Trusted AI Agents and Fraudulent Automation
Consider the following scenario: A customer asks an AI assistant to find running shoes under $150, compare delivery dates, apply loyalty points, and complete the purchase. At the same time, another automated system visits the same merchant to create an account, test promotional codes, cycle through payment credentials, and buy high-demand inventory.
Both visitors are automated. Both use a full browser, execute JavaScript, have a normal-looking IP address, retain cookies, and move through an otherwise standard shopping journey. But only one is acting with a real customer's authorization. Can you tell which?
Existing fraud and bot management solutions remain critical to understanding behavior, identity, device characteristics, and transaction risk. But agentic commerce introduces another important question: What can the infrastructure behind the session tell us about who or what is actually making the request?
Answering that question requires enriching existing fraud signals with network and infrastructure context behind the session.
Why Traditional Signals Aren't Enough
Historically, identifying automation was itself a valuable fraud signal. Merchants could look for abnormal browsing behavior, browser characteristics, unusual request rates, CAPTCHA failures, or other indicators that suggested a human wasn't behind the keyboard. But agentic commerce complicates that model.
Some automated activity may be initiated specifically by a trusted customer. An AI agent could research products, compare prices, manage subscriptions, interact with loyalty programs, or complete transactions on a consumer's behalf.
At the same time, fraudsters have access to increasingly sophisticated automation of their own. Their tools can mimic browser behavior, execute JavaScript, retain state, rotate infrastructure, and distribute activity across large pools of residential IP addresses that make their activity look legitimate.
IP reputation has long been one component of online fraud prevention. But a simple "good IP/bad IP" determination is increasingly inadequate. Instead of originating from an obvious hosting provider or data center, malicious traffic can be routed through residential devices and consumer internet connections. The merchant sees what appears to be an ordinary residential IP address, even though the connection may actually be part of a commercial proxy service or other anonymization infrastructure.
Browser and device characteristics face a similar challenge. A sophisticated malicious agent can increasingly present many of the characteristics expected from a normal browser session.
Cookies, device identifiers, behavioral analytics, IP reputation, and bot detection all provide valuable signals. But they lack detailed context about the network infrastructure behind the individual session, such as the anonymization service being used, the nature of the connection, or whether that infrastructure is consistent with the agent's claimed identity.
Session Enrichment Adds a Needed Layer of Context
Session enrichment adds real-time context about the network and infrastructure behind an individual interaction. Rather than looking only at an IP address, device, or browser, it enriches the session with signals such as whether the connection is using a VPN, residential proxy, data center, or other anonymization service; which service is behind it; and whether those characteristics are consistent with the identity and activity being presented.
In practice, session enrichment means taking an interaction that a fraud platform might otherwise see as "IP address X, browser Y, account Z" and adding context such as "this connection is anonymous, it is associated with a residential proxy service, and its infrastructure is inconsistent with the claimed agent."
This context does not replace bot management, identity, device intelligence, or payment fraud systems. Instead, it gives those systems another layer of evidence they can use to make a better risk decision.
Using Session Enrichment to Improve Trust Decisions
Not every automated action carries the same risk. An agent searching a product catalog is fundamentally different from an agent changing an account email address. Comparing shipping options is different from redeeming loyalty points. Checking inventory is different from purchasing the last 20 units of a limited-release product.
A merchant might allow low-risk automated activities when there is reasonable confidence in the agent while requiring stronger evidence or additional customer verification for higher-risk actions. For example:
- Lower risk: Search, product comparison, availability checks, and general browsing.
- Moderate risk: Adding products to a cart, retrieving personalized pricing, accessing account-specific information, or applying promotions.
- Higher risk: Account creation, credential changes, loyalty-point redemption, adding payment methods, purchasing high-demand inventory, or completing high-value transactions.
The required level of confidence can increase along with the potential impact of the action. This model is familiar to fraud teams. Merchants already use risk-based approaches to determine when customers should encounter additional authentication or friction. Agentic commerce simply extends the same concept to a new participant in the transaction -- the software acting on the customer's behalf.
Understanding intent therefore creates an opportunity to apply graduated trust rather than making a binary allow-or-block decision.

From Bot Management to Agent Trust
This does not mean existing bot, fraud, identity, or payment controls become obsolete. Instead, agentic commerce will require merchants to combine signals that historically lived in different parts of the security and fraud stack.
Bot management can help identify automation and behavioral anomalies. Identity systems can establish the customer associated with an interaction. Device and browser intelligence can provide additional characteristics of the endpoint. Payment fraud systems can assess transactional risk.
Network and session intelligence determines whether infrastructure actually observed behind this session supports the story the agent is telling.
Together, those signals enable merchants to move beyond simply detecting automation toward evaluating trust.
Four Questions Merchants Should Start Asking
Agentic commerce is still evolving, and no single signal or technology will definitively separate every legitimate AI agent from malicious automation. Merchants can, however, change the questions they ask about automated traffic.
- Can we identify more than the presence of automation? Knowing that a visitor is automated is useful, but merchants increasingly need to understand the operator or service behind that automation.
- Can we validate that identity independently? Self-identification should be treated as a claim to evaluate, not proof. Network infrastructure can help establish confidence.
- Can we recognize when signals contradict one another? A trusted identity arriving through unexpected infrastructure or displaying unusual session behavior may warrant additional scrutiny.
- Can we apply trust according to the action being requested? The goal should be to apply policies that consider both confidence in the agent and the potential impact of its requested action.
Trust Is Becoming the Better Question
The running-shoe shopper and the fraudster from our opening example may increasingly look alike from the perspective of traditional bot detection. The meaningful difference between the two is who is behind the automation, whether network and session evidence supports that identity, and whether the requested action is appropriate for the level of trust established. Session enrichment gives merchants another layer of evidence for making that distinction.
As agentic commerce grows, merchants will need to become comfortable with a world in which some of their best customers aren't the ones clicking the buttons. The challenge will be making sure merchants can tell the difference between an agent working for the customer and automation working against them.
About Spur Intelligence

Spur Intelligence helps organizations understand the infrastructure behind internet traffic, including VPNs, residential proxies, hosting networks, and other anonymization services. Fraud and security teams use this network and session context to improve decisions about online activity.
For more, including free access through Spur Community to 100,000 session assessments per month, visit https://spur.us/.
About the Author
Alastair Parr is Chief Technology Officer at Spur, where he leads the company's technology strategy, platform architecture, and product innovation. He brings deep experience building security and risk platforms that translate complex data into actionable insight for enterprises.
Prior to joining Spur, Alastair served as Senior Vice President of Global Products and Services at Prevalent and was a founder of 3GRC, where he played a central role in defining the company's products and services. His background spans governance, risk, and compliance, with a focus on developing scalable solutions for complex risk management challenges.
Earlier in his career, Alastair was Operations Director for InteliSecure, a global managed security services provider, overseeing data protection and risk management programs for enterprise clients. He holds a degree in Politics and International Relations and maintains several information security certifications.