Your Competitors Are Already Reading This

Don’t get left behind. Join 1,000+ store owners and marketers getting the breaking ecommerce news, viral product trends, and algorithm updates that matter. Before they hit the mainstream.

Published:

Nearly Half of All Ecommerce Traffic Is Now AI Bots

Akamai's latest commerce security report finds that 48% of all ecommerce traffic across its global network is now driven by AI bots, not human shoppers. The majority are training crawlers. A growing minority are shopping agents running on behalf of real customers. And an emerging, harder-to-detect category are fraudulent agents that cybercriminals have hijacked to trigger purchases using stored payment credentials, or replaced entirely with malicious bots designed to look like legitimate ones.

Author: Ivana Soldat

6 MIN READ
Nearly Half of All Ecommerce Traffic Is Now AI Bots

48% of all ecommerce traffic across Akamai’s global network is now driven by AI bots. Not human shoppers browsing product pages. Not humans adding things to cart.

The largest category is AI training crawlers, bots systematically scraping product data, pricing, descriptions, and images to feed the large language models that power AI shopping assistants and product discovery tools. Akamai’s data shows AI training crawlers account for more than 70% of all AI bot triggers in commerce. North American retail alone generated 33 billion AI bot counts, representing nearly 16% of the global total. EMEA retail accounted for another 26 billion, at 12.4%.

These crawlers are a nuisance and a cost, but they are not the threat. The threat is what is emerging on top of them.

When a Shopping Agent Gets Hijacked

The second category is shopping agents: AI systems that have been given explicit permission by a real human to act on their behalf, to find a product, compare prices, add to cart, and complete checkout. Steve Winterfeld, advisory CISO for Akamai, describes two distinct attack vectors now targeting these legitimate agents specifically.

The first is agent hijacking. Cybercriminals are developing tactics to take over AI agents that have already been granted access to stored payment credentials, and using that access to invoke purchases the original user did not authorize.

An AI agent that has been given permission to shop, including permission to use a stored credit card, is from a security perspective a pre-authenticated access point to both a user’s account and their payment method. Compromise the agent and you have compromised everything it was authorized to do.

The second is agent replacement. Criminals are building malicious AI agents designed to look and behave like legitimate ones, which at some unpredictable moment launch a malware attack or exfiltrate the payment credentials they were supposedly processing. The user set up an AI shopping agent. At some point, the agent they set up is no longer the one running their transactions. They have no obvious way to know.

The Frankenstein Account Gets Smarter

The third category connects directly to the synthetic identity piece EcomWatch covered last week. Cybercriminals are using large language models combined with deepfake technology to build what Akamai is calling Frankenstein accounts: synthetic identities built from one piece of real stolen data, a Social Security number, a date of birth, a genuine address record, combined with AI-generated names, backgrounds, and supporting details that pass the identity checks most ecommerce onboarding flows are designed to run.

The UK data we reported on last week showed 421,000 identity fraud cases in 2024, with false identity fraud up 60% year on year. Akamai’s report confirms the same dynamic is now operating at ecommerce account level, not just in financial services onboarding. The AI tools accelerating the creation of these identities are the same ones being deployed to make the resulting accounts behave convincingly like real shoppers. The two threats are feeding each other.

The Old Playbook Does Not Work Anymore

The existing binary approach to bot management, where traffic is either allowed or blocked based on whether it matches known bot signatures or suspicious behavior patterns, does not work for AI shopping agents.

A legitimate agent shopping on behalf of a real customer looks identical, in behavioral terms, to a malicious agent shopping on behalf of a fraudster. Both move fast. Both hit APIs directly rather than browsing page by page. Both complete checkout without the hesitation and abandonment patterns that human shoppers generate.

Winterfeld’s prescription is to move from binary allow/block models to risk-based governance that categorizes bots by intent and business value. The question ecommerce fraud and security teams need to answer is not simply “is this a bot?” It is “what is this bot trying to do, and does that align with the authorization it claims to have?”

Akamai’s data suggests the industry is not there yet. Ecommerce sites placed more than 90% of their AI bot activity in the “monitor” category, but allowed three-quarters of the remaining activity to pass unrestricted. Monitoring without action and permissive treatment of unclassified traffic reflects a security posture designed for simple automated scrapers and credential stuffing attacks, not sophisticated agents operating with real user credentials and real purchase intent.

Most Retailers Are Not Segmented Enough for This

One specific technical finding worth pulling out separately is that 92% of organizations use basic network segmentation to limit how far an attacker can move if they compromise one part of the system. Only 35% have moved beyond that to microsegmentation, the practice of creating granular boundaries within a network so that a compromised AI agent cannot move laterally to access systems or data beyond its immediate task.

For an ecommerce operator, the practical meaning is this: a compromised shopping agent should not be able to access your entire customer database, your fulfilment system, your payment processor integration, and your CRM from the same foothold. It should be contained to exactly what it was authorized to do. Most organizations have not built that containment yet.

As AI agents become a larger share of ecommerce transaction volume, the blast radius of a single agent compromise grows accordingly.


Our Take

Your Site Is Half Bot Traffic and You Are Watching Most of It Without Acting

Akamai’s report lands on the same day EcomWatch is publishing a follow-up to last week’s piece on AI agents being incorrectly blocked by fraud systems as if they were malicious bots. The two stories are the same problem viewed from opposite angles.

On one side, legitimate AI agents getting blocked because they look like threats. On the other side, fraudulent AI agents getting through because they look like legitimate ones. The middle ground where ecommerce security and fraud prevention need to operate, distinguishing between authorized agents, unauthorized agents, and compromised agents in real time at scale, does not yet have mature tooling, established standards, or widely deployed solutions.

The vast majority of ecommerce operators are running allow/block logic built for a world where the attacker was a human using a scripted tool, not an AI agent with a stored credit card and a convincing behavioral signature.

The gap between where the threat is and where the defenses are is closing slowly. The threat is moving faster.

Author

Ivana Soldat

Ivana writes about what’s actually happening in ecommerce right now, from major platform updates to the trends on how people shop online.

Focused on verified industry developments, she covers marketplace dynamics, DTC and omnichannel growth, conversion and performance strategies, retail media, and shifts in consumer behavior across leading ecommerce platforms and emerging commerce technologies.