Skip to content
A Akamai Security Reference

Emerging

AI Bots & Agentic Security

Automated traffic is no longer just crawlers and attackers. AI agents now browse, research, compare and transact on behalf of users — which breaks the assumption that “bot” means “block”.

The shift: from blocking bots to governing agents

For twenty years bot management was a binary question with a mostly binary answer: search crawlers in, everything else out. Agentic AI dissolves that model, because a large and growing class of automated traffic is acting for a legitimate customer. An AI assistant that researches a product, compares prices and completes a purchase is revenue — if you can recognise it and trust it. Blocked indiscriminately, it is lost revenue and an invisible customer.

Three distinct populations now need distinct policy:

PopulationIntentSensible default
AI crawlers / training data collectorsIngest content at scale for model training or index buildingPolicy decision: allow, restrict, or monetise — but always identify
Retrieval / answer-engine agentsFetch a page in real time to answer a user's question, often with attributionUsually allow — this is referral traffic in a new shape
Transacting user agentsAct on behalf of an identified end user: browse, add to cart, purchaseAllow under verified identity, with fraud and rate governance

Malicious automation dressed as an AI agent is the fourth population, and it is precisely why identity — not User-Agent strings — must be the basis of policy.

Agentic Security Framework

Akamai's Agentic Security Framework is aimed at powering trusted AI-driven interactions and commerce. The problem it addresses is trust establishment between three parties who previously had no protocol for it: the user on whose behalf an agent acts, the agent itself, and the site the agent transacts with.

The functional requirements this creates for a defender:

Web Bot Auth — cryptographic bot identity

Web Bot Auth replaces reputation-by-IP-range with reputation-by-signature. The bot operator holds a private key and signs its HTTP requests; the site verifies the signature against the operator's published public key. The practical consequences are significant:

Reference: Redefining trust with web bot authentication.

Visibility into AI bots and agents

Before any policy is possible you need to answer, with data: which AI bots and agents are hitting my properties, what are they fetching, how much origin cost are they generating, and is that traffic producing any value? Improved visibility into AI bots and agents means classification that distinguishes training crawlers from retrieval agents from user-delegated agents, reported per property and per path.

Practical reporting questions to answer before deciding policy:

Monetization for publishers

For publishers, blanket blocking of AI crawlers converts an asset into nothing; blanket allowing gives it away. Monetization integrations create a third option: identify the AI crawler, then require a commercial arrangement for access to content — per-crawl licensing, negotiated agreements, or tiered access — enforced technically at the edge for operators who have not agreed to terms.

This only works if identification is reliable, which is why Web Bot Auth and monetization are two halves of one strategy. See the Akamai sales-digest posts on monetization integrations and improved visibility into AI bots and agents.

Building an AI bot policy

  1. Measure first. Two weeks of classified AI traffic reporting, by operator and path.
  2. Decide by content class, not site-wide. Marketing pages, documentation, paywalled editorial and transactional flows deserve different answers.
  3. State it machine-readably — robots.txt directives and any emerging preference signals — then enforce technically, because well-behaved operators honour the file and the rest do not.
  4. Prefer verified identity to heuristics. Support signed-request verification and validate self-declared crawlers.
  5. Treat user-delegated agents as customers, with fraud and inventory controls appropriate to automated purchasing rather than human pacing.
  6. Revisit quarterly. This area is moving faster than any other in bot management.

Reference documentation compiled from Akamai TechDocs, Akamai blog/newsroom material and Cloudflare Learning Center fundamentals. Product behaviour and limits change — validate against current vendor documentation before production use.