AI agents are changing how people interact with businesses over the internet. The increasing adoption of AI and the rapid development of agentic capabilities has led to people increasingly relying on AI agents to search for information, compare options, complete tasks, and take actions on their behalf.
For businesses, this is a new class of internet traffic to deal with and a new type of application interaction. Some agent-driven activity can create new opportunities to engage customers, enable revenue, and deliver services. Other activity can introduce security, fraud, and business risks. The challenge is knowing the difference when both are automated in nature and look normal in isolation.
Existing approaches to automated traffic largely focus on detecting and mitigating malicious activity. But as AI agents become more capable and more deeply involved in customer journeys, businesses need to think beyond whether traffic is automated.
They need to build a basis for trust, and that starts with three questions.
1) Can you identify the agent?
Before businesses can make informed decisions about AI agent traffic, they need to know what is interacting with their applications. AI agents can come from different platforms and providers, and identifying agentic traffic along with the agent behind an interaction can provide important context for deciding how much to trust it.
Businesses need visibility into all AI agent activity on their applications, where those agents originate, and whether they can be verified through authentication standards such as Web Bot Auth or through some other mechanism. While agent identity alone does not determine trust, knowing the agents behind an interaction can provide additional context to businesses and to understand what they are dealing with.
2) Can you understand its intent?
The next question is more important: to understand that agent’s intent and what it is trying to do. An AI agent might be searching for information, browsing products, initiating a transaction, logging in, or performing other actions within an application. These activities can have very different implications for a business, and carry different levels of risk and business value.
A legitimate or identifiable agent may be misdirected, attempt a malicious action, or carry out unexpected, potentially harmful tasks. Understanding intent therefore becomes an important part of establishing trust. Is the agent carrying out its intended task? Does its actions align with the context of the interaction? Understanding and validating intent provides another critical signal for establishing trust.
3) Can you make an informed decision and govern what the agent can do?
Once a business can identify the agent and evaluate its intent, it has the context needed to make a more informed decision. It does not have to be between blanket allowing or blocking an agent throughout the site.
A business may choose to enable an agent to perform certain activities while placing greater restrictions on others, or blocking some other sensitive interactions altogether. The appropriate response can depend on the agent, its intent, the context of the interaction, the impact on business and in general how much the business trusts the agent.
Rather than treating all agent traffic as inherently good or bad, businesses can take a more nuanced approach: enable trusted agent interactions, restrict others that need more control, and block those that present unacceptable risk.
Building trust to enable valuable agent activity
AI agents are becoming a new channel through which customers interact with businesses. That creates an important opportunity, but only if businesses can distinguish valuable activity from those that introduces risk.
Building trust in this scenario starts with understanding the agentic traffic interacting with your applications and understanding what it is trying to do. And it depends on having enough context to make an informed decision to govern the interaction.
This is a different approach to managing automated traffic. It is not about assuming that all AI agent activity should be allowed, or that it should all be blocked. It is about having the visibility, context, and control to make trust-based decisions.
As AI agents become a more significant part of how business gets done online, the ability to establish trust will be essential to capturing their value while managing the risks they introduce.