DEV Community

Cover image for Someone Else Pays for Your AI Access

Someone Else Pays for Your AI Access

Daniel Nwaneri on June 30, 2026

you probably didn't think about this when you signed up. you entered your card details, verified your phone number, maybe uploaded a government ID...
Collapse
 
sylwia-lask profile image
Sylwia Laskowska

You’re absolutely right, Daniel. This feels like yet another chapter of the same story.

I'm not even talking about things like wealthy countries exporting their waste to poorer ones. Now we're seeing another level of inequality emerging, this time around access to AI.

I'm really glad you're writing about it, because I don't think enough people are talking about these consequences yet.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

the waste comparison is the right one and it's sharper than people want to admit.

wealthy countries have exported the physical cost of consumption for decades — landfills, e-waste, emissions. what's new here isn't the pattern, it's that the export is now happening to something nobody thought could be exported: identity. a face, a fingerprint, a thing that's supposed to be the one thing that stays yours no matter where you are.

That's what makes this chapter different from the ones before it. you can clean up a landfill eventually. you can't un-harvest a biometric...

Collapse
 
unitbuilds profile image
UnitBuilds

It's down to the same line it's always been, rich exploits poor, so rich gets richer, poor gets poorer and the divide grows. But you cant tell someone on the breadline to decline the $30, they need it, more than you need the food in your fridge. And it's not just identify in terms of biometrics, @dannwaneri hasnt even touched on hardware identity theft. Which comes in 2 forms, shadow proxy networks (malware that proxies traffic through your residential gateway) and physical theft and repurposing (the new one, surprisingly). You buy a windows 11 laptop, it has secure boot. You log in, it signs the hardware to your microsoft account. You're officially liable for anything that laptop does in the wild, because you're the authorized owner of it and it's linked to your name, even if it's formatted, until you go through the mile-long process of logging in to your microsoft account and removing the device from your list of owned devices. A small little detail they dont tell you when they say it's 'for your data security'.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, "a system built on accountability, not morality" . That's the thesis. write that sentence on a wall somewhere. the cow-versus-murder sentencing line makes it impossible to argue the system is broken by accident. it's calibrated. it just isn't calibrated to protect people.

The hardware identity theft angle changes the scope of what we're writing. I was building a piece about biometric liability. you just showed me the same mechanism exists at the device layer — secure boot binding ownership to an account that survives a format, survives resale, survives the original owner having no idea their hardware identity is still theirs in the eyes of Microsoft. that's not a follow-up section. that might be the better second half of the piece.

I don't want to paraphrase this anymore. send me what you're comfortable having attributed to you directly . The pensioner story, the cow sentencing line, the secure boot mechanism and I'll build the piece around your material with you credited as co-author, not cited. this is yours as much as mine at this point.

Thread Thread
 
unitbuilds profile image
UnitBuilds

Feel free to use whatever you like. The internet is a place where once your opinion is voiced, it's public record, so before I write anything, I make sure I'm comfortable taking accountability for every word. So feel free to quote as much as you like, you'll have no objections from me

Collapse
 
laxmansubadi profile image
laxman Subedi

From Bug Reports to GitHub Analysis—Everything in One Place.


GitHub Repo
Error Logs
Screenshots
From Bug Reports to GitHub Analysis—Everything in One Place.
bugdetect.com

Collapse
 
dannwaneri profile image
Daniel Nwaneri

this piece closes out a month that started with @pascal_cescato_692b7a8a20's "1%" story and ran through a long thread with @sylwia-lask about access inequality. pascal wrote the 2029 fiction. sylwia kept asking what happens to the people priced out at the frontier. this is the answer neither of those conversations had room for — the supply chain underneath the access war, and who actually pays for it.

Collapse
 
pascal_cescato_692b7a8a20 profile image
Pascal CESCATO

This is the piece that makes 1% look comfortable.
Jensen gets to stand at a window. The person in Cambodia trading their face for $30 doesn't get a window, or a name in the story, or a line in anyone's postmortem. The fiction had the luxury of ending on an unfinished thought. This doesn't get that luxury — the cost already landed, on someone who never agreed to carry it.
"Nobody is arguing about the back" is the sentence that should follow every access control headline from now on.
Glad you went here. This was the conversation underneath the conversation.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

"The fiction had the luxury of ending on an unfinished thought" is the line I'll keep.

That's the actual difference between writing forward from 2026 and writing backward from 2029 . you get to leave a thought open. the person in Cambodia doesn't get that. the cost already landed.

this was always the conversation underneath the conversation. glad we found it.

Thread Thread
 
pascal_cescato_692b7a8a20 profile image
Pascal CESCATO

Writing backward lets you choose where the silence falls. Writing forward, you don't get to choose — the silence is just whoever didn't make it into the policy paper.
Good month.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

good month, Pascal. wouldn't have written this one without it....

Thread Thread
 
pascal_cescato_692b7a8a20 profile image
Pascal CESCATO

Wouldn't have read it the same way without yours either.

Collapse
 
unitbuilds profile image
UnitBuilds

Especially scary when you consider personal liability. That person who got paid $30 doesnt know it, but if their account gets used maliciously, they're held liable for it. The rush on restrictions and legislations to control ethical AI usage has severe caveats, because the best they can do at the moment is tie the task to the account.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, That's the gap the piece didn't name and it's the worse version of the problem. the $30 isn't the cost. the liability sitting on an account they don't control and didn't choose to operate is the cost

and it's open-ended, not capped at $30.
"the best they can do is tie the task to the account" is exactly the architecture problem.

identity verification was supposed to fix attribution. instead it just moved attribution onto whoever's identity got harvested, regardless of who's actually behind the keyboard.

Collapse
 
unitbuilds profile image
UnitBuilds

And worse yet, phishing. They do all that, except you dont even get paid. Because you thought you hit the lotto getting an overseas job, all you have to do is submit your ID and do the facial verification and send the code that's SMS'd to you. And that's the last you ever hear of them.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, the border arrest scenario is the one that should be unimaginable and isn't. someone trying to build a better life walks into a warrant they had no way of knowing existed, for a crime committed using their face on the other side of the planet. that's not a hypothetical edge case. that's the predictable output of a system that ties liability to identity without any mechanism for the identity holder to know they're exposed.

The phishing variant is worse because it removes even the thin justification of "they got paid something." no $30. no awareness they were part of a supply chain at all. just a fake job offer, a verification step that looked routine, and a warrant waiting somewhere they'll never check until they're standing at a border with someone telling them why they're not getting through.

This is the piece underneath the piece. I wrote about who pays. you're naming exactly how the bill arrives.

Thread Thread
 
unitbuilds profile image
UnitBuilds

Not to mention, in many cases, those details are enough for them to file by proxy for a credit card/bank account too, they can reuse the same verifications to spoof other sites too, given that they all use the same system (face the camera, look left, look right). Now it's not just a potential problem when they cross a border, it's an immediate chargeback the second they open a bank account themselves. That was the dominant risk up till AI came out, people think it's just selling an email address to advertisers, meanwhile it's buying claude on credit now, racking up massive bills, that especially for people from third world countries are beyond their capability of paying. Take my country (Namibia) for instance. I know people working jobs for $100 a month... Not a gardener, or a housekeeper, someone working 8-5 for a company, under contract. Imagine that, an entire month's pay gone, on a single ai subscription they never even knew existed, from a bank account they never made. And they dont have the finances to actually fight it in court.

Thread Thread
 
dannwaneri profile image
Daniel Nwaneri

UnitBuilds, $100 a month against a Claude subscription bill they never authorized . That's the number the piece needed and didn't have. "third world countries are beyond their capability of paying" isn't rhetoric. it's arithmetic. a contract job at $100 a month doesn't survive a single month of unauthorized charges, let alone the legal cost of proving they didn't make them.

The "they don't have the finances to fight it in court" line is the actual mechanism of harm. it's not that the system produces injustice. it's that the system produces injustice specifically against people who structurally cannot contest it. The verification step that was supposed to protect against fraud becomes the instrument that makes fraud unanswerable.

I think this thread is the next piece. not a follow-up. the actual continuation . what happens after the $30, told through the people it happens to.

Collapse
 
itskondrat profile image
Mykola Kondratiuk

every new verification layer raises the cost for legitimate users and creates a market for people to bear that cost on their behalf. access control is a filter, not a ceiling - the real ceiling just got outsourced.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Mykola, "the real ceiling just got outsourced" is the cleanest compression of the piece I've seen. a filter raises the cost of passing through it . it doesn't eliminate the throughput, it just decides who pays for it. and when the cost gets outsourced, it doesn't land on whoever was trying to get through. it lands on whoever was available to absorb it. that's the mechanism the piece is trying to name.

Collapse
 
itskondrat profile image
Mykola Kondratiuk

yeah that's the mechanism - once the cost moves to whoever absorbs it, the accountability chain breaks. no ticket for that work, just diffused overhead the system can't see.

Collapse
 
sylwia-lask profile image
Sylwia Laskowska

Hahaha look Daniel, we're in The Context newsletter 😀 It's almost like being in the newspaper 😆
newsletter screenshot

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Sylwia, we made the newspaper. pascal started it, you kept asking the right questions, and apparently that's how you end up on the front page. Congratulations!!!

Collapse
 
leob profile image
leob • Edited

Wild stuff! Man, please let them get rid of all this ridiculous and useless geo-based gatekeeping, it's disgusting and people get around it anyway ...

P.S. echoes of the already famous "1%" article here on dev.to - the more the powers that be (read: US government) try to protect their turf by shutting out foreign competitors, the larger the likelihood that they'll lose the battle long term - it's a losing proposition, motivated by fear ...

Collapse
 
dannwaneri profile image
Daniel Nwaneri

leob, the 1% connection is the right one .That's where this piece started. whether the US wins or loses that battle long term,

The people absorbing the cost right now aren't on either side of it. That's the part that doesn't resolve even if the gatekeeping eventually fails.

Collapse
 
hayrullahkar profile image
Hayrullah Kar

the proxy log breakdown is wild. devs think they're just getting cheap api tokens, but leaking entire repository contexts to operators is a massive pipeline vulnerability. compliance loops always have a brutal downstream cost.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Hayrullah, "compliance loops have a brutal downstream cost" is the right framing. the proxy doesn't just expose your code . it exposes the reasoning behind your code. the tool calls, the iterations, the decisions you rejected before settling on the one you shipped. that's not just a vulnerability. it's a complete picture of how you think, held by someone whose incentives you can't verify.

Collapse
 
hayrullahkar profile image
Hayrullah Kar

exactly. it's a cognitive audit trail. exposing the rejected paths and tool iterations means they don't just steal the codebase, they reverse-engineer your entire engineering playbook. that's the real margin they're harvesting.

Collapse
 
hemapriya_kanagala profile image
Hemapriya Kanagala

This was an interesting read. I hadn't really thought about AI access from this angle before. It's one of those topics that makes you stop and think a bit more about what's happening behind the scenes.

Thanks for sharing.

Collapse
 
aniruddhaadak profile image
ANIRUDDHA ADAK

This article powerfully exposes the hidden human costs behind AI access. Your Namibia example - where someone could lose their entire month's pay on an AI subscription they never authorized - is haunting. The comparison between physical waste export and now AI access inequality is something we need to talk about more. Thank you for this crucial perspective!

Collapse
 
kenielzep97 profile image
Self-Correcting Systems

Everyone argues the front of the supply chain, nobody argues the back” is the whole pattern, and you walked it all the way down. The loud fight is always at the visible layer. The cost moves to the layer nobody’s looking at, where the people absorbing it have the least power to refuse it. The detail that should scare people more is the model-swapping one. Pay for opus, get haiku, sometimes glm, and you can’t verify which model answered. That’s not just theft, it’s an integrity break your logs say one thing ran and something else did, and no receipt survives the proxy. Controls and evasions as a paired system is the right frame. A control that can’t see its own downstream doesn’t stop the harm, it relocates it. Strong piece, man.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Self-Correcting Systems, "an integrity break . your logs say one thing ran and something else did, and no receipt survives the proxy" is the part I didn't push hard enough on. I framed model-swapping as a pricing scam. you're right that it's worse . it's a provenance failure.

anyone building anything that depends on knowing which model produced an output has no way to verify it once a proxy sits in the middle. that's not a developer being shortchanged. that's an entire category of downstream trust breaking silently.

"a control that can't see its own downstream doesn't stop the harm, it relocates it" . That's the sentence I'll be thinking about for the next piece. it applies past biometrics too. every access control anyone designs needs to answer: where does the relocated harm land, and can you see it from where you're standing? most can't. that's the actual failure, not the intent behind the control...

Collapse
 
kenielzep97 profile image
Self-Correcting Systems

That reframe is the right one and it’s cleaner than mine. “Pricing scam” has a victim and an end. “Provenance failure” doesn’t end it just keeps quietly breaking every downstream thing that assumed the log was true. “Where does the relocated harm land, and can you see it from where you’re standing” might be the best one-line test for a control I’ve heard. Most controls get evaluated on whether they stop the thing in front of them. Almost nobody asks whether they can even see where it went. That’s worth its own piece on its own not a footnote in mine.

Collapse
 
voltagegpu profile image
VoltageGPU

As someone working with GPU infrastructure, it's no surprise that the cost of AI access is often hidden behind free tiers—those GPUs aren't free to run. I've seen teams hit unexpected charges when training models on cloud platforms, especially with spot instances or when auto-scaling triggers unexpectedly. Always check what's included and what's billed separately.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

VoltageGPU, the hidden cost angle is real . The proxy economy exists partly because the visible cost of frontier AI is already high enough that a 90% discount justifies the risk for most developers.

Collapse
 
alexshev profile image
Alex Shev

This is the budget-control problem in a different costume. If access can be delegated, spend and abuse controls have to follow the actor, not just the account. Otherwise one shared key becomes both a security and finance incident.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Alex, "follow the actor not just the account" is exactly where the architecture breaks down. the proxy is the account. the actor is invisible behind it.

Every control designed around account-level attribution fails the moment delegation is possible and delegation is always possible when the economic incentive is large enough. the fix isn't better account controls. it's attribution that survives delegation.

Collapse
 
manolito99 profile image
Lolo

The 'cost per successful task' framing is the one most people miss. A cheaper model that needs two retries or human correction isn't cheaper at all, it's just cheaper on the pricing page. For side project devs the extra cognitive load of tracking that across providers is often the bigger cost anyway.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Lolo, "cheaper on the pricing page" is the line. the proxy economy runs on that gap. The 10% price looks like a deal until you count the retries, the model swapping you can't detect, the cognitive overhead of not knowing which model answered. the total cost of ownership calculation never appears on the pricing page of anything.

the cognitive load point is the one that doesn't get written about. tracking quality variance across providers, across sessions, across a proxy you can't audit — that's work. for a side project dev it might cost more in attention than the token savings are worth. and attention is the one resource that doesn't show up in any infrastructure bill.

Collapse
 
motedb profile image
mote

Your point about the transfer station economy hits differently when you realize the verification layer is the problem, not the API itself. Once there's a centralized gate, someone will find a way through it — and the cost of that workaround lands on whoever is cheapest to extract from.

The interesting thing about the on-device / local AI angle — which you mentioned briefly at the end — is that it removes the middleman entirely. No API call means no account. No account means no verification. The harvesting supply chain you're describing has a precondition: there's something worth harvesting. Local inference means there's nothing to harvest.

The hard part, of course, is getting capable models on-device. Gemma 4 is a start but it's not there yet for serious agentic tasks. The other hard part is persistent state — if the agent lives on the device, it needs a place to store context across sessions without that storage becoming another attack surface. Encrypted local storage, trusted execution environments, on-device fine-tuning: none of these are solved at the stack level yet.

But the direction is right. The infrastructure you need to escape the verification lottery is the same infrastructure you'd build for a robot or a drone — no server, no cloud, no middleman. What's your sense from Port Harcourt: is the local AI path something developers there are actively pursuing, or is the API path still too compelling because the model quality gap is still too wide?

Collapse
 
dannwaneri profile image
Daniel Nwaneri

mote, "the harvesting supply chain has a precondition" is the frame that connects directly to what we're building for the Africa DeepTech Challenge . a coding assistant that runs entirely offline, no API key, no account, no verification surface. the precondition doesn't exist if there's nothing to harvest.

from Port Harcourt: the API path is still compelling because the model quality gap is real and felt. a developer here building something serious reaches for Claude or GPT because the alternatives still underperform on complex reasoning tasks. but the Fable shutdown changed the calculation when access disappears overnight because of a government directive on the other side of the planet, the "good enough local model" starts looking different. reliability has a quality floor that outweighs raw benchmark performance when the benchmark model isn't available.

The persistent state problem you named is the one nobody has solved cleanly. encrypted local storage is table stakes. trusted execution environments are not. on-device fine-tuning at 8GB RAM without destroying inference performance . That's the hard constraint the challenge is built around.

The direction is right. the infrastructure gap is the same one that makes diesel generators a feature, not a bug.

Collapse
 
larryxue profile image
larry

This is a really good way to frame it. Access restrictions don’t kill demand; they just push people into messier workarounds.

I get why developers look for cheaper or unblocked access, but the proxy market has real hidden costs: leaked prompts, fake models, stolen quotas, and now even identity harvesting.

Feels like pricing, regional access, and safety controls need to be discussed together, not as separate problems.

Collapse
 
allenrichard12 profile image
Allen Richard

There’s a real conversation to be had here about how security systems sometimes shift risk onto the most vulnerable people instead of actually solving the problem.

At the same time, not every verification system is designed with that outcome in mind — a lot of it is just trying to reduce fraud, even if the side effects aren’t well thought through.

The bigger issue is how to build safeguards so security doesn’t end up depending on people who are least protected.

Collapse
 
motedb profile image
mote

The transfer station economy framing is the right lens for this. The proxy operators aren't just reselling API access — they're arbitrageurs of trust, identity, and geographic inequality simultaneously. And the asymmetry you identified is sharp: the developer in Lagos paying premium latency can't opt out of the infrastructure they didn't build, and neither can the person in Cambodia whose face got harvested to make that infrastructure possible.

What makes this harder to fix than the VPN precedent is that biometrics don't rotate. A compromised credit card gets cancelled and replaced. A compromised API key gets revoked. A harvested face — especially one matched against government IDs — stays compromised indefinitely, often with no recourse available in the legal systems where the harvesting occurred.

The export control dynamic is the part I keep thinking about. The policy debate assumes that restricting access protects something. But the transfer station supply chain means the restriction itself creates the new attack surface. It's not that controls fail — it's that the failure mode of a control is often someone else's biometric data being collected without meaningful consent. The control and the harm are causally linked, not sequential.

One thing I'd push back on slightly: the framing of "someone else is paying" could extend further upstream. The developers using Chinese proxy services aren't innocent end points either — the log extraction you describe (repository context, engineering decisions, reasoning traces) is often the actual product being sold, not the API margin. The developer thinks they're buying cheap tokens; they're actually underwriting a surveillance infrastructure on top of a biometric harvesting pipeline. That's a harder problem to solve than "access inequality" because the people being harmed are also, in a sense, complicit in ways they're not fully aware of.

Have you looked at any technical proposals for verifiable model access that doesn't require centralized identity verification? There are some interesting approaches using zero-knowledge proofs for age verification rather than identity verification — proving you're above a threshold without revealing who you are. Whether that actually helps depends on whether the restriction itself is the right mechanism, which I think is the deeper question your piece is ultimately asking.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

mote, "biometrics don't rotate" is the line that makes the harm irreversible in a way nothing else in the piece stated precisely. a compromised card gets cancelled. a harvested face stays compromised indefinitely, with no recourse available in the legal systems where the harvesting occurred. that asymmetry is load-bearing and I didn't name it clearly enough.

The complicity point is fair and harder than "access inequality" — the developer buying cheap tokens is underwriting a surveillance infrastructure they're not seeing. that's not innocence, it's incomplete information at the point of purchase. the follow-up piece needs to hold both: the person in Cambodia didn't choose the supply chain, and the developer in Beijing didn't fully understand what they were buying. neither exonerates the system that produced the information asymmetry.

on ZK proofs — "proving you're above a threshold without revealing who you are" is the right direction but it only helps if the restriction is age or humanity, not geography. the geographic restriction is what produces the transfer station economy. ZK can prove you're human without revealing your face. it can't prove you're in an approved country without revealing where you are. so it solves the biometric harvesting problem without solving the access inequality problem. those need different fixes.

Collapse
 
wrencalloway profile image
Wren Calloway

@dannwaneri Glad the amortization framing landed, because it also reframes what "tightening verification" even buys you. If the face is priced as a fraction of its total value across buyers, then a stricter Claude check doesn't shrink supply — it just shifts which fraction of the face's lifetime Anthropic is paying for. You might raise the per-check friction and still not move the acquisition economics at all, because the acquisition already happened for other reasons. That's the uncomfortable version: the control you can actually build sits downstream of the market you'd need to break.

On the sourcing — good, and the fact that Qian and Worldcoin are solid is exactly why the two soft spots hurt more, not less. A reader doesn't audit your citations evenly; they find the one thing they can't confirm and let it color everything. Anchoring the Attal quote to where and when it was said does more work than any amount of prose defending it.

One thing I'd add, since you're revising: if Fable/Mythos is confident-but-hard-to-cite, say that in the text rather than around it. "Reported but not independently confirmed" reads as rigor. Stated flatly and then unverifiable reads as a hole. Same fact, very different trust cost.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Wren, "the control you can actually build sits downstream of the market you'd need to break" is the sentence that makes the whole access control debate look different. The controls aren't just ineffective . They're structurally incapable of addressing the supply side because the supply exists for reasons that have nothing to do with Claude. tightening the check doesn't move the acquisition economics. it just changes which slice of the face's value Anthropic captures as friction.

on the sourcing note — "reported but not independently confirmed" is going in before publication. the Attal quote is anchored now — AI Frontiers Media, dated, with the quote in context. the Fable shutdown has the Anthropic official statement and Fortune's coverage. both are linkable. the soft spots you flagged are covered.

Collapse
 
mudassirworks profile image
Mudassir Khan

the proxy log point is the one most agent teams haven't internalized. it's not just prompts — every tool call, every reasoning trace, every mcp server interaction gets logged by the proxy operator. if your agent is doing repo operations, that's the full decision sequence, not just the code.

we ran into this evaluating a cheaper gateway: operator terms said nothing about retention. 'fast, cheap, compatible' was the whole pitch.

the 'follow the actor not just the account' framing from the thread is right. has anyone actually shipped attribution that survives delegation, or does it always collapse back to account level controls once you're in production?

Collapse
 
falaq_ai profile image
Falaq

This is a useful way to frame access controls: the policy debate usually stays at provider/user level, while the workaround market pushes risk onto people who never chose the tool. The logs angle is scary too; cheap proxy access is basically paying for someone else to hold your prompts.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Falaq, "paying for someone else to hold your prompts" is the cleanest way I've seen that put. The 10% price isn't a discount. it's what your data is worth to someone who isn't you.

The policy/workaround framing you named is the whole structure in one sentence . The debate stays clean at the top because nobody at that level has to look at who's holding the risk underneath it.

Collapse
 
wrencalloway profile image
Wren Calloway

The framing that treats KYC-bypass biometric harvesting as a distinct, new supply chain undersells how fungible the identity actually is. A face harvested for a Claude verification isn't earmarked for Claude. The recruiter isn't running an AI-access operation — they're running an identity-acquisition operation, and AI KYC is just the current buyer. That's why the "controls produce evasions" model is almost too clean: it implies each new control spawns a bespoke evasion layer. What actually happens is the existing identity-fraud infrastructure — the same one that already services fraudulent bank accounts, SIM swaps, and Worldcoin iris farms — adds AI verification as one more revenue stream. The marginal cost of pointing it at Anthropic is nearly zero because the human, the database, and the recruiter network already exist.

Which sharpens your last point rather than softening it. If biometric verification were the actual bottleneck, tightening it would raise costs and shrink the pool. But when the identity is reusable across a dozen unrelated frauds, the $30 gets amortized across all of them — so each new control barely dents the price and mostly just adds another buyer to a face that's already for sale.

One flag on accuracy: I can't verify the Fable/Mythos shutdown, the Attal quote, or the Qian paper, and readers who can't either will use that to dismiss the parts that are demonstrably real — the Kenya moderators, the Worldcoin black market. If any of those specifics are illustrative rather than sourced, I'd mark them as such, because the load-bearing argument doesn't need them and one unverifiable detail lets people wave off the whole thing.

Collapse
 
dannwaneri profile image
Daniel Nwaneri

Wren, the amortization point is the one that breaks the framing I was working with. I built the piece around "each control spawns a bespoke evasion layer" . you're right that's too clean. the identity-acquisition infrastructure already exists, already services a dozen fraud verticals and AI KYC is just the newest buyer at nearly zero marginal cost. that changes the argument: tightening AI verification doesn't raise the price of the face, it just adds Anthropic to the list of buyers the face gets sold to. the $30 doesn't even reflect the cost of the Claude access. it reflects the fraction of a face's value that this particular buyer represents.

That's a harder and more accurate version of what I was trying to say.

On the accuracy flag . The Qian paper is real and sourced, the Worldcoin black market is documented. the Fable/Mythos shutdown and the Attal quote I'm confident in but you're right that readers who can't verify them will use that uncertainty to dismiss the load-bearing parts. I'll add sourcing to those specifics before this gets wider distribution. the argument doesn't need them to be illustrative . it needs them to be verifiable and they are, so there's no reason not to show the work.

Collapse
 
rexpsunny profile image
Rex Sunny

Powerful and unsettling piece. The most striking example was how biometric KYC can push the real cost of AI access onto people in places like Cambodia or Kenya, trading permanent identity risk for a one-time $30 payment.

Collapse
 
fromzerotoship profile image
FromZeroToShip

The "it migrates" framing is the part I can't shake. Most access debates stop at "is this convenient or affordable for me" — you push it all the way to who actually absorbs the cost once it's out of sight. That's a much harder question, and you don't let the reader off easy.

The logs-retention point deserves its own post, honestly. People weighing a cheap proxy think about price and model quality; almost nobody pictures a stranger holding their full prompt history and repo context indefinitely. The $30 biometric trade is the visible injustice, but that quiet data capture is a second one stacked on top of it.

Thanks for writing the part nobody's arguing about.

Collapse
 
xm_dev_2026 profile image
Xiao Man

Wow, this is such an eye-opener! I never thought about the hidden costs behind AI access like this. Thanks for shedding light on this important topic.

Collapse
 
benjamin_nguyen_8ca6ff360 profile image
Benjamin Nguyen

interesting article, Daniel!

Collapse
 
laxmansubadi profile image
laxman Subedi

hay everyone I recently my launch my AI if you are a double or anything today everyone now check this out bugdetectai.con now save your time fix your bug anything you need