AI Shopping Assistants Are Wrecking Your CVR

Your conversion rate dropped last month and nobody on the team changed anything. Ad spend on Meta and Google is up, but the “high-intent” traffic those platforms are optimizing toward doesn’t seem to buy anything. Your fraud team flagged a wave of declined cards that don’t match your usual chargeback pattern. Separately, all three of these look like noise. Together, they have one likely explanation: your store is being visited by AI shopping assistants, and neither your analytics stack nor your bot defenses can currently tell the difference between one of those and a real customer — or a fraud bot pretending to be one.
This isn’t a future problem. It’s already showing up in dashboards this quarter.
The traffic surge nobody flagged in the dashboard
Security firm HUMAN Security, which tracks bot and automated traffic across major retail platforms, recorded a 6,900% increase in AI-agent and agentic-browser requests to websites since July 2025. Zoom into the highest-stakes shopping window of the year and the number gets sharper: agent traffic targeting ecommerce sites surged 144.7% during the five days from Black Friday to Cyber Monday 2025, compared with the five days before it. That’s not a rounding error in a traffic report — it’s a new category of visitor arriving at scale, during your highest-revenue week, that most analytics setups still bucket in with regular human sessions.
Why your bot blocker can’t see it
The reason this traffic slips past standard defenses is architectural, not a tuning problem. OpenAI’s ChatGPT Atlas (released October 21, 2025) and Perplexity’s Comet browser (released July 2025) are both built on the Chromium engine — the same rendering engine as Google Chrome itself. HUMAN Security’s analysis found that at the network and user-agent level, both browsers are “almost identical to a generic Chrome browser.” Signature-based bot filtering — the rule sets most WAFs and bot-management tools still lean on — was built to catch headless scrapers and scripted crawlers with obviously non-human fingerprints. An agentic browser doesn’t have one. It renders pages, executes JavaScript, and clicks through checkout the same way a person would, because functionally, in that moment, it’s doing exactly what a person asked it to do.
That same blind spot cuts both ways. HUMAN Security also documented a fraud pattern inside Comet sessions resembling early-stage carding: rapid card additions, repeated payment attempts, and a fallback to loyalty-point redemption when a card was declined. A detection layer that can’t distinguish “AI assistant completing a purchase I authorized” from “automated script testing stolen cards” isn’t just misclassifying good traffic — it’s leaving a door open for the bad kind.
Where this is already costing you
Conversion rate reporting. Agent sessions land in the same denominator as human sessions in most CVR calculations. A store that mixes in a meaningful share of agent traffic without separating it can watch a genuinely healthy campaign report a falling conversion rate — one cited example put a real-world swing at 2.5% down to 1.8% purely from the traffic-mix shift, with nothing about the underlying campaign performance actually changing.
Ad platform bidding. Meta Advantage+ and Google Smart Bidding both optimize toward signals like add-to-cart events. If an AI agent adds an item to a cart while comparison-shopping on a customer’s behalf and never completes checkout, that event still trains the algorithm — and for stores near Meta’s roughly 50-events-per-week optimization threshold, a run of agent-driven adds can meaningfully skew where ad dollars get pushed next.
The retailers who blocked vs. the retailers who opened up
Amazon chose defense. In late 2025 it updated its robots.txt to block OpenAI’s ChatGPT-User and OAI-SearchBot crawlers, reportedly rejecting on the order of 50 million shopping-related queries a day. That stance escalated on March 10, 2026, when a U.S. District Court in San Francisco granted Amazon a preliminary injunction against Perplexity’s Comet agent, barring it from accessing password-protected Amazon accounts and ordering data destruction — an early and closely watched test case for how far an agent can go while shopping on a user’s behalf.
Walmart, Target, Shopify, Etsy, and Wayfair took the other route, building ChatGPT integrations or opening agent-accessible checkout paths instead of blocking on sight. Neither posture is obviously wrong — but “block everything that looks automated” and “let everything through that looks like Chrome” are both worse options than knowing which is which.
What actually distinguishes a shopping assistant from a fraud bot
Can bot-blocking tools tell the difference between an AI shopping assistant and a fraud bot?
No. ChatGPT Atlas and Perplexity Comet run on Chromium and send the same user-agent string as a real Chrome browser, so signature-based bot blockers can’t separate a legitimate AI shopping assistant from a scripted fraud bot. Distinguishing them requires session-level behavioral analysis — pacing, navigation patterns, payment-retry behavior — not IP or user-agent rules.
That’s an architecture decision, not a plugin. It’s the same category of work MnT Future does when building the AI search, recommendation, and shopping-assistant layer for a commerce platform: the systems have to be built agent-aware from the start — able to serve a legitimate assistant a clean, structured answer while still verifying the human authorization and payment integrity behind any transaction it completes, the same session-and-transaction-aware approach behind MnT Commerce, our own AI-native commerce platform.
What to check this week
Three things a D2C brand can do without a platform rebuild: split agent sessions out of your core CVR reporting so campaign performance isn’t judged against a moving denominator; audit which events are feeding Meta Advantage+ and Google Smart Bidding for signs of non-converting agent-driven add-to-carts; and resist the instinct to blanket-block Chromium-based automated traffic, since a chunk of it is customers who authorized an assistant to shop for them, not an attacker.
Most stores don’t know which side of that line their current traffic falls on yet. That’s worth finding out before the next high-volume shopping window, not after.
Free agent-readiness audit: MnT Future will show you exactly how your store’s search, recommendations, and checkout hold up against agentic shopping traffic — what’s getting through, what’s getting blocked, and what a fraud bot could still slip past. Book a free strategy session →
