KoreaTechToday - Korea's Leading Tech and Startup Media Platform
  • Topics
    • Naver
    • Kakao
    • Nexon
    • Netmarble
    • NCsoft
    • Samsung
    • Hyundai
    • SKT
    • LG
    • KT
    • Retail
    • Startup
    • Blockchain
    • government
  • Lists
KoreaTechToday - Korea's Leading Tech and Startup Media Platform
  • Topics
    • Naver
    • Kakao
    • Nexon
    • Netmarble
    • NCsoft
    • Samsung
    • Hyundai
    • SKT
    • LG
    • KT
    • Retail
    • Startup
    • Blockchain
    • government
  • Lists
KoreaTechToday - Korea's Leading Tech and Startup Media Platform
No Result
View All Result
Home Cybersecurity

AI is making traditional identity checks obsolete

Dae-Hyun by Dae-Hyun
PUBLISHED: June 17, 2026 UPDATED: July 2, 2026
in Cybersecurity
0
AI is making traditional identity checks obsolete

As AI agents become increasingly capable of mimicking human behavior and bypassing conventional authentication methods, cybersecurity experts say South Korea’s digital economy must shift from verifying identity to continuously evaluating user behavior.


South Korea has built one of the world’s most digitally connected economies. From digital banking and fintech to ecommerce, gaming, public services, and AI-powered consumer applications, millions of daily transactions depend on systems that can accurately distinguish legitimate users from malicious actors. For decades, that trust has relied on familiar safeguards such as passwords, one-time authentication codes, and CAPTCHAs designed to separate humans from bots.

That model is beginning to break down. Advances in generative AI and agentic AI are enabling automated systems to solve visual puzzles, imitate human browsing patterns, and interact with digital services with increasing sophistication. At the same time, organizations worldwide are rapidly expanding their use of APIs and cloud-native applications, creating new pathways for attackers to bypass traditional front-end defenses entirely. According to the 2026 Thales Bad Bot Report, bots accounted for 53% of global web traffic in 2025, while AI-driven bot attacks increased 12.5 times compared with the previous year. Rather than simply automating repetitive tasks, AI agents are emerging as an entirely new category of internet traffic capable of interacting directly with enterprise systems.

For South Korea, where artificial intelligence is becoming a national strategic priority and digital services underpin nearly every sector of the economy, the implications extend beyond cybersecurity. As organizations adopt AI across finance, healthcare, manufacturing, mobility, and government services, protecting digital identities may increasingly depend not on proving someone is human, but on understanding whether their behavior aligns with legitimate activity.

AI is changing the foundations of digital identity

Traditional authentication was designed around a relatively simple assumption: once a user demonstrated they were human and successfully logged in, they could generally be trusted throughout the session.

Modern AI is challenging that assumption. Large language models, multimodal AI systems, and autonomous agents are becoming increasingly capable of completing tasks that previously required direct human interaction. They can navigate websites, interpret visual information, complete forms, execute workflows, and communicate with applications in ways that closely resemble legitimate users.

Consequently, cybersecurity is shifting from static identity verification toward continuous evaluation of user behavior. Rather than asking whether a login request comes from a human, organizations are increasingly asking whether the actions being performed are consistent with legitimate user intent. This represents one of the most significant architectural changes in cybersecurity since the widespread adoption of multi-factor authentication.

South Korea’s digital economy raises the stakes

Few countries illustrate this transition more clearly than South Korea. The country continues expanding AI adoption across industries while simultaneously investing in sovereign AI capabilities, advanced semiconductors, cloud infrastructure, and digital transformation initiatives. Korean companies are integrating AI into financial services, healthcare, manufacturing, smart factories, mobility, and consumer electronics at an accelerating pace.

These sectors all depend on trusted digital identities. Banks must distinguish customers from fraudsters. Ecommerce platforms must prevent automated account abuse. Gaming companies must detect sophisticated bot activity without disrupting legitimate players. Healthcare systems increasingly rely on secure digital identities to protect sensitive patient information, while public-sector platforms continue expanding digital citizen services.

As AI becomes embedded across these environments, traditional verification methods alone are becoming less effective. The challenge is no longer limited to preventing unauthorized access. Organizations must continuously determine whether authenticated users continue behaving as expected after gaining access.

Identity protection is becoming behavior protection

During a conversation with KoreaTechToday, Andy Zollo, Senior Vice President for Asia Pacific and Japan, Application and Data Security at Thales, said organizations should rethink identity protection in light of increasingly sophisticated AI-driven automation.

“CAPTCHAs still have a role in some environments, but they are no longer sufficient on their own. The bigger shift is that identity protection now needs to be built around behaviour, not just identity, because the report shows that attackers are bypassing front-end defenses and targeting APIs and identity systems directly. In that context, the question is no longer just whether a user looks human, but whether the activity is doing what it is supposed to be doing.

That means organizations need stronger controls at the API and identity layers, along with better visibility, policy enforcement, and monitoring that can distinguish legitimate automation from abuse. So rather than relying on a single point of friction, companies need a broader set of signals, not just who is asking, but what they are doing once they are in.”

His comments reflect a broader evolution occurring throughout enterprise cybersecurity.

Identity is increasingly becoming dynamic rather than static. Authentication no longer represents the end of security verification but instead marks the beginning of continuous risk assessment.

APIs are becoming the new cybersecurity frontline

Another important shift accompanies the rise of AI agents. Historically, many cyberattacks targeted websites through visible user interfaces. Today, attackers increasingly bypass those interfaces entirely by interacting directly with application programming interfaces, or APIs, that power modern digital services.

According to the Thales report, 27% of bot attacks in 2025 targeted APIs, allowing automated systems to interact directly with backend infrastructure while appearing to use legitimate authentication credentials.

This trend has particular significance for South Korea’s technology ecosystem. Cloud-native startups, fintech companies, digital banks, AI platforms, ecommerce marketplaces, and enterprise software providers increasingly depend on APIs to deliver services efficiently. While APIs accelerate innovation and improve interoperability, they also expand the potential attack surface available to sophisticated automated systems.

As AI agents become more capable of interacting autonomously with enterprise applications, organizations must gain greater visibility into machine-to-machine communication rather than focusing exclusively on traditional web traffic.

The future of cybersecurity will be continuous

The rise of AI-powered automation is accelerating broader adoption of security frameworks such as Zero Trust Architecture, which assumes that no user, device, or application should be trusted automatically, even after successful authentication.

Instead of relying on one-time verification, modern security increasingly evaluates multiple signals throughout every interaction. Organizations are investing in technologies that assess behavioral patterns, device characteristics, session context, geographic anomalies, API activity, and continuously changing risk profiles.

For South Korean enterprises, this transition aligns with the country’s broader digital transformation agenda. As AI becomes integrated into financial services, manufacturing, healthcare, smart cities, and government platforms, protecting digital ecosystems will require security models capable of adapting alongside increasingly intelligent forms of automation.

Trust in the AI era will depend on behavior

The shift toward AI-driven digital ecosystems is likely to reshape identity security across industries. Organizations should increasingly focus on:

  • Continuous behavioral monitoring rather than one-time authentication alone.
  • Stronger API security and identity governance as machine-to-machine interactions grow.
  • Risk-based access controls that adapt dynamically to changing user behavior.
  • Greater visibility into legitimate AI agents versus malicious automated activity.
  • Security architectures designed to evolve alongside increasingly autonomous AI systems.

Artificial intelligence is transforming far more than productivity and software development. It is fundamentally reshaping how organizations establish digital trust.

The assumption that proving a user is human is sufficient for ensuring security is becoming increasingly outdated. As AI agents continue improving their ability to imitate legitimate users and interact autonomously with digital services, organizations will need security models that evaluate intent and behavior throughout every interaction rather than relying on a single verification step.

For South Korea, whose digital economy depends on trusted online services across finance, healthcare, manufacturing, government, and consumer technology, this transition carries strategic significance. The country’s leadership in artificial intelligence will ultimately depend not only on developing more capable AI systems but also on building cybersecurity frameworks capable of distinguishing beneficial automation from malicious activity.

In the next phase of digital transformation, trust will no longer be established simply by asking who is requesting access. It will increasingly depend on understanding what they do after they arrive.

 

Tags: CaptchacybersecuritySingaporeThales

Related Posts

AI Has Made Impersonation Cheap. Korean Businesses Now Have to Make Verification Cheap Too.
Cybersecurity

AI Has Made Impersonation Cheap. Korean Businesses Now Have to Make Verification Cheap Too.

September 2, 2026
No Result
View All Result

Most Popular

  • Government-Backed Initiative: KT Unveils Budget-Friendly Galaxy Jump 3 Smartphone

    0 shares
    Share 0 Tweet 0
  • South Korea Unveils Bold Plan to Train 30,000 Aerospace Experts by 2045

    0 shares
    Share 0 Tweet 0
  • Samsung to Construct Second EUV Foundry Line in Korea

    0 shares
    Share 0 Tweet 0
  • Hyundai & Kia Bet Big on Battery Innovation with W1.2tn R&D Campus in Anseong

    0 shares
    Share 0 Tweet 0
  • Samsung’s Gauss2 AI Model Enhances Efficiency and Personalization

    0 shares
    Share 0 Tweet 0
  • From Samsung to Hyundai: Social Media Impersonation Scams Spark Alarm

    0 shares
    Share 0 Tweet 0

PRODUCTS

[ads_amazon]

TOPICS

  • Naver
  • Kakao
  • Nexon
  • Netmarble
  • NCsoft
  • Samsung
  • Hyundai

FREE NEWSLETTER

[mc4wp_form id="4726"]

FOLLOW US

  • About Us
  • Cookie policy
  • home
  • homepage
  • mainhome
  • Our Services
  • Privacy Policy
  • Terms of Use

Copyright © 2024 KoreaTechToday | About Us | Terms of Use |Privacy Policy |Cookie Policy| Contact : [email protected] |

No Result
View All Result
  • Topics
    • Naver
    • Kakao
    • Nexon
    • Netmarble
    • NCsoft
    • Samsung
    • Hyundai
    • SKT
    • LG
    • KT
    • Retail
    • Startup
    • Blockchain
    • government
  • Lists

Copyright © 2024 KoreaTechToday | About Us | Terms of Use |Privacy Policy |Cookie Policy| Contact : [email protected] |