TL;DR: More than half of web traffic is automated, and Netacea argues that businesses are still struggling to distinguish revenue-driving agents from extractive bots, which creates risk across fraud, data integrity, and compliance. The governance problem is no longer about blocking automation outright, but about classifying intent, trust, and economic impact before agent traffic reshapes platform controls.
NHIMG editorial — based on content published by Netacea: Agent Trust Management: The Business Case
Questions worth separating out
Q: How should organisations classify automated traffic when AI agents and bots look similar?
A: Use intent, entitlement, and economic impact as the primary classification criteria.
Q: Why do traditional CAPTCHAs create problems for identity and fraud teams?
A: Because they optimise for stopping bots, not for preserving legitimate access at scale.
Q: What breaks when organisations rely on detection after an agent acts?
A: What breaks is containment.
Practitioner guidance
- Define trust tiers for automated actors Classify AI agents, crawlers, and workflows into approved, conditional, and blocked categories based on business purpose, not just technical behavior.
- Align fraud and identity policy Create a shared decision model between IAM, fraud, and commerce teams so legitimate automation can proceed while extractive automation is constrained.
- Instrument auditability for non-human traffic Log the actor, intent, entitlement, and downstream action for each meaningful automated transaction so investigators can separate revenue activity from abuse.
What's in the full report
Netacea's full research covers the operational detail this post intentionally leaves for the source:
- The seven business reasons behind agent trust management, including commercial and compliance decision criteria.
- The Netacea Agent Trust framework and how it maps trust decisions to platform policies.
- The standards discussion around Visa TAP, Google AP2, and MCP in production contexts.
- The commercial distinction between beneficial automation and extractive automation across digital commerce workflows.
👉 Read Netacea's research on agent trust management and the business case →
Agent trust management: where commerce, fraud, and governance collide?
Explore further
Agent trust management is emerging as a governance layer, not a point solution. The article frames a real problem: enterprises are no longer dealing with a clean split between human users and malicious bots. That means control decisions need to move above the transport layer and into identity, intent, and business-purpose assessment. For CISOs and fraud leaders, the practical conclusion is that traffic governance now belongs in the same conversation as access governance.
A question worth separating out:
Q: Who is accountable when beneficial automation causes fraud or data exposure?
A: Accountability should sit with the teams that own the trust policy, the transaction channel, and the audit trail. In practice, that usually means identity, fraud, digital commerce, and security leaders sharing responsibility rather than treating automation as a tooling issue. Frameworks for access, logging, and data governance should reflect that shared ownership.
👉 Read our full editorial: Agent trust management is becoming a board-level governance issue