Cequence Security launched two capabilities, Intent Graph and Biometric Check, designed to distinguish human users from bots and AI agents across web, mobile, API, and agentic traffic. The release is part of a broader move among bot-management and identity vendors away from CAPTCHAs and toward behavioral signals and device-bound attestation, as challenge-based tests lose effectiveness against increasingly automated traffic.

Biometric Check replaces CAPTCHAs, puzzles, SMS codes, and email verification with hardware-bound cryptographic attestation through a device’s Secure Enclave. When the system flags a session as falling outside a configurable confidence threshold, the user completes a familiar biometric interaction, such as Touch ID, Face ID, or Windows Hello, and the device returns signed proof that a real person on a registered device completed the action. The biometric data never leaves the device, and Cequence says verification completes in under a second.

Intent Graph is the behavioral component. Cequence describes it as a system that maps what a user, bot, or agent is actually doing on an application, regardless of how the session arrived, without relying on the client-side signals that sophisticated bots have learned to imitate or defeat. The stated aim is to identify automated activity by its behavior rather than by a one-time gate at the front door.

Cequence cited an enterprise deployment in which adversaries retooled an attack more than ten times over two days using virtual browsers and rotating proxy networks. The company said Intent Graph blocked every iteration without showing a CAPTCHA, puzzle, or other challenge to legitimate customers.

The launch reflects the inverse of much of the current work on AI-agent identity. Where a wave of vendors and standards bodies is focused on giving agents verifiable identities and folding them into the enterprise identity stack, tools like Cequence’s are aimed at the opposite problem: separating legitimate human traffic from the growing volume of automated and agent-driven traffic hitting applications and APIs. That volume has been rising alongside a broader surge in API attacks.

As AI agents take on more browsing, purchasing, and API calls on behalf of users, the question of whether a session is human is becoming harder to answer with a visible test. Cequence’s approach, like others moving in the same direction, shifts that determination to device-level attestation and behavioral analysis.

Sources: Cequence, Help Net Security


By the Control Plane Editorial Team