There is an old comic premise where a character has to prove they are human. It used to be science fiction. For anyone running an online survey in 2026, it is the daily job — and it turns out to be genuinely hard, in ways that the obvious solution makes worse rather than better.
The instinct, when you worry about bots, is to reach for a CAPTCHA: the little "click all the traffic lights" or "type these wavy letters" challenge that is supposed to separate people from programs. It feels like a door with a lock on it. The trouble is that the lock no longer works, and it was never on the right door.
The lock no longer works
CAPTCHAs were designed for a world where machines were bad at perception. That world is gone. Modern bots and AI-assisted fraud systems can solve many CAPTCHA-style tasks well enough that the old bargain has collapsed: the test no longer reliably separates people from automation, but it still interrupts real respondents. When your "prove you're human" test creates more friction than confidence, the test is not protecting anything. It is just taxing the real people.
And that tax is not free. CAPTCHAs add friction exactly when response rates are already falling and every abandoned survey is a lost real respondent. You end up in the worst position: annoying the honest majority while waving through the sophisticated minority you were trying to stop.
The lock was on the wrong door
Here is the deeper problem, and the one most "are you a bot?" features miss entirely. The majority of survey fraud today is not bots at all. As NORC's analysis of the current wave makes clear, most of it is human — click farms, rooms of low-paid workers taking surveys for incentives. A CAPTCHA, even a perfect one, does nothing about a real person clicking through your survey in bad faith. They are human. They pass.
This reframes the whole question. "Can you tell a human from a bot?" is the wrong thing to ask, because a click-farm worker is human and a sloppy AI is not the main threat. The question that actually matters is: is this one real, attentive respondent, answering in good faith, once? That is a much richer thing to detect than humanity, and you cannot detect it with a single gate at the door.
What actually moves the needle
The methods that work share two traits: they are layered, and they are mostly invisible. No single signal is decisive, so good detection stacks many weak signals into a confidence score rather than betting everything on one challenge.
Behavioural signals do a lot of the work without bothering anyone: how long someone spends per question, whether answers are pasted in, whether the same device or environment is taking the survey forty times, whether a hidden field is filled, whether the answers follow suspiciously mechanical patterns. Honeypots — fields a person never sees but an automated script will dutifully fill — catch naive bots silently. Internal consistency checks catch respondents whose answers contradict each other or whose claimed profile is statistically improbable. And crucially, all of these can score a response rather than block it, flagging the doubtful ones for review instead of slamming a door in a real person's face.
The most powerful move of all happens before the survey even starts: establishing who someone is up front. Provenance — knowing a respondent came from a verified source or a first-party relationship — does more than any in-survey trick, because identity is settled before the incentive to cheat exists. An in-survey test is always trying to recover information that a better recruitment model would never have lost.
This is not an abstract concern for us. At Dayalogs we care about it enough to have built these ideas into surveys directly — a layer of invisible signals that scores each response's confidence and flags the doubtful ones for review rather than blocking anyone. We mention it because it is exactly the approach this article argues for, not because a score settles anything on its own.
An arms race, not a fix
It would be comforting to end with the technique that solves this. There isn't one. Both NORC and the researchers documenting AI-driven fraud describe the same thing: a war of attrition, where each detection method provokes a new evasion, which provokes a new method. Today's clever consistency check is tomorrow's training data for the fraud operation. Detection is not a wall you build once; it is a process you run forever.
That sounds bleak, but it points at the right posture. Stop looking for the magic question that proves humanity, because it does not exist and the search for it produces friction-heavy gimmicks that catch the wrong people. Instead, raise the cost of cheating with many quiet signals, keep a human in the loop to judge the doubtful cases, and — wherever possible — know who your respondents are before they arrive. You will never be certain a respondent is real. The realistic goal is to make faking it more expensive than answering honestly, and to keep paying attention as the other side adapts.