The same infrastructure that makes agentic commerce possible is about to stress-test every assumption your fraud detection systems were built on.
When Amazon sued Perplexity in November 2025 to stop the startup’s AI browser from making purchases on its platform, the e-commerce giant’s complaint contained a revealing admission. Amazon’s own filing noted that Perplexity’s Comet agent was vulnerable to “even the oldest tricks in the scammer’s playbook,” including scanning phishing emails, visiting malicious websites, and prompting users for banking credentials. The company suing to control AI shopping agents was simultaneously acknowledging that those agents can’t reliably distinguish legitimate merchants from fraudulent ones.
That tension captures where the retail industry finds itself. AI-driven traffic to U.S. online retail sites surged 4,700% year over year in late 2025. Shopify reported AI-driven orders up 11x since January 2025. The channel is arriving whether merchants have prepared for it or not, and the fraud systems designed to protect them weren’t built for buyers that behave this way.
Why fraud detection loses visibility
The fraud detection systems protecting most e-commerce platforms were built on an assumption so fundamental it rarely gets examined: buyers are human. Device fingerprints, browsing patterns, session analytics, interaction timing: these inputs work because human shoppers leave distinctive behavioral trails as they navigate, compare options, hesitate over decisions, and eventually purchase. The entire detection architecture depends on signals that emerge from how humans shop.
AI agents generate almost none of them. An agent executing a purchase task moves directly from product identification to checkout without the exploratory behavior that distinguishes legitimate shoppers from credential-testing fraudsters. When Experian released its 2026 Future of Fraud Forecast, the company named this the year’s top threat: “machine-to-machine mayhem” in which cybercriminals blend legitimate shopping bots with malicious ones. “It’s not enough anymore to say that it’s a bot, so we need to stop this traffic,” said Kathleen Peters, Experian’s chief innovation officer for fraud and identity. “Now, we need to say, ‘Is it a good bot or is it a malicious bot?'”
Early data from Riskified’s merchant network suggests the risk differential is already measurable. LLM-referred traffic was 2.3 times riskier for ticketing merchants and 1.8 times riskier for electronics retailers compared to traditional Google search traffic. Those figures predate widespread autonomous purchasing. As agents gain actual transaction authority rather than just research and recommendation functions, the gap will widen.
The signal degradation would matter less if the infrastructure enabling agentic transactions addressed the resulting vulnerability. It doesn’t.
What commerce protocols don't protect
OpenAI’s Agentic Commerce Protocol, developed with Stripe, provides frameworks for secure checkout flows and credential handling. Google’s Agent Payments Protocol addresses similar concerns. Both represent genuine engineering achievements for a problem their architects understand well: payments integrity.
What neither protocol addresses is merchant legitimacy. An agent following ACP or AP2 specifications can complete a technically valid transaction with a completely fraudulent storefront, and nothing in the protocol layer flags the discrepancy. The question of whether a merchant actually represents the brand it claims to represent falls outside the design scope entirely.
This creates an asymmetry that brand impersonation operators are already positioned to exploit. Fake storefronts hosted on trusted platforms, credential harvesting pages, and counterfeit checkout flows work against agents just as effectively as they work against humans, but agents lack any mechanism for suspicion. A human might notice something feels off. An agent completing its assigned task has no equivalent instinct.
Liability frameworks haven’t caught up either. When a human customer falls for a phishing site impersonating a brand, the fraud occurred because a person was deceived. When an AI agent routes a customer’s credentials to a fraudulent storefront, the customer delegated authority to software that couldn’t distinguish legitimate from fake. The protocols don’t allocate responsibility for that failure, and case law hasn’t developed to fill the gap. The account takeover that follows looks the same in the fraud logs regardless of whether a human or an algorithm was deceived.
The result is a detection problem that falls entirely on merchants: behavioral signals disappearing on one side, protocol-level protection absent on the other.
Which fraud signals survive
The merchants encountering agentic commerce risk firsthand are learning which signals survive the transition and which don’t. Behavioral analytics, the foundation of most contemporary fraud detection, largely don’t. Device fingerprinting, session tracking, browsing cadence, interaction timing: these inputs either vanish entirely or become unreliable when the buyer is an algorithm.
What remains viable are transactional signals that exist independent of how a purchase was initiated. Shipping address velocity still distinguishes normal purchasing from fraud rings cycling through stolen credentials. Payment method patterns still identify mismatches between card characteristics and transaction behavior. Account-level baselines still flag anomalies when an agent operating on behalf of an established customer suddenly exhibits purchasing patterns that diverge from history.
The implication is a reweighting exercise that many merchants haven’t begun. Systems trained on behavioral inputs will degrade as agent traffic increases, not because the models are wrong but because the inputs they depend on are disappearing. The merchants who recognized this early are already recalibrating. The merchants who haven’t will discover the gap when their false-negative rates climb.
The timeline for retailers
Amazon’s lawsuit against Perplexity wasn’t just a competitive maneuver to protect its marketplace. It was an acknowledgment that even the largest retailer in the world doesn’t have answers for what happens when AI agents encounter the fraud infrastructure already waiting for them. The admission in their own complaint—that Comet falls for “the oldest tricks in the scammer’s playbook”—applies equally to every agent architecture currently in development.
The timeline for preparation is shorter than many merchants assume. Agent traffic is already growing faster than the fraud models designed to evaluate it, and the detection windows that matter for human-targeted attacks compress further when buyers operate at machine speed. Protocol standards are solidifying without merchant verification built in. Liability frameworks remain undefined. The merchants who navigate this transition successfully will be those who recognized that the assumptions underlying their existing systems stopped holding the moment buyers stopped being human.
The Bottom Line
Agentic commerce represents a channel shift that will stress-test fraud detection, brand protection, and liability frameworks simultaneously. The behavioral signals that made fraud detection work for a decade are disappearing. The protocols enabling agent transactions don’t verify merchant legitimacy. The attackers building fake storefronts don’t need to adapt their techniques because the techniques already work against buyers that can’t feel suspicion.
What’s underway isn’t a future problem. The traffic is already here, the risk differentials are already measurable, and the preparation window is already narrowing.
Key Takeaways
Traditional fraud prevention relies on behavioral signals like device fingerprints, browsing patterns, and hesitation timing. AI agents generate almost none of these signals. Fraud models trained on behavioral inputs will degrade as agent traffic increases.
Early data shows LLM-referred traffic is 2.3 times riskier for ticketing merchants and 1.8 times riskier for electronics retailers compared to traditional search traffic. Those figures predate widespread autonomous purchasing and will likely increase.
The Agentic Commerce Protocol and similar frameworks focus on payments integrity, not merchant legitimacy. An agent can complete a valid transaction with a fraudulent storefront impersonating a brand, and nothing in the protocol layer detects the problem.
Transactional signals that exist independent of how a purchase was initiated remain viable: shipping address velocity, payment method patterns, and account-level baselines that flag anomalies when purchasing behavior diverges from established history.



