Video summary
The video explores the transformative impact of Agentic AI on e-commerce security, highlighting a shift from traditional human shoppers to autonomous "AI shoppers" that interact directly with commerce sites via APIs. These synthetic entities, such as an instance of ChatGPT tasked with researching and purchasing hiking shoes, bypass human decision-making loops by executing tasks like browsing products and completing transactions independently. This evolution means that storefronts are no longer interacting with humans but rather with machines that make decisions on their behalf, fundamentally changing the nature of customer engagement and rendering traditional methods of identifying legitimate users obsolete.
A critical challenge emerging from this shift is the inability to distinguish between legitimate AI agents and malicious actors, as nearly 19% of these synthetic entities represent genuine user intent. Consequently, security teams can no longer simply block non-human traffic without risking disruption to valid business operations, necessitating a more nuanced approach to API security. The transcript notes that commerce has become a primary target for criminals because it generates significant revenue through these machine-to-machine interactions, with 85% of companies reporting API-related attacks in the last year. This trend extends beyond retail into finance, healthcare, and other sectors where APIs facilitate critical interactions, making the differentiation between real people and their synthetic representations a complex security hurdle.
To address these threats, organizations must adopt new controls that understand the context of API interactions rather than relying solely on human behavior patterns. The rise of Agentic AI forces defenders to recognize that the source of a transaction may be an application or an AI model rather than a direct human user, requiring a reevaluation of how trust is established in digital ecosystems. As these autonomous agents become more sophisticated and prevalent, the security landscape must evolve to protect against attacks that exploit the very mechanisms designed for efficiency and automation, ensuring that revenue-generating APIs remain secure without stifling legitimate innovation.
In conclusion, the integration of Agentic AI into commerce has rewritten the rules of e-commerce security by blurring the lines between human and machine activity. The industry is moving away from a model where every interaction is visibly human to one where synthetic entities drive significant portions of traffic and transactions. This transition demands that defenders develop advanced strategies to identify malicious activities within a sea of legitimate AI-driven requests, acknowledging that the most valuable targets for cybercriminals are now the high-revenue API endpoints used by these autonomous shoppers. Ultimately, securing this new frontier requires a deep understanding of both the capabilities of Agentic AI and the specific vulnerabilities inherent in modern API architectures.
Read the full video transcript
Can you walk us through this new agentic
storefront? Who exactly are these AI
shoppers and how are they interacting
with commerce site? Then we'll talk
about what threats they pose.
>> And so today what we're going to do is
we're going to share some insights from
the Aami state of the internet report.
And this one is called um you know
attacks on commerce. And it really is
interesting because we see this growth
of zero clicks or the Gentic shopper.
And so what we've done is is we've
looked across all of our security
platforms here at Akami, protecting the
the edge and the web page, protecting AI
instances, and and across all that,
we're starting to see some themes. One
of these is the storefront for more and
more. Commerce is by far in the lead,
but finance and so many other industries
are interacting over the web through
APIs. And so again, an API is a
machine-to-achine designed interface.
You know, if if you if I go to a web
page, it should be designed for my eyes.
If an API goes to a website, it's
designed for that machine toachine
interaction. And so the storefronts are
no longer having me come to it. It's
having one of the apps on my phone or
really what we're talking about here for
that Gentic shopper is let's say I'm in
I'll pick a flavor chat GPT and I want
to buy a pair of shoes.
Well, I'm not going to do my research
about the best hiking shoe inside of
Chat GPT and then leave it and then go
to the store and buy it myself.
I'm going to tell ChatGpt to do the
research and then to go buy the shoes
themselves. And so, this has caused a
couple things. One, the store is not
interacting with me. Sure, it'll get my
credit card, but it's not seeing all the
decisions. It's not seeing what shoes I
looked at. It's not all of that is
suddenly gone. And now the source is
just getting this synthetic customer.
And so, you know, now turning from the
shopper to the defender.
I used to be able to say, "Okay, well,
that's not a legitimate shopper. That's
not a human."
Well, now I can't do that anymore
because we've seen this increase in and
19% of the these could be legitimate
shoppers. And so
I can't just block these these synthetic
entities anymore. And so as we're doing
this, I need new controls and and need
to understand this because again we're
talking about these APIs interacting it
and the AI API security impact study
found that 85% of all the companies
responding
in commerce said they'd had API related
attacks in the last 12 months. So now
it's uh you know again go where you can
make the most revenue. So if you can if
if they're making the most money on
these APIs
you know that's where the criminals are
going to go. And so that's kind of what
we're talking about is is commerce is a
leading boat to what you said anybody in
e-commerce anybody interacting with
customers healthc care finance anybody
it is now becoming a challenge to
understand what's a real person what's a
synthetic representation of a real
person and what's a malicious activity.