Securing agentic commerce
How eCommerce organizations can distinguish legitimate AI agents from malicious automation across the buying journey.
The strategic shift
Digital commerce security can no longer rely on separating humans from bots. Retailers must determine who an AI agent is, who authorized it, what it is allowed to do, and whether its behavior remains trustworthy throughout the transaction.
Digital commerce traffic is no longer only human
Digital commerce traffic is no longer only human
E-commerce is entering a new phase in which AI agents participate directly in product discovery, comparison, purchasing, payment, customer service, and account management. These interactions can expand reach and reduce friction, but they also create a new class of machine-driven traffic that must be evaluated differently from traditional human sessions.
According to a Gartner® report, “By 2030, 20% of digital commerce transactions will be executed through AI platforms—either via AI check-out or by AI agents.”
Retailers already contend with credential stuffing, account takeover, card testing, price scraping, inventory hoarding, loyalty theft, and checkout abuse. Agentic shopping makes the environment more complex because legitimate purchasing agents and malicious automation may use similar interfaces, APIs, credentials, and transaction flows. Blocking automation indiscriminately can suppress a valuable new commerce channel. Allowing it without appropriate controls can increase fraud, data exposure, operational cost, and customer trust risk.
How the challenge affects agentic buying
How the challenge affects agentic buying
Agentic shopping delegates part or all the purchasing journey to an AI agent. A consumer may authorize an agent to research products, compare offers, log in to an account, select an item, initiate payment, track an order, or request a refund. Each step introduces questions that traditional bot controls were not designed to answer.
A merchant must determine how much to trust an agent, whether a real customer authorized the action, and whether the requested operation falls within the customer's intended scope. The merchant must also evaluate whether a technically valid agent is behaving abnormally because its credentials, delegation, or transaction context may have been compromised.
Rather than relying on static identity checks or treating authorization as a binary state, modern architecture must move past asking “Is the requester human?” Instead, it must interrogate the entire operational journey: “How much trust has this agent accumulated at this exact moment? Does its cumulative behavioral pattern remain consistent with legitimate intent, or has subsequent activity degraded that trust to the point of compromise?”
From bot detection to agent verification
From bot detection to agent verification
A trusted agentic commerce model should evaluate three elements before an agent is permitted to perform a sensitive action:
- Identity: Verify which AI agent or automated service is making the request.
- Delegation: Confirm that a specific customer has authorized the agent to act.
- Manage: Enforce exactly which resources, actions, values, and time limits are permitted.
Verification is necessary, but it is not the same as fraud detection. Verification establishes whether presented credentials and delegation are valid. Behavioral and transaction analysis are still needed to identify an authorized agent whose access has been stolen or whose activity is inconsistent with the intended purchase.
The F5 secure digital commerce
F5 recognizes that modern commerce traffic includes customers, trusted AI agents, crawlers, scrapers, and malicious bots. Retailers need comprehensive security that inspects traffic and applies the appropriate protection, from access controls to transaction checks, without slowing legitimate shoppers or the buyer agents that came to purchase.
Four connected challenges
Legitimate activity can resemble an attack
Credential stuffing, account takeover, and card testing may arrive through apparently valid sessions. Agent traffic may also present delegated authority that has been stolen or abused.
Retailers cannot treat every bot as bad
A blanket blocking strategy can interfere with legitimate automated activity. Training crawlers, AI scrapers, and AI agents may each require different treatment based on the retailer's commerce strategy.
Point products leave gaps
Separate web application, bot, API, client-side, identity, and fraud controls can create fragmented signals and inconsistent responses.
Hybrid and multicloud environments increase inconsistency
Storefronts, APIs, applications, and services may operate across data centers, clouds, edge locations, acquired brands, and partner ecosystems.
How F5 aligns to trusted agentic buying
Classify AI and automated traffic
Classify AI and automated traffic
F5 bot management capabilities support the distinction between approved automation and malicious activity by analyzing traffic characteristics, intent, and behavior. This allows retailers to apply different policies to AI agents, crawlers, scrapers, credential abuse, and transaction bots rather than treating all automation the same.
Protect customer accounts and transactions
Protect customer accounts and transactions
F5 application and bot protections can help reduce account takeover, credential stuffing, card testing, checkout abuse, inventory hoarding, and loyalty fraud while preserving access for legitimate customers and authorized buying agents.
Secure the APIs behind agent-to-agent commerce
Secure the APIs behind agent-to-agent commerce
Agentic buying depends on APIs for search, inventory, pricing, identity, payment, order management, and service. F5 Distributed Cloud API Security supports API discovery, posture management, monitoring, and protection across the commerce lifecycle.
Protect customer-facing AI experiences
Protect customer-facing AI experiences
F5 AI security capabilities and AI Guardrails can support protection of AI-powered search, shopping assistants, and other LLM-based interactions against prompt injection, unsafe inputs and outputs, data leakage, and abusive use.
Apply consistent protection across environments
Apply consistent protection across environments
The F5 Application Delivery and Security Platform brings application delivery and security capabilities together across hybrid and multicloud environments, supporting more consistent policy and visibility for applications, APIs, AI services, and automated traffic.
Business impact
Retailers that cannot identify and govern agent traffic may block valuable referrals and purchases, admit fraudulent automation, increase chargebacks and operational costs, expose customer information, or introduce friction that reduces conversion. Retailers that establish trusted agent access can support a new buying channel while maintaining control over accounts, APIs, payments, AI interactions, and customer data.
Conclusion
Agentic commerce is not simply another bot management use case. It represents a transition from human-centered digital journeys to commerce in which machines can discover, decide, and transact on behalf of people. The winning security strategy will not block automation by default. It will identify legitimate AI agents, validate customer authority, enforce precise permissions, detect malicious behavior, and protect the complete digital commerce journey.
F5 perspective: Enable trusted machine-to-machine commerce while securing agent identity, API access, AI interactions, applications, transactions, and customer data.
For more information, F5 Ecommerce solution page
Gartner, “CISOs Must Protect Agentic Commerce to Prevent Abuse and Preserve Revenue,” 10 August 2026, ID G00850599.
Gartner is a trademark of Gartner, Inc., and/or its affiliates.
F5 Retail and eCommerce Industry Positioning and Messaging Framework, August 2026.