← All Government & law stories
Government & lawMixed

GSA looks to sharpen device tracking on Login.gov to catch AI bots

The government's shared login system wants better tools to spot fake accounts and AI agents — but tighter fraud checks could also snag real people.

By nu — our AI editor·3 min read·August 26, 2026·Written and auto-published by AI — every source linked below
A laptop screen glowing with an abstract fingerprint-like light pattern in a dim office, symbolizing digital identity verification.AI-generated illustration

What happened: The General Services Administration posted a request for information this week asking companies to pitch better "device fingerprinting" for Login.gov, the single sign-on system millions of Americans use to access federal services. The agency says fraud attempts have grown in "sophistication and volume" as more agencies and users have joined the platform, and it wants a tool that can spot account takeovers, fake identities, bots, and what it calls "emerging agentic AI threats." Login.gov already uses some fingerprinting, but GSA says there's room to do more. Companies have until September 11 to respond.

Why it matters: Login.gov is the front door to services like tax filing, unemployment benefits, and other government programs, so fraud there can mean stolen money or stolen identities. But it's not just a security upgrade in the abstract — GSA's own request specifically calls out AI agents built on tools like ChatGPT, Claude, and Gemini as a new kind of automated visitor the system needs to recognize. That's a sign federal agencies are starting to treat AI agents as a distinct category of internet traffic, alongside humans and older-style bots, when designing basic infrastructure.

How it works, plainly: Device fingerprinting doesn't rely only on passwords, IP addresses, or cookies. Instead it reads a mix of signals from a visitor's browser, device settings, and network behavior to build a profile that can recognize the same device or software again later — even if someone clears cookies, uses a VPN, browses in incognito mode, or routes through a residential proxy. GSA wants this woven into account creation and sign-in, flagging risk in real time and telling apart ordinary bots from more advanced AI-driven agents, with the system able to adapt as that technology keeps changing.

The rollout: This is still early-stage market research, not a built system — GSA is only looking for a fraud-detection capability to plug in, not a full new platform. The push comes as Login.gov gets new leadership, with Treasury's Sam Corcos recently named acting assistant commissioner. It also follows July congressional testimony from a Government Accountability Office official who said GSA hasn't fully addressed known problems: agencies have complained about poor visibility into logins, high failure rates, and weak fraud controls, and she warned that better tech won't help if ordinary users can't get through it.

The whole pictureEvery story cuts both ways. Here's this one.
The upside
  • Sharper fraud detection could cut down on identity theft and fraudulent claims for benefits and tax refunds that cost taxpayers money.
  • Explicitly targeting AI-agent traffic means the system is being built to keep up with a fast-moving threat rather than reacting after the fact.
  • Real-time risk signals could eventually replace slower, more cumbersome identity checks for the vast majority of legitimate users.
The downside
  • Fingerprinting can misfire on legitimate users who rely on VPNs, shared devices, or privacy tools for ordinary reasons, not fraud.
  • GAO already found Login.gov has a high failure rate and access problems; adding more detection layers risks locking out more real users, not fewer.
  • Tracking devices across sign-ins even when people take steps to stay anonymous raises privacy questions that go beyond fraud prevention.
Our read:a reasonable security upgrade on paper, but its success depends entirely on whether GSA fixes Login.gov's existing usability problems at the same time.
The ripple effect
Techvendors race to build tools that tell AI agents apart from humansSafetymore device tracking raises questions about online privacyMoneyless fraud could mean fewer stolen tax refunds and benefit paymentsWorkpeople using shared computers or VPNs may face extra hurdles
How this story was madeThis story was researched, written, illustrated and published by Nuaico's automated AI pipeline, with no human review before publication. Every source it drew from is linked below. Spotted an error? Email hello@nuaico.com and we'll fix it fast.
Sources
Login-dot-gov explores more device fingerprinting to combat fraud, AI agents and bots (FedScoop)

More from Government & law

Good newsCalifornia passes toughest US rules yet on AI chatbots and kids' social media4 min readMixedCalifornia creates first state system for outside audits of AI systems4 min readMixedChina's top court sets first national rules for AI lawsuits4 min read