For most of the last decade, eCommerce fraud teams have had a reliable tell. Humans behave like humans at checkout. You see it in mouse movement, typing cadence, the order in which someone fills out a shipping form and how long they linger before adding to the cart. Behavioral analytics built on those patterns catches a lot, and merchants are right to trust them. They work because a person sits at the other end of the session.
That assumption is thinning out. Traffic to U.S. retail sites from genAI tools rose 693% year over year during the 2025 holiday season, and shoppers arriving via AI assistants converted at a rate 31% higher than other traffic sources. Some of that is a person clicking a link that an assistant surfaced. A growing share is an agent doing the clicking. Once the software fills the form, the behavior layer stops telling you anything useful about the person paying.
What Agentic Checkout Removes From Fraud Detection
The person behind the agent hasn’t disappeared. They’ve moved a step back. Someone still has to provide the payment method, receive the goods and own the account the agent is acting for. That identity layer doesn’t get automated away, and in retail, it’s the layer that carries the loss.
What breaks is the session-behavior read. Fraud teams can’t ask whether a checkout looks human anymore, because for a growing share of legitimate traffic, the answer is no. The better question is whether the human behind the agent is trustworthy.
That reframe holds up under pressure. A technically flawless agent still rides on an identity, a device and a payment method. An agent paired with a three-day-old email address, no digital footprint and a VOIP number is high risk at a $400 checkout, exactly as it would be if someone had typed those details in by hand.
The Identity Signals That Survive Agentic Checkout
Most classic retail fraud signals survive the shift intact. A new email address, an email tied to prior fraud, a disposable domain, a throwaway phone number, device fingerprint history, IP and proxy risk. Each attaches to the customer rather than the session, which is why agentic traffic leaves them untouched.
Digital footprint analysis carries more weight in an agentic checkout, not less. Strip out the behavioral layer and what remains is the depth of the identity presenting itself. An email address with a decade of registrations across retail, social and payment platforms tells you something no agent can manufacture on demand, and an address that returns nothing anywhere is a risk signal, not a data gap.
It’s the read SEON is built around: turn a bare email address or phone number into a history of where an identity has existed and for how long, and let that depth carry the decision the behavioral layer no longer can.
Where Agentic Traffic Shows Its Hand
Agentic traffic leaves the same patterns wherever it touches retail. Three show up first.
Card Testing in Agentic Checkout
Card testing hits retail first. Guest checkout and low-value SKUs make a $1 authorization cheap to process at volume, so an agent can work through a batch of low- or zero-dollar amounts until one clears, then raise the amounts on the cards that stick. What surfaces in the review queue is a single device or identifier touching an unusual number of distinct cards inside a short window, with the values climbing as it goes.
Promo Abuse at Machine Speed
The same speed advantage shows up in promotional abuse. An attacker who opens accounts faster than a person can will work through first-order discount codes, loyalty balances and gift card stacking before the pattern registers anywhere. Redemptions and new accounts trace back to one agent and one identifier, spaced at intervals no human would hit that consistently.
Unsigned Agents Flag Themselves
Some agents give themselves away outright. A growing number of legitimate agents sign their requests, so an agent claiming to act for ChatGPT with a missing or forged signature is caught regardless of how human the rest of its behavior looks.
How Bad Agents Mimic Good Ones
The most common masking technique is cadence. Operators add jitter and delay so an agent looks less robotic, spacing actions unevenly to defeat timing-based rules. More sophisticated setups go further: replaying captured human interaction traces, randomizing mouse paths and routing sessions through residential proxies so the device and IP read clean. It works often enough to be worth their effort, and it will keep improving.
Mimicry only reaches the layer it controls. Every technique on that list targets the session — how the agent moves, when it acts and where it appears to connect from. None of it touches the identity underneath. A convincing imitation still needs an identity and a payment method, and the email address, device history and card behind the order stay as risky as they were before the agent smoothed out its timing.
What the Protocols Solve and Where They Stop
As agents get better at looking human, the industry’s answer is to stop judging behavior and start verifying credentials. Visa’s Trusted Agent Protocol and Stripe and OpenAI’s Agentic Commerce Protocol are often treated as fraud infrastructure, but they’re closer to a trust and permissioning layer. What they do well is establish that an agent is who it claims to be, through signed requests or certificates, and that it’s operating within agreed rules of engagement with a given merchant.
Visa’s protocol, released in October 2025, uses agent-specific cryptographic signatures so that a merchant can verify that an agent is who it claims to be and is operating within agreed-upon rules of engagement. That’s worth having. It closes off a class of impersonation attacks and lets merchants separate certified-agent traffic from anonymous bots.
What it doesn’t establish is whether the human behind a verified, protocol-compliant agent is legitimate. A cryptographically valid agent acting for a fraudster, a stolen identity or a synthetic account will pass protocol-level checks because the protocol verifies the agent, not the underlying customer. They raise the floor, making it harder to spoof as an agent altogether, but they don’t replace identity-based fraud detection.
Where Agentic Commerce Fraud Moves Next
Expect the protocols to reduce basic impersonation fraud as adoption spreads. The harder problem shifts upstream, to identity risk on the human behind an increasingly well-authenticated agent. Merchants who spent the last decade tuning behavioral models will spend the next one tuning what they know about a customer before the session starts. The agent is getting easier to verify. The person paying for the order still isn’t.
