Manav.id
Research · 14 min read

Detection debt: the obituary the detection vendors wrote themselves

An entire security industry is built on estimating whether a signal is genuine. That estimate is getting worse as generation gets cheaper, and spending is rising to compensate. That is not an investment, it is a debt, and the clearest evidence for it was written by the vendors themselves.

It is renewal season at a mid sized bank, and the head of fraud has three quotes open on her desk. Bot management, up nineteen percent. Device intelligence, up twenty two percent. A new line item for deepfake detection on the voice channel, which did not exist in last year's budget at all. She needs a paragraph of vendor language for the business case, the kind of sentence you paste into a slide so the committee nods and moves on.

So she opens the vendor's own website, scrolls past the logos, and reads a line of marketing copy explaining that the industry's traditional device fingerprinting techniques are becoming unreliable, because browser makers are deliberately restricting them and attackers can emulate them anyway.

She reads it twice. It is on the homepage. It is not buried in a whitepaper or hedged in a footnote. A company that sells detection has written down, in its own shop window, that a core detection technique is running out of road. And she is about to sign a renewal for nineteen percent more of it.

That moment, repeated across thousands of budget cycles, is what this piece is about. Not a conspiracy, and not incompetence. Something more interesting: an entire category of control that has been quietly telling you it has reached its limit, while the invoices go up, because the buyers have no vocabulary for the alternative.

Short answer. Detection still works for triage, for volume, and for known patterns. It is failing as a last line of defence wherever an attacker can forge the signal being graded, because generation improves faster than classification and the attacker gets unlimited attempts. The clearest evidence is the public record of detection vendors and platforms conceding it. The alternative is not better detection. It is a control that does not estimate.

What is detection debt?

Detection debt is compounding expenditure on classification against a declining classification rate, where the decline is structural rather than a product quality problem.

Each word is doing work, so take them one at a time.

Compounding expenditure, because detection budgets rarely shrink. When a detector misses, the remedy offered is another detector, or a higher tier of the same one, or a second vendor to cover the first vendor's blind spot. Nobody proposes removing a layer, because no layer can be proven unnecessary. Spend accretes.

Declining classification rate, because the thing being classified is getting cheaper to forge. A deepfaked voice cost a research lab a month in 2019 and costs a consumer a coffee today. A synthetic face that defeats a liveness check was a novelty and is now a product with a support channel.

Structural rather than a product quality problem, and this is the part that matters most. If detection were failing because vendors were lazy, better vendors would fix it. It is failing because of the shape of the contest. The defender must classify correctly every time on a signal the attacker fully controls, while the attacker needs one success and can iterate against the detector as many times as they like, observing the result each time. No amount of engineering talent changes that arithmetic. It is the same reason nobody builds a spam filter that is right one hundred percent of the time, except the stakes moved from a cluttered inbox to a wire transfer.

The counterfeit note analogy, and where it stops being an analogy

For most of the history of paper money, anti counterfeiting was a detection problem. Central banks made notes intricate, and bank tellers, shopkeepers and eventually machines learned to spot the fakes. The system worked because producing a convincing note required a press, a plate maker, specialist inks, and a skill set that took years to acquire. Detection was viable because forgery was expensive.

Then high quality colour printing and scanning became cheap and domestic. The response of the world's central banks was not, notably, to hire better inspectors or fund a decade of research into improved fake spotting. It was to change the note. Holographic patches, embedded threads, colour shifting ink, polymer substrates, microlenses. Every one of those is the same design move: stop asking whether the note looks right and start requiring a physical feature that the attacker cannot manufacture at any plausible cost.

That is the move this piece is arguing for, and the analogy holds tightly right up to the point where it becomes literal. In the digital case the unforgeable feature is a private key held in hardware on a device the attacker does not have. The attacker can copy your face, your voice, your writing style, your device fingerprint, your session cookie and your email domain. They cannot copy a signature they cannot compute.

What did the detection vendors actually admit?

The strongest case against detection is not made by companies selling an alternative. It is in the public record of the detection industry and its customers, and it accumulated with remarkable speed across 2025 and 2026. What follows is that record. Each item is presented as evidence rather than as a gotcha, because in every case the organisation involved was being commendably honest, and honesty is what makes the pattern visible.

The fingerprint vendors

Device fingerprinting is the quiet backbone of a great deal of bot management and fraud scoring: assemble enough entropy from the browser, the device, the fonts, the canvas rendering and the network, and you can recognise a returning visitor without a cookie. It has been a workhorse for over a decade.

It is now being squeezed from both directions at once, and the vendors say so. Marketing copy from at least one major bot mitigation provider has acknowledged that traditional fingerprints are losing reliability, because browser vendors are actively closing the interfaces that leak entropy and because attackers can emulate a plausible fingerprint at scale. We are paraphrasing rather than quoting, because homepage copy changes and we would rather you check it yourself than trust our transcription. Go and read the front pages of the bot management vendors you use. Look for the paragraph explaining why their newer technique is needed. That paragraph is an obituary for the older one.

The squeeze is real regardless of any single sentence. Privacy work in the major browsers has spent years reducing passive fingerprinting surface, and that work is a public good, deliberately pursued, and not going to reverse. Meanwhile the commercial anti detect browser market exists precisely to produce convincing synthetic fingerprints on demand. A signal that the platform is suppressing and the adversary is manufacturing is not a signal with a long future.

The platform that stopped grading traffic

In January 2026, Deezer announced that it was demonetising fully AI generated music streams, having concluded that a large majority of the streams attached to such tracks were fraudulent (Deezer newsroom, January 2026). Reporting around the announcement described AI generated uploads running into the tens of thousands of tracks per day and forming a substantial share of new uploads, while the fraudulent streams themselves remained a low single digit percentage of total listening.

Read that as an engineering decision rather than a music industry story, because it is one of the most consequential public data points available. Deezer had detection. It had built and shipped its own AI music identification tooling, and had been labelling AI generated albums before anyone required it to. With that detection running, the fraudulent share of streams on fully AI generated tracks was still overwhelming. So the company stopped trying to grade individual streams and changed the payout rule for the category instead.

That is a platform concluding that per event classification was not going to get there and switching to a structural remedy. It is the single clearest example in recent memory of an organisation with good detection choosing not to rely on it.

The maintainers who closed the door

In January 2026, the curl project ended its bug bounty programme. The maintainer's explanation, echoed across the reporting at the time, was not that the reports were malicious but that the volume of low quality, frequently AI generated vulnerability submissions had made triage unsustainable for a small team (curl project, January 2026, widely reported including by The Register and BleepingComputer).

The complication that makes this genuinely interesting, and that a one sided account would omit, is that AI assisted security research also produces real findings, and platforms have reported substantial year over year growth in valid AI assisted vulnerability discoveries. Both things are true at once. The tooling generates real value and real noise from the same source, and the cost of separating them falls entirely on the reviewer.

curl did not respond by building a better slop classifier. It removed the incentive that was attracting the volume. Again: a structural remedy, chosen by capable engineers, over a detection remedy.

The contact centres

Industry surveys of contact centre leaders through 2025 and 2026 have repeatedly found two things together: that voice deepfakes rank among the threats they are most concerned about, and that a majority do not believe they could reliably detect one (survey findings reported by CX Today and by vendors including Corsound). Treat those as survey findings with the usual caveats about self selection, because they are.

Even heavily discounted, the shape is the point. The people operating the control are telling you the control does not work. A voice authentication system whose operators believe it cannot distinguish a clone is not a security control, it is a queue management feature with a security story attached.

The identity verification vendors

Identity verification providers have published research on injection attacks, where synthetic frames are fed directly into the capture pipeline through a virtual camera or a modified application rather than presented to a real camera. Yoti has reported injection attack volumes in the millions across 2025, with a pronounced spike coinciding with the United Kingdom's Online Safety Act age assurance duties taking effect. Group-IB, in a January 2026 report, documented thousands of biometric injection attempts against liveness checks at a single financial institution over an eight month period (Group-IB, Weaponized AI, January 2026).

These are vendors publishing evidence that the attack class most damaging to their own product category is scaling. That is admirable transparency, and it is also, read plainly, a category admitting that the camera is no longer evidence. We have written about the mechanics of that shift separately in the camera is no longer evidence.

The pattern

Five independent domains: bot management, music streaming, open source security, voice authentication, identity verification. Five organisations with no shared interest, all reporting the same thing in the same eighteen months. In three of the five, the organisation responded by changing a structural rule rather than improving a classifier, which is the tell. When capable teams with working detection choose to change the rules of the game instead, they are telling you what they think of their odds.

Why does detection lose when the attacker can forge the signal?

Detection is not doomed everywhere. The claim needs to be bounded or it is not worth making. Detection degrades toward uselessness when three conditions hold together, and holds up perfectly well when they do not.

Condition one: the attacker controls the signal being graded. If the thing you are classifying is produced entirely by the adversary, such as a video frame, an audio sample, a browser fingerprint, a written report, or a session token, then the adversary can shape it until it passes. If the signal is partly outside their control, such as the physics of a card present transaction or the routing of a payment network, detection retains real traction.

Condition two: generation improves faster than classification. This is the generative AI effect, and it is asymmetric for a structural reason: the generator can be trained against the detector, and often is, while the detector can only be trained on generations it has already seen. The classifier is always fighting the previous model.

Condition three: the attacker gets unlimited attempts with feedback. Online systems tell the attacker whether they passed. That single bit of feedback, repeated cheaply, is an optimisation loop. Anything that can be probed can be tuned against.

Where all three hold, and they hold for deepfakes, injected video, emulated fingerprints, cloned voices, generated text and stolen valid sessions, the detector's accuracy converges toward the coin flip and its marketing claims become unfalsifiable, for the reason set out in the next section.

Why can nobody audit a detection vendor's accuracy?

Here is a question worth putting to your next renewal call, and it is not rhetorical. Ask your detection vendor for their miss rate in your production environment. Not their benchmark accuracy on a research dataset. The proportion of real attacks against your systems, over the last year, that their product did not flag.

They cannot tell you. Not because they are hiding it, but because nobody can compute it. The number is unobservable in principle.

Think about a burglar alarm. At the end of the year you know exactly how many times it went off. You know how many of those were the cat. What you do not know, and cannot know, is how many people walked past the house, looked at it, and were not detected because they never triggered anything. The only performance data an alarm generates is the set of events it caught, which is by definition the complement of the set it missed.

Detection systems have exactly this shape. The measured true positive rate is a count of caught attacks. The miss rate requires knowing about attacks that were not caught, which you learn about only through some other channel: a customer complaint, a loss written off, a regulator, a journalist, a researcher, or a breach disclosure eighteen months later. And every one of those channels is itself a biased sample, weighted toward attacks large enough to be noticed.

The consequence is uncomfortable and worth sitting with. A detection product that is getting worse and a detection product that is working perfectly can produce identical dashboards. Alerts down could mean fewer attacks or more misses. There is no internal signal that distinguishes them. This is why the vendor admissions in the previous section carry so much weight: they are among the very few data points in the entire category that are not generated by the detector grading its own homework.

Loss categoryMature detection deployed?Can the attacker forge the graded signal?Reported outcome trend
Business email compromiseYes, email security is a decades old categoryYes, the message comes from a real compromised account$3.05B in reported 2025 US losses, up on 2024 (FBI IC3)
Account takeoverYes, risk scoring and device intelligenceYes, a stolen valid session is indistinguishable from the userOver $262M reported since January 2025 (FBI IC3 advisory, November 2025)
Invalid ad trafficYes, an entire verification industryYes, traffic is fully attacker generatedVendor estimates of annual losses range from tens of billions to $165B, and disagree wildly
Identity verification at onboardingYes, liveness and document checksYes, via injection into the capture pipelineInjection attack volumes reported in the millions for 2025 (Yoti)
Streaming royalty fraudYes, including the platform's own AI identificationYes, streams and tracks are both generatedCategory demonetised after detection proved insufficient (Deezer, January 2026)
Card present payment fraudYesNo, the chip cryptogram is not forgeable at scaleStructurally suppressed since EMV migration

The last row is the control group, and it is the most important line in the table. Card present fraud did not fall because the industry got better at spotting suspicious purchases. It fell because EMV put a cryptographic operation in the card that a counterfeiter cannot perform. The payments industry already ran this experiment, at enormous cost, and reached the conclusion this piece is arguing for. The rest of the table is the set of places where that lesson has not yet been applied.

Where does detection still genuinely win?

A piece that claimed detection was worthless would be wrong, and would deserve to be ignored. Detection remains the correct tool for a large share of the work, and any security programme that removed it would immediately regret it.

Volume suppression. The overwhelming majority of hostile traffic is unsophisticated, automated, and cheap to filter. A rate limiter and a decent bot score remove an enormous amount of nonsense for almost nothing. Nobody should sign every request.

Triage and prioritisation. When a human analyst can review fifty cases a day and ten thousand arrive, a ranking function is not optional. Detection is excellent at ordering a queue, and ordering a queue is most of operational security.

Known pattern matching. Signatures, indicators, known bad infrastructure, previously seen fraud rings. When the pattern is genuinely known, matching it is cheap and effective, and always will be.

Post hoc investigation. After an incident, the telemetry that detection systems collect is often the only way to reconstruct what happened and scope the blast radius. That value is real and independent of whether the detector fired at the time.

Domains where the attacker does not control the signal. Plenty of fraud problems involve physical goods, real world logistics, or network level facts that the adversary cannot fully fabricate. Detection has a long future there.

The bounded claim, then, is this: detection is a fine first filter and a poor last line. It should not be the thing standing between an attacker and an irreversible, high value action, in any domain where the attacker can forge the signal being graded.

What does a control that does not estimate look like?

The alternative to a better guess is not a perfect guess. It is a different kind of question.

A detection control asks: does this look like the legitimate user? That question has a probability as its answer, and probabilities can be pushed around by an adversary with enough attempts.

A deterministic control asks: did the legitimate user produce a value that only they could produce, over this specific action? That question has a yes or a no as its answer, and no amount of adversarial effort changes it, because the answer depends on possession of a private key rather than on resemblance.

Concretely, for a payment release: instead of scoring the session, the release endpoint requires a fresh signature from the approver's enrolled device over the exact payload of this payment. Here is what actually gets signed, and it is worth looking at closely, because the specificity is the whole point.

canonical = {
  "action":    "payment.release",
  "amount":    "48250.00",
  "currency":  "GBP",
  "payee":     "Northgate Supplies Ltd",
  "account":   "GB29NWBK60161331926819",
  "requestId": "PR-2026-09-4471",
  "issuedAt":  "2026-09-18T09:14:02Z"
}

challenge = SHA256(canonicalJSON(canonical))
assertion = navigator.credentials.get({
  publicKey: { challenge, userVerification: "required" }
})

Note what the attacker has to defeat. Not a model's opinion about whether the session looks normal. The private key on the approver's device, plus the device unlock, for this amount, this payee, this account, this request. Change any field and the challenge changes and the signature is invalid. A deepfake on the video call cannot produce it. A stolen session cannot produce it. A convincing email from the real compromised mailbox cannot produce it.

The verification side is equally boring, which is the compliment it deserves:

ok = ed25519.verify(receipt.signature,
                    SHA256(canonicalJSON(receipt.payload)),
                    publishedKeyFor(receipt.keyId))
# no callback, no vendor availability dependency,
# verifiable by the bank, the auditor and the insurer,
# today and in seven years

We have written up the transaction binding mechanics in more detail in passkeys prove you logged in, who signed the wire, and you can try the flow in the signing demo or read the integration in the developer documentation.

How do you calculate your own detection debt?

Here is a metric you can actually compute, this quarter, from data you already have. It is deliberately crude, because a precise number would be false precision, and the value is in the trend rather than the level.

For a given loss category, over the same period, year on year:

  D = (spend growth on detection controls)
      - (reduction in realised losses)

  D > 0  : detection debt is accumulating
  D <= 0 : the spend is buying outcomes

Worked example, one bank, card not present fraud, FY25 to FY26:
  detection spend           +19%
  realised net fraud losses  +4%   (i.e. reduction of -4%)
  D = 19 - (-4) = 23 points of detection debt

Then ask the question the number does not answer:
  of the losses that got through, how many involved a signal
  the attacker fully controlled?

That final question is the one that turns a budget metric into a design decision. Split your realised losses into two buckets. In bucket one, the attacker forged a signal your controls were grading: a cloned voice, an injected video, an emulated device, a stolen session, a compromised but genuine mailbox. In bucket two, everything else, including the losses where a real, authorised human was deceived into acting knowingly, which no signature can prevent and which we are careful about elsewhere in this series.

Bucket one is your addressable set. It is the portion of your losses where a deterministic control would have produced a different outcome, and it is usually far larger than a security team expects before they do the exercise. We ran a version of this against the published national numbers in the twenty billion dollar re-read, including the categories where the honest answer is that no signature would have helped at all.

What this argument does not prove

Every piece in this series carries a section like this, because the alternative is marketing. Here is what the detection debt argument does not establish.

What to do this week

  1. Compute D for your two largest loss categories. Detection spend growth minus loss reduction, year on year. Two numbers you already have. Take the result to your next budget conversation.
  2. Split last year's realised losses into forgeable and non forgeable. For each loss, ask whether the attacker controlled the signal your controls were grading. The ratio tells you how much of your problem is addressable by a deterministic control.
  3. Ask every detection vendor for their production miss rate. Not benchmark accuracy. Their answer, and how they handle the question, is diagnostic. A good vendor will explain why the number is unobservable, which is the correct answer and a sign of an honest partner.
  4. Read your vendors' own homepages and archive them. Save them to the Wayback Machine with a date. Marketing copy is the most candid public document most security companies produce, and it changes without notice.
  5. List your irreversible actions. Payment release, payee changes, credential resets, bulk data export, production deletion, privilege elevation. That list is short, and it is where deterministic controls belong.
  6. Pick one and pilot a signature on it. One action class, one team, one quarter. Measure the friction honestly, including the support tickets. If the friction is unacceptable, you have learned something real and cheap.
  7. Stop buying a new detector as the response to a detector missing. At minimum, make the case for the additional layer explain why this one will not have the same structural problem.

Frequently asked questions

Does bot and deepfake detection still work in 2026? For volume filtering, triage and known patterns, yes, and it remains worth paying for. As the last line of defence against a determined attacker who can forge the signal, the evidence is against it, and the clearest evidence comes from detection vendors and platforms describing the limits of their own techniques through 2025 and 2026.

What is detection debt? Compounding spend on classification against a declining classification rate, where the decline is structural rather than a product quality issue. You can estimate it as detection spend growth minus realised loss reduction, year on year, for a given loss category. A positive number means the spend is not buying outcomes.

Why can nobody measure how many attacks a detector misses? Because the miss rate is unobservable in principle. A detector only generates data about events it caught. Misses become visible through some external channel such as a customer complaint or a breach disclosure, and every such channel is biased toward attacks big enough to notice. A worsening detector and a working one can produce identical dashboards.

Is device fingerprinting still effective? It is being squeezed from both sides. Browser vendors are deliberately reducing passive fingerprinting surface as a privacy measure, and a commercial anti detect browser market exists to manufacture convincing fingerprints. Several bot management vendors now acknowledge the technique's declining reliability in their own materials while selling newer approaches.

Why did curl end its bug bounty programme? The maintainers reported in January 2026 that the volume of low quality, frequently AI generated vulnerability submissions had made triage unsustainable for a small team. Notably they removed the incentive rather than building a classifier to filter submissions, which is a structural remedy chosen over a detection remedy.

What is the alternative to fraud detection? A control that does not estimate: requiring a value only the legitimate human can produce, cryptographically bound to the specific action. The answer is yes or no rather than a probability, and it does not degrade as generation improves. It costs user friction, so it belongs on a small set of irreversible, high value actions rather than everywhere.

Should we remove our detection layers? No. Detection and deterministic controls are complementary. Detection handles volume and ranking cheaply. A signature handles the small number of actions where being wrong is expensive and irreversible. The error is not having detection, it is having only detection in front of a wire transfer.

Sources

  1. FBI Internet Crime Complaint Center, 2025 Internet Crime Report, for business email compromise and total reported loss figures. ic3.gov
  2. FBI Internet Crime Complaint Center public service announcement on account takeover fraud, November 2025. ic3.gov
  3. Deezer newsroom, announcement on demonetising fully AI generated music streams, January 2026. newsroom-deezer.com
  4. curl project, bug bounty programme wind down and maintainer commentary, January 2026. curl.se and the project repository at github.com/curl/curl
  5. Reporting on the curl decision, The Register and BleepingComputer, January 2026. theregister.com, bleepingcomputer.com
  6. Group-IB, Weaponized AI report on biometric injection attempts against liveness checks, January 2026. group-ib.com
  7. Yoti published research on injection attack volumes during 2025. yoti.com
  8. Microsoft Security Blog, research on adversary in the middle phishing and device code phishing campaigns, 2026. microsoft.com/security/blog
  9. Contact centre survey findings on voice deepfake concern and detection confidence, as reported by CX Today and by Corsound. cxtoday.com
  10. Anura, executive briefing on invalid traffic rates and estimated advertiser losses, 2026. anura.io
  11. hCaptcha and other bot management vendors, current product and homepage materials. Archive them with the Internet Archive before citing, as marketing copy changes without notice.
Ask your detection vendor for their production miss rate. The reason nobody can answer that question is the entire argument.