TL;DR: More than half of web traffic is now non-human, and Netacea argues that platform policies built for people no longer distinguish legitimate AI agents from extractive automation. The practical problem is governance, not simple blocking: teams need a way to classify agent behaviour, apply intent-aware controls, and align fraud, security, and commerce decisions.
NHIMG editorial — based on content published by Netacea: The Governance Gap - Why Your Platform Policies Were Not Written for AI Agents
Questions worth separating out
Q: How should security teams handle delegated access when AI agents act on behalf of customers?
A: Security teams should treat delegated access as a separate governance layer, not as a normal login session.
Q: Why do human-first access controls fail for AI agents?
A: Human-first controls assume a person, a session, and an intent that stay relatively stable.
Q: What do organisations get wrong about bot detection and agent governance?
A: Many organisations treat bot detection as a perimeter problem when the real issue is governance across identity, access, and business rules.
Practitioner guidance
- Define agent trust tiers Classify AI agents by purpose, data scope, transaction authority, and revocation rules so platform policy can differentiate helpful automation from extractive behaviour.
- Map policy to runtime context Use session, pacing, and action context to decide when a machine actor can browse, transact, or access data instead of relying on static human-user rules.
- Unify fraud and identity governance Bring fraud, product, and security teams together around a shared control model so one team does not optimise revenue exposure while another only sees authentication events.
What's in the full report
Netacea's full research covers the operational detail this post intentionally leaves for the source:
- How Netacea frames the Agent Trust governance layer for live platform decisioning and traffic classification.
- The report's discussion of Visa TAP, Google AP2, and MCP as emerging standards shaping machine-to-platform interaction.
- The commercial distinction between beneficial automation and extractive automation in digital commerce and fraud contexts.
- The briefing's intended stakeholder view across digital, fraud, product, and security teams.
👉 Read Netacea's executive briefing on the governance gap for AI agents →
AI agents and platform policy gaps: what practitioners need to fix?
Explore further
Human-first policy is now a governance liability: platform rules built for consumer sessions cannot reliably classify agentic behaviour. The distinction between legitimate automation and extractive automation is now an identity governance problem as much as a fraud problem. Organisations should treat machine behaviour as a first-class policy input, not an edge case.
A question worth separating out:
Q: Who should be accountable when an AI agent causes a security incident?
A: Accountability should sit with the human owner, platform team, or business function that granted and operated the agent. The identity may act independently, but governance cannot detach responsibility from the delegation chain. Programs should define ownership, escalation, and remediation paths before deployment so responsibility is clear when the agent's behaviour changes.
👉 Read our full editorial: AI agents expose a governance gap in platform policy and fraud rules