Here is a number worth sitting with. Akamai measured AI bots at 47.9 percent of commerce traffic on its global network in the second half of 2025, according to Retail Dive. Nearly half. Some of that traffic is scraping prices to undercut you. Some of it is a customer's shopping agent trying to give you money.

The same defenses fire on both.

Two pieces landed on September 8 making versions of this argument: the Retail Dive piece on authenticating AI buying agents, and a Total Retail essay arguing that the future retail customer will not shop like a human at all. I have been writing about this gap since February. What changed is that the traffic is no longer hypothetical.

Merchants spent a decade building walls to keep bots out. The paying customer now arrives looking exactly like the traffic those walls were built to stop.

The signals point the wrong way

Bot detection works by spotting the absence of a human. High request velocity. Headless browsers. Linear navigation with no mouse jitter, no scroll noise, no time spent lingering on product photos. Every one of those signals is also a perfect description of a well-built shopping agent doing its job efficiently.

That is not a tuning problem. It is structural. The engineering that makes an agent useful, speed, precision, no wasted motion, is the same engineering that makes it indistinguishable from the traffic merchants have spent years training their systems to block.

I named this problem in The Security Gap Nobody Fixed: the fraud and authentication stack was built on the assumption that a human is at the keyboard. That assumption is now wrong often enough to cost real money. Hubert Behaghel, CTO of identity verification firm Veriff, put the commercial stakes plainly in the Retail Dive piece: "It's 10 times a bigger business concern to reject a good person than to let a fraudster through." He is selling the fix, so weigh the source. The underlying tension holds anyway.

The traffic is already here, and it converts

The numbers on agent-driven commerce stopped being speculative this year. Adobe Analytics data reported by Digital Commerce 360 shows AI-associated referral traffic to US ecommerce sites rose 62 percent year over year in July. Shoppers arriving from AI tools generated 53 percent more revenue per visit than everyone else.

Read that second number again. The traffic your bot rules are most likely to misclassify is the highest-value traffic you have.

The supply side is moving to meet it. Anthropic released a merchant blueprint this month for retailers building shopping and service agents on Claude, aimed at the holiday season, PaymentsJournal reports. Early partners saw 60 percent higher conversion on AI-driven visits and cart sizes up 30 to 35 percent. Notably, the agents stop short of completing the purchase. Checkout stays with the merchant. Don Apgar of Javelin Strategy & Research summarized the state of demand in the same piece: "The tech is there, consumers are not yet." Fair. But the gap between "arriving and browsing" and "arriving and buying" is exactly where authentication decisions get made, and merchants are making them today with tools built for a different enemy.

Discovery is shifting too. Digital Commerce 360's rankings with ReFiBuy show ChatGPT as the top AI traffic source for 722 of the top 1,000 North American retailers in Q2, with Google's Gemini doubling its count and Claude jumping from one retailer to 15 in a single quarter. Which agent shows up at your door is changing quarter to quarter. Whether you let it in should not depend on guesswork.

Detection is the wrong frame. Attribution is the right one.

The instinct is to build a better classifier: train the fraud model to tell good bots from bad ones by behavior. I think that race is unwinnable. Adversaries iterate weekly, and legitimate agents keep changing shape as the platforms behind them ship updates. Behavioral detection will always be a lagging signal.

The durable answer is attribution: an agent that arrives carrying verifiable evidence of who it acts for and what it is permitted to do. This is the authorization layer of the MM Trust Layer Model, and it is the layer moving slowest. Discovery is racing ahead. Settlement rails are getting attention. The middle, proving an agent's mandate at the point it acts, is still mostly unbuilt. Agent attribution is also one of the six commitments in my open letter on finishing the AI control stack, and the storefront is where that abstract commitment becomes a revenue line.

Theodora Lau of Unconventional Ventures showed the other face of this opacity in a Forbes piece in June. She asked four AI chatbots the same eight banking questions for two different users; only 12 of the 32 question pairs returned the same lead recommendation. Her point was about consumers trusting AI advice shaped by invisible variables. Flip it to the merchant side and the problem is the same shape: you do not know why an agent chose your store, and you cannot interrogate its reasoning at the door. The only thing you can verify is its credentials. If it does not carry any, every decision you make about it is a guess.

You cannot audit an agent's intentions. You can audit its mandate. Merchants should demand the second and stop guessing at the first.

Three moves for this quarter

The standards work will take quarters. These will not.

Instrument agent traffic separately. If AI-referred and agent-driven sessions are not segmented in your analytics and your decline reporting, you cannot see what your own defenses are costing you. Adobe's 53 percent revenue-per-visit premium suggests the number is not small. This is the cheapest fix on the list and most merchants have not made it.

Rebaseline the bot rules. Most rulesets predate 2025. They need re-testing against the headers, declared user agents, and traffic patterns of the mainstream agent platforms, starting with the ones Digital Commerce 360's rankings say are actually sending you buyers.

Put attribution requirements in your vendor conversations now. Ask your bot-management and fraud vendors a specific question: when an agent presents verifiable evidence of the customer it acts for, can your system consume it? Most cannot yet. Vendors build what customers demand, and right now merchants are not demanding it.

I argued in The Agent Tax that the real costs of agentic commerce hide in the plumbing. Revenue declined by your own defenses is the purest example yet: a cost you incur precisely because your security stack is working as designed.

The holiday test

Chris Bartosik of Concentrix, writing in Total Retail, expects most retailers will not be ready for agentic transactions by the holidays; next year is more realistic. He is probably right about full readiness. But the traffic will not wait for readiness. Anthropic is explicitly targeting holiday deployment, and the referral numbers are compounding now.

So the test comes this quarter regardless. Merchants that can tell a mandated agent from a scraper will quietly collect a conversion premium. Merchants that cannot will be blocking their best customers at the door and reading the loss as fraud prevention doing its job.

The question is not whether agents are coming to your storefront. It is whether you will recognize the ones carrying money.

If your fraud stack blocked a customer's shopping agent yesterday, would anything in your reporting tell you, or would it just look like a job well done?

Charlie Major is a Product Development Manager at Mastercard. The views and opinions expressed in Major Matters are his own and do not represent those of Mastercard.