AI agents are now transacting, browsing, and making decisions on behalf of real people. They are also being spoofed, deceived, and weaponized. For brands, the impersonation problem just expanded in three directions at once.
Agentic AI refers to artificial intelligence systems that can take independent actions, make decisions, and execute multi-step tasks without waiting for a human to approve each step. Where earlier AI tools generated text or answered questions, agentic systems browse the web, manage subscriptions, complete purchases, schedule meetings, and interact with services on a user’s behalf. The World Economic Forum’s 2026 Annual Meeting estimated that by 2028, one in four data breaches could result from AI agent exploitation. Bain projects that agentic AI will handle 15 to 25 percent of all ecommerce volume by 2030.
The security implications are moving just as fast. OWASP published its 2026 State of Agentic AI Security report, and unlike its 2025 predecessor, which catalogued plausible threats, the 2026 edition documents real CVEs, vendor advisories, and breach reports tied to nearly every category of agentic risk. Darktrace found that 92% of security professionals are concerned about AI agents’ impact on their organizations, and a Dark Reading poll reported that 48% of cybersecurity professionals named agentic AI the single most dangerous attack vector for 2026. The concern is not theoretical. It is operational, and a significant portion of the risk traces back to impersonation.
Three impersonation problems, not one
The conventional framing of agentic AI security focuses on prompt injection, privilege escalation, and data leakage. These are real technical risks, but they obscure a simpler observation: AI agents introduce impersonation vulnerabilities that run in three directions simultaneously, and each one matters for brand protection.
The first is that AI agents themselves are being impersonated. DataDome’s AI Traffic Report tracked nearly 8 billion AI agent requests across its network in January and February 2026 and found that trusted agent identities are being spoofed at scale. Meta-ExternalAgent saw 16.4 million spoofed requests in that two-month window. ChatGPT-User saw 7.9 million. PerplexityBot carried a 2.4% impersonation rate. The mechanism is straightforward: platforms that extend preferential treatment to recognized AI agents, reduced friction, priority access, relaxed rate limits, are creating a trust layer that attackers exploit by presenting their own agents under a trusted name. Half of the traffic from compromised agent instances was dedicated to vulnerability scanning. The rest targeted scraping, account takeover, and payment fraud.
The second is that AI agents are being deceived by brand impersonation. When Guardio Labs ran its “Scamlexity” experiments, researchers directed AI shopping agents to purchase products and navigate real-world scam scenarios. The agents could not distinguish a counterfeit Walmart storefront from the real one. They proceeded to enter payment details on fake checkout pages without flagging any inconsistency, because the visual and structural signals that a human might catch (or might not) are not part of how most AI agents evaluate a website’s legitimacy. As agentic commerce scales toward Bain’s 15-25% projection, the brands being cloned in fake storefronts face a new category of victim: automated buyers that have even less ability to verify authenticity than the humans they represent.
The third is that AI agents are being used as tools for impersonation. KnowBe4’s 2026 analysis documented how AI agents now support multilingual phishing campaigns, voice-based impersonation, and contextually accurate social engineering that eliminates the grammatical and tonal errors defenders have traditionally relied on as detection signals. Cybercriminals use AI agents to scan websites, social media, and leaked datasets for targeting information, then generate personalized lures at a speed and scale that manual operations could never match. The Chainalysis finding that AI-enabled scam operations generate 4.5 times the revenue of traditional ones reflects this advantage directly.
What this means for brand protection
For organizations whose brands carry consumer trust, the agentic AI shift expands the impersonation surface in ways that existing monitoring may not cover.
The spoofing of AI agent identities means that platforms need to verify not just human users but the agents acting on their behalf, and any brand operating a platform where AI agents transact needs to consider whether its trust signals are being borrowed by malicious agents posing as legitimate ones. The deception of AI shopping agents means that fake storefronts impersonating your brand will soon face a growing population of automated buyers with no ability to distinguish the clone from the original. And the weaponization of AI agents for phishing means the impersonation campaigns targeting your customers will be more personalized, more convincing, and harder to detect than anything the pre-agent era produced.
Mastercard and Visa have both responded with agent-specific payment rails, Mastercard’s Agent Pay with Agentic Tokens and Visa’s Intelligent Commerce with scoped credentials, designed to verify which agent is transacting and within what limits. These are infrastructure-level responses to an infrastructure-level problem. For individual brands, the operational response is to extend the same monitoring and takedown discipline applied to phishing pages and fake storefronts into the surfaces where AI agents interact with your brand: fake checkout pages that automated buyers will not question, spoofed agent traffic that borrows your platform’s trust signals, and AI-generated phishing that uses your name with a precision no human operator could sustain.
The Bottom Line
Agentic AI has expanded the impersonation surface in three directions simultaneously. AI agents are being impersonated to exploit the trust platforms extend to recognized automation. AI agents are being deceived by brand impersonation they cannot distinguish from the real thing. And AI agents are being used to conduct impersonation campaigns at a speed and personalization that manual operations cannot match. For any organization whose brand carries the kind of trust that moves transactions, the agentic era does not create a new category of threat. It accelerates the one that already existed and introduces a population of automated participants that are, in many cases, even more susceptible to impersonation than the humans they represent.
Key Takeaways
Artificial intelligence systems that take independent actions, make decisions, and execute multi-step tasks without waiting for human approval at each step. Agentic systems browse, purchase, schedule, and interact with services on behalf of users, and are projected to handle 15-25% of all ecommerce by 2030.
DataDome tracked 16.4 million spoofed Meta-ExternalAgent requests and 7.9 million spoofed ChatGPT-User requests in just two months. Attackers present their agents under trusted names to exploit the preferential treatment platforms extend to recognized AI traffic.
Yes. Guardio Labs found that AI shopping agents could not distinguish counterfeit storefronts from real ones and proceeded to enter payment details on fake checkout pages without flagging any inconsistency.
AI agents generate multilingual phishing campaigns, conduct voice-based impersonation, and produce contextually accurate social engineering at scale. Chainalysis found AI-enabled scam operations generate 4.5 times the revenue of traditional schemes.
Extend monitoring and takedown capabilities to the surfaces where AI agents interact with your brand: fake storefronts that automated buyers will not question, spoofed agent traffic exploiting your platform’s trust signals, and AI-generated phishing campaigns using your name with precision no human operator could match.



