The internet is bad because the fakes are too good. Here’s how to fix it.
A VeryAI manifesto.
The most important and pressing issue on the internet today is authenticity.
I don’t mean “be your true self.” More: Is this person responding to my post a real person trying to genuinely engage in conversation, or a spam account trying to bait engagement? Is that really my friend that DMed me, or is their account hacked? Is this the link to a video call or a DPRK trap?
Online hacks, manipulation, and spam are not new problems. Using the word “sock puppet” to refer to fake accounts to change opinions can be dated back to at least 1995 on Usenet. In 1994, hackers used stolen credentials to move $10 million dollars from Citibank. One of the earliest prosecutions for platform manipulation was an eBay scammer manipulating prices with bids back in 2001. In 2004, an Amazon glitch showed that authors were writing fake reviews of their own books.
The issue is that all of these behaviors have been supercharged with the widespread adoption of AI and agents by bad actors. LLMs aren’t new, but they weren’t common, and the type of malicious behavior that makes the internet experience bad for everyone required some level of technical skills, manpower, or both. Now the bar for setting up bots has dropped dramatically, to the point where what once took an entire content farm can be set up by a single person.
The results have been catastrophic.
Per the FTC, $12.5 billion was lost to identity theft in 2024. In 2025, the first year the FBI tracked AI-related complaints, they received 22,364 complaints with more than $893 million in losses. Brute forced data hacks are common, and most (if not all) email addresses are compromised. A single disclosed data breach in November 2025 affected 2 billion addresses alone. In a 2024 transparency report, X reported that they removed 677,798 accounts for misleading or deceptive identities.
The mainstream solutions we use to prevent these attacks are still stuck in the pre-AI era. CAPTCHA can be solved by AI 100% of the time, even visually complex ones. OTPs sent via or text or email can be intercepted by compromised devices or accounts. They are not strong enough to withstand the tsunami of attacks.
Though people warned you to be careful on the internet, it was still a place where you could mostly start from a place of good faith. Bad actors are using AI to turn the internet into a place where everyone needs to be defensive.
Doxxing is not the solution
Desperate times call for extreme measures. Some companies and governments have started calling for the widespread adoption of KYC (Know Your Customer), which requires a user to share government documents like a drivers license or passport before joining a website or platform.
While KYC is important for specific use cases, like compliance or sanctions screening, KYC everywhere is a broad overreach. Anonymity is a core part of internet culture, and forcing you to show your ID would be the end of it as we know it. It’s also a major security risk, as the recent disclosure of more than 153 million drivers licenses stolen from an identity provider just a few weeks ago proves.
More importantly: Widespread KYC solves the wrong problem. You don’t need every piece of private data about a person for them to participate in a conversation or to enter the public square; You don’t need to show your ID just to meet a friend for coffee.
What you actually need to solve
In most cases, you really just need to answer one of three questions:
- Is this a real person?
- Is this a real, unique person?
- Is this the same person who registered the account?
This can be solved with low-friction biometric authentication. There are a few companies pursuing this with fingerprints, face, and iris scans, but many of these are not scalable due to external hardware or suffer from privacy concerns.
At Very, we believe that scanning your palm with your smartphone camera is going to be the most private, least intrusive way to answer those questions. Recent advances in computer vision and smartphone cameras have made palm verification at a global scale achievable for the first time. We also allow users to vouch for their agents, so that genuine AI activity, like trading or personal assistants, can be separated out from bad actors.
Our palm scan is a highly accurate way to confirm whether a person is real or not. With four in five people over the age of 10 owning a smartphone, our method is scalable. Unlike faces, which can be fabricated with existing image datasets that already exist on the internet, there is no “Palmbook.” Most importantly, they’re quick and nearly frictionless; if a platform uses our SDK, users can complete the entire verification process without ever leaving the app.
The answer is quite simple. Proving you’re a real person can be as easy as a quick palm scan. It’s a small action for each user, but if added at scale, we’ll rapidly see the internet change for the better.
An internet where we don’t need to be defensive is not out of reach. It’s possible, even probable. All it takes is your palm.
Ready to build with VeryAI?
Integrate digital trust into your platform today.