Akamai’s latest
The more revealing figure, however, is what happened after that traffic arrived. Commerce organizations placed more than 90% of AI bot activity into a monitoring category, yet allowed three-quarters of the remaining activity to pass through without restriction.
That gap is quickly becoming one of the defining security challenges of agentic commerce. Retailers know automated traffic is pouring into their websites and applications, but many still lack a reliable way to determine what that traffic is trying to accomplish.
Some of it comes from legitimate shopping assistants comparing prices, checking inventory or completing purchases for customers. Some from conventional crawlers gathering information. And others hail from fraud rings probing checkout flows, loyalty programs and account recovery systems.
Then there is the activity that sits somewhere in between: an authorized agent performing a legitimate task in a way the customer or retailer never intended.
For
Transmit Security works across customer identity, authentication and fraud prevention, helping large enterprises evaluate risk throughout the digital identity journey rather than treating login as the only meaningful security checkpoint. That perspective is becoming increasingly relevant as AI agents begin to act with more independence.
Authorization Is Not the Same as Control
Traditional ecommerce security is built around a reasonably understandable sequence. A customer signs in, proves their identity and receives permission to access an account. Fraud systems then look for familiar warning signs, such as an unusual device, a suspicious location or a transaction that does not match prior behavior.
Agentic commerce disrupts that model because the entity completing the task may not be the customer.
A consumer might authorize an AI agent to find a particular product at the lowest available price. From the retailer’s perspective, the resulting activity could include repeated searches, rapid cart additions, discount-code testing and multiple checkout attempts. Those actions may resemble inventory abuse or credential-stuffing automation even when the original request was harmless.
The reverse problem is more dangerous. Once an agent is permitted to act for a customer, it may continue operating beyond the point at which a conventional system would question its behavior. The agent may technically have valid access, but that does not mean every action it takes reflects the customer’s actual intent.
A shopping assistant instructed to pursue the best possible deal could repeatedly add the same item to a cart while testing promotions. A returns agent might attempt to initiate a refund before confirming that an item was shipped. Neither agent has to be malicious to create financial losses, distort inventory or trigger operational work.
This is the access problem at the center of agentic commerce. Authentication can establish that an agent has been authorized. It can't, by itself, establish that every subsequent action remains appropriate.
Fraud No Longer Begins With a Stolen Login
Retail fraud has historically revolved around compromised credentials, account takeover, payment abuse and synthetic identities. Those threats are not disappearing. Akamai’s report notes that attackers are already experimenting with agent hijacking and using legitimate AI assistants to exploit stored payment credentials. But AI agents also create an entirely different attack surface because they interpret information and make decisions.
An attacker may not need to steal a customer’s password if the customer has already handed execution authority to an agent. Instead, the attacker can look for ways to influence the instructions the agent encounters.
That could include malicious text placed in a product description, seller profile or other content the agent considers while completing its assignment. To a human shopper, the text may look irrelevant or suspicious. To an agent, it may be processed as another instruction to follow.
This possibility turns ordinary retail content into part of the security boundary. Product catalogs, third-party marketplace listings and promotional pages were never designed to govern autonomous software. Yet agents may now use that information to decide what to buy, where to send it and which steps to complete next.
The result is a threat model in which intent can be manipulated without a conventional account compromise.
Why Existing Bot Detection Falls Short
The instinctive response might be to block more automated traffic, however, that would solve one problem while creating another.
Retailers increasingly want legitimate agents to access their businesses. Shopping assistants can help customers discover products, reduce friction and complete transactions. Blocking all bots would mean blocking a channel that may soon influence a meaningful share of digital commerce.
The harder task is separating a helpful agent from a malicious or malfunctioning one while both are moving at machine speed.
Many fraud controls still depend heavily on signals tied to human behavior. They look at how someone types, scrolls, pauses or navigates a page. AI agents don't behave that way. They may operate from cloud infrastructure rather than the customer’s device, making traditional device signals less useful. Their activity can appear suspicious simply because it is automated, while sophisticated malicious traffic can hide inside otherwise legitimate agent workflows.
This is why
A legitimate agent buying one item at an expected price may present little risk. The same agent attempting hundreds of cart changes, redirecting a shipment or initiating an unsupported return should trigger a different response.
Retailers Need More Than an Allow-or-Block Decision
Akamai recommends that commerce organizations move away from binary bot controls and toward risk-based governance that evaluates automation according to its intent and business value.
In practice, that means retailers need visibility into what an agent is authorized to do, what it is currently doing and whether those two things still match.
Some actions may be allowed without friction. Others may require the customer to confirm the agent’s request. Higher-risk behavior may need to be restricted, delayed or sent for review. The important part is that the decision can change as the interaction unfolds.
Retailers cannot assume every AI agent is hostile, and they also cannot assume an authorized agent remains trustworthy simply because it passed an initial check.
Organizations must treat identity, bot management and fraud prevention as connected parts of the same problem and evaluate trust across the entire transaction rather than only at the front door.
Agentic commerce is arriving before most companies have finished defining what safe agent behavior looks like. Akamai’s findings suggest that many retailers are currently compensating by watching nearly everything and meaningfully challenging very little.
That approach may have been manageable when bots were mainly scraping pages or testing passwords. It is far less sustainable when software can shop, negotiate, purchase and initiate returns on a customer’s behalf.
The next phase of ecommerce security will not be about deciding whether machines belong in the store. They are already there. It will be about determining, in real time, which machines should be trusted with what.
This story was distributed as a release by Jon Stojan under HackerNoon’s Business Blogging Program.