The Problem Nobody's Monitoring
You've got Cloudflare Bot Management running. Maybe DataDome or PerimeterX. Your fraud stack is doing its job: blocking credential stuffing, stopping scalpers, keeping the bad bots out.
But here's the thing—it's also blocking a new category of traffic that looks exactly like a bot, behaves exactly like a bot, and is technically a bot. Except this one has a credit card and actually wants to give you money.
I'm talking about AI shopping agents.
Why Your Bot Detection Hates AI Agents
Modern bot detection doesn't just check user agents. It's far more sophisticated:
- Behavioural analysis: Mouse movement patterns, scroll velocity, interaction timing
- Browser fingerprinting: Canvas fingerprints, WebGL signatures, font enumeration
- TLS fingerprinting: ClientHello analysis, cipher suite ordering
- Velocity checks: Request rates, session duration, navigation patterns
- Challenge responses: CAPTCHA solving patterns, JavaScript execution environments
AI agents—whether they're Claude with computer use, AutoGPT with browsing, or custom LangChain implementations—fail most of these checks. They don't move mice naturally. They often run in headless browsers or use HTTP libraries directly. Their TLS fingerprints don't match standard browsers. They navigate too efficiently.
From your fraud stack's perspective, they look exactly like the scrapers and automated checkout bots you've spent years fighting.
The Revenue Impact You're Not Measuring
Here's where it gets uncomfortable: you probably don't have telemetry for this.
Most bot management platforms give you dashboards showing blocked requests, threat scores, and mitigation actions. But they don't categorise "blocked legitimate AI agent attempting purchase." That traffic just vanishes into your blocked bot metrics, and nobody's asking whether some of those blocks were false positives with purchasing intent.
The commercial exposure isn't theoretical. If you're in:
- B2B SaaS: Procurement agents are starting to automate vendor research and trial signups
- E-commerce: Early adopters are using agents for price comparison and automated reordering
- Travel: Booking agents are becoming more sophisticated than your rate scrapers
You're potentially blocking the agents trying to pay you without realising it.
What You Can Actually Do About It
1. Audit Your Bot Management Rules
Most platforms let you tune sensitivity. Review your current posture:
# Example concept - check your actual config
bot_management:
action: challenge # vs block
sensitivity: medium # vs high
exemptions:
- known_good_agents
- verified_api_traffic
Consider whether you need to be blocking aggressively at every stage, or whether challenging and monitoring would give you better signal.
2. Implement Progressive Trust
Not all traffic needs the same treatment:
- Anonymous browsing: Standard protection
- Authenticated session: Relaxed checks
- Payment intent signals: Minimal friction
- Repeat customer: Trust by default
Your bot detection should be context-aware. A logged-in user adding items to cart shouldn't face the same challenges as anonymous traffic hitting your login page 1000 times.
3. Create an Agent-Friendly Path
If you're serious about not leaving money on the table:
- API-first checkout: Properly authenticated, rate-limited, monitored
- Agent identification header support: Let well-behaved agents identify themselves
- Separate telemetry: Track agent traffic distinctly from human traffic
This isn't about opening the floodgates. It's about creating a monitored path that doesn't require pretending to be human.
4. Talk to Your Security Team
This sits in an awkward gap. Security teams optimise for threat prevention. Product teams optimise for conversion. Nobody's dashboard shows "potential revenue blocked by false positives."
If you're in platform engineering or e-commerce tech, this is a conversation worth having. Bot management policy shouldn't be set-and-forget.
The Standards That Aren't Here Yet
The technical community is working on this—Anthropic's Model Spec touches on agent behaviour, there are emerging proposals around agent identity verification—but nothing's standardised yet.
In the meantime, you're making trade-offs with imperfect information.
Start Measuring
The first step isn't changing your fraud rules. It's visibility.
Can you currently answer:
- How much traffic gets blocked at each stage of your funnel?
- What percentage of blocks are at checkout vs browsing?
- Do any blocked sessions show high-intent behaviour before blocking?
- Are blocks increasing while conversion is flat or declining?
If you can't answer those questions, you don't know whether you have this problem.
For teams working on this intersection of commerce, fraud, and automation, agencies focused on AI automation and software development are starting to build specific tooling for agent-aware fraud detection.
The Bottom Line
Your fraud stack was built for a world where all bots were bad. That world is changing faster than your tooling is adapting.
You don't need to trust every bot. But you probably need better telemetry to know which ones you're blocking—and what it's costing you.
Top comments (0)