Apple says it is building Real User Indicator, a new tool for developers that uses on-device intelligence to detect bot-like activity during new account signups
Nick Statt / The Verge : Tweets: @nickstatt Tweets: Nick Statt / @nickstatt : Some news from the usually sleepy and code-filled Platforms SOTU At #WWDC19. Apple is making an on-device bot test called Real User Indicator. Says it won't violate user privacy, but will let a dev know when a new account seems fishy and maybe automated. https://www.theverge.com/...
Context & Ripple Effects
Real User Indicator lands at WWDC19 alongside Sign In with Apple, Apple's masked-email login service that becomes mandatory for iOS apps offering third-party logins — together they extend Apple's push to rebuild identity infrastructure for a post-Cambridge Analytica privacy environment, this time targeting not who signs in but whether a human did.
The shared design choice is that the computation stays on the device: the tool flags bot-like signup behavior to developers without shipping personal data off the phone, a template Apple later scales up in its plan to analyze user data on-device against synthetic data to improve AI.
First-order effects
- Developers get a privacy-preserving fraud signal at account creation — they learn a signup looks automated without ever receiving the underlying user data, closing a gap that previously forced them to choose between detection and privacy compliance.
- Bot networks that mass-register accounts through iOS apps now face an on-device classifier at exactly the moment their activity begins, raising the cost of fake-account farming on Apple's platform specifically.
Second-order effects
- Sign In with Apple's mandatory status means the bot-detection signal rides along with the login service Apple is already forcing into iOS apps' authentication flows, pressuring incumbent third-party login providers to offer comparable fraud signals without raw data export.
- Developers currently paying for external bot-detection and CAPTCHA services on iOS signups have an incentive to shift that spend toward the free platform-provided signal, squeezing vendors whose product is precisely what Apple just commoditized for this surface.
Third-order effects
- If the pattern holds — on-device intelligence for Siri's crawler heritage, signup screening, and eventually AI training data — trust and abuse decisions migrate from app developers' servers into the operating system, making the platform vendor the de facto arbiter of whether a user is human.
- That consolidation points toward proof-of-personhood becoming an OS-level feature, where verification is computed locally and attested outward, reshaping how regulators and developers think about what 'user data' even is.
The trend: Platform vendors are moving identity-trust and anti-abuse computation onto the device, letting Apple and peers verify humanity without collecting the personal data that verification used to require.