Every business in this atlas sells the same underlying promise: that the person who produced the output is who they said they are, did the work themselves, and did it once. All three limbs of that promise are under documented, active attack, and the strongest technical defence against the first two is about to become unlawful for a quarter of the likely supply pool.
The threat that changed procurement: DPRK IT workers
This stopped being exotic and became a hiring-controls checklist item.
Christina Chapman was sentenced to 8.5 years in July 2025 for running an Arizona "laptop farm" hosting company-issued devices for North Korean remote workers defrauding Fortune 500 employers [WEAK — Politico, The Record, Fortune, NPR, 24–25 July 2025]. Two US nationals were sentenced in April 2026 for the same scheme in New Jersey [WEAK — The Record, 16 April 2026]; a Ukrainian national got 5 years in February 2026 for facilitation [WEAK — CyberScoop, 19 February 2026]. OFAC designated a DPRK IT-worker network in March 2026 [WEAK — The Hacker News; TRM Labs].
The operationally important item is the most recent: an eleven-nation joint advisory in August 2026 warned that DPRK IT workers are using real-time deepfakes to beat hiring checks [WEAK — Tech Times, 2 August 2026].
That single sentence invalidates the standard control. A live video interview with a human on the other end — the exact mechanism Mercor built its funnel on and Handshake uses to vet contributors — is no longer proof of identity. The market has priced this in: Deel acquired the deepfake-detection startup Clarity in August 2026 specifically because of the fake-hire problem [WEAK — The Next Web, 4 August 2026].
The sanctions consequence is what makes this existential rather than annoying. OFAC is effectively strict liability. Paying a sanctioned person through a payout rail is a violation whether or not you knew, and your PSP will freeze funds and file. A crowd operator running 30,000+ contributors across 45+ countries is running a sanctions-screening business whether it thinks so or not.
The person is real but the work is not
The second failure mode is contamination: a verified human who outsources the task to a model.
The canonical measurement is old and probably conservative. On Amazon Mechanical Turk, 33–46% of crowd workers used LLMs on an abstract-summarisation task, detected by combining keystroke analysis with synthetic-text classification (Veselovsky, Ribeiro & West, arXiv:2306.07899). That was 2023, before the models were good and before the workers were practised.
What it looks like in a real vendor's operations: Inc obtained internal logs showing Scale's "Bulba Experts" programme for Google's Bard and Gemini was overrun by spam for eleven months, March 2023 to April 2024 — contributors using ChatGPT despite an explicit prohibition, writing gibberish, faking required advanced degrees, non-native speakers on English-fluency projects, accounts logged 18+ hours daily implying shared credentials, and one incident where "the Allocations Department had dumped 800 spammers into our team" (Inc). Scale says safeguards caught the spam before delivery.
Eleven months is the number to hold on to. Not that it happened — that it ran for eleven months inside the sector's largest and best-resourced vendor, on its largest customer's flagship programme.
The other two vendors have left their own evidence. Mercor ran a public Kaggle competition to "identify candidates exhibiting cheating behavior during interviews using behavioral signals and social graph structure" (Kaggle) — you do not crowdsource your fraud-detection research on a problem you have solved. And Handshake's stated grounds for deactivating contributors include credential discrepancies, work performed outside the declared country, and task completion times 3–4x the benchmark (AOL/Business Insider) — which is a timing-outlier detector being used as a cheating detector, with pay forfeiture as the penalty.
For a lab buying "verified human expert" data, undetected LLM contamination is the worst possible product defect, because it is silent and it inverts the purchase. Human preference data contaminated with model output is not degraded data — it is self-distillation sold at $100/hour. The buyer cannot detect it downstream and the vendor's incentive to look hard is weak. That asymmetry is why the premium for verified human work is fragile.
Note also that deactivation-as-enforcement is now a litigation surface in its own right: the Handshake pay-withholding cases, the Mercor fraud-and-contract docket wave, and after 2 December 2026, Art. 11 of the EU Directive requiring written reasons for every refusal to pay. See the classification page.
Multi-accounting, and the ad side where nobody even pretends
On the creator side the fraud is not hidden — it is the business model. MediaMaxxing's own homepage case studies advertise creators earning across 17 to 20 accounts each (MediaMaxxing). X's platform-manipulation policy caps accounts at 10, distinct purposes only, and bans coordinated engagement exchange outright (X); X reported suspending ~800 million accounts in a year over spam and manipulation [WEAK — The Guardian, 9 March 2026].
And the unit being sold is unverifiable by construction: clippers are paid per 1,000 views with no mechanism separating authentic from bot views. Content Rewards' Daniel Bitton calls bot fraud "the single biggest threat" to the model and concedes the incentive structure is permanently problematic (TechBuzz). The hard numbers:
| Measure | Figure | Source |
|---|---|---|
| Invalid traffic, Q1 2026 | 18.12% across 26.3 billion ad impressions | Fraudlogix, cited by FORKOFF [WEAK] |
| Fake/bot followers | 56.5% of reported creator-marketing fraud issues | Influencer Marketing Hub 2026, same source [WEAK] |
| Documented campaign | $2,000 spend, ~40 submissions over 3 days, ~90% apparent bot traffic | same source [WEAK] |
| Programmatic fraud generally | 10–30% of volume | TechBuzz |
The arithmetic that follows is the point. A $1 CPM at 50% bot is a $2 CPM; at 90% it is a $10 CPM, which is worse than the paid social it was supposed to undercut. The 18.12% figure is general programmatic rather than clipping-specific, and no independent audit of clipping bot rates exists — which is itself the finding.
The constraint that forces a two-track stack
Here is where the design problem gets genuinely hard rather than merely expensive.
Art. 7(1)(f) of Directive (EU) 2024/2831 prohibits platforms from processing "biometric data… of a person performing platform work to establish that person's identity by comparing that data to stored biometric data of natural persons in a database." Art. 7(2) applies the prohibition "from the start of the recruitment or selection procedure." Art. 7(1)(c) separately bars collecting personal data "while that person is not offering or performing platform work" (EUR-Lex CELEX:32024L2831).
Periodic 1:N face re-verification against your enrolled gallery is the single most effective control against both DPRK substitution and multi-accounting. It is the one thing that catches a deepfaked interview enrolled under one name reappearing under three others. And for EU-resident contributors it becomes unlawful on 2 December 2026. Always-on screen or keystroke monitoring outside task time is unlawful regardless of geography. LLM-based sentiment or engagement scoring of workers is prohibited under Art. 7(1)(a).
You need two identity stacks, not one. Outside the EU: document plus liveness verification, sanctions screening, and periodic 1:N gallery re-matching. Inside the EU: document verification and 1:1 liveness only, with behavioural signals — keystroke and timing distributions, paste-event detection, completion-time outliers, device and ASN clustering, gold-standard task injection, inter-annotator agreement drift, and payment-graph analysis for accounts converging on one payout instrument — carrying the load the biometrics used to carry. The 1:1-versus-1:N reading turns on "comparing that data to stored biometric data… in a database" and is an interpretation, not settled law [UNVERIFIED — get an EU privacy opinion]. Either way, the EU pool costs more to police and catches less.
Costs, in the right order of magnitude. Persona lists Essential from $250/month on a 12-month minimum, priced per successful verification with no charge on drop-off, bundling government ID, selfie, phone/email, and watchlist and sanctions screening (Persona); per-verification unit prices are quote-only, with an industry range around $0.50–$2.50 per completed check [UNVERIFIED]. Budget roughly $1–3 per worker for onboarding IDV, 5–15% of task volume as gold-standard overhead, and a trust-and-safety headcount ratio near 1:200–1:500 active contributors [UNVERIFIED — practitioner estimates, not sourced].
The risk everyone assumes and nobody has evidenced
The security conversation with a lab customer is always about the crowd leaking the lab's data. No clean, well-sourced example of that happening was found. The adjacent verified facts run the other way: the enforceable confidentiality remedy in this sector has been company-versus-company, in Scale AI, Inc. v. Mercor.io Corporation, 3:25-cv-07402 (N.D. Cal., 3 September 2025), a Defend Trade Secrets Act claim naming a departing individual alongside the competitor.
And the one large documented breach ran in the opposite direction — the operator lost the workers' data. Mercor's March/April 2026 incident exfiltrated ~4TB including SSNs, dates of birth, passports, biometric face and voice data and recorded interviews, attributed to a supply-chain attack via LiteLLM and claimed by Lapsus$, producing six class actions and a pause in Meta's work (Staffing Industry Analysts).
Treat "the crowd leaked a lab's data" as an assumed rather than an evidenced risk. That does not make it cheap: the contractual remedy your customer will demand is an uncapped carve-out for confidentiality breach, so the balance-sheet exposure exists whether or not the incident base rate does. Meanwhile the evidenced security failure in this sector is that a middleman running a biometric identity stack to defeat fraud thereby becomes the highest-value target on the board — and is not built like a security company.