AI · 7 October 2026
The next hurdle for AI agents: getting websites to let them in
Websites' anti-bot defences can't reliably distinguish legitimate AI shopping agents from malicious scrapers, blocking a key promise of agentic AI commerce. A new technical standard aims to let agents identify themselves and gain trusted access.
What happened
AI shopping agents built to browse and transact on behalf of consumers are running into a basic problem: most websites cannot reliably tell them apart from malicious bots. Anti-bot and anti-scraping defences, built long before agentic AI existed, tend to block or throttle automated traffic indiscriminately — catching legitimate agents in the same net as scrapers and fraud bots. According to reporting from TechCrunch, a new technical standard is now being developed to let AI agents verifiably identify themselves to websites, so that trusted agents can be granted access while bad actors remain blocked.
The move reflects a growing recognition across the web and e-commerce industry that the current binary of "human or bot" is no longer adequate. As more commerce and service interactions are initiated by autonomous software acting for a person, sites need a way to verify intent and provenance rather than simply detecting automation and shutting it out.
Why it matters
This is fundamentally an infrastructure problem standing in the way of agentic commerce becoming workable at scale. Even sophisticated AI shopping agents are of limited use if the websites they need to interact with cannot distinguish them from threats — the promise of an agent that compares prices, fills a basket or completes a purchase on a customer's behalf collapses if it gets CAPTCHA'd or IP-blocked at the first hurdle.
For organisations investing in digital transformation and AI-enabled service, the story is a reminder that enabling AI agents isn't just a model or product decision — it's also a trust and identity-architecture problem. Retailers, marketplaces and service providers will increasingly need to decide how they authenticate and govern non-human visitors, balancing openness to legitimate agentic traffic against fraud, scraping and security risk.
The Renascence take
Much of the agentic AI conversation focuses on what agents can do; this story is about whether they'll be let in the door at all. That's a trust-design problem as much as a technical one, and it echoes a familiar service-design lesson: systems built to screen out bad actors often end up penalising good ones unless identity and intent can be verified cleanly.
What's really at stake here is who gets to vouch for an AI agent's intent, and on what terms. Businesses that treat this purely as a security configuration will miss the service-design opportunity: verified agent access is, in effect, a new customer channel, and the brands that design clear, fair "agent experience" policies now — rather than reactively blocking traffic — will be the ones agentic commerce actually routes through.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
