Understand the risk

AI agents, bots, and AI-assisted people: what is the difference?

Bots, AI agents, fraudulent participants, and AI-assisted people are not interchangeable. They use different paths, create different evidence, and require different responses; a control designed for a simple script may say very little about a person who passes screening and later uses an AI assistant.

Why does the distinction matter?

“Bot” is often used for every unwanted submission. That shortcut hides the actual mechanism. If the mechanism is unclear, teams choose controls that are easy to bypass or exclude the wrong people.

A scripted bot, a browser-controlling AI agent, a person using AI for one answer, and a coordinated survey farm may all produce a completed form. They do not produce the same interaction or require the same response.

A practical taxonomy

Type How the submission is produced Typical integrity concern More relevant evidence
Scripted bot Code sends requests or operates predictable page controls. Volume, spam, repeated submissions Request validity, rate, honeypots, session and device repetition
Computer-using AI agent A model interprets the interface and operates mouse and keyboard controls. Human-like navigation with automated reasoning and generated answers Complete behavioral sequence, task-specific checks, cross-response patterns
AI-assisted person A real person uses AI to draft, translate, summarize, or choose answers. The response may not reflect the person’s own wording or reasoning Study policy, task design, within-response and cross-response evidence
Fraudulent person A person lies about eligibility, repeats participation, or fabricates experience. Incentive abuse or invalid representation Identity and eligibility verification, consistency, duplicate analysis
Hybrid operation People handle difficult steps while software or AI handles scale. Conventional entry checks pass while later work is automated Evidence across access, session, behavior, content, and groups
Inattentive participant An eligible person answers with little care. Low-quality data without automation or deliberate fraud Attention, consistency, timing, task engagement

This taxonomy is about how a submission is produced, not a moral label. A person may use AI legitimately in one process and violate the rules of another.

What is a scripted bot?

A scripted bot follows programmed instructions. It may submit direct requests, populate known fields, click predictable controls, or repeat the same sequence across many sessions. Traditional anti-bot controls are strongest here because the automation often lacks flexible interpretation.

Rate limits, request validation, honeypots, token checks, and browser consistency can remove a large share of simple automation. They are still worthwhile even though they do not settle more advanced cases.

What is a computer-using AI agent?

A computer-using agent interprets what appears on the screen and decides which action to take next. It can adapt to page layout, scroll, click, and type without a custom connection to the form. OpenAI’s computer-using agent demonstrates how current models can perform ordinary web tasks through visual interaction.

This changes detection because the session may contain realistic browser events and flexible answers. Static field names or simple instruction checks are less dependable when the agent can read the same interface as a participant.

What is an AI-assisted person?

A genuine participant may ask an AI to translate a question, improve grammar, recall examples, or generate an entire response. Whether that is acceptable depends on the purpose of the form.

If an application measures the final information only, assistance may be allowed. If a study measures unaided knowledge, personal language, recall, or opinion, assistance may change what is being measured. The policy must therefore be explicit before collection begins.

Research discussed in Communications Psychology shows why this group is difficult: genuine respondents can use AI while remaining real, eligible participants. Blocking “AI-like text” would collapse two separate questions—who participated and how the answer was produced—into one unreliable decision.

What are hybrid operations?

Hybrid operations combine people and automation. A person may pass screening and CAPTCHA, then hand the longer task to software. A coordinated group may use AI to create consistent personas. Automation may pause only when a verification step requires human input.

The NORC review identifies this hybridization as one reason status-quo defenses are insufficient. It also explains why a single entry check cannot protect an entire workflow.

Match controls to the mechanism

  • Use request controls and rate limits against simple automated volume.
  • Use unique access and duplicate analysis against repeated participation.
  • Use interaction and sequence evidence when browser automation is plausible.
  • Use explicit participation rules and task design when AI assistance changes the measurement.
  • Use identity or eligibility verification when the participant’s qualification matters.
  • Use cross-response analysis and human review when coordination is suspected.

What does this not prove?

No taxonomy label can be assigned reliably from one feature. A person can behave mechanically. An agent can introduce delays. A shared device can look duplicated. Polished language can come from education, translation, or AI assistance.

Use the categories to improve the investigation, not to claim certainty that the evidence cannot support.

The question to ask first

Do not begin with “How do we block AI?” Begin with: “What must be true for this submission to be valid?”

That answer determines whether you need to protect human identity, unique participation, unaided judgment, eligibility, response quality, or simply the receiving system from unwanted volume. Only then can the controls fit the risk.

Sources and further reading

  1. OpenAIComputer-Using Agent
  2. NORC at the University of ChicagoFraudulent respondents and bots in nonprobability surveys
  3. Communications PsychologyIdentifying generative AI use among genuine responders in online survey research
  4. ACM Web ConferenceBeyond Bot Detection — Combating Fraudulent Online Survey Takers

External sources open in a new tab.

Behavioral survey fraud detection

Add a Human Score after the survey.

Ramon adds behavioral evidence to survey fraud detection by turning completed online survey interactions into a Human Score. It supports review; it does not prove identity or make an automatic fraud decision.