The Agentic Survival Guide: How Security and Marketing Leaders Can Learn to Trust AI Agents
Sometime in the last year, the fastest-growing group of visitors to your website stopped being human. HUMAN watched over a quadrillion interactions in 2025 and saw AI agent traffic grow 7,851%, with automation overall growing eight times faster than human traffic.
Everyone is asking how to handle this, and the answer has a shape. Before an organization can trust what's happening on its sites, it has to see what's happening, then judge what each agent is there to do, then decide what it's allowed to do. See, judge, govern. The middle of that arc holds the uncomfortable part almost nobody is saying: you cannot solve agent identity from your side of the wall. Identity has to be born in the agent platforms themselves, with every agent action carrying an identity claim, and until that happens, everything sold as "agent identity" is correlation, meaning we get signal by combining signal from multiple different sources throughout the organization. E.g., endpoint, cloud, network, application, identity, etc. Correlation is useful and you should do it aggressively. But you should know what you're buying. If you run security, this is how you get past blocking and into governing. If you run marketing, it's why your numbers stopped adding up.
In 2016 I wrote a book called The Real Internet of Things whose central prediction was that everyone would get a personal agent, I called them daemons, that would go out and deal with businesses on their behalf. And we're starting to absolutely see this happen, with the MCP-ification of all sorts of services that are being accessed by agents.
Your instruments assume people, and the people are leaving
Security teams and marketing teams built their entire operating model on the same quiet assumption: the thing on the other end of the session is a person. That assumption is now wrong a growing percentage of the time, and it breaks each department differently. Worse: the two departments' instruments disagree about what they're seeing, and reconciling them is nobody's job.
Security's version: fraud models trained on human behavior, bot detection tuned to catch things that don't act human, account protection built around human login rhythms. An agent with legitimate credentials and a real customer behind it trips these systems constantly, because it isn't human. A well-built malicious agent sails through, because it fakes humanity better than the old botnets ever did.
Marketing's version is worse because it's silent. Attribution assumes a human followed a click path. Funnel metrics assume a human saw the ad. So when an agent researches ten travel sites and buys on one, your analytics records ten bounces and a conversion from nowhere, and the model keeps producing confident reports about a world that no longer exists. A missed threat announces itself eventually. A broken attribution model just quietly moves budget to the wrong places, quarter after quarter.
The self-awareness numbers are bad. Fewer than half of the senior marketers HUMAN surveyed were confident they could tell human, bot, and agent traffic apart. Yet 76% say they plan to optimize their strategies for AI. They're planning campaigns for traffic they just admitted they can't see.
It compounds, because people don't want to leave their AI. I've written before that the winning move in AI is living inside the systems people already use. Once someone trusts an agent, they stop visiting ten websites themselves. The agent becomes the interface, and your site becomes an API endpoint whether you designed it as one or not.
Blocking agents is how security teams get bypassed
The block-everything reflex is the wrong answer, and I say that as someone who spent twenty-five years building that reflex. For most of my career, "automated traffic" meant attack, and the paranoia is still earned: AI scraper activity grew 597% last year, attempts to hijack already-logged-in accounts quadrupled, and retail alone faced 440,000+ unique threat profiles.
But this is the oldest lesson in security. We cannot be the "no people," because people bypass the "no people." Every veteran has watched shadow IT bloom wherever the answer was no. The game was never to say no. It's yes, with guardrails. And this is the fastest technology adoption that has ever happened, so the lesson applies with more force than it ever has. And people are so incentivized to perform using AI that we have seen so many instances of people standing up their own versions of a harness or a platform to just move as quickly as possible, often bypassing the approved way of using AI.
The guardrails can be surgical, because you're writing rules about actions rather than visitors. A retailer can block agent-driven account creation, where the fraud concentrates, and still let a verified agent check out on behalf of an existing customer, because that's a sale. Same agent, two different answers, both right. Writing those calls down is what an actual agent policy looks like, and none of it waits on new technology. Notice what the checkout rule quietly requires, though: knowing which customer the agent is acting for. Behavior alone can't tell you that.
The reflex is winning anyway. In HUMAN's August 2026 numbers the share of agentic traffic getting blocked roughly tripled in one month, from 8.9% to 21%, mostly without a policy behind it. Three details in the data say this will hurt:
- LLM scrapers scout ahead of the buying agents, checking whether your site has what an agent will need. Block the scout and you never meet the buyer it was scouting for.
- Agents don't come back. A frustrated human might return tomorrow; an agent completes the purchase at a competitor and remembers which site worked. No retargeting campaign wins back a daemon.
- The customers are already on the agents' side. In HUMAN's survey of 2,300+ Americans, 64% planned to use AI for 2025 holiday shopping, and nearly three in four are open to an AI browser buying things outright. When your defenses block a customer's agent, the customer doesn't see security working. They see a broken site, and their agent learns to shop somewhere else.
So security can't just block and marketing can't just count. Both playbooks have two categories, human and bot, and the interesting traffic is now a third thing.
Governance runs on identity, and identity has to come from the platforms
The reason you can't skip identity and jump straight to governing is that you cannot build policy around behavior alone. Whether an action is malicious usually depends on who's doing it. The same thousand catalog requests can be a competitor's scraper or your biggest customer's shopping agent, and a policy that treats them the same is wrong twice.
A massive amount of the identity problem comes down to the agent-harness providers themselves. OpenAI, Anthropic, and the other harness companies are going to have to build identity into their platforms so that every agent action carries an identity claim with it. Without that shift, I think it's close to impossible for anyone else to assign identity to agent actions from the outside. You can't bolt provenance onto traffic that was born without it.
Underneath that sits a hard computer science problem: tying a low-level action, a Unix action, a shell command, strongly to the user who caused it. We never had to solve it before. The human at the keyboard was the identity. Agents break that assumption at the bottom of the stack, and until it's solved down there, every identity signal above it is inference. The marketing translation: nothing in your traffic can tell you who sent it, and neither can your attribution.
I've been saying for years that the real AI security problem is agents with misunderstood identities. Most companies can't tell you what their own agents are doing, let alone anyone else's. What's hitting your website is that same problem arriving at internet scale.
I run agents myself, every day. My personal AI does real work on real systems on my behalf. From the outside its traffic looks like automation, because it is. Whether it's me depends entirely on whether my identity travels with its actions. Right now it mostly doesn't.
We have to trust someone, and it will be the platforms
Platform-issued identity puts the vouching power with the companies selling the agents. I'm fine with that, because the alternative is nobody vouching for anything. We have to trust someone. I think the frontier labs become some of the most trusted entities in this ecosystem, alongside the big platforms that have spent decades earning trust. That's how internet trust has always bootstrapped: certificate authorities, app stores, payment networks. Imperfect anchors beat no anchors.
If that makes you uncomfortable, good. I don't see a workable alternative in the next five years.
Everything you can buy today is correlation, use it with your eyes open
Until identity claims ride with agent actions natively, the honest interim play is to audit the actions themselves with extreme granularity and correlate on your side of the wall: this session, this behavior, this declared operator, this account history. Do they belong together?
That work has three layers, and the order matters: visibility, then identity, then governance. Each layer is meaningless without the one before it. None of it waits on OpenAI and Anthropic: visibility and governance are yours to build today, and correlation covers most of the identity gap for the traffic that matters. Trust is achievable now. The platforms complete it; they don't start it.
Visibility means an actual census of the automated traffic on your properties, not a bot percentage on a dashboard. Training crawlers turn out to be 67.5% of AI-driven traffic, not the shopping agents everyone pictures. Then search bots, scrapers, user-directed agents, transaction agents, and attacks dressed as each. The census is concrete: user agent and ASN from your CDN logs, declared bots split from undeclared automation, the rest bucketed by behavior. Your CDN's bot report is the start, not the answer. Most organizations have never run it. Every organization I'd trust has.
Identity, in the interim, means correlation, and vendors can genuinely help here. The test I'd apply: do they call it what it is? A chunk of this industry is selling correlation relabeled as solved identity, and the vendors worth your money are honest about which side of that line they're on. Done well, this is serious machinery: classifying sessions against known operator signatures, catching the moment one shifts from browsing prices to strip-mining the catalog, and tying declared identity to observed behavior across billions of requests, fast enough to act mid-session. That takes vantage: HUMAN sees it because it classifies a quadrillion interactions a year, and companies watching traffic at that scale do this better than you will in-house. The tractable part: a handful of named operators generate most agent traffic today, Comet Browser alone is nearly half, major consumer agents self-declare rather than hide, and cryptographic agent verification is real standards work now: HTTP Message Signatures (RFC 9421) and the IETF's Web Bot Auth draft, already backed by OpenAI, Cloudflare, Amazon, and Akamai. Demand them from every platform that sends agents to your door; if you're behind Cloudflare, signature-based verification is live today. The long tail is where the granular auditing earns its keep.
Governance is where yes-with-guardrails becomes concrete, and it's a business decision, not a firewall rule. Verified shopping agents can browse and buy but not scrape your catalog. Training crawlers get marketing pages and nothing behind login. Unknown automation gets rate-limited into irrelevance rather than blocked, so you can watch what it wants. I've written that the right way to set an agent's authority is to calibrate each action by risk against leverage, not habit. I wrote that about my own agents; it's the same exercise pointed at other people's. Right now most companies are doing it by accident, through whatever their CDN's bot settings defaulted to in 2021.
Marketing's new job is being legible to agents
If you run marketing, all of this can sound like a security problem. It isn't, and the marketing moves are just as concrete. We've been told to believe that human is good and automated is bad. But now we're gonna have to rethink this and look at the activity itself, because there could be all sorts of human behavior that's malicious and activity that is benign. We have to rethink how we're looking at this entire thing.
Start with measurement: your dashboards have two buckets, human and bot, and the traffic that matters now needs a third. Until it exists, treat every attribution report as an estimate, and say so when budget rides on it. Concretely: ask your analytics vendor when agents get their own dimension, and ask your attribution vendor how they classify declared agents today.
Then flip from measuring agents to marketing to them. 79% of agent activity sits on product and search routes: agents are reading your product pages right now, deciding what to put in front of humans. The sites that win that traffic are the ones agents can use: accurate structured product data, clean pages, working flows. And consumers are already delegating the buying itself, starting with household goods and moving up the trust curve. The funnel increasingly ends at an agent.
And if you own digital experience, ecommerce, or product, the disruption is even more direct: your site becoming an API endpoint is your product now. Agent users don't care about hero images; they care whether the catalog parses and the flow completes. That makes the customer's agent a first-class user you design for on purpose: machine-readable product data, stable flows, and a checkout a delegated purchase can clear without tripping an alarm. Someone on your team should own agent legibility the way someone owns SEO. There are even terms for this, such as AEO and GEO, and more and more places are putting agent visibility and AI results above the classic link style.
Nobody at your company owns this, and that's the most fixable problem here
The technical gaps above have vendors and roadmaps. The organizational gap has neither, and it's the one I care most about.
Run this through your own company. An AI shopping agent working for a real customer gets blocked at checkout. Security logs a win. Marketing blames the funnel. The customer sees a broken site. A paying customer got turned away, and it appears in nobody's metrics as what it was. Now flip it: a scraper inflates your traffic while strip-mining the product data competitors' agents will use to undercut you. Marketing celebrates the engagement. Security sees nothing, because nothing was attacked.
Same root cause both times: the CISO and the CMO are looking at the same traffic through instruments that were never designed to agree, and no meeting exists where the pictures get reconciled. The ownership numbers confirm it: asked who monitors AI agent traffic, 38% of marketers said analytics, 19% said nobody owns it, and 5% said security. The fastest-growing traffic category on the internet has no owner at one company in five.
Companies don't move at the speed of their problems. I've written that if you handed most companies a magic button that tripled profits, it would take months of meetings to press it. This is that, except the button is a meeting. One hour. The CISO, the CMO, and whoever owns digital experience. Three questions, one per layer: what automated traffic are we actually seeing (visibility), which of it do we want more of (identity), and who makes the account-creation-versus-checkout calls for the rest (governance). It produces something concrete: a named owner for agent traffic, and the census as a 30-day deliverable, counting both directions: the agents hitting your properties and the agents your own org is quietly running. This meeting should exist at every company with a website, and mostly it never has.
The window is open, and it won't stay open
There's one capability underneath all of this: being able to trust the agentic traffic you've decided to welcome, and to act on the traffic you haven't. I'd call that capability agentic trust, because that's just what it is. The companies that build it get to treat the agent wave as a distribution channel while their competitors argue about whether to block it. The companies that don't will spend the next five years getting defrauded and out-marketed by the same traffic.
One number keeps this urgent rather than hopeless. As of June 2026, 79% of agent activity sits on product and search routes and only about 2% touches checkout. The agents are still window-shopping. They arrived before the money did, which means whoever builds visibility and governance now sets the terms before the transaction volume shows up. With the leading agent-building platforms growing 4x in a month, I wouldn't bet on that window staying open long.
All the data here is HUMAN's, from its benchmark report, monthly agentic-traffic tracking, and Iris surveys (full links below). The one thing I'd bet on without hedging: the agents are coming either way. Growth like 7,851% doesn't ask permission.
I waited ten years to see whether the daemon prediction would come true. It did, and now it's on your infrastructure. Whether the agents show up as customers, parasites, or attackers is mostly up to the agents. Whether you can tell which one just showed up is up to you.
Sources
- The 2026 State of AI Traffic & Cyberthreat Benchmark Report — traffic growth, scraper and account-takeover trends, threat profiles, AI-driven traffic composition.
- State of Agentic Traffic — June 2026 — monthly tracking: blocking rates, operator share, route distribution, agent-platform growth.
- The Agentic Audience: AI Agents and the New Marketing Reality — Iris survey of consumers and marketers on agentic commerce.
- Iris Report: Marketers' Perceptions — senior-marketer confidence in distinguishing human, bot, and agent traffic.
- humansecurity.com — company and product context.