Your customer knew exactly what they were looking for. They made it to checkout quickly. Suspiciously quickly. With no scrolling, mouse movement, or clicking from one page to the next, the customer is clearly not a human. The fraud system flags the transaction as a possible card-testing attack and declines it accordingly.

Except the bot was an AI agent acting on behalf of a legitimate human customer.

The core challenge of agentic commerce fraud is telling the two apart. Forter’s network was already seeing a steady growth in agentic orders, which has skyrocketed since Meta launched Muse.  If merchants can’t distinguish those transactions from fraud, they risk losing a lot of sales — and customers. 

Agents don’t introduce themselves

Merchants can typically see a customer’s browsing behavior, device, IP and location, email address, payment details, and account information. When agents shop, many of those signals become generic, tokenized, or worse, missing. The merchant may see a virtual machine, network proxy or cloud IP, or a freshly-minted token instead of richer payment context.

Legitimate and malicious bot activity often appear identical.

It’s possible that agents and AI personal assistants haven’t found the right protocol yet to make themselves known. Adoption of Cloudflare’s Web Bot Auth and Visa TAMP, for example, remains very low. When personal assistants don’t use a proper User-Agent, they take on the appearance of a normal browser, dodging detection. We expect this to continue over the next few months.

Additionally, Cloudflare has announced plans to become a Certificate Authority (CA), which means it can issue digital certificates to any device, browser or website. If Cloudflare starts issuing them to agents, it can identify them cryptographically and much more efficiently than any existing protocol.

However, that wouldn’t happen until 2027, after the holiday shopping rush. That’s an important context because consumers are already planning their shopping and looking to use AI. 

Surveying 2,000 UK consumers, we found that 53% have used or are open to using AI to find holiday gifts this year. That survey predated the launch of Muse, which shot to the top of the iOS App Store within 10 days. 

Blocking all bots increasingly means blocking good customers. It’s also training AI agents to understand that they cannot complete their task on your site. Forter recommends that merchants check whether their bot provider can recognize AI agents, and if so, relax policies for them.

Looking at the identity over the transaction

You can’t set rules for traffic you can’t identify. 

We fingerprint the device, network, and behavior behind each session. That tells us whether we’re looking at a human shopper, an AI agent shopping on behalf of a human, or a malicious bot perpetuating agentic commerce fraud. We identify them throughout the visit and tag them at checkout.

That allows them to decide whether to block agentic traffic or give it a smooth path to checkout. Agents need a frictionless flow to function. It’s important that internal teams align on what that looks like. For example, the digital team may remove a CAPTCHA to improve approvals for AI-led orders. If the fraud team reintroduces it for security reasons, the good agent may not be able to make a purchase.

How Forter helps merchants stop agentic commerce fraud

Merchants usually have six months to a year to react to shifts in consumer behavior. This time, with the holiday season upon us, they may have four weeks.

Our Agentic Orchestration enables headless checkout journeys across every protocol, which allows merchants to own and protect the customer experience. Agentic purchases become 10x faster while maintaining the same level of trust and integration as any other channel.

Published on October 7, 2026
  •  

3 minute read
  •  

Author: Forter Team


Source link
ScamBuzz

Share
Published by
ScamBuzz

Recent Posts

Google News

Punjab AAP Leader Marriage Turns Into Fraud Case: Wife Posed as PCS Officer, Hid Previous…

6 minutes ago

Chinese spies 'sham marriage' scandal exposes 'targeted' national security threat at major US base: expert – Fox News

Chinese spies 'sham marriage' scandal exposes 'targeted' national security threat at major US base: expert  Fox…

1 hour ago

Black Friday Scam Alert: From Fake Websites To AI Videos, Watch Out For These Common Scams – NDTV

Black Friday Scam Alert: From Fake Websites To AI Videos, Watch Out For These Common…

1 hour ago

Woman who wed multiple men in Vegas fraud scheme to plead guilty, authorities say – Las Vegas Review-Journal

Woman who wed multiple men in Vegas fraud scheme to plead guilty, authorities say  Las Vegas…

2 hours ago

How TikTok’s Weakened Ad Rules Allowed Fake E-Commerce Sites To Scam Tens Of Thousands – Forbes

How TikTok’s Weakened Ad Rules Allowed Fake E-Commerce Sites To Scam Tens Of Thousands  Forbes Source…

2 hours ago

FTC and USDA Seek Public Comment on Agricultural Equipment Manufacturing and Distribution Market Practices

The Federal Trade Commission and the U.S. Department of Agriculture launched a joint public inquiry…

4 hours ago