AI Shopping Agents Are Flooding Retail. Most Security Systems Still Cannot Tell Which Ones to Trust
AI shopping agents are reshaping ecommerce security. Learn why agentic commerce demands continuous trust, fraud prevention, and identity verification.
A recent report by Akamai highlights a growing security concern for retailers: the influx of AI shopping agents. Between July and December 2025, nearly half of all observed bot traffic on Akamai's global network was directed at the commerce sector. However, only three-quarters of the remaining traffic was allowed through without restriction. This growing issue poses significant challenges for retailers, as they struggle to differentiate between legitimate and malicious AI agents.
Mickey Boodaei, CEO and co-founder of Transmit Security, emphasizes that the ambiguity surrounding AI agents is the more pressing issue. Retailers are no longer dealing with a clear distinction between trusted human customers and malicious bots. Instead, they are facing machines operating on behalf of people, often across multiple sessions, accounts, devices, and transactions.
Traditional ecommerce security models are being disrupted by AI agents. While customers typically sign in, prove their identity, and receive permission to access an account, agentic commerce introduces new complexities. Authorized agents may perform legitimate tasks in unintended ways, creating financial losses, inventory distortions, and operational challenges. Additionally, malicious agents can exploit stored payment credentials without directly stealing a customer's password.
This new threat model requires retailers to rethink their security approaches, as traditional bot detection methods are largely ineffective against AI agents. The instinct to block more automated traffic may solve one problem but inadvertently blocks legitimate agents that could significantly impact digital commerce. Retailers must find a balance between allowing helpful AI agents while protecting against malicious or malfunctioning ones.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
