On August 4, the Ninth Circuit vacated the injunction Amazon had won against Perplexity's shopping agent.
The reasoning matters more than the result. When a person directs an agent to shop on their behalf, the court held, it is the user who accessed Amazon's computers — not the AI company — because the traffic routed through the user's own device. An injunction against conduct that likely does not violate the Computer Fraud and Abuse Act, the court said, would not serve the public interest.
The largest retailer in the world spent nine months and a preliminary injunction trying to keep an automated agent off its store, on the theory that this was a computer-crime problem. It is not. It is a contract and terms-of-service problem, which the court expressly left open.
This edition is about what is actually measured in agentic commerce, what is not, and the three things worth doing before anyone publishes a loss number.
What is actually measured
Set the agents aside for a moment. The automated traffic underneath them is measured, large, and pointed at you.
Bots are now 53% of internet traffic, and bad bots alone are 40% — up three points year over year, with 17.2 trillion bad bot requests blocked in 2025. AI-driven bot attacks went from 2 million a day in 2024 to 25 million a day in 2025 (Thales/Imperva, April 2026).
Retail is the most-targeted sector for AI-driven bots, accounting for 20% of AI bot attacks, and leads all sectors in business logic abuse at 24% — the category that includes denial of inventory.
Commerce absorbs 47.9% of all AI bot traffic across Akamai's global network — the largest single vertical. Read that carefully: it is 47.9% of AI bot traffic landing in commerce, not 47.9% of commerce traffic. Several outlets inverted it.
And here is the operational finding. Akamai reports organizations placed more than 90% of AI bot activity in monitor mode, and allowed roughly three-quarters of the remainder to pass unrestricted. The controls exist. They are switched to observe.
One honest note on the fraud numbers, because two credible vendor networks disagree. Signifyd measured account takeover up 78% in the first four months of 2026; Sift measured ATO attempts up 4% over a comparable period. Same phenomenon, same window, wildly different figures — and neither attributes any of it to shopping agents.
What is not measured
There is no published estimate of loss attributable to AI shopping agents. None. Not from Visa, Mastercard, NRF, the Merchant Risk Council, or any of the fraud platforms.
What circulates instead is worth naming, because it will reach your inbox. The "$4.5 million average annual AI fraud loss" figure now appearing in trade press comes from a survey asking 500 risk leaders to estimate their own losses from AI in general. The Adobe and Salesforce numbers — AI traffic up 393%, AI influencing 20% of Cyber Week orders — measure AI referral and recommendation, not agents transacting.
Meanwhile the checkout surface actually contracted this year. OpenAI discontinued Instant Checkout in March, six months after launching it. Walmart exited the integration the same month, with an executive calling it "a very temporary moment in time."
So the honest picture is not the one the vendors are selling. Agent-driven purchasing stalled in 2026. Agent-driven crawling, browsing and probing grew sharply. Those are different problems, and only one of them is currently hitting your infrastructure.
A perspective from the field
I have watched this industry adopt a threat narrative ahead of the data twice now — with organized retail crime, and with self-checkout. Both times the correction cost us credibility we did not need to spend.
So I am not going to tell you agentic commerce is the next shrink, because nobody can show you a number. What I will say is that a court has just moved the question out of computer crime and into contract, a measured control gap is sitting in your own bot configuration, and the payment networks have published frameworks with nothing in them about who eats the loss. Those three things are true today, and none of them require a forecast.
The liability gap, dated and named
The rails are being built. The loss allocation is not.
Worldpay, on the record in July: for properly authenticated tokenized agent transactions, liability follows existing rules. But "where it gets murkier is everything short of outright fraud," with allocation among issuer, acquirer, agent platform and merchant "still being negotiated in real time." Their summary: "No liability shift exists yet."
Visa's Trusted Agent Protocol and Mastercard's Agent Pay launches contain no liability, chargeback or dispute language at all. Merchants have been given frameworks for identifying an agent and nothing for allocating what it costs them.
American Express is the only network to put its own money behind it. Its Agent Purchase Protection, launched in April, covers cardmembers against charges resulting from agent errors — conditional on the agent being registered, authorized, and transmitting authenticated purchase intent.
No regulator has issued guidance. Not the FTC, not the CFPB. Anyone telling you otherwise is selling something.
The standards work is similarly half-built: signed agents ship today at the network layer, while the IETF group meant to succeed robots.txt has a target date of last month, no published specification, and a charter that explicitly excludes enforcement and auditing.
Three practical moves for the next 90 days
Re-read your bot mitigation contract against the ruling. If your defence assumed the agent operator was the party accessing your site, the Ninth Circuit just moved that ground. The enforceable surface is now your terms of service and your contracts — which means Legal owns a piece of this that Security used to own alone.
Get one surface out of monitor mode. More than 90% of AI bot activity sits in observe-only across the industry. Pick your highest-value inventory or your account-login path, move it to enforce, and measure what breaks. This is a control you already own and are not using.
Write your agent policy before you need it. Amazon's terms now require agents to identify themselves as automated systems and permit discretionary revocation. Whether you allow, block or partner, the position should exist in writing — because the first time an agent files a refund claim on a customer's behalf, someone will ask what your policy was, and "we hadn't decided" is an expensive answer.
Closing note
There will eventually be a number for what AI agents cost retail. It does not exist today, and the industry's habit is to fill that vacuum with a vendor estimate and regret it eighteen months later.
The useful posture in the meantime is narrow and unglamorous: fix the control gap you can already see, get Legal into a conversation the court just handed them, and write down a position you can defend before the first dispute lands.
If your organization has taken a formal position on AI shopping agents — allow, block or partner — I want to know how the decision was made and who owned it. Reply with anything you can share, anonymized always.
Forward this to one LP or AP leader who should be reading it.
— Gabriel
The LP Brief is a weekly intelligence read for senior loss prevention and asset protection leaders. Free. No vendor noise.
Not yet subscribed? thelpbrief.com