July 20, 2026

The Bot Gate Becomes the Storefront Door: Commerce Tops the Attack Charts, Agent Readiness Gets Ranked, x402 Gets a Standards Body

Week of July 14-20, 2026. Akamai published a security report naming commerce the most targeted industry on the internet, with AI bots now accounting for 47.9 percent of all commerce traffic and attackers hijacking legitimate shopping agents to spend other people’s stored credentials. Digital Commerce 360 and ReFiBuy launched the first public ranking of how ready the Top 1000 retailers are for agent-driven shopping, and one of the four scores is simply whether you let bots read your catalogue. The Linux Foundation made the x402 Foundation operational with 40 members and Coinbase’s protocol contribution complete. And the regulatory picture split, with a US bill drafting forced agent interoperability while the EU’s own review found the DMA does not currently reach AI agents.

Last week we covered Walmart putting hard numbers behind its own shopping agent, AI-referred shoppers outconverting every other channel at Prime Day, and Visa turning on live agent checkout across Europe. That settled the question of whether agents sell. This week the follow-on question arrived, and it is harder: which agents do you let in?

For twenty years the answer to bot traffic was simple. Block it. Bots scraped prices, hoarded inventory, and cost bandwidth. Nobody lost revenue by turning them away. That calculation just inverted. Half your traffic is now machines, a growing share of those machines are shoppers carrying real intent and real payment credentials, and the ones that are not shoppers have learned to look exactly like the ones that are. Meanwhile someone has started publishing a public score for how well you serve them.

Here’s what happened.


Akamai names commerce the most attacked industry, and half its traffic is now bots

On July 15, Akamai published its State of the Internet report, titled “Securing the Agentic Storefront: Attacks on Commerce.” The headline finding is a threshold crossing: as of December 2025, AI bots made up 47.9 percent of all commerce traffic across Akamai’s global network, and commerce is now the world’s most targeted industry by cybercriminals. More than 70 percent of those AI bot triggers come from LLM training crawlers, with OpenAI, ByteDance, and Anthropic the three most-observed. Retail absorbed 84 percent of all DDoS volume, with roughly 3 trillion Layer 7 attacks aimed at commerce in 2025.

The part that matters most for merchants is not the volume, it is the disguise. Akamai describes a signal-masking problem, where autonomous AI shopping agents mimic human microbehaviours well enough that the behavioural signals bot defences have relied on for a decade stop separating humans from machines. On top of that, attackers are hijacking legitimate AI assistants to abuse the payment credentials those assistants already hold, and using LLMs to assemble synthetic “Frankenstein” identities that walk past static fraud rules. The report also found that commerce organisations put more than 90 percent of AI bot activity into a “monitor” bucket and then let three-quarters of what remained pass unrestricted, which is not a policy so much as an absence of one. On the API side, 85 percent of commerce respondents had at least one API incident in the past year, but only 22 percent knew which of their APIs expose sensitive data.

Why it matters for merchants: This is the bill arriving for a year of good news. Every week we have covered another surface where an agent can find and buy your product, and each one of those agents reaches you as a non-human request. You now have to make a decision you never had to make before, because both of the old answers are wrong. Block bots aggressively and you block the buying agents that Prime Day just showed are your best-converting traffic. Let everything through and you are the soft target in the most attacked industry on the internet, with attackers who can imitate a shopping agent well enough that your existing defences will not tell them apart. The practical read is that bot management stops being an IT setting and becomes a commercial one, because the allow list now determines which sales channels exist for you. This is exactly the problem Visa’s Trusted Agent Protocol and Agent Directory were built to answer: a way to tell a verified, cardholder-delegated agent from something wearing its clothes. Akamai’s numbers are the argument for why you should care that those things exist. Ask your platform or CDN provider today what they can currently distinguish, because “monitor everything, block nothing” is now measurably the industry default and measurably a bad one.

Update: In August a federal appeals court narrowed the options further, ruling that an agent acting on a customer’s instruction is legally that customer. Anti-hacking law is no longer the lever for keeping agents out. Terms of service and verified agent identity are what remain.


Your agent readiness stops being private: Digital Commerce 360 starts publishing the score

Also on July 15, Digital Commerce 360 and ReFiBuy launched the AI Commerce Rankings, a quarterly benchmark scoring how prepared Top 1000 retailers are for AI-driven shopping and agentic product discovery. It is the first structural expansion of the Top 1000 in more than 25 years of publication. The methodology scores four signals: bot friendliness, meaning how accessible your catalogue data actually is to AI agents; the share of your web traffic arriving from AI discovery sources; the diversity of those AI sources, so that dependence on a single engine is visible; and 90-day momentum, the direction that AI-source traffic is trending. ReFiBuy, which coined the term Agentic Commerce Optimization, produced the underlying data and scoring; the rankings update every quarter.

Why it matters for merchants: Look at what the very first industry benchmark for agentic readiness chose to measure. Not checkout integration. Not which protocol you support. Not payment rails. It measures whether agents can read your catalogue, whether they are sending you traffic, and whether that traffic is growing. That is discoverability, scored, and it is the argument this site has made since it started: the protocols solve checkout, but the thing that decides whether you exist in agentic commerce is whether an agent can find and understand your products in the first place. Two things follow. First, this is now competitive intelligence that runs both ways, because your buyers, your investors, and your competitors can see a number that used to be invisible, and quarterly updates mean the trend is visible too. Second, it hands you a diagnostic you can run on yourself for free, whatever platform you are on and whether or not you are in the Top 1000. Check what a crawler actually receives from your product pages, check what share of your sessions come from ChatGPT, Gemini, Perplexity, and Google AI Mode, and check whether that share is concentrated in one source. Note also how directly this collides with the Akamai finding published the same day: bot friendliness is now a public score at exactly the moment bot hostility became a defensible security posture. Getting that balance right is the merchant skill of the next twelve months. (See our coverage of how far most catalogues still are from agent-ready.)


x402 gets a standards body: 40 firms agree on how machines pay

On July 14, the Linux Foundation announced the operational launch of the x402 Foundation, with Coinbase’s contribution of the x402 protocol complete and 40 organisations signed up as members. The premier tier alone is a map of the agentic payment stack: Visa, Mastercard, American Express, Stripe, Adyen, Fiserv, Google, Amazon Web Services, Cloudflare, Coinbase, Circle, Ripple, Shopify, MoonPay, and the Solana, Stellar, and Monad foundations. The protocol itself revives HTTP status code 402, “Payment Required,” which Tim Berners-Lee reserved in 1991 and which sat unused for 35 years because card minimums made sub-dollar payments unworkable. It embeds payment directly into the web request itself, so an agent, API, or application can send and receive value as easily as it exchanges data, with support spanning cards through to stablecoins. Board chair Alin Dragos of AWS Payments framed the gap plainly: participants can exchange information, but there has never been a good way to exchange value. The stated aim is vendor-neutral governance, so the payment layer stays open, interoperable, and free from lock-in.

Why it matters for merchants: Two weeks ago we covered the payments industry rallying 140-plus firms behind Open USD. This is the other half of that story and the more consequential one. Open USD is a token, a thing that settles. x402 is the grammar, the agreed way a machine asks to pay and a server says how much. Standards bodies are boring right up to the moment they decide the defaults everyone inherits, and this one has Visa, Mastercard, Stripe, Adyen, Google, AWS, Cloudflare, and Shopify inside the same governance structure, which is a rare degree of agreement this early. For a merchant the near-term implication is not that you integrate anything. It is that agent-initiated payment is consolidating on one open handshake rather than fragmenting into a payment method per AI platform, which is the outcome that would have been genuinely expensive for you. It also means the interesting new price points, the per-request and per-item micropayments that card economics made impossible, become technically available. Watch whether your payment provider joins, and note that Adyen and Shopify are already in the room.


The European angle: Washington drafts forced agent access while Brussels finds its gatekeeper law does not reach agents

The regulatory picture pulled apart this period. On July 14, law firm Davis Wright Tremaine published an analysis of the federal AI AGENT Act, a US discussion draft that would require large platforms, those with 50 million or more US users, to let authorised third-party AI agents access the platform on the same terms as a human user, through interoperable and non-discriminatory interfaces, and would bar platforms from favouring their own agents. The draft also proposes fiduciary-style duties for agents, obliging them to prioritise price, efficiency, and the user’s stated preferences, and to refrain from using shopper data for advertising or behavioural profiling. Notably, it explicitly contemplates merchants attempting to influence agent behaviour with content written for machine consumption, without resolving where product description ends and manipulation begins.

Europe is on a different track. The Commission’s DMA review, published in April, concluded that the Act remains fit for purpose but flagged AI as an area needing focus, and analysis from the International Center for Law and Economics argues the DMA cannot designate AI agent providers as gatekeepers at all unless their services fit the existing core platform service categories, which agentic systems largely do not. An agent that navigates a retailer’s site and concludes a contract for a consumer does not need a contractual relationship with that retailer, which breaks the triangular structure the DMA assumes. Meanwhile Europe’s one firm date is now under two weeks away: the AI Act’s Article 50 transparency obligations apply from 2 August 2026, and EuroCommerce filed formal concerns in June that the Commission’s transparency guidelines are disproportionately broad for the retail sector.

Why it matters for merchants: The asymmetry here is worth understanding, because it cuts against the usual assumption that Europe regulates first and hardest. On agent access, the US is the one drafting a rule that would force the largest platforms to admit third-party agents, which is the rule that would decide whether a shopping agent can reach Amazon’s catalogue or only Amazon’s own. Europe has the more mature transparency regime and the earlier hard deadline, but its competition instrument was written for platforms that sit between two contracting parties, and an agent acting for a shopper does not sit there. That leaves European merchants with a specific near-term posture. The compliance work due on 2 August is real and it is about disclosure: if AI generates or materially shapes your product copy, images, reviews summaries, or your customer-facing chat, you need to be able to say so. The competition question, whether the big platforms must let agents in, is unresolved on this side of the Atlantic and may be decided in Washington first, with European practice following the defaults that get set there. That is the same US-first, Europe-fast-follow pattern we have tracked since April, except this time the thing following is the rulebook rather than the technology. (See our earlier coverage of the August 2 clock and EuroCommerce’s exemption request.)


What moved this period

Development What happened Why a merchant cares
Akamai State of the Internet Commerce is the top-attacked industry, 47.9% of traffic is AI bots Blocking bots now costs sales, allowing them costs security
DC360 + ReFiBuy AI Rankings Quarterly public score of Top 1000 agent readiness Bot friendliness and AI traffic are now measured in public
x402 Foundation goes operational 40 members incl. Visa, Stripe, Adyen, Google, AWS, Shopify Agent payment consolidates on one open handshake, not many
US AI AGENT Act draft Would force large platforms to admit third-party agents Decides whether agents can reach the biggest catalogues
EU AI Act Article 50 Transparency obligations apply from 2 August 2026 AI-generated product content needs disclosure in under 2 weeks

What merchants should do this period

1. Turn bot management into a commercial decision, not an IT default. Akamai found commerce organisations monitoring more than 90 percent of AI bot activity and then letting three-quarters of the rest through unrestricted. That is the worst of both positions. Get a list of which agents currently reach your product pages, decide deliberately which ones you want as sales channels, and ask your CDN or platform provider what they can actually verify. The goal is not “allow” or “block,” it is knowing the difference between a delegated shopping agent and something imitating one.

2. Score yourself on the four signals before someone else does. The AI Commerce Rankings measure bot friendliness, AI-source traffic share, source diversity, and 90-day momentum. All four are things you can check yourself this week. Fetch your own product page the way a crawler would and see whether price, availability, and variants are present without JavaScript. Then segment your analytics by AI referrer and look at both the share and the trend. If one engine accounts for nearly all of it, that is concentration risk worth knowing about.

3. Do not chase x402, but ask who your provider is standing with. Nothing to integrate this week. The useful question for your payment provider is whether they are participating in the x402 Foundation and what their roadmap is for agent-initiated payment. Adyen, Stripe, Shopify, Visa, and Mastercard are all inside. If yours is not, you want to know what they plan to support instead. (See our earlier coverage of Adyen positioning itself as the translation layer.)

4. European merchants: the 2 August disclosure deadline is now the near thing, and it lands on product content. Article 50 applies in under two weeks. Inventory where AI touches anything a customer sees: generated or rewritten product descriptions, AI-produced imagery, synthesised review summaries, and your on-site chat assistant. Decide what needs a disclosure and get it in place. EuroCommerce is still arguing the scope is too broad, but the date does not move on an open objection, and this is the first EU rule that reaches directly into the product data agents read.


Sources

Stay ahead on agentic commerce

New research, experiments, and insights on how AI agents are reshaping e-commerce. No spam, just signal.