FROM PLATFORMS TO COMMONS

Identity, Trust and Human Verification

> 2.2 Identity, Trust and Human Verification

Digital identity has become unstable in ways that directly affect how civil society operates. Technologies that once felt peripheral now shape whether people can organise safely, participate meaningfully or trust the information in front of them. The growing availability of generative AI has made impersonation, falsified audio and fabricated statements more common and more convincing. Research from the European Digital Media Observatory and the Stanford Internet Observatory in 2024 and 2025 shows an increase in synthetic accounts and deepfakes aimed at discrediting public interest organisations. The World Economic Forum’s Global Risks Report 2025 identifies misinformation and synthetic content as the highest short-term threat to global stability.
â–ş Sources: https://edmo.eu and https://cyber.fsi.stanford.edu and https://reports.weforum.org

Civil society often experiences these shifts first. Activists face targeted impersonation. Organisations receive fabricated messages that appear to be from partners. Public audiences struggle to distinguish genuine communication from manipulated media. These dynamics  create an operational challenge that affects everything from campaigning to community engagement.

Why identity is becoming harder to rely on

Digital identity has entered a period of instability. For many years, people relied on simple cues to judge authenticity online. A familiar username, a writing style, a profile with a history of posts or a video that appeared genuine were usually enough to trust that an interaction involved a real person. These cues no longer provide reliable assurance. A major reason is the rapid spread of generative AI. Tools that imitate voices, faces and writing styles now operate at a level that makes manual detection extremely difficult. A short  audio sample can be cloned. Video footage can be convincingly altered. Written communication can be generated to match a person’s tone or the norms of a local community.

At the same time, automated systems that imitate human behaviour have become far more sophisticated. These include traditional bots, as well as newer hybrid systems where human oversight and automated generation blend together. They can maintain plausible posting patterns, mimic community language and react in real time, which undermines the assumption that a persistent online account must represent a real individual.

Composition of internet traffic (past 10 years). The rise in the number of accessible AI tools has significantly lowered the barrier for entry for cyber attackers enabling them to create and deploy malicious bots at scale. Bad Bot Report 2025

Authentication systems have not kept up with these developments. Password based systems are insecure, SMS verification can be intercepted, commercial verification labels can be purchased, and biometric identity remains highly contested due to privacy risks and the consequences of any data breach.

Finally, identity standards are diverging across regions. The European Union is moving toward digital wallets, some governments continue to expand biometric schemes and others rely on device level or behavioural identifiers. These approaches are often incompatible and follow different legal and political logics, which adds further uncertainty. The result is a landscape where identity is easy to imitate and increasingly difficult to confirm. Civil society has to operate within this broader shift, recognising that many older assumptions about authenticity and trust are no longer reliable.

The difference between identity and verification

Identity and verification are frequently treated as synonyms, but they serve different purposes. Identity is about who someone is. Verification is about confirming that an interaction involves a real human acting in good faith.

Most civil society activity does not require formal identity. It requires confidence that:

  • a participant is not an automated agent
  • a message originates from a legitimate source
  • people in a shared process are who they claim to be in context
  • participation is safe even when anonymity is necessary

In practice, this means distinguishing between three related concepts that are often blurred together. Authentication refers to proving that a person controls a specific account or credential, for example logging in with a password, passkey or secure token. Identification describes linking that account or credential to a known individual, which is only needed in limited circumstances such as safeguarding or legal compliance. Verification is the middle layer. It confirms that a real, accountable human is participating without requiring them to reveal their personal identity. Many civic processes only require verification. Participants can remain pseudonymous or anonymous while still giving others confidence that they are genuine, unique and participating with integrity.

This distinction matters because systems that require formal identity, such as biometric databases or centralised national ID frameworks, often introduce risks that are unnecessary for most civic processes. When identity is tied to state-issued documents or sensitive personal data, participants can be exposed to surveillance, profiling or data misuse. These systems can also exclude people who lack official documentation, who face discrimination when accessing ID services or who rely on anonymity for their safety. Research from Privacy International (https://privacyinternational.org) and Access Now (https://www.accessnow.org) shows that these harms are especially acute in environments with weak safeguards, limited oversight or politicised use of digital infrastructure. For this reason, civil society requires verification models that are proportionate, privacy preserving and appropriate to the local context. The goal is to confirm that a real human is taking part, not to force individuals to surrender their identity in situations where it is neither necessary nor safe.

Approaches to verification that are emerging

As older cues of authenticity disappear, new ways of confirming that a real human is taking part in a digital interaction have begun to emerge. These approaches differ in method and maturity, but they reflect the same underlying reality. Identity can no longer be assumed, so verification has become part of the infrastructure of trust. One approach relies on social trust built over time. In long standing communities such as Debian or Wikimedia, a person becomes credible because others have observed their behaviour and contribution across many interactions.

This makes impersonation harder. The drawback is that this only works in communities where people already have a shared history. It is not a practical solution for large public processes with many newcomers.

Another direction focuses on what is often called proof of personhood. The aim is to confirm that someone is a real, unique human without requiring them to reveal their identity. Different projects take very different routes. BrightID uses a network of people vouching for one another. Proof of Humanity uses short video submissions that others can challenge. The heavily criticised Worldcoin project uses iris scans to generate a unique biometric code. These examples sit under the same broad idea but raise very different questions about privacy, power and control. Some approaches lean on social networks. Others rely on sensitive data. The underlying concept is promising, but the implementations vary in their risks and values.

A third set of methods uses technical signals from devices. Technologies such as WebAuthn and platform attestation systems can distinguish actions performed by a real device from basic automated activity. These tools can reduce simple manipulation but depend heavily on large technology companies and do not resolve questions about who controls the verification layer or how to protect vulnerable participants.

None of these approaches is sufficient on its own. Verification is moving toward a blend of social recognition, technical proof and contextual judgement. Civil society will need to understand how these methods work, not necessarily to build them, but to recognise which systems support privacy, safety and fair participation, and which recreate the very power imbalances they are meant to address.

Risks and ethical considerations

Verification systems can cause harm if they are designed without regard for safety, inclusion or political context. Some approaches require hardware, connectivity or documentation that many people do not have.

Others create centralised databases that could be accessed by hostile authorities. Even privacy preserving systems can create a false sense of security if they are not well understood.

Another challenge concerns governance. Verification systems grant significant power to whoever controls them. Decisions about who is allowed into a process, who appears legitimate or whose participation is restricted carry political weight. These decisions can shape who feels safe to speak and who is excluded.

Civil society needs verification approaches that reinforce rather than undermine its values. This includes transparency about how verification is carried out, clear lines of accountability, protections against misuse and methods that avoid reinforcing social inequalities.