The rise of agentic AI and autonomous bots is transforming how web services handle automation, requiring a shift from traditional bot management approaches to more sophisticated identity and authentication strategies. New standards such as Web Bot Authentication, Know Your Agent (KYA), and Visa’s Trusted Agent Protocol (TAP) are being developed to provide cryptographic verification for bot and agent interactions, enhancing trust and transparency between websites and non-human clients. Rather than simply blocking all bots, organizations are exploring monetization models and partnerships that allow for controlled, value-based access by legitimate AI agents, while advanced detection methods continue to identify and mitigate malicious or unverified automation.
A key component of this evolution is the use of JSON Web Tokens (JWTs) and OAuth/OIDC protocols to assign strong, unique identities to AI agents and bots. By issuing distinct cryptographic credentials to each non-human entity, organizations can enforce least privilege, enable granular audit trails, and quickly revoke access if a credential is compromised. This approach addresses critical risks highlighted by security frameworks such as OWASP’s Non-Human Identity Top 10, including the dangers of over-privileged bots and static credentials. Together, these developments lay the groundwork for secure, accountable, and scalable agentic commerce and automation in the digital ecosystem.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Help Net Security summarized findings from the Thales 2026 Bad Bot Report, which said automated traffic became the majority of internet activity in 2025 at 53%, with bad bots accounting for 40%. The report also highlighted a 12.5-fold rise in AI-driven bot activity, growing abuse of APIs, and the emergence of AI agents as a third category of automation complicating bot detection and policy enforcement.
Cloudflare and GoDaddy announced a collaboration to bring AI crawler controls to GoDaddy's hosting platform and support emerging AI agent identity standards. The initiative includes Cloudflare's AI Crawl Control and support for identity-verification approaches such as GoDaddy's Agent Name Service and Cloudflare's Web Bot Auth framework.
Akamai published a blog post focused on bot management for the emerging agentic era. The reference provides no further synopsis, but it represents a distinct public guidance publication on managing AI-driven automated traffic.
A Security Boulevard article described how AI agents and other non-human identities can use OAuth/OIDC flows and JWTs for authentication, emphasizing short-lived scoped tokens, strong key management, proof-of-possession, and lifecycle automation. It framed JWT-based machine identity as a security best-practice approach rather than announcing a specific incident or product launch.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcesdxcentral.com
Open sourceakamai.com
Open sourcesecurityboulevard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.