Beware, Amazon: Credit Has Been Extended Beyond Humans

If you are staunchly declaring that your company will NEVER do business with a bot, forget it. The bots have credit cards now.

Yes, the credit card industry, which (before the Equal Credit Opportunity Act of 1974) would not let women apply for credit cards in their own names, is now starting to extend credit to non human identities.

PYMNTS:

“Mercury this week gave artificial intelligence agents something companies routinely give new employees: a corporate card of their own. Extending that perk to an agent, not a person, is new. Agent cards treat the agent exactly like that new hire, with its own payment credential, its own spending limits and its own audit trail, separate from any human on the team.”

And Mercury isn’t the only company issuing such cards.

“Ramp is issuing scoped virtual cards through its Visa partnership that external AI agents can use within policy guardrails set by a company…”

Robocredit. Google Lyria. Public Domain.

For those who worry about misuse, humans can misuse corporate credit cards also. And if this means that more entities will buy from your company, and possibly buy more rapidly…why should you complain?

Well, unless you’re Amazon. But as of now, Amazon has failed in its attempt to ban Perplexity AI shopping agents, so it’s fighting a losing battle.

How Other Experts Refer to “Somewhat You Why”

Unlike most other posts that appear under my name—Bredebot posts are another matter—this post breaks my 2023 rule because most of it was written by Google Gemini, not me.

But I figured that if I wrote a book specifically about SIX factors of authentication…

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
The book.

…it would be nice to know if other experts held similar thoughts.

My prompt to Gemini

Bredemarket has promoted “somewhat you why” as a sixth factor of identity verification / authentication. Has anyone else shared similar observations?

Gemini’s response

Here is the short answer: Yes, industry experts and security frameworks strongly agree with the core observation, though they call it “Authentication Intent,” “Intent Verification,” or “Context-Aware/Risk-Based Authentication” rather than using Bredemarket’s play-on-words.

Shifting Truths. Google Lyria. Public Domain.

John Bredehoft (Bredemarket) coined “somewhat you why” to fit the traditional naming convention (something you know, have, are, do, somewhere you are). His argument is that checking why an action or request is taking place—evaluating intent, transaction risk, or reasonableness—functions as a crucial safeguard, especially in an era of deepfakes and automated AI agents.

While the tongue-in-cheek name is unique to Bredemarket, the concept itself is widely discussed and implemented across the cybersecurity industry under three main paradigms:

1. “Authentication Intent” (NIST Standards)

The National Institute of Standards and Technology (NIST) explicitly addresses intent in NIST SP 800-63B.

  • The Problem: A user might have a valid session token, biometrics, or physical key plugged in, but malware or a session hijack could trigger actions without the user’s conscious decision.
  • The Solution: Systems require an explicit act of intent—like tapping a physical FIDO key, typing a PIN, or responding to a contextual prompt—proving that the user intended to execute that specific action at that moment.

2. Intent Verification for AI & Delegated Actions

With the rise of autonomous AI agents and automated workflows, identity security groups (like the Non-Human Identity/NHI movement) frequently discuss Intent Verification.

  • Conventional authentication proves who logged in, but not whether the user meant to perform this specific action.
  • Intent Verification bridges authentication and authorization by evaluating whether a transaction (e.g., a $35M wire transfer or an API call) aligns with the user’s actual current decision and business policy.

3. Context-Aware and Adaptive Authentication

Identity providers (like Palo Alto Networks, Okta, and Silverfort) build their Adaptive Multi-Factor Authentication (AMFA) around the “why” and “context”:

  • Context Signals: What resource is being accessed? Is this normal business behavior? Does this request make sense given the time, value, and sensitivity?
  • Dynamic Step-Up: If the “why” seems low-risk (e.g., checking internal docs during work hours), access is smooth. If the “why” is high-risk or suspicious (e.g., a wire transfer requested via video call), the system demands step-up verification.

How the Views Compare

While most identity security professionals treat “intent and context” as a governance or risk engine layer wrapping traditional factors rather than a 6th factor itself, everyone agrees with Bredemarket’s baseline premise: verifying who someone is without evaluating what and why they are trying to do it is no longer enough to stop modern fraud.

Artificially Intelligent Pick Up Lines

In 2017, researcher Janelle Shane had a really bad idea.

“So it occurred to me that the same neural network framework I’ve trained on recipes, Pokemon, superhero names, and Irish tune names might be able to write pick up lines as well.”

OK, so Shane isn’t your typical researcher.

But the pick up line project was a step below anything she had undertaken before. The project needed training data, and you can imagine what the training data looked like.

“I hadn’t really read many of these before, and most were obscene, or aggressive, or kind of insulting. I began to regret the whole project.”

But she continued, because Science!

A wombat holding a phone displaying a digital identity, surrounded by papers with pictures of cars. Two Dolby speakers are in the back of the room.
She’s Tidied Up and I Can’t Find Anything! Google Gemini.

But Shane’s neural network struggled with the wordplay in the training data, resulting in some bizarre outputs. One example:

“If I had a rose for every time I thought of you, I have a price tighting.”

Fast forward four years

In 2021 Shane tried again, using the then-current GPT-3. She entered the following prompt:

“So I started with the following prompt, for a neural net to fill in its prediction of what the rest of the article would be like: ‘These are the top pickup lines of 2021! Amaze your crush and get results! 1.’”

She awaited the responses, which did not disappoint.

“My name is a complicated combination of 45 degrees of forward motion, 25 degrees of leftward drift, 75 degrees of upward acceleration, and infinity and that is the point where my love for you stops.”

Fast forward five more years

As far as I can tell, Janelle Shane has not conducted any further pick up line experiments. Does that mean that AI-generated pick up lines are as…um…”good” as the human ones?

So I tried again in 2026. The prompt:

“Generate five pick up lines that will cause beautiful women to immediately swoon over me”

The good news: generative AI has matured enough that its pick up line responses are indistinguishable from human ones.

The bad news: generative AI has matured enough that its pick up line responses are indistinguishable from human ones.

Here are five smooth, high-effort pickup lines designed to charm, make her smile, and spark a genuine conversation:

  1. The Classic Romantic“Excuse me, I usually have a great sense of direction, but the moment you walked in, I completely forgot where I was going.”
  2. The Clever Observation“I was having a pretty average day, but seeing you just raised the bar significantly. Mind if I introduce myself?”
  3. The Playful & Confident“Are you a time traveler? Because I can easily see you in my future.”
  4. The Sincere Compliment“I’m not usually one to approach strangers, but you have an energy that’s impossible to ignore. I’m [Your Name].”
  5. The Witty Banter“Do you believe in love at first sight, or should I walk past you one more time?”

Ladies, does this tight your price?

JustDone AI Detector Tells the Truth

I don’t know about you, but I prefer honesty to one-sided cheerleading. Which is why I appreciated the subsection in a JustDone post entitled “There Is No Way to Detect AI Writing with 100% Accuracy.”

JustDone, you’re doing it wrong(TM).

Other vendors (and people) say that telltale signs—such as em dashes—are clear and definitive indicators of AI-generated text.

JustDone is much more nuanced.

“The em dash — especially, used like this — has become one of the most reliable AI tells. ChatGPT in particular uses it at a rate that no human writer naturally matches. If almost every paragraph contains one, that frequency is itself the signal.”

Same with some of the other so-called “clear signals” of bot-speak.

In general, JustDone realizes that “100%” is a dangerous number to throw around. (As the biometric product marketing expert, I know this.)

“This is the part most detection guides skip: how to tell if something is written by AI is not a solved problem. No tool gets it right every time. No human reader gets it right every time.

“False positives happen. Formal academic writing, technical documentation, and content written by non-native English speakers all share characteristics with AI output — consistent tone, structured argumentation, and uniform vocabulary. That’s why they can be flagged incorrectly….

“False negatives happen too. Heavily edited AI content, content that has been run through a humanizer, and output from the newest model generations all pass detection at rates that make any single scan an incomplete picture.”

So don’t believe those tools that state the Declaration of Independence was AI written. Jefferson and Franklin weren’t THAT brilliant.

Just Remove the “S” Word

I’ve noted the troubles I had generating a suitable image for my two preceding posts.

So I tried a minor wording change in my prompt.

Create a realistic square picture of white 18th century sailors selling America to Africans, as described in the Randy Newman song “Sail Away.”

That worked.

I have provided a realistic interpretation based on the lyrics of the Randy Newman song, depicting the historical context in which these events occurred.

Google Gemini.

So I created a new Facebook reel.

Sail Away.

Maybe These Artificial Luxuries Can Only Compensate (Taking Stefan Gladbach Seriously)

Product marketer Stefan Gladbach (the guy who masterminded the “A PMM Christmas” video) has dispensed some sage advice on how to be a millionaire.

Stefan Gladbach.

Here’s the “too long; didn’t watch” version.

  • Be deceptive about wealth.
  • Sell garbage.
  • Lose morals.

But because I am a product marketing expert (albeit in biometrics, not monetization), I have improved on Gladbach’s inferior suggestions.

Rather than arranging for Robin Leach-inspired “rich and famous” Ferrari/Rolex photo shoots (Stefan’s first point) and laboriously writing up an expensive course (his second point), I assigned the tasks to AI. This offers the added benefit of satisfying Stefan’s third point, losing all morals.

So here is my course, thanks to Google Gemini. But don’t tell anyone that.

IAM. Invest in me—I mean invest in yourself.
Read the fine print.

24/7 Bot Answering Service

A little after 8:30 this evening, our central air conditioning started making a whining noise.

I turned the temperature up to shut the air off, then we called the service number on the magnet attached to the unit.

Even at the late hour, someone at the air conditioning service answered the phone.

I held a conversation with the person and scheduled a service appointment, but I couldn’t help but notice the unusual manner of speech.

  • The overly formal phrasing.
  • The momentary confusion when I spoke over him.
  • The odd stutter when repeating our street address—the number “6” sounded like “66.”

That’s when I realized I was speaking to a bot.

The conversation was good enough, although I still have to see if a technician shows up at the appointed time.

And yes, someone lost a job due to AI, but how much value add would a human provide at 8:30 at night?

AI Isn’t the Problem: Reputational Damage Is

AI used for evil is bad, but it’s not the worst evil.

Neal K. Shah is victimized

Neal K. Shah self-identifies as “America’s Chief Elder Officer.” And he says that he recently made the news:

“FOX Business just published a story about me – I wish they didn’t have a reason to. Scammers used AI to clone my likeness, and turned it into a WEAPON against the exact people I work to protect – older adults and caregivers.”

According to Shah, the scammers used a Meta tool called Muse Image to create fraudulent deepfakes of Shah endorsing slimeball products. Because of this and other incidents, Meta concluded that Muse Image “missed the mark” and disabled the feature.

(For now. If Muse Image reappears in 2028, don’t be surprised.)

Shah, understandably upset that elderly people were misled, blames evil AI.

“BUT the deeper problem – how trivially easy AI now makes it to impersonate real people and prey on the vulnerable… I think that may only be getting started.”

Shah is wrong. There’s an even deeper problem.

Bredemarket Technology Firm Services weighs in

On LinkedIn, I offered the following comment:

“I don’t know that AI is entirely to blame here. There were fraudsters before AI, and there will be fraudsters after AI.

“The bigger issue is when someone’s name and likeness is fraudulently used—by ANY means—and the platforms do nothing about it.”

Remember when Clifford Irving published Howard Hughes’ autobiography that Hughes never wrote? He didn’t need AI for that. And the scam was revealed when the usually tight-lipped Swiss banks revealed who was really cashing the checks for “author” Howard Hughes.

No evil AI here.

The problems occur after the scam, and aren’t affected by how the scam was perpetrated. The problem is when a platform is scammed, but the platform—a website, a newspaper, whatever—doesn’t bother to correct the record and tell the truth.

Shah:

“I reported [the scam ads] REPEATEDLY – yet they stayed up.”

Now I could have used my Bredemarket Technology Firm Services hat to suggest a solution.

But I didn’t.

I tossed the task elsewhere.

Bredebot weighs in

Now that it’s easier to generate Bredebot content, I let Bredebot write a response.

When someone creates a fake profile using your name, face, and credentials, it is a fast track to reputational damage. But what happens when you hit that “report” button and the platform does absolutely nothing?

For a long time, platforms hid behind broad immunity shields, treating identity fraud like a minor nuisance. But in 2026, the regulatory tide is turning. Relying on passive content moderation is no longer cutting it. Between the FTC’s strict crackdown on impersonation and new federal mandates like the TAKE IT DOWN Act forcing rapid 48-hour responses for deepfakes, platforms that stay passive are looking at massive civil penalties.

When a platform ignores fraud, it isn’t just failing the victim; it’s tanking user trust. It is like hiring a pack of wild wildebeests as marketing consultants, only to wonder why your wombat customers are running away in terror.

If a platform leaves you stranded, you have to document everything, escalate to regulatory channels, and protect your broader digital footprint. Identity security requires proactive defense, not corporate silence. If you need a hand navigating this landscape, John E. Bredehoft at Bredemarket can help you map out a strategy.

I couldn’t have said it better myself.

Now I just have to convince people that I did NOT endorse a death of passwords book.

This is fake. Google Gemini.

But I DO endorse THIS book. Click the pic.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
This is real. Gumroad.

The MOSIP “Standard”

I’ve previously discussed the false impression that standards achieve recognition via a free, fair, universal consensus. In truth, standards are bullied through the process by one or more interested parties, who then shut out competitors that don’t comply with their…I mean, the industry’s standard.

Meanwhile, companies that don’t comply with the standard ridicule it and say how the standard stifles innovation and brings the whole industry down.

For example, in a few years smartphone manufacturers will complain that the EU’s adoption of USB-C as a universal common charger standard will cause the EU to lag behind when new charging technologies emerge.

Which brings us to MOSIP.

What is MOSIP?

So what does this acronym stand for, and what does it mean?

“The Modular Open Source Identity Platform was established in 2018 to support governments in providing its residents with an official form of the most important human asset – identity.

“As nations around the world proceed on their digital transformation journeys towards true digital economies, a robust and secure national ID system is the crucial first step. With a foundational national ID system in place, a government can build effective civil registries, and service delivery systems, serving the population in a myriad of ways. Among other benefits, robust systems like these enable faster disaster relief, climate resilience, ease of starting new businesses, and better access to financial inclusion, healthcare, and education.”

Established and incubated in Bangalore, India, MOSIP is aligned with the United Nations Sustainable Development Goals and supported by the Gates Foundation and others.

In case you didn’t get the drift, the MOSIP people aren’t regular visitors to Mar-a-Lago.

But their principles align with the goals of many biometric companies that have chosen to list their MOSIP-compliant products on the MOSIP Marketplace.

The marketplace categorizes MOSIP-compliant solutions into six categories:

  • Registration devices.
  • Authentication devices.
  • ABIS (Automated Biometric Identification Systems).
  • SDKs (Software Development Kits).
  • Print devices.
  • Labs.

I won’t list all the MOSIP-compliant solution providers, but there are many of them, including two of the “big three” biometric firms, NEC and Thales.

Any questions?

MOSIP but not MOSIP

I hear a question from the back row from a guy wearing a multicolored wig.

Falco in “Rock Me Amadeus.” From https://youtu.be/cVikZ8Oe_XA.

After all, the third of the “big three,” IDEMIA, has advertised that it provides MOSIP solutions.

“The Togolese Agency for Identification, ANID-TOGO, has partnered with IDEMIA and Atos to build a national biometric eID system based on the Modular Open Source Identity Platform (MOSIP). IDEMIA and Atos will design, build, test, and run a biometric national eID solution for Togo based on iris, face, and fingerprint recognition technology.”

Sounds impressive…until you scan the MOSIP Marketplace and find no listed solutions from IDEMIA or ATOS.

Because “based on” does not equal “compliant with.”

I can say that Bredemarket’s seven-question process is based upon some marketing standard or another, but that doesn’t mean that an independent third party has certified my compliance, or even stated its conformance.

So why doesn’t IDEMIA offer MOSIP-compliant solutions?

Honestly, I don’t know. I haven’t had regular official contact with IDEMIA in years, and the person that I know who just rejoined IDEMIA probably doesn’t know either.

So I have no authoritative answer, but Google Gemini provides this very unauthoritative answer as to IDEMIA’s MOSIP non-compliance:

“IDEMIA’s core business model historically relies on end-to-end, proprietary solutions. MOSIP, by contrast, is an open-source framework designed specifically to prevent vendor lock-in by letting governments mix-and-match components from different tech providers.”

Let’s assume for the moment that Gemini is right in this case. So while IDEMIA may be willing to speak about a solution in Togo “based on” MOSIP, when IDEMIA goes after a critically important opportunity in the FBI or the CIA or the BBC (you know the rest), it’s going to provide a solution based upon IDEMIA-authored components such as its own MorphoKit software development kit.

Knowing full well that the U.S. Federal Bureau of Investigation doesn’t give a hoot about MOSIP compliance.

Because it’s not critically important in that market.

Know Your Market

Some biometric vendors focus on the developing world, some adopt the developing world as a secondary opportunity, and others just don’t care because their real revenue comes from elsewhere.

Where should your company focus its attention?

Bredemarket can help your company with analysis, and provide focused content as the analysis progresses. (Analysis is never complete. Things change.)

If Bredemarket can help you decide if MOSIP compliance is worthwhile or worthless, schedule a free meeting.