Published on
Zach Jackson

For decades, the rule of thumb for website security and analytics has been to, wherever possible, block non-human traffic. After all, besides some notable exceptions such as search engine crawlers, bot traffic is a nuisance.

But the shape of traffic is changing, and the line between bot and buyer is blurring.

As agentic commerce technology becomes more capable and commonplace, businesses need to reassess their outlook, analytics, and access settings regarding bots.

Moving away from the ‘bot = bad’ mindset

There’s no question that bot traffic has earned its bad name. Typically, non-human traffic meant four things: 

  • Skewed Google Analytics data
  • Ad fraud
  • Server slowdowns
  • Security threats like credential stuffing or price scraping 

But continuing to treat all automated traffic as the enemy could become a major commercial liability.

We all already acknowledge that there is a distinction between good bots and bad bots, with the good ones being central to search functionality and site visibility. Now, we just need to broaden our understanding of what constitutes a good bot to include AI search agents, bots that make purchases on the user’s behalf.

Agentic AI - here comes the hybrid traffic

You may have heard talk of the “agentic era”. This refers to agentic AI, which, in a nutshell, is AI that can complete actions online based on a human’s request.

What is agentic artificial intelligence? - a simple explanation

Agentic artificial intelligence (or agentic AI) describes AI that can work towards a goal by organising and carrying out a series of steps, rather than simply responding to a single prompt.

You can think of agentic AI as a manager in a business. It takes the overall objective and works out what needs to happen to achieve it. It may delegate individual tasks to “workers” (AI agents) designed to carry out specific jobs as part of the bigger process.

So, in simple terms, agentic AI is the broader approach or capability, while AI agents are the individual systems that can carry out tasks within that process.

It’s worth noting that agentic AI isn’t limited to consumer-facing applications. Businesses can also use agentic systems internally. For the purposes of this article, however, we’re interested in agentic commerce, where the AI acts on behalf of people as they search, research, compare and ultimately transact online.

From a website’s perspective, the resulting traffic may not look like traditional human traffic, but it isn’t a conventional bot either. It is, in effect, hybrid traffic.

Agentic AI vs generative AI

Agentic AI can also be generative AI, but not all generative AI is agentic.

A non-agentic generative AI search tool might retrieve information from webpages and generate a summary in response to a user's query. But it isn't necessarily able to interact with those websites to achieve a goal, for example, clicking a CTA button, completing a form or making a booking.

In agentic commerce, on the other hand, the AI can use the interactions available on a webpage to complete a task.

As a simple example of agentic shopping in action, a user might type, ‘find and book a 4 star hotel in edinburgh under £200 for next weekend’. The AI can then navigate websites, compare prices and availability, and potentially complete the transaction on your behalf.

These “bots” are consumer proxies with direct purchasing intent and real budgets behind them. For businesses, it will become increasingly important not only to grant the right bots access to your website, but to ensure that they can easily understand, navigate, and take action on your website. These are the building blocks of an effective agentic AI strategy.

Letting the right bots in - AI agent verification in agentic commerce

AI commerce optimisation should first focus on ensuring agentic bots with purchasing power can actually access your site and its resources.

To achieve this while also blocking nuisance scrapers, businesses need to transition from IP-based blocking to identity and behavioural verification.

Identity

In simple terms, the goal shifts from blocking anything that looks on the surface to be a bot, to giving the good bots a reliable way of identifying themselves.

There are several ways of doing this, from dedicated API endpoints and cryptographic handshakes to using verified bot frameworks such as those Cloudflare has been working on. However, these methods must be implemented correctly.

Making a mistake can result in blocking the wrong bots, potentially even Googlebot!

Behavioural

Agentic bots may behave differently to nuisance bots on your website. For instance, an agent’s traffic patterns will likely be low-frequency and direct, focusing on inventory availability and price, whereas a nuisance bot may exhibit a high frequency travel pattern, enabling broad scanning and scraping.

Using certain systems, you can set controls that allow one set of behaviours while restricting another. Rate limiting is a good example here.

Rate limiting is a network security control that restricts how many times a user or automated bot can send requests to an application or server within a specific timeframe. 

  • For legitimate AI buyers: An agent executing a purchase might need to make 5 to 10 quick requests (check stock, get price, fill form). A sensible rate limit lets it finish the job without triggering a hard security block.
  • For aggressive scrapers: If a bot tries to query 10,000 product pages in 30 seconds to copy your database, rate limiting slows it to a crawl, or results in a full block.

Again, though, careful implementation is essential. If your rate limits are set too aggressively, you may inadvertently restrict or block genuine AI buyers or the crawlers from AI search platforms, such as ChatGPT.

Optimising for agentic AI buyers

Putting out the welcome mat for AI search agents is just part of the agentic commerce optimisation process. At this stage, AI commerce agents can enter the “front door”, but what about finding their way around, understanding your offerings, or actually taking action?

Preparing your digital footprint for agentic commerce means ensuring your site is as easy for a machine to parse and act upon as it is for a person. As a bonus, this can also support visibility in AI search platforms and help you navigate the current zero-click search trend in the UK.

Generally speaking, it comes down to three focus areas:

  • Content optimisation - structuring your content so large language models and reasoning engines can easily extract, trust, and cite your information when an AI search agent is evaluating options.
  • Machine-readable structure - using clean, standardised metadata (like Schema markup) and ensuring compliance with web accessibility guidelines gives AI buyers explicit, real-time context about your pricing, stock availability, specifications, and booking steps.
  • Removing technical friction - the elements that frustrate human users, such as broken form fields, confusing navigation or overly aggressive bot-blocking walls, will stop an AI agent in its tracks.

At TDMP, our technical and content SEO strategies are already designed to eliminate user friction, structure site data cleanly, and maximise visibility across modern search ecosystems. Request a free SEO audit to find out if your website is prepared for the agentic era.

Build agentic commerce readiness with TDMP

Agentic commerce readiness begins with a shift in perspective and continues with technical implementation that reflects this new understanding. 

By distinguishing agentic AI from nuisance bot traffic, and providing a clear path to take action, you ensure your site is open, readable, and ready to convert.

If you’re considering how agentic AI or visibility in AI search should factor into your digital strategy, TDMP can help. Contact us today to get started future proofing your business online.

Keep your finger on the TDMPulse

Sign up to our newsletter for monthly insights, news & guides