RankShield
RANKSHIELD NETWORK Get started

Should you block AI shopping agents on your store?

Nearly half of commerce traffic is now AI bots. Here is how to allow real buyers and AI referrals while blocking the abuse, without making your store invisible to AI search.

July 19, 2026 · 11 min read · should I block AI shopping agents on my store
Share

You should not block AI shopping agents wholesale, and you should not allow them all either; the right move is to tell legitimate AI shoppers and referrers apart from abusive bots and treat each accordingly. Blanket-blocking makes your store invisible in AI search and turns away real buyers; blanket-allowing invites scraping, fake accounts, and agentic fraud. The scale is why this is now a real decision and not a niche one: Akamai reported that AI bots make up 47.9% of commerce traffic, with agentic AI traffic up 7,851% year over year (Akamai1). Nearly half your traffic is now automated, and some of it is your future customers arriving through a new channel while some of it is abuse. The stakes are high enough that Amazon went to court over it, winning a preliminary injunction to block Perplexity’s Comet shopping agent from its marketplace (GeekWire2). I build agent-verification tooling at RankShield, and the mistake I see most is treating this as a single block-or-allow switch when it is really a sorting problem. What most advice leaves out is how to distinguish a legitimate AI shopper from an abusive bot, which is the whole game. This guide covers the three kinds of AI traffic, which agents actually send you buyers, how to tell good from bad, and what the Amazon case means for your store. One honest note: you cannot block your way to safety without also blocking your future customers.

How much of your traffic is now AI agents?

Close to half of it. Akamai reported that AI bots account for 47.9% of commerce traffic, with agentic AI traffic growing 7,851% year over year (Akamai1). That means the question is no longer whether AI agents visit your store but what mix of them you are already receiving, and whether your current setup treats a buying agent the same as a scraping one. For most merchants, the honest answer is that they have no policy at all, so every agent is handled identically by default.

This traffic is not one thing, and that is the crux. Some of it is the search-indexing bots that let ChatGPT, Perplexity, and Google AI surface your products to shoppers, which you want. Some is agents fetching your pages on behalf of a specific human shopper, which is often a real buyer in a new wrapper. And some is abusive automation: scraping your catalog and prices, testing stolen cards, or creating fake accounts. Lumping these together is what leads to bad decisions in both directions.

The size of the shift is why a default of no policy is now a risk. When half your traffic is automated and rising fast, treating it as background noise means you are neither capturing the buyers it contains nor stopping the abuse it hides. The rest of this guide sorts the traffic into categories you can actually make decisions about, starting with the three kinds that matter.

DOWNLOADABLE INFOGRAPHIC

The three kinds of AI agent traffic

RANKSHIELD // AGENTIC COMMERCE Not all AI traffic gets the same policy AI bots are now 47.9% of commerce traffic (Akamai). Sort it into three kinds: 1. SEARCH-INDEXING Makes you visible in AI answers OAI-SearchBot, PerplexityBot, Google POLICY: Allow Blocking = invisible in AI search 2. USER-FETCH Retrieves your page for a real shopper ChatGPT-User, agents acting for a person POLICY: Allow + watch Often a real buyer; rate-limit and verify 3. BUY-FOR-ME + ABUSE Completes purchases, or scrapes and tests Buying agents (verify) vs scrapers, card tests POLICY: Verify or block Allow verified buyers, block unidentified abuse Source: Akamai (agentic AI traffic +7,851% YoY, 47.9% of commerce traffic). The goal is to sort, not to block everything.
AI bots are now 47.9% of commerce traffic (Akamai). Not all of it is the same, and it should not get the same policy. Free to share with attribution.

What are the three kinds of AI agent traffic?

The three kinds are search-indexing bots, user-fetch agents, and buy-for-me agents, and each deserves a different policy because each does something different to your business. Search-indexing bots crawl your store so AI answer engines can recommend your products; blocking them makes you invisible in AI search. User-fetch agents retrieve a specific page because a real shopper asked their assistant about it; these are often real buyers in a new wrapper. Buy-for-me agents actually complete purchases on a shopper’s behalf, which is genuine revenue if the agent is legitimate and fraud if it is not.

The distinction that matters most is legitimate versus abusive, and it cuts across the three types. A user-fetch agent retrieving your page for a real customer is welcome; a scraper harvesting your catalog and prices to undercut you is not, even though both may look similar at the network level. A buy-for-me agent completing an authorized purchase is revenue; the same shaped traffic testing stolen cards is fraud. The policy you want is not per-type but per-intent, and that requires telling the two apart.

THREE KINDS OF AI TRAFFIC

What each kind is, and what to do

Kind of agentWhat it doesRight policy
Search-indexing botCrawls your store so AI engines can recommend itAllow, blocking makes you invisible in AI search
User-fetch agentRetrieves a page for a specific real shopperAllow and watch, often a real buyer; rate-limit
Buy-for-me agent (legit)Completes an authorized purchase for a shopperAllow if verifiable; treat as real revenue
Scraper / card testerHarvests catalog and prices, or tests stolen cardsBlock, this is abuse regardless of shape

Sort AI traffic by intent, not by a single allow-or-block switch. Illustrative.

Which AI agents actually send you buyers?

The agents that send you buyers are the search-indexing bots that make you discoverable and the user-fetch agents retrieving your pages for real shoppers, so blocking those is blocking demand. When a shopper asks ChatGPT or Perplexity for a product recommendation and your store surfaces, that visibility depends on having let the indexing bot crawl you. When their assistant then fetches your page to compare or buy, that fetch represents a real person with intent. Treating either as noise to block is turning away customers arriving through the fastest-growing discovery channel in commerce.

This is the strategic reason not to blanket-block. Amazon can afford to lock down AI agents and build its own assistant, Rufus, because it is a destination shoppers seek out directly (CNBC3). A smaller store that blocks AI discovery does not gain independence; it just disappears from the AI answers where a growing share of shoppers now start. For most merchants, being findable and buyable by legitimate agents is a channel to protect, not a threat to eliminate.

The nuance is that not every agent is a buyer, which is why you allow-and-watch rather than allow-and-ignore. A user-fetch agent is probably a real shopper; a high-velocity scraper hitting every product page is not. Allowing the traffic that represents demand while watching for the patterns that represent abuse is the balance, and it depends entirely on being able to tell them apart, which the next section covers.

How do you tell a real AI shopper from a bot?

You tell them apart by behavior and identity: legitimate agents act like a single shopper with a purpose, while abusive bots act like automation at scale, and increasingly, legitimate agents can prove who they are. A real user-fetch or buy-for-me agent retrieves a handful of relevant pages and may complete one purchase; a scraper hits hundreds of pages fast, and a card tester attempts many transactions in a short window. Velocity, breadth, and purchase behavior separate a shopper from a harvester even when both are automated.

Identity is the stronger signal, and it is where agentic commerce is heading. A legitimate agent that can present a verifiable identity, proving which platform it represents and that it is acting for a real, authorized shopper, is one you can allow with confidence, while an agent that conceals or spoofs its identity is one you should not. This is exactly the issue in the Amazon case: Amazon alleged Perplexity disguised Comet as a regular Chrome browser and refused to identify it (GeekWire2), which is the difference between an agent you can trust and one you cannot.

The durable answer is verifiable agent identity and attestation, not an ever-growing blocklist of user agents you recognize. A blocklist fails the moment a bot spoofs a known-good agent string, which abusive bots routinely do. A system that requires an agent to prove its identity and its authorization, rather than trusting a self-reported label, is what lets you allow legitimate AI buyers and block abuse without playing whack-a-mole. That is precisely what RankShield’s verifiable AI security is built to provide.

What does the Amazon versus Perplexity case mean for you?

The Amazon versus Perplexity case means the ground rules for agentic commerce are being set in court right now, and identity is at the center of them. In March 2026, a federal judge issued a preliminary injunction blocking Perplexity’s Comet shopping agent from Amazon, after Amazon argued the agent accessed its platform without authorization and concealed its identity (PYMNTS4). The early signal is that agents which hide what they are and act without authorization can be blocked, while the door stays open for agents that identify themselves and act for authorized shoppers.

For your store, the practical read is that you have both the right and a growing set of tools to insist on identity. You do not have to choose between blocking all AI and allowing anonymous automation; the emerging norm is to allow identified, authorized agents and refuse concealed ones. Amazon is enforcing that as a destination with leverage, but the same principle scales down: require agents to be what they claim, and you can welcome legitimate AI buyers while excluding the ones operating in disguise.

The other signal is that cooperation is coming. While Amazon litigated, Walmart and Target were testing ways to work with AI shopping platforms rather than block them outright (CNBC3). The likely future is not a wall but a handshake: agents that prove their identity and authorization get to shop, and merchants that can verify that identity get the sales. Positioning your store to verify rather than to block is how you end up on the winning side of that shift.

Should you block AI agents in robots.txt?

Do not block search and indexing AI bots in robots.txt, because that makes your store invisible in AI search, which is where a growing share of shoppers now discover products. There is a three-tier distinction that matters: training crawlers can be blocked if you do not want your content used for model training, but search and indexing bots like OAI-SearchBot, PerplexityBot, and Google’s crawlers should be allowed so your products can be recommended, and user-retrieval agents should be allowed so a shopper’s assistant can fetch your page. Blocking the wrong tier is how stores accidentally disappear from AI answers.

robots.txt is also the wrong tool for stopping abuse, because it is a request, not an enforcement mechanism. Well-behaved crawlers honor it; abusive bots and spoofed agents ignore it entirely, which is exactly the behavior at issue in the Amazon case. So robots.txt is where you express your discovery policy, allow the indexing and retrieval bots you want, but it cannot be your defense against scrapers, card testers, or agents operating in disguise. Those require enforcement at the edge and identity verification, not a politely worded file.

The right setup is therefore two layers: use robots.txt to stay visible to the AI search and retrieval bots that bring you buyers, and use behavioral limits plus verifiable agent identity to block the abuse that ignores robots.txt anyway. That combination keeps you discoverable and buyable by legitimate AI while stopping the automation that would scrape or defraud you, which is the balance every merchant needs as agentic commerce grows.

AI AGENT POLICY CHECK

What should your AI agent policy be?

  1. Do you currently allow AI search bots (OAI-SearchBot, PerplexityBot) to crawl your store?
  2. Do you rate-limit and watch high-velocity automated traffic?
  3. Can you distinguish a user-fetch agent from a scraper?
  4. Do you require agents to prove identity rather than trusting a self-reported label?
  5. Do you block card-testing and scraping at the edge, not just in robots.txt?

How do you win in an agentic-commerce world?

Do not treat AI shopping agents as one thing to block or allow, because nearly half your traffic is now automated and some of it is your future customers. Sort it: allow the search and indexing bots that make you discoverable, allow and watch the user-fetch and buy-for-me agents that represent real shoppers, and block the scrapers and card testers that represent abuse. Use robots.txt to stay visible, and use behavioral limits plus verifiable agent identity to stop the abuse that ignores robots.txt anyway. That is how you capture AI-driven demand without opening the door to agentic fraud.

The Amazon versus Perplexity case is the signal to read: the emerging rule is that agents which identify themselves and act with authorization get to shop, while concealed ones can be blocked. Position your store to verify identity rather than to block wholesale, and you end up on the winning side of that shift, discoverable and buyable by legitimate AI while protected from the abuse. If you want to allow the agents you can trust and block the ones you cannot, see how RankShield verifies AI agents so you keep the buyers and stop the bots.

FREQUENTLY ASKED

Questions, answered.

Jamie Kloncz
Jamie KlonczCEO, RankShield · online

Should I block AI bots in robots.txt?

Jamie Kloncz

Not the search and indexing bots. Blocking bots like OAI-SearchBot, PerplexityBot, and Google’s crawlers in robots.txt makes your store invisible in AI search, which is where a growing share of shoppers now discover products. There is a three-tier distinction: you can block training crawlers if you do not want your content used for model training, but you should allow search and indexing bots so your products can be recommended, and allow user-retrieval agents so a shopper’s assistant can fetch your page. robots.txt is also the wrong tool for stopping abuse, because abusive bots and spoofed agents ignore it. Use it to express your discovery policy, and enforce against scrapers and card testers at the edge instead.

Do AI shopping agents help sales?

Jamie Kloncz

Yes, the legitimate ones do, because they are how a growing share of shoppers now find and buy products. Search-indexing bots let AI answer engines recommend your store, and user-fetch agents retrieve your pages for real shoppers who asked their assistant about a product, so both represent demand arriving through a new channel. With AI bots now 47.9% of commerce traffic and agentic traffic up 7,851% year over year, blocking all of it turns away customers, not just abuse. The nuance is that not every agent is a buyer: a scraper or card tester is abuse regardless of how it presents. The winning approach is to allow the agents that represent real shoppers while blocking the ones that represent abuse, which requires telling them apart.

Can I block Perplexity from my store?

Jamie Kloncz

You can attempt to, and Amazon successfully obtained a preliminary injunction blocking Perplexity’s Comet shopping agent from its marketplace in March 2026 after arguing the agent accessed its platform without authorization and concealed its identity. But blocking a specific named agent is a blunt instrument for a smaller store, because it can both turn away legitimate shoppers using that assistant and be evaded by an agent that spoofs its identity. The more durable approach is to require agents to prove their identity and authorization rather than blocking by name, so you allow identified, authorized agents acting for real shoppers and refuse concealed or unauthorized ones. That scales better than maintaining a blocklist of individual platforms.

Which AI bots drive real referral traffic?

Jamie Kloncz

The search-indexing bots that make you discoverable in AI answers and the user-fetch agents that retrieve your pages for specific shoppers are the ones that drive real demand. When a shopper asks ChatGPT or Perplexity for a recommendation and your store surfaces, that visibility depends on having allowed the indexing bot to crawl you; when their assistant fetches your page to compare or buy, that fetch represents a real person with intent. Blocking these is blocking demand. Scrapers and card testers, by contrast, drive cost, not revenue, even though they may use similar-looking automation. The practical takeaway is to allow the discovery and retrieval bots while watching for the velocity and behavior patterns that mark abuse.

How do I tell a real AI shopper from a bot?

Jamie Kloncz

By behavior and identity. A legitimate user-fetch or buy-for-me agent acts like a single shopper with a purpose: it retrieves a handful of relevant pages and may complete one purchase. An abusive bot acts like automation at scale: a scraper hits hundreds of pages fast, and a card tester attempts many transactions in a short window. Velocity, breadth, and purchase behavior separate a shopper from a harvester. The stronger signal is identity: a legitimate agent that can present a verifiable identity, proving which platform it represents and that it acts for an authorized shopper, is one you can allow, while an agent that conceals or spoofs its identity is one you should not. Verifiable agent identity beats a user-agent blocklist, which spoofed bots defeat easily.

Will blocking AI agents hurt my SEO or AI visibility?

Jamie Kloncz

Blocking the wrong agents will hurt your AI visibility significantly. If you block search and indexing bots like OAI-SearchBot and PerplexityBot in robots.txt, your products stop appearing in the AI answers where a growing share of shoppers now start, which is a direct loss of discovery. This is separate from traditional SEO, but as AI search grows it is just as consequential. The safe approach is to keep the search, indexing, and user-retrieval bots allowed so you remain discoverable and buyable, and to handle abuse through edge enforcement and identity verification rather than by blocking AI broadly. Blocking training crawlers is a defensible choice about model training that does not affect your AI-search visibility, but blocking search and retrieval bots does.

Try one of the suggested questions above.

References

  1. Akamai (via GlobeNewswire). AI bots are 47.9% of commerce traffic; agentic AI traffic grew 7,851% year over year in 2026.
  2. GeekWire. Judge blocks Perplexity’s AI bot from shopping on Amazon in an early test of agentic commerce (preliminary injunction, March 2026).
  3. CNBC. Amazon wins court order to block Perplexity’s AI shopping agent; Amazon has blocked dozens of agents while building Rufus; Walmart and Target test cooperation.
  4. PYMNTS. Amazon injunction could change the future of agentic commerce.
Jamie Kloncz
WRITTEN BY

Jamie Kloncz

Founder & CEO, RankShield

Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.

Make every AI action provable.

RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.