Before Kevin Gosschalk made a business out of frustrating machines, he learned how to entertain people. In Brisbane, where he was born and educated, he studied games and interactive entertainment. The choice sounds almost mischievously unrelated to cybersecurity. It turned out to be the first clue. Games are rule systems with incentives, feedback and players who probe every boundary. Online fraud is much the same, except the people testing the rules are trying to empty an account, manufacture an identity or buy the good seats before anybody else can click.
Gosschalk was also the sort of student whose family wondered why he spent so much time playing World of Warcraft. Years later, when Queensland University of Technology named him its Outstanding Young Alumnus, he thanked them for tolerating the habit. Gaming had supplied more than diversion. Compromised accounts and forced password resets gave him an intimate view of the small domestic misery of digital theft. Someone had got into a place that felt like his, and the security ritual arrived only after the damage.
His early work moved through interactive applications, social technology and biomedical machine vision. The fields shared a concern that would stay with him: how software reads behavior, and how a human being experiences the reading. By 2012 he had co-authored peer-reviewed imaging research and helped build a winning prototype at Startup Weekend Brisbane. Soon he and game-industry veteran Matthew Ford were developing FunCaptcha, an answer to one of the web's least lovable customs.
Level oneThe puzzle was a piece of product design
The conventional CAPTCHA presented a bargain with the grace of a parking fine: decipher this mangled word to prove you deserve entry. FunCaptcha replaced the typographic ordeal with small visual games. Rotate an object. Recognize a scene. Do something that could be varied, measured and made progressively costly to automate. The word “fun” was not decoration. It was an argument that security should reserve its worst manners for the attacker.
The visible puzzle mattered, but the business underneath it mattered more. Gosschalk's durable idea was that fraud should be treated as an economy. Attackers buy infrastructure, rent tools, recruit labor and calculate returns. A defender who merely blocks one attempt may teach them to try again more cleverly. A defender who adds a tailored cost to every suspicious attempt can spoil the margin. The aim was not to make an attack metaphysically impossible. It was to make it financially ridiculous.
“If they're not making money they will move on.”Kevin Gosschalk
That notion gave the young company a clean story. FunCaptcha emerged from Brisbane, found customers including game and social platforms, and reported a stretch of 20 percent month-on-month revenue growth in 2017. The company became Arkose Labs, named for a hard sandstone. PayPal made a strategic investment in 2018. The following year, Gosschalk pitched as a top-ten finalist at the RSA Innovation Sandbox. In 2021, a $70 million Series C led by SoftBank Vision Fund 2 supplied the familiar Silicon Valley proof of arrival: a large number attached to a difficult problem.
Level twoA bouncer who studies the business plan
Gosschalk speaks about attackers less like monsters than operators. They have acquisition costs. They test suppliers. They abandon unprofitable routes. This vocabulary is useful because melodrama rarely improves a security system. A bot does not feel shame. A fraud farm does, however, receive a bill.
Arkose's approach joined risk assessment to adaptive challenges. Traffic judged ordinary could pass quietly. Suspicious traffic could be handed work whose difficulty changed with the risk and the attack. The interaction generated signals of its own, while every unsuccessful try consumed resources. It was a loop a game designer could appreciate: observe the player, adjust the level, learn from the response.
The Gosschalk loop
There is a practical modesty hidden in this. Gosschalk does not need to know a criminal's soul. He needs enough behavioral and contextual evidence to choose a response, then enough leverage to change the arithmetic. It also explains why his public remarks return to accountability. A security vendor can boast of effort while the customer continues losing accounts. Economics is harsher. Either the attack pays or it does not.
Recognition followed the company's growth. QUT honored him in 2022. EY named him a Bay Area Entrepreneur Of The Year winner in 2024. Television appearances put him in the now-familiar founder's chair, explaining bots to a general audience while the invisible traffic behind ordinary websites grew more organized. Yet the neatest part of his thesis was about to become its problem.
Level threeWhen the good customer sends a machine
For most of Arkose's first decade, “bot” and “bad” were close enough to be useful companions. Automation arriving at a login page was usually not there to arrange flowers. Then consumer AI agents learned to browse, sign in, compare, choose and buy. A customer might reasonably send software to book a flight. A fraudster might send remarkably similar software to test stolen credentials. Same cloud. Same headless browser. Same unnervingly tireless hands.
Gosschalk responded by retiring the question that had organized his own category. In his 2026 book, After Bots, and in the launch of Arkose Agent Trust Manager, he argued that “bot or human?” could no longer carry the decision. Detection still mattered, but it could not tell a platform whether an automated visitor was welcome. The next work was classification: who sent this agent, what does it intend to do, and is that act authorized?
“Detection was a prerequisite. Classification is the work.”Kevin Gosschalk, After Bots
He has tested the dilemma in the least abstract way available: by making AI agents do his shopping. In September 2026 he described routing ten days of online commerce through one, from groceries and theater tickets to flights and dog food. The agent used formal connections when they existed and an ordinary browser when they did not. A merchant did not have to invite the agent. Its public website was invitation enough.
This produces an awkward guest list. There are agents that identify themselves and behave as declared. There are agents acting for legitimate customers that do not identify themselves. There are adversarial agents built for abuse. Worse, one agent can shift roles during a single errand. A useful assistant comparing prices may become a sensitive actor when it reaches a bank transfer. Trust cannot be stamped on its forehead once and left there. It has to be evaluated by action, endpoint and moment.
The change reveals something consistent in Gosschalk's work. He is less attached to a particular test than to the design of the contest. FunCaptcha altered the interaction. Arkose altered the attacker's price. Agent trust alters the unit of judgment, from the nature of the visitor to the permission attached to the visit. Each move asks the same game-design question: are these rules producing the behavior we want?
The next boardPermission is the new perimeter
The fashionable story about AI agents is that they will remove errands from human life. Gosschalk's less fashionable addition is that every removed errand leaves an authorization problem. If an agent can read a calendar and reserve a hotel, which facts may it disclose? If it can enter an account, which buttons may it press? If it can move money, when must a person return to the loop? Convenience walks briskly; governance arrives carrying binders.
Gosschalk's aspiration is not a web scrubbed clean of machines. That web has already vanished, if it ever existed. He wants platforms to distinguish useful automation from abuse without punishing the customer who delegated a task. For hostile agents, his older economic principle remains available: challenges, computation and human intervention can make scale expensive. For helpful agents, the job is to recognize intent and grant only the authority the moment requires.
It is a long way from rotating a cartoon object, though the family resemblance remains. The screen still hosts a game between a system and a visitor. The system still needs to observe without making ordinary people miserable. The visitor still has a goal that may or may not deserve fulfillment. Gosschalk's career has been an extended argument that security is not a wall. It is a set of rules, prices and permissions.
The gamer from Brisbane built his first company by making a dreary test playful. He built the larger one by making fraud costly. Now, as machines become customers as well as criminals, he is trying to make trust specific. The internet used to ask whether anyone was human. Its harder question is whether this particular action, by this particular agent, should be allowed. Harder questions are inconvenient. They are also where the interesting games begin.