What's the pattern?

Every time a new medium makes impersonation cheap, we build a proof layer. And the proof layer always outlives the crisis that created it.

Before the First World War, most international travel required no document at all. Wartime security made passports mandatory, and in October 1920 the League of Nations convened delegates from 22 nations in Paris and standardized the booklet: 32 pages, a photograph required, national language plus French. By 1926, more than 40 countries had adopted it.

Six years from emergency measure to global infrastructure. Then something else happened. The same decade that standardized the passport was the decade that built immigration quotas around it. The document created to verify who you were became the instrument that decided where you could go.

That is the pattern, and it is the one to watch here. Proof layers never stay narrow.

I built the problem in 2020

In 2020, while I was CEO of a company developing AI video software, I became one of the first people to build a working digital clone of myself.

Same face. Same voice. For the mind, fifteen years of my own commonplace books, everything I had published, everything I had ever posted on a public network. I sang to her. I read her poetry. Before long I had a program that could imitate not just my likeness but my attitude and my perspective, responding to things she had never seen before.

I have shared a version of her publicly. I keep the most advanced version private, and the reason is simple: the whole thing freaks me out.

When a clone can appear on a video call and convince business associates, and family, and friends, that they are talking to the real Sam Rad, the question stops being technical. She does not take my calls yet. Not quite. But soon.

That was four years before the research community proposed a fix. The problem arrives first. It always does.

So what actually gets built?

The honest answer for why this is happening now is that the thing we used to verify humanness stopped working. CAPTCHAs were built on tasks machines could not do. Machines can do them.

In 2024, a group of 32 researchers from MIT, OpenAI, Microsoft, Harvard and others published a proposal for what they call personhood credentials: digital credentials that let you demonstrate you are a real person, issued one per person per issuer, verified cryptographically, disclosing nothing else. Their argument is that existing countermeasures are inadequate against sophisticated AI, while full identity verification is too invasive for ordinary use.

That paper is now the reference point for a conversation that has moved out of research and into procurement.

What nobody is asking loudly enough

The design debate is about privacy, and on privacy the design is genuinely good. That is not where the risk is.

The risk is bundling. A credential that proves personhood is cheap to issue alongside one that proves age, residency, employment, or creditworthiness, and whoever issues it will be asked to do exactly that within a year of launch. Not by conspiracy. By procurement, because it is more efficient.

By 2029, I expect human verification to be a default requirement in at least one high-volume commercial category, and I expect it to arrive in enterprise before it arrives in social media. The agent problem hits business first. When your supplier's negotiating bot talks to your procurement bot, somebody has to be accountable for the contract.

What should leaders do now?

Three things, none of which require predicting the outcome.

Decide what your organization actually needs to verify. Humanness, identity, and authorization are three different questions, and most systems currently collapse them into one. Separating them is the work.

Assume any verification you adopt will be repurposed. Ask at design time what happens when someone requests this system answer a question it was not built for. Then decide in advance whether the answer is no.

Watch who the issuers turn out to be. That is the whole game. A credential issued by a government behaves differently from one issued by a platform, and the difference will not be visible in the interface.

We have built proof layers before, and we survived them. We also, every time, worked out what they were really for about a decade too late. This one we can see coming.

Related: Blurring Reality: AI and the Perceptual Breakdown

Sam Rad, The Change Futurist. Keynote speaker on change, transformation, resilience, and AI adoption. Author of Radical Next. Book a keynote