This is going to be an unpopular one, and I would like to be argued out of it.
A capable agent driving a real browser on a residential connection is indistinguishable from a person by construction. Not "hard to distinguish". Not "we are working on it". By construction — because every property you can measure is genuinely present.
The browser is real, so the fingerprint is real. The connection is a home connection, so the address is clean. The mailbox is real, so the code arrives. Automation flags like navigator.webdriver are trivially patched, and any vendor relying on them is selling you a headstart measured in weeks.
So when a product claims it detects AI agents, one of a few things is true. It detects unsophisticated agents, which is real value, honestly stated — most abuse is unsophisticated. Or it detects declared agents, which is not detection, it is reading a header. Or it is selling certainty in a place where certainty does not exist, and the arms race is the business model rather than the problem.
The version I believe: you cannot detect a capable agent, but you can verify one that identifies itself, and you can catch volume through linkage regardless of what any single request looks like. One device across twelve addresses, fifty signups from one subnet in an hour — that is visible whether or not you ever worked out what was making the requests.
Detection is the wrong axis. Identity and shape are the right ones.
Tell me where this is wrong — I would genuinely rather be corrected than confident.
Top comments (0)