There is a quiet irony unfolding across UK e-commerce infrastructure. Retailers have spent years hardening their platforms against bots — the scalpers, credential stuffers, and inventory hoarders that erode margins and frustrate genuine customers. Those defences are now working exactly as designed. The problem is that 'exactly as designed' increasingly means blocking a new category of actor that retailers very much want on their sites: AI shopping agents acting on behalf of real, paying customers.
As tools like Perplexity's built-in buying feature and OpenAI's Operator move from novelty to mainstream, they are sending automated, headless requests to product pages, checkout flows, and payment endpoints. To a bot-detection system trained on pre-agentic threat models, that behaviour looks indistinguishable from a scalper. The result is a growing, largely unacknowledged gap between the security stacks retailers deployed to protect revenue and the agentic commerce layer now being built on top of them.
How Modern Bot Detection Works — and Why It Struggles Here
Contemporary fraud tooling — from Cloudflare's Bot Management to specialised platforms like Kasada and DataDome — identifies malicious automated traffic through a combination of fingerprinting signals: TLS handshake patterns, JavaScript execution behaviour, mouse movement entropy, request velocity, and IP reputation. These systems are genuinely sophisticated, and for the threat landscape they were designed to address, they perform well.
AI shopping agents, however, share several surface characteristics with the bots these tools are trained to catch. They operate headlessly or in stripped-down browser environments. They navigate checkout flows at non-human speeds. They may originate from data centre IP ranges associated with cloud providers. They do not accumulate the ambient behavioural history — browsing patterns, cookie trails, interaction telemetry — that signals 'real human' to a risk engine. The detection logic was never designed to distinguish between a bot trying to steal value and an agent trying to deliver it. That distinction simply did not need to exist when the models were built.
The Revenue Exposure Retailers Are Not Measuring
The commercial stakes are more immediate than many retailers appreciate. Agentic commerce is not a theoretical future state — it is arriving in the purchasing habits of early adopters right now, and adoption curves for AI-assisted tools tend to compress. If an AI agent fails to complete a purchase on your platform, the customer who delegated that task does not necessarily receive an error message explaining why. The transaction simply does not happen. The basket is abandoned. The revenue does not appear in any abandonment report tied to a human session, so the failure mode is largely invisible in standard analytics.
For categories where AI agents are most likely to operate — consumer electronics, travel, subscription services, B2B procurement — the aggregate value of silently blocked agentic transactions could become material within a relatively short timeframe. There is no industry-wide measurement of this yet, which is itself part of the problem. Retailers are not losing sleep over a number they cannot see.
The Emerging Standards Gap and What Is Being Done
The technical community is beginning to engage with this problem, but solutions remain fragmented and nascent. Anthropic's Model Spec and emerging proposals around agent identity verification gesture at the need for AI systems to be identifiable and accountable, but these are not yet operationalised in ways that fraud platforms can consume. There is no widely adopted handshake protocol by which a shopping agent can credibly assert 'I am acting on behalf of a verified human customer' in a way that a bot-detection layer will trust.
Some AI platform providers are in quiet dialogue with retailers and payment processors about whitelisting arrangements, but these are bilateral, ad hoc agreements — the kind of patch that creates fragmentation rather than resolving the underlying architectural mismatch. The Payment Services industry's existing Strong Customer Authentication frameworks were designed around human-initiated transactions, and they offer no clean accommodation for delegated agentic purchases. Until standards bodies, platform providers, and fraud tooling vendors converge on a common model, the gap will widen as agent adoption accelerates.
Where Responsibility Sits in Your Technology Stack
For most retailers, bot management policy sits somewhere between the security team and the platform engineering team, with limited visibility at the commercial or product level. That ownership structure is now a liability. Decisions about detection thresholds and challenge responses — made defensively, with good reason — are quietly affecting the conversion funnel for an emerging customer segment. The commercial team almost certainly does not know this is happening.
Fraud tooling vendors are not standing still, but their roadmaps are driven by customer feedback, and most retailers have not yet articulated this as a problem requiring a solution. If you are not raising it with your vendor, it will not be prioritised. Similarly, if your platform uses a CDN or WAF layer with aggressive bot scoring, the configuration choices made at deployment may predate any consideration of agentic traffic — and default-aggressive settings are the norm, not the exception.
The practical starting point is visibility. Audit your current bot management configuration and ask your vendor directly: how does your system classify headless browser traffic originating from known AI agent infrastructure? Is there a mechanism to whitelist verified agent user-agent strings or IP ranges? Are challenge responses logged in a way that would surface agentic abandonment separately from human abandonment? Most organisations will find the honest answer is 'we do not know.'
From there, the conversation needs to move cross-functionally. Security, engineering, commercial, and product leads all have a stake in how this is resolved — and it will not be resolved by any one of them acting in isolation. The retailers who move earliest to establish a coherent position on agentic traffic will have a meaningful advantage as AI-assisted purchasing becomes a routine part of the customer journey. The risk of inaction is not dramatic or sudden; it is the slow accumulation of transactions that never quite happened, on a channel you were never quite watching.
Which AI shopping agents are most likely to trigger bot detection systems right now?
Agents that operate in headless or semi-headless browser environments are most at risk — this includes OpenAI's Operator, Perplexity's buying feature, and similar tools that automate checkout flows programmatically. Any agent that bypasses full JavaScript rendering or originates from cloud-provider IP ranges is likely to score poorly on behavioural fingerprinting systems.
How can I tell if my site is already blocking legitimate AI agents?
Standard analytics will not surface this cleanly because blocked agentic sessions often do not register as identifiable abandonment events. The most direct method is to run controlled test transactions using known AI agent tooling and monitor your WAF and bot management logs for challenge responses or silent blocks. You should also review your CDN's bot score distributions for headless browser signatures.
Do any bot management vendors currently offer specific support for legitimate AI agents?
As of now, no major bot management vendor has released a fully productised solution for distinguishing legitimate AI shopping agents from malicious bots. Some vendors are in early-stage dialogue with AI platform providers, and a small number offer configurable allow-listing, but there is no industry-standard framework yet. This is an active area of product development you should be raising directly with your vendor.
Is there a way to whitelist specific AI agents without opening security gaps?
Bilateral whitelisting based on user-agent strings or IP ranges is feasible but imperfect — user-agent strings can be spoofed, and IP ranges for cloud providers are shared with genuinely malicious traffic. A more robust approach would require cryptographic agent identity verification, which is under discussion in the AI standards community but not yet deployed at scale.
Does Strong Customer Authentication (SCA) affect AI agent purchases under UK payment regulations?
Yes, and this is a significant unresolved issue. SCA was designed around human-initiated transactions and typically requires an interactive authentication step that AI agents cannot complete without user interruption. Delegated purchasing via AI agents does not map cleanly onto existing SCA exemption categories, meaning payment authorisation itself — not just site access — can fail. This requires engagement with your payment processor.
What is the difference between a scalper bot and a legitimate AI shopping agent from a technical standpoint?
Functionally, both may execute automated HTTP requests, navigate checkout flows at non-human speeds, and operate without traditional browser telemetry. The key distinction is intent and authorisation: a legitimate AI agent acts on behalf of a specific, consenting human customer and aims to complete a genuine transaction. Current bot detection systems have no reliable mechanism to verify this distinction, which is the core of the problem.
Should we be concerned about AI agents being used maliciously to bypass fraud controls, rather than being blocked by them?
Both risks are real and not mutually exclusive. While this article focuses on legitimate agents being incorrectly blocked, the same agentic capabilities could be exploited by bad actors to conduct more sophisticated automated fraud. Your fraud strategy needs to account for both scenarios — the answer is not simply to lower your defences, but to build more nuanced classification capabilities.
Are there industry bodies or standards groups working on agent identity protocols that retailers should follow?
Several workstreams are relevant: Anthropic's guidance on model behaviour and identity, emerging W3C discussions around web agent standards, and the broader AI safety policy work from the UK's AI Safety Institute. None has yet produced an operationalisable agent identity standard. Retailers should monitor these developments and engage through trade bodies to ensure commercial perspectives are represented.
How does this issue affect B2B e-commerce platforms differently from B2C retail?
B2B platforms may face this challenge sooner and at higher transaction values, since procurement automation is already an established use case and AI agents are a natural extension of existing purchasing workflows. B2B platforms often have more negotiated, account-based relationships that could accommodate whitelisting arrangements, but their underlying security infrastructure is frequently less sophisticated than major B2C retailers.
What should we ask our platform vendor or systems integrator to assess our exposure?
Ask specifically: how does our current bot management configuration handle headless browser traffic from cloud infrastructure? Are challenge events logged in a way that distinguishes session types? What is our process for updating bot scoring thresholds as agent traffic grows? And critically — who in our organisation owns the decision to adjust these settings when commercial impact becomes measurable?
Get in touch today
Book a call at a time to suit you, or fill out our enquiry form or get in touch using the contact details below