The Day ‘I Am Not a Robot’ Stopped Being a Promise
There is a small box. “I am not a robot.” To post, to log in, to make a reservation, you had to check that box. For more than a decade, it was the smallest and most taken-for-granted contract between people and the internet. Since 2023, that contract has quietly broken. The side checking the box is no longer only human. The era of “bidirectional authentication” on the internet, as reported by Chosun Ilbo, is the start of a system in which humans say “I am human” and AI says “I am AI.” This post begins from that report and goes one layer deeper, to the questions that companies are asking.
Visualizing the core concept of this post.
53 to 47: The Day the Majority Changed
Start with the numbers. In 2023, automated traffic, including AI bots, was 53% of global internet traffic. Human traffic was 47%. It is the first moment in the history of the internet when non-humans outnumbered humans. The mainstream of automated traffic used to be crawlers that scraped search keywords. The center of gravity has now moved to intelligent bots that understand and generate language, to the point of passing even the classic tests for telling a human from a machine. When a premise collapses, everything built on top of it has to be reconsidered.
This is exactly why the existing authentication stack is being disabled. Passwords, SMS verification, and CAPTCHA were all built on the premise of separating humans from machines, and when the machine side becomes intelligent, those devices lose their meaning. Chosun Ilbo points out that since 2023, threats such as mass fake account creation, opinion manipulation, and deepfake fraud have grown exponentially. E-commerce, social platforms, and public platforms sit directly exposed to fake reviews, bot voting, and deepfake fraud.
So what is the industry’s answer? Surprisingly direct. It gives up the strategy of blocking machines and moves to a system where both sides state their own identity. This is where the diagnosis appears that the core question of internet security has shifted from “Who are you?” to “Are you human, or AI?”. The forecast is that identity verification technology is now settling in as essential infrastructure for the AI era. Bidirectional authentication is not a security patch. It is rebuilding the system on the premise that the majority of the internet is no longer human.
“I Am Human,” “I Am AI”: Two Birth Certificates
On the human side, what has grown quietly is iris-based identity proof. Tools for Humanity, founded by Sam Altman, raised $250 million to build World ID, which proves “this is human” by photographing the iris without exposing personal information. The user base has already passed 18 million. It has been adopted by platforms including Tinder, and it is expanding at the national level to the governments of Taiwan and Malaysia. What this certificate verifies is not “which human” but the fact of “being human” itself. It works because the structure verifies only species while preserving privacy.
On the AI side, a separate certificate is being issued. Anthropic has started applying a technology that places a watermark in text generated by Claude, statistically detectable without human perception, to tell AI-generated output from human output. Anthropic is not alone. A trend is running through which major AI companies make watermarking and provenance labeling mandatory on their models’ output. What the watermark verifies is also not “who made it” but “what made it.” If the human certificate verifies species, the AI certificate verifies origin.
Put the two together and the structure of the internet changes. It moves from a one-way system that suspected and blocked every participant to a two-way system that discloses first and then interacts. The market’s reaction supports this. Industry forecasts see the global identity verification market growing from $16.5 billion in 2024 to $45.5 billion by 2033. A market that was built to block bots is being rebuilt to identify bots. The paradox at the center of today’s news is here. The strongest defense of the AI era is the act of saying “I am AI” on its own.
Companies Ask Not “Human vs. AI” but “Who Sent It”
In the enterprise field, the question goes one step further. If the internet asks “what is it,” the company asks “whose is it.” When facing an agent that acts on the internet on behalf of a company, what is visible from the outside is not “human or AI” but “which agent of which organization, with what authority, executed what, and can that be proven later?” And this question is not abstract. It is already reality in Korea.
Today’s domestic news provides the evidence. “Mirae Asset 3.0,” declared by Mirae Asset Securities, is an attempt to connect information search through actual operation with AI. Generative AI translates and summarizes the disclosures of 1,500 companies listed in the US, Japan, China, and Hong Kong, and it also provides breaking “AI earnings analysis” on US company conference calls. This month an IRP product called “Retirement Pension Robo Wrap” also came out. It is a discretionary product in which a robo-advisor builds a global asset allocation portfolio and, on the client’s behalf, executes the actual trades. Cumulative investment grew from 100,000 units and 5 trillion won in December 2025 to 140,000 units and 8.3 trillion won by late July 2026, in seven months. After building GPU-based in-house AI infrastructure last year, the company changed the research center’s name to “AI Research Center” and carried out an organizational restructuring that converts RAs into analysts. It also newly created an AI Engineering Headquarters under the Tech & AI division, and first quarter KOSDAQ research output grew 79% year over year. In a phase of low growth and pension market expansion, insurers are entering the fight for retirement pension share with fee-free and AI expansion cards, so the early positioning of large financial groups in AI asset management is reshaping the competitive landscape fast. The moment an agent moves real money, “who issued this instruction, under what policy, with what verification” becomes not a security theory but a compliance requirement.
The government is heading the same direction. The Ministry of Science and ICT launched a cross-ministry “Agentic AI Initiative” in July and set three major strategies of safety, execution, and demand for the actionable AI ecosystem. Of the three, “safety” overlaps most directly with the theme of this post. The Science and Technology Ministerial Conference has met 12 times since its first session last November, and the weight of policy has moved from strategy formulation toward demonstration, commercialization, and outcome creation. The government has passed through the “board setting” stage of the AI national strategy and the allocation of roughly 10,000 advanced GPUs. It is now lowering the center of gravity to more concrete industry and technology units: physical AI, agentic AI, and autonomous driving AI. At the 11th session, a physical AI port strategy including Jinhae New Port and a regulatory sandbox linkage for the Agentic AI Initiative were approved, and a decision was made to add 520 GPUs for major projects such as “AI for All.” Deputy Prime Minister Baek Keun-hoon summed it up: “The true outcome of the AI competition is not superior technology development alone, but AI that is actually used in industrial fields and in the daily lives of citizens.”
The most symbolic event in this flow is the “K-Mythos” competition. In 2025, four companies including Upstage, SKT, and LG AI Research Institute were selected for the specialized foundation model program, and this year the competition has spread to the security domain as “specialized model plus field demonstration.” Only two consortia entered the Ministry of Science and ICT’s call for security-specialized AI foundation models: the SKT and Upstage consortium (13 institutions) and the Naver Cloud and LG consortium (32 institutions). The background is clear. Cases emerged in which Anthropic’s “Mythos” model found security vulnerabilities that had gone undetected for over 20 years and automatically generated attack code, and with them the perception spread that AI has become a primary security threat. The moment a threat behaves like an agent, defense has to operate like one too. The SKT camp’s task is “developing an all-direction cybersecurity-specialized AI foundation model family and demonstrating agentic security services,” and it includes even a specialized AI red team firm that verifies vulnerabilities from the attacker’s perspective. The Naver Cloud camp brings demand organizations such as the Financial Security Service, KAI, and Korea Hydro and Nuclear Power together with LG CNS and LG AI Research Institute, and it runs under the theme of “developing an AI foundation model to internalize national cybersecurity capabilities.” In follow-up reporting by gdnews Korea, an industry view also appeared: “we need open source attack detection and tracking capabilities.” Selected consortia will receive 256 B200 GPUs for 10 months, and the contest is decided by a presentation evaluation in early September. As Digital Today points out, the fact that the government allocates limited GPUs by hand makes the sovereign computing argument stronger. It means that the security model, and the agents acting inside it, must run on infrastructure where data sovereignty is guaranteed.
Before Scaling Autonomy, Start with Identity
This is where today’s news becomes an infrastructure question. The majority of internet traffic is already machine, and companies are delegating real work to agents. Where “agent identity” should be handled is not the project layer but the platform layer. Who is this agent, where did it come from, what is allowed, how much autonomy does it have, and does it leave an execution record. The list of questions is not long, but handcrafting the answers every time is impossible.
The limits should be seen together. 53 to 47 is a 2023 global average, and watermarks and iris authentication solve the “what is it” question but cannot solve the “whose is it” question. Even if a watermark proves that a document is AI-generated, it cannot prove that a particular API call happened under a particular organization’s policy. At that point, the agent’s own identity, authority, and records are needed. All of today’s pain converges on this list. In Mirae Asset’s discretionary Robo Wrap, the pain is audit and authority. In the two-horse race for the security-specialized foundation model, the pain is safe execution in the demonstration environment and data sovereignty. If the SKT camp’s “agentic security service demonstration” task is placed in an operations center, the demonstration is not complete without a record of how far the agent progressed from detection to tracking and response and where it was stopped. In the government’s Agentic AI Initiative, the pain is “safety” itself. If this is patched together per project, a new identity system has to be built every time one more agent is added.
ThakiCloud’s answer to this question is Paxis. It is ThakiCloud’s Agent-Native Cloud and a formal product that has reached v1.1 GA. In Paxis, skills, tools, policies, and audit logs are designed as first-class resources, not decorations added after the fact. Each agent’s autonomy is governed in stages from L0 to L3, policy gates decide what is allowed before execution, and everything executed is left in the audit log. It runs safely in an isolated sandbox, connects to enterprise systems through MCP connectors, receives verified skills through the skill market, and CostRouter picks the right model per task to hold cost down. Sovereign and on-premises deployment are also supported on Kubernetes. Paxis is the question “who sent it” translated into a system capability in advance.
Back to the first box. One day, the sentence that goes into that field will change. “I am not a robot. I am an agent, and this is my audit log.” The day that sentence stops being a joke and becomes a form the platform should have ready is the moment the majority of the internet operating system changes. The 53 to 47 of 2023 is not the end of the story. It is the first line.
References
This article is a synthesis of the following news.
- Chosun Ilbo, “I Am Human” “I Am AI”… The Internet Enters the Era of “Bidirectional Authentication”
- Digital Today, Science and Technology and AI Policy Moves from “Strategy” to “Outcomes,” With Weight on Demonstration and Commercialization
- Money Today, “Let’s Build K-Mythos”… SKT and Naver’s Two-Horse Race
- Digital Today, Security Specialized Foundation Model Two-Horse Race… Naver “Cybersecurity” vs. SKT “Security Agent” Showdown
- Onil Economy, [AI, Becoming a Broker ⑦] Mirae Asset Securities Adds AI to “Global”… From Information to Operation