they don't control and didn't choose to operate is the cost

and it's open-ended, not capped at $30.
"the best they can do is tie the task to the account" is exactly the architecture problem.

identity verification was supposed to fix attribution. instead it just moved attribution onto whoever's identity got harvested, regardless of who's actually behind the keyboard.

Collapse
 
unitbuilds profile image
UnitBuilds

And worse yet, phishing. They do all that, except you dont even get paid. Because you thought you hit the lotto getting an overseas job, all you have to do is submit your ID and do the facial verification and send the code that's SMS'd to you. And that's the last you ever hear of them.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, the border arrest scenario is the one that should be unimaginable and isn't. someone trying to build a better life walks into a warrant they had no way of knowing existed, for a crime committed using their face on the other side of the planet. that's not a hypothetical edge case. that's the predictable output of a system that ties liability to identity without any mechanism for the identity holder to know they're exposed.

The phishing variant is worse because it removes even the thin justification of "they got paid something." no $30. no awareness they were part of a supply chain at all. just a fake job offer, a verification step that looked routine, and a warrant waiting somewhere they'll never check until they're standing at a border with someone telling them why they're not getting through.

This is the piece underneath the piece. I wrote about who pays. you're naming exactly how the bill arrives.

Thread Thread
 
unitbuilds profile image
UnitBuilds

Not to mention, in many cases, those details are enough for them to file by proxy for a credit card/bank account too, they can reuse the same verifications to spoof other sites too, given that they all use the same system (face the camera, look left, look right). Now it's not just a potential problem when they cross a border, it's an immediate chargeback the second they open a bank account themselves. That was the dominant risk up till AI came out, people think it's just selling an email address to advertisers, meanwhile it's buying claude on credit now, racking up massive bills, that especially for people from third world countries are beyond their capability of paying. Take my country (Namibia) for instance. I know people working jobs for $100 a month... Not a gardener, or a housekeeper, someone working 8-5 for a company, under contract. Imagine that, an entire month's pay gone, on a single ai subscription they never even knew existed, from a bank account they never made. And they dont have the finances to actually fight it in court.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, $100 a month against a Claude subscription bill they never authorized . That's the number the piece needed and didn't have. "third world countries are beyond their capability of paying" isn't rhetoric. it's arithmetic. a contract job at $100 a month doesn't survive a single month of unauthorized charges, let alone the legal cost of proving they didn't make them.

The "they don't have the finances to fight it in court" line is the actual mechanism of harm. it's not that the system produces injustice. it's that the system produces injustice specifically against people who structurally cannot contest it. The verification step that was supposed to protect against fraud becomes the instrument that makes fraud unanswerable.

I think this thread is the next piece. not a follow-up. the actual continuation . what happens after the $30, told through the people it happens to.

Thread Thread
 
unitbuilds profile image
UnitBuilds

And what's worse, is that fraud prevention method was actually a cloak and dagger. Reality is, they dont care who did it, they just care who they send the bill to. The second someone less privileged takes that $30, they signed off on being liable for the rest of their lives. Someday, when they've made a life for themselves, it'll come back to bite them. It's really making a deal with the devil, momentary prosperity for a lifetime of suffering. That fraud prevention method just seals their fate in the eyes of the law, because they authorized it, wittingly or no, they authorized it and that's where the legal system fails, because they can contest in court, but they wont win, by law they cant win, because the very definition of the authentication is that you, as yourself, fully authorize yourself and anyone else by proxy, to use your account to do with, for whatever purposes, assuming full responsibility for it. You dont go to court to fight the bill, you go to court to fight jailtime.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, "they can't win, by law they can't win" is the sentence that should be in the piece verbatim. that's not a gap in the system. that's the system working exactly as designed — authentication legally defined as full assumption of responsibility, applied to someone who never understood what they were authenticating.

"you don't go to court to fight the bill, you go to court to fight jailtime" — that's the line that makes the abstraction collapse.

This was never a fraud prevention story. it's a liability transfer mechanism wearing a fraud prevention costume and the person it transfers liability to is selected specifically because they're the least equipped to refuse it or contest it afterward.

I want to write this with your voice in it directly not paraphrased. would you be open to being named and quoted if I put the follow-up together??

Thread Thread
 
unitbuilds profile image
UnitBuilds

You're more than welcome to. These are just some of the things I've seen people close to me go through, not with AI, but with other forms of scams.

Eg. someone spoofs the bank's number, calls, asks for account confirmation, boom, all their money is gone and bank says 'you authorized it, you should read your messages more carefully' (paraphrasing of course, but that's the gist of it). Or same scheme, but impersonating a relative, to get whatsapp code, which they then clone and they spread it out to their entire contact list, for the exact same reason, to harvest personal information, so they can create these fake identities and load bills and liability onto them. They target old people, who are used to getting a call from the bank and it actually being the bank, they dont know it's a scammer who spoofed the number, all they know is the person spoke clearly, confidently and they complied... Life-savings gone from pensioners, who have no means of earning it back or fighting the bank for it. Some had to choose between food on the table and paying their wifi, losing access to communication with everyone they know, for the sake of not going hungry, because someone scammed them out of 50 years worth of hard work. It's a system built on accountability, not morality and the legal system is there to defend the dollar not the person. Case in point, in Namibia you go to prison for longer for poaching a cow than you do for murder. Make it make sense...

Collapse
 
unitbuilds profile image
UnitBuilds

Exactly. You end up with a system where 1 bad actor could put millions of dollars in liability on some random person from Nigeria, or Cambodia. Lets say someday that person gets lucky and gets a job overseas, travels there, gets locked up at the border, because there's a warrant for their arrest, all their funds seized and they're stuck in a prison for a crime they didnt commit. That's just 1 of the scenarios. The alternative is the company affected launches a lawsuit against them and they're put into a debt they cant repay in a hundred lifetimes. All things that ruin their lives for $30... So someone else can get Claude at a discount/anonymously.

Collapse
 
itskondrat profile image
Mykola Kondratiuk

every new verification layer raises the cost for legitimate users and creates a market for people to bear that cost on their behalf. access control is a filter, not a ceiling - the real ceiling just got outsourced.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Mykola, "the real ceiling just got outsourced" is the cleanest compression of the piece I've seen. a filter raises the cost of passing through it . it doesn't eliminate the throughput, it just decides who pays for it. and when the cost gets outsourced, it doesn't land on whoever was trying to get through. it lands on whoever was available to absorb it. that's the mechanism the piece is trying to name.

Collapse
 
itskondrat profile image
Mykola Kondratiuk

yeah that's the mechanism - once the cost moves to whoever absorbs it, the accountability chain breaks. no ticket for that work, just diffused overhead the system can't see.

Collapse
 
sylwia-lask profile image
Sylwia Laskowska

Hahaha look Daniel, we're in The Context newsletter 😀 It's almost like being in the newspaper 😆
newsletter screenshot

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Sylwia, we made the newspaper. pascal started it, you kept asking the right questions, and apparently that's how you end up on the front page. Congratulations!!!

Collapse
 
leob profile image
leob • Edited

Wild stuff! Man, please let them get rid of all this ridiculous and useless geo-based gatekeeping, it's disgusting and people get around it anyway ...

P.S. echoes of the already famous "1%" article here on dev.to - the more the powers that be (read: US government) try to protect their turf by shutting out foreign competitors, the larger the likelihood that they'll lose the battle long term - it's a losing proposition, motivated by fear ...

Collapse
 
dannwaneri profile image
Daniel Nwaneri

leob, the 1% connection is the right one .That's where this piece started. whether the US wins or loses that battle long term,

The people absorbing the cost right now aren't on either side of it. That's the part that doesn't resolve even if the gatekeeping eventually fails.

Collapse
 
hayrullahkar profile image
Hayrullah Kar

the proxy log breakdown is wild. devs think they're just getting cheap api tokens, but leaking entire repository contexts to operators is a massive pipeline vulnerability. compliance loops always have a brutal downstream cost.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Hayrullah, "compliance loops have a brutal downstream cost" is the right framing. the proxy doesn't just expose your code . it exposes the reasoning behind your code. the tool calls, the iterations, the decisions you rejected before settling on the one you shipped. that's not just a vulnerability. it's a complete picture of how you think, held by someone whose incentives you can't verify.

Collapse
 
hayrullahkar profile image
Hayrullah Kar

exactly. it's a cognitive audit trail. exposing the rejected paths and tool iterations means they don't just steal the codebase, they reverse-engineer your entire engineering playbook. that's the real margin they're harvesting.

Collapse
 
hemapriya_kanagala profile image
Hemapriya Kanagala

This was an interesting read. I hadn't really thought about AI access from this angle before. It's one of those topics that makes you stop and think a bit more about what's happening behind the scenes.

Thanks for sharing.

Collapse
 
aniruddhaadak profile image
ANIRUDDHA ADAK

This article powerfully exposes the hidden human costs behind AI access. Your Namibia example - where someone could lose their entire month's pay on an AI subscription they never authorized - is haunting. The comparison between physical waste export and now AI access inequality is something we need to talk about more. Thank you for this crucial perspective!

Collapse
 
kenielzep97 profile image
Self-Correcting Systems

Everyone argues the front of the supply chain, nobody argues the back” is the whole pattern, and you walked it all the way down. The loud fight is always at the visible layer. The cost moves to the layer nobody’s looking at, where the people absorbing it have the least power to refuse it. The detail that should scare people more is the model-swapping one. Pay for opus, get haiku, sometimes glm, and you can’t verify which model answered. That’s not just theft, it’s an integrity break your logs say one thing ran and something else did, and no receipt survives the proxy. Controls and evasions as a paired system is the right frame. A control that can’t see its own downstream doesn’t stop the harm, it relocates it. Strong piece, man.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Self-Correcting Systems, "an integrity break . your logs say one thing ran and something else did, and no receipt survives the proxy" is the part I didn't push hard enough on. I framed model-swapping as a pricing scam. you're right that it's worse . it's a provenance failure.

anyone building anything that depends on knowing which model produced an output has no way to verify it once a proxy sits in the middle. that's not a developer being shortchanged. that's an entire category of downstream trust breaking silently.

"a control that can't see its own downstream doesn't stop the harm, it relocates it" . That's the sentence I'll be thinking about for the next piece. it applies past biometrics too. every access control anyone designs needs to answer: where does the relocated harm land, and can you see it from where you're standing? most can't. that's the actual failure, not the intent behind the control...

Collapse
 
kenielzep97 profile image
Self-Correcting Systems

That reframe is the right one and it’s cleaner than mine. “Pricing scam” has a victim and an end. “Provenance failure” doesn’t end it just keeps quietly breaking every downstream thing that assumed the log was true. “Where does the relocated harm land, and can you see it from where you’re standing” might be the best one-line test for a control I’ve heard. Most controls get evaluated on whether they stop the thing in front of them. Almost nobody asks whether they can even see where it went. That’s worth its own piece on its own not a footnote in mine.

Some comments may only be visible to logged-in visitors. Sign in to view all comments.