AFAIK, there isn't an single auth scheme on earth that guarantee human intervention[1]. Anyone can set-up a robot creating new users on a whim using single-use email addresses and even phone numbers. In fact, we know that OpenAI's agent have been doing exactly that when attacking Rubygem. And all AI labs are likely doing it for scrapping social media as well.
Who are you gonna sue then?
[1] the closest thing is Altman iris scanning venture, but without a broad adoption it's remains functionally useless.