peach_fotolia - stock.adobe.com
Behavioral biometrics: How to detect nonhuman threat actors
How do security teams distinguish between people and AI? It's getting harder, but behavioral biometrics might help discern human users from machine impersonators.
As Anthropic's Mythos model makes clear, AI is a cybersecurity game changer. When released in preview, Mythos proved unexpectedly effective in finding and exploiting bugs in software. Anthropic said the preview release found more than 10,000 critical vulnerabilities across every OS and application it encountered. In addition to exposing the bugs, Mythos was able to execute an attack chain around each one, including the full attack lifecycle: reconnaissance, exploit and lateral movement.
Mythos isn't alone. Other AIs have been shown to operate autonomously to generate attacks. The Jadepuffer attack discovered in early July 2026, for example, executed a complete ransomware and extortion operation driven end-to-end by an LLM -- no human required.
AI-enabled attacks
It's clear that AI poses an unprecedented threat to cybersecurity. But it's important to note that AI-enabled attacks aren't a separate category of attack; they're classical attacks at unprecedented speed, scale and mutability. They include all the standard types of cyberattacks, such as the following:
- Voice impersonation. AI mimics a trusted party's voice, convincing listeners to make wire transfers or approve other financial transactions.
- Automated phishing. AI generates highly realistic and personalized phishing emails in seconds, increasing the likelihood that targets will click malicious links.
- Intelligent vulnerability scanning. AI identifies software vulnerabilities and creates exploits on the fly.
- Chatbot scams. AI agents engage victims in casual conversations to extract sensitive personal details, login credentials or other confidential information.
Like biological viruses, AI-enabled attacks mutate, and do so at warp speed. This makes response even more difficult, since human defenders respond at human speed. For this reason, AI-enabled attacks have become a priority for CISOs. A recent survey by Darktrace found that 78% of CISOs now say AI-powered cyberattacks are having a significant impact on their organizations.
These attacks aren't hypothetical. Real-world incidents such as the following occur regularly:
- AI-driven phishing. Microsoft threat teams flagged phishing attacks in which AI crafts phishing lures that more easily evade detection by seeming more human. These attacks include realistic personalization and imitation of human grammar and speech.
- Deepfake social media scams. Much of social media is now AI-generated, including propaganda intended to inflame passions, spread lies or solicit money.
- AI-enabled malicious insiders. North Korean operatives use AI to illegally land jobs with U.S. companies, putting enterprise data security at significant risk.
Behavioral biometrics
CISOs and their teams could stymie many AI-driven attacks if they could determine whether an attacker is an AI agent or a human -- an enterprise version of the Turing Test. That's the focus of the burgeoning field of behavioral biometrics. Behavioral biometrics analyze user activity to distinguish humans from AI agents. These technologies work passively in the background, continuously monitoring behavioral parameters during the course of a user session and learning as baseline norms evolve.
Unlike elementary humanity tests such as CAPTCHA, which confirm human identity only at the start of a session, behavioral biometrics can detect whether an entity that previously passed as human is failing to behave as expected, thus indicating a possible session hijack or a sophisticated AI agent.
Another noteworthy component of behavioral biometric technologies is that they aren't static. Physical biometrics such as fingerprints or retinal prints are unique to a specific human being and consistent across the life of that human being. Behavioral biometrics, in contrast, look at the patterns of interaction humans have with technology. These are learned habits that can vary over time and apply to more than a single person.
Behavior biometrics parameters
Most behavioral biometric systems look at multiple parameters. These include but are not limited to:
- Typing patterns. Includes typing speed, typing rhythm, keystroke pressure, dwell time on each key and flight time between keystrokes. Humans are naturally erratic while AI agents are unnaturally precise.
- Mouse movement patterns. Includes speed, acceleration and cursor positioning. Again, human users naturally hesitate and correct mouse movements, while AI agents perform with machine precision.
- Touchscreen gestures. Show how users swipe, scroll and tap on mobile devices. These movements can demonstrate unique interaction styles specific to individuals. Similarly, behavioral biometric systems can track how users hold and orient their mobile devices while using them. By capturing accelerometer and gyroscope data, these systems can distinguish between human and synthetic device movements.
- Navigation analysis. Tracks how users move through applications and websites and complete various tasks, including page visit duration, task sequencing and form completion.
- Gesture and movement analysis. Tracks how users adjust posture and movement while working. This can include hand positioning, head movement and eye tracking. Gesture recognition analyzes intentional hand and finger movements users make during video interactions.
These parameters can be combined with a virtually infinite array of other parameters to confirm that a given user is, in fact, human and that they are the particular authorized human. Other parameters might include geographic location, IP address and device type. For instance, an alert would trigger if an employee in New York who has never logged in on a mobile device suddenly shows up on a phone in Los Angeles.
How behavioral biometric systems work
The beauty of behavioral biometric systems is that they work in the background, without interfering with the user experience. The systems automatically capture device information such as keystroke timing, mouse coordinates, touchscreen pressure and device position. A centralized system then analyzes the collected data to build comprehensive behavioral profiles in the aggregate and for individual users, identifies patterns, establishes baselines and calculates normal behavior ranges. Constantly comparing user behavior against established profiles, the system then flags deviations from established patterns and triggers responses ranging from contacting the user to blocking the session.
What's next for security teams?
The early use of behavioral biometrics shows promising results. In the financial sector, Mastercard's 2025 payment fraud prevention research found that 42% of issuers saved more than $5 million in fraud attempts over two years using behavioral biometrics.
In e-commerce and online retail, organizations already use behavioral biometrics to identify bot attacks, credential stuffing and account sharing, as well as to prevent inventory hoarding, coupon abuse and payment fraud. Manufacturing companies and other organizations with high-value intellectual property use behavioral biometrics to protect facilities and detect and protect against AI-enabled insider threats.
What can CISOs do to implement behavioral biometrics to protect against AI-enabled attacks in their own organizations? Here are four recommendations:
- Select specific use cases with clear quantitative metrics and goals.
- Select a set of parameters to implement initially, with others to come later.
- Assess wisely, looking for systems that focus on your particular use case and integrate with your existing and future systems. You can minimize human effort by integrating into existing dashboards and automated systems.
- Continuously monitor and tweak behavioral biometrics tools to optimize results, remembering that these aren't set-it-and-forget-it technologies.
Johna Till Johnson is CEO and founder of Nemertes Research, where she sets research direction and works with strategic clients.