AsiaTechDaily – Asia's Leading Tech and Startup Media Platform
For much of the internet’s history, digital trust was built on a straightforward principle. If a user could prove they were human and authenticate their identity, they were generally considered trustworthy. Passwords, multi-factor authentication, CAPTCHAs, and device verification became the foundation of modern cybersecurity, protecting everything from online banking and e-commerce to enterprise software and government services.
That foundation is now under pressure. The rapid advancement of generative AI has significantly changed the capabilities available to both legitimate users and cybercriminals. Large language models can generate convincing phishing campaigns, multimodal AI systems can solve increasingly sophisticated visual challenges, and autonomous AI agents are beginning to perform complex digital tasks with minimal human intervention. Rather than simply automating repetitive work, these systems are capable of interacting with applications, accessing APIs, retrieving information, and executing workflows in ways that increasingly resemble legitimate human activity.
For enterprises across Asia, where digital banking, fintech, cloud computing, e-commerce, and AI adoption continue to accelerate, the implications extend far beyond bot detection. Security leaders are increasingly asking a broader question: if machines can convincingly behave like humans, how should organizations define digital trust in the AI era?
For decades, cybersecurity strategies focused primarily on authentication. Organizations invested heavily in verifying identities before granting access to systems and applications. Passwords evolved into multi-factor authentication, CAPTCHAs helped distinguish humans from automated bots, and identity management platforms became central to enterprise security architectures. These approaches were designed around a relatively simple assumption. Humans logged into systems. Bots attempted to break in. The objective was to distinguish between the two. While these mechanisms remain valuable, the emergence of AI has blurred the distinction that made them effective.
Modern AI systems can increasingly interpret images, solve visual puzzles, understand natural language, and navigate digital interfaces with a level of sophistication that was previously associated only with human users. At the same time, organizations themselves are deploying AI assistants, autonomous agents, and workflow automation tools that legitimately interact with enterprise applications around the clock. The result is a digital environment where both trusted and malicious automation increasingly resemble normal user behavior.
The evolution of AI has also changed where cyberattacks occur. Rather than focusing exclusively on user interfaces, attackers increasingly target APIs, identity systems, cloud services, and backend infrastructure where much of today’s digital activity takes place. Once inside a system, malicious actors often move laterally, access sensitive resources, or automate actions that appear legitimate on the surface. This means that authentication alone no longer provides sufficient protection.
Thales recently highlighted this shift through findings published in its 2026 Bad Bot Report, which noted that increasingly sophisticated automated attacks are bypassing traditional front-end defenses while focusing more heavily on APIs and identity infrastructure. The report reflects a broader industry trend in which organizations must continuously evaluate activity after authentication rather than relying solely on who has logged in.
Building on these findings, while conversing with AsiaTechDaily, Andy Zollo, Senior Vice President for Asia Pacific and Japan at Thales, argued that identity protection is increasingly becoming a question of understanding behavior rather than simply confirming identity.
“CAPTCHAs still have a role in some environments, but they are no longer sufficient on their own. The bigger shift is that identity protection now needs to be built around behaviour, not just identity, because the report shows that attackers are bypassing front-end defenses and targeting APIs and identity systems directly. In that context, the question is no longer just whether a user looks human, but whether the activity is doing what it is supposed to be doing.
That means organizations need stronger controls at the API and identity layers, along with better visibility, policy enforcement, and monitoring that can distinguish legitimate automation from abuse. So rather than relying on a single point of friction, companies need a broader set of signals, not just who is asking, but what they are doing once they are in.”
His comments illustrate one of the most significant shifts occurring across enterprise cybersecurity. Identity is no longer viewed as a single verification event. Instead, it is becoming part of a continuous process in which organizations evaluate activity, context, and intent throughout every digital interaction.
This transition reflects the growing adoption of behavioral security across enterprise environments. Instead of relying exclusively on credentials, organizations increasingly combine multiple signals to determine whether activity should be trusted. User behavior, device posture, access patterns, location, transaction history, application usage, and network context collectively contribute to dynamic risk assessments. This approach is especially important because AI can imitate legitimate users without necessarily behaving like them over extended periods.
For example, an employee may regularly access internal financial systems during business hours from familiar devices. An AI-powered attacker using valid credentials might successfully authenticate but immediately begin querying hundreds of APIs, downloading unusual volumes of information, or accessing systems unrelated to that employee’s responsibilities. Identity alone would not detect the anomaly. Behavior would. This shift aligns closely with the broader evolution of Zero Trust architectures, where trust is continuously evaluated rather than permanently granted after login.
Another consequence of enterprise AI adoption is the rapid growth of machine identities. Organizations increasingly operate environments where software agents, APIs, cloud workloads, containers, robotic process automation, IoT devices, and AI assistants interact continuously with enterprise systems. Many organizations now manage significantly more machine identities than human users. Unlike traditional software, however, AI agents increasingly make independent decisions, interact with external services, retrieve information, and initiate actions across multiple business systems.
This introduces new governance questions. How should organizations authenticate autonomous agents? What permissions should they receive? How should their activities be monitored? How should abnormal behavior be detected when the actor is not human? These questions extend identity management beyond employees and customers to encompass an expanding ecosystem of intelligent digital participants.
The implications extend well beyond cybersecurity departments. Digital trust increasingly influences customer confidence, regulatory compliance, financial services, healthcare, government platforms, digital commerce, and enterprise AI adoption. Consumers expect online services to protect personal information without creating unnecessary friction. Businesses require secure collaboration across increasingly connected digital ecosystems. Governments continue expanding digital identity initiatives while regulators introduce stricter requirements around AI governance, cybersecurity, and data protection.
For startups, the challenge is equally significant. As AI-powered products become more autonomous, companies must build security models capable of distinguishing legitimate automation from malicious activity without undermining user experience or slowing innovation. Achieving that balance will likely become one of the defining competitive advantages of enterprise software in the coming years.
Artificial intelligence is not simply introducing new cybersecurity threats. It is fundamentally redefining how trust is established across the digital economy. For decades, proving a user’s identity served as the primary gateway to online security. That approach remains important, but it is no longer sufficient in an environment where AI can solve visual challenges, imitate legitimate behavior, automate attacks, and increasingly participate alongside humans in digital systems. The future of digital trust will depend less on verifying identity once and more on continuously understanding behavior, context, intent, and risk throughout every interaction. Organizations that successfully make this transition will be better positioned to secure increasingly autonomous digital environments while maintaining the seamless user experiences that modern businesses demand.
As AI continues to blur the boundary between humans and machines, trust itself is becoming dynamic rather than static. In the next generation of cybersecurity, the most important question may no longer be who is accessing a system, but how they behave once they are inside.