Submind YouTube summaries
Thumbnail for How Agentic AI Is Rewriting E-Commerce Security | Steve Winterfeld, Akamai

How Agentic AI Is Rewriting E-Commerce Security | Steve Winterfeld, Akamai

Watch on YouTube

Video summary

The video explores the transformative impact of Agentic AI on e-commerce security, highlighting a shift from traditional human shoppers to autonomous "AI shoppers" that interact directly with commerce sites via APIs. These synthetic entities, such as an instance of ChatGPT tasked with researching and purchasing hiking shoes, bypass human decision-making loops by executing tasks like browsing products and completing transactions independently. This evolution means that storefronts are no longer interacting with humans but rather with machines that make decisions on their behalf, fundamentally changing the nature of customer engagement and rendering traditional methods of identifying legitimate users obsolete. A critical challenge emerging from this shift is the inability to distinguish between legitimate AI agents and malicious actors, as nearly 19% of these synthetic entities represent genuine user intent. Consequently, security teams can no longer simply block non-human traffic without risking disruption to valid business operations, necessitating a more nuanced approach to API security. The transcript notes that commerce has become a primary target for criminals because it generates significant revenue through these machine-to-machine interactions, with 85% of companies reporting API-related attacks in the last year. This trend extends beyond retail into finance, healthcare, and other sectors where APIs facilitate critical interactions, making the differentiation between real people and their synthetic representations a complex security hurdle. To address these threats, organizations must adopt new controls that understand the context of API interactions rather than relying solely on human behavior patterns. The rise of Agentic AI forces defenders to recognize that the source of a transaction may be an application or an AI model rather than a direct human user, requiring a reevaluation of how trust is established in digital ecosystems. As these autonomous agents become more sophisticated and prevalent, the security landscape must evolve to protect against attacks that exploit the very mechanisms designed for efficiency and automation, ensuring that revenue-generating APIs remain secure without stifling legitimate innovation. In conclusion, the integration of Agentic AI into commerce has rewritten the rules of e-commerce security by blurring the lines between human and machine activity. The industry is moving away from a model where every interaction is visibly human to one where synthetic entities drive significant portions of traffic and transactions. This transition demands that defenders develop advanced strategies to identify malicious activities within a sea of legitimate AI-driven requests, acknowledging that the most valuable targets for cybercriminals are now the high-revenue API endpoints used by these autonomous shoppers. Ultimately, securing this new frontier requires a deep understanding of both the capabilities of Agentic AI and the specific vulnerabilities inherent in modern API architectures.
Read the full video transcript
Can you walk us through this new agentic storefront? Who exactly are these AI shoppers and how are they interacting with commerce site? Then we'll talk about what threats they pose. >> And so today what we're going to do is we're going to share some insights from the Aami state of the internet report. And this one is called um you know attacks on commerce. And it really is interesting because we see this growth of zero clicks or the Gentic shopper. And so what we've done is is we've looked across all of our security platforms here at Akami, protecting the the edge and the web page, protecting AI instances, and and across all that, we're starting to see some themes. One of these is the storefront for more and more. Commerce is by far in the lead, but finance and so many other industries are interacting over the web through APIs. And so again, an API is a machine-to-achine designed interface. You know, if if you if I go to a web page, it should be designed for my eyes. If an API goes to a website, it's designed for that machine toachine interaction. And so the storefronts are no longer having me come to it. It's having one of the apps on my phone or really what we're talking about here for that Gentic shopper is let's say I'm in I'll pick a flavor chat GPT and I want to buy a pair of shoes. Well, I'm not going to do my research about the best hiking shoe inside of Chat GPT and then leave it and then go to the store and buy it myself. I'm going to tell ChatGpt to do the research and then to go buy the shoes themselves. And so, this has caused a couple things. One, the store is not interacting with me. Sure, it'll get my credit card, but it's not seeing all the decisions. It's not seeing what shoes I looked at. It's not all of that is suddenly gone. And now the source is just getting this synthetic customer. And so, you know, now turning from the shopper to the defender. I used to be able to say, "Okay, well, that's not a legitimate shopper. That's not a human." Well, now I can't do that anymore because we've seen this increase in and 19% of the these could be legitimate shoppers. And so I can't just block these these synthetic entities anymore. And so as we're doing this, I need new controls and and need to understand this because again we're talking about these APIs interacting it and the AI API security impact study found that 85% of all the companies responding in commerce said they'd had API related attacks in the last 12 months. So now it's uh you know again go where you can make the most revenue. So if you can if if they're making the most money on these APIs you know that's where the criminals are going to go. And so that's kind of what we're talking about is is commerce is a leading boat to what you said anybody in e-commerce anybody interacting with customers healthc care finance anybody it is now becoming a challenge to understand what's a real person what's a synthetic representation of a real person and what's a malicious activity.