GSA looks to sharpen device tracking on Login.gov to catch AI bots
The government's shared login system wants better tools to spot fake accounts and AI agents — but tighter fraud checks could also snag real people.
What happened: The General Services Administration posted a request for information this week asking companies to pitch better "device fingerprinting" for Login.gov, the single sign-on system millions of Americans use to access federal services. The agency says fraud attempts have grown in "sophistication and volume" as more agencies and users have joined the platform, and it wants a tool that can spot account takeovers, fake identities, bots, and what it calls "emerging agentic AI threats." Login.gov already uses some fingerprinting, but GSA says there's room to do more. Companies have until September 11 to respond.
Why it matters: Login.gov is the front door to services like tax filing, unemployment benefits, and other government programs, so fraud there can mean stolen money or stolen identities. But it's not just a security upgrade in the abstract — GSA's own request specifically calls out AI agents built on tools like ChatGPT, Claude, and Gemini as a new kind of automated visitor the system needs to recognize. That's a sign federal agencies are starting to treat AI agents as a distinct category of internet traffic, alongside humans and older-style bots, when designing basic infrastructure.
How it works, plainly: Device fingerprinting doesn't rely only on passwords, IP addresses, or cookies. Instead it reads a mix of signals from a visitor's browser, device settings, and network behavior to build a profile that can recognize the same device or software again later — even if someone clears cookies, uses a VPN, browses in incognito mode, or routes through a residential proxy. GSA wants this woven into account creation and sign-in, flagging risk in real time and telling apart ordinary bots from more advanced AI-driven agents, with the system able to adapt as that technology keeps changing.
The rollout: This is still early-stage market research, not a built system — GSA is only looking for a fraud-detection capability to plug in, not a full new platform. The push comes as Login.gov gets new leadership, with Treasury's Sam Corcos recently named acting assistant commissioner. It also follows July congressional testimony from a Government Accountability Office official who said GSA hasn't fully addressed known problems: agencies have complained about poor visibility into logins, high failure rates, and weak fraud controls, and she warned that better tech won't help if ordinary users can't get through it.
