BeaconSpec

← All articles

Agentic commerce • Market briefing

Amazon couldn't keep an AI shopping agent out. Neither can you.

The quiet fallback for any business nervous about AI agents was always "we'll just block them." On August 4 a federal appeals court took that off the table. What's left is a decision about what you publish for agents, and most businesses haven't made it.

David Soden  •  Market briefing  •  6 min read
A neoclassical county courthouse with white columns photographed from below against a clear blue sky, standing in for the federal appeals ruling that AI shopping agents acting for a person may reach a retailer's site.
The first federal appellate word on whether an AI agent working for a shopper is allowed to reach your site. The answer was yes, and the reasoning is the part worth reading.

On August 4, a federal appeals court threw out the injunction Amazon had won against Perplexity's Comet browser. The result is smaller than the reasoning. Under the anti-hacking statute Amazon was using, the court held, it is the shopper who accesses Amazon's servers, not the AI company. The agent is acting as that person's browser, and the law does not reach it.

Read the caveats before you build anything on this. The court called its own holding narrow and said the law around agentic AI is going to change. Amazon's trademark and state-law claims are still alive. This is direction, not a settled rule. But the direction only points one way, and it arrives with a detail nobody can talk their way past: Amazon has the best legal team in retail, and it could not keep one shopping agent off its own site.

You no longer decide whether agents reach you. You decide what they find when they do.

What's happening

The fallback plan just stopped existing.

Almost every business I talk to has an unspoken plan B for agentic commerce, and it is some version of keeping the machines out. Tighten robots.txt. Put the traffic behind a firewall rule. Wait and see. That plan was already shaky, because a crawler and an agent are not the same animal. A crawler shows up on behalf of a model. An agent shows up carrying a customer, one who has already decided to buy something.

What the ruling does is retire the plan properly. When the person at your door is legally your own customer, walling them off is not a security posture, it is turning down business. So the control point moves. It is not the perimeter anymore, it is the interface you publish: what an agent is shown, whose account it is acting in, and what it is allowed to do once it is there.

Publish nothing and the agents still come. They just read whatever they can scrape off your pages and act on their best guess about your prices, your stock, and your return policy. You get the exposure either way. The only variable is whether the version they see is the one you wrote.

What's changed since our last briefing

The standard walked out of retail and into services.

Our last briefing was about the big commerce platforms starting to ship agent-readable catalogs as a built-in feature, which turns being findable into a floor rather than an edge. That still holds, and it comes with a quiet assumption: that your software vendor will handle this for you. Two days after that piece went up, Google moved the standard somewhere that assumption breaks.

Ask Maps can now order food conversationally, live with Square and Toast and with Uber Eats on the way, and Google committed to co-developing a Universal Commerce Protocol for Food alongside those partners and DoorDash. Skift confirmed separately that Google is testing agentic hotel booking. The standard is spreading into categories that never had a dominant commerce platform to begin with.

A hand pressing a silver service bell on a dark hotel reception counter, standing in for the booking and ordering systems that AI agents are now arriving at in food and lodging.
Restaurants, hotel groups and local service businesses run their own booking engines and ordering systems. They have just been handed a standard to meet, and nobody is shipping them an update that meets it.

The same day the court ruled, Cloudflare gave AI agents an identity and a wallet. Each account gets a verifiable, human-readable handle that can be delegated down to individual agents, with per-agent spending limits on top. Be careful repeating this one: the handles can be reserved today, but the funding and the programmable spend controls are described as arriving over the coming months. It is a direction with a date attached, not something you can use this afternoon. What it tells you is where the infrastructure companies think the money is, and the answer is identity and authorization.

The traffic arrived. The checkout didn't.

Year-over-year growth in AI-driven retail traffic and orders. Adobe measured AI-referred traffic to US retail sites in the first quarter; Shopify reported its own merchants for the second. The last bar is how much more a visit from AI traffic is worth than one that arrives any other way.

HOW MUCH MORE AGENT TRAFFIC IS ARRIVING US retail sites +393% Shopify traffic +200% Shopify orders +200% AND THOSE VISITS ARE WORTH MORE Revenue per visit +37% vs non-AI traffic

Sources: Adobe data reported by PYMNTS, August 8, 2026 (US retail traffic and revenue per visit, Q1 2026 year over year); Shopify Q2 2026 results, August 5, 2026 (AI-referred traffic and AI-channel orders both roughly tripled).

Why this matters to you

Your best customers are arriving through a channel that can't close.

Shopify's second quarter put the strongest number yet on the board. AI-referred traffic tripled year over year, AI-channel orders tripled with it, and new buyers arrived from AI channels at nearly twice the rate of every other channel. Revenue grew 34 percent, gross merchandise volume 32 percent. Management said the plainest thing in the whole set of results: this disproportionately helps smaller merchants, because an agent does not care how big your brand is.

Then read the other half. Adobe's data has AI-referred traffic to US retail sites up 393 percent year over year, carrying 37 percent more revenue per visit than traffic from anywhere else. In the same reporting, shoppers are using AI to compare and shortlist, then stepping in to finish the purchase themselves. Your best-converting visitors are showing up through a door that opens halfway.

That is not a demand problem. It is plumbing. An agent that cannot sign your customer in, cannot read a firm price, and cannot complete an order against your system has to hand the job back to the human, and plenty of those handoffs never come back.

An overhead view of a row of ticket gates at a transit station, each one open but requiring a valid pass, standing in for controlling what an AI agent may do rather than trying to keep it out.
Nobody runs a station by welding the doors shut. You put gates in, decide what counts as a valid pass, and let everyone else through.

The rest of the market is already building for exactly this. The Secure Technology Alliance launched an Agentic Trust and Commerce Forum on August 4 to settle how an agent's identity gets established, what counts as valid consumer authorization, and who resolves a dispute when no human was in the room, citing more than $300 billion of US agentic commerce by 2030. Visa is paying $2.4 billion for behavioral biometrics firm BioCatch. Mastercard closed its $1.8 billion acquisition of BVNK. Harvard Business Review ran a piece on August 7 asking whether companies are ready for algorithmic shopping, which is a fair signal that this has left the trade press.

If you want the size of the prize, the standing forecasts are McKinsey's $3 to $5 trillion of global agentic commerce by 2030 and Gartner's estimate that about 90 percent of B2B purchasing, near $15 trillion, runs through AI agents by 2028. Both are forecasts from 2025, so hold them loosely. The measured numbers above are the ones that should move you.

A separate, related free tool

One clarification worth making: crawlers and agents are different things, and robots.txt still governs the bots that index and train on your site. It was never what stopped an agent shopping for a customer. If you want that first file written correctly, our free AI Visibility Checker does it in a couple of minutes. It matters most if you're on Cloudflare, whose defaults change on September 15, 2026.

Set your AI crawler rules →

No sign-up, about two minutes, and it doesn't touch your search ranking.

Why we're built for this

Control was always the product. The court just made it the only option.

BeaconSpec takes the REST and GraphQL APIs your business already runs and turns them into one curated server that agents discover and use over UCP, published at your own domain. You choose exactly which operations are exposed, so nothing goes out that you haven't approved. The standard login handshake is handled for you, so an agent signs the shopper into your existing accounts, with no shared passwords and no separate build for each AI. If your rules say it all has to run inside your own walls, you can host it yourself.

Notice that every one of those is a decision about limits, not about visibility. That has always been the shape of this product, and for a year the honest objection to it was "couldn't we just block them instead?" That objection is gone. The choice is between an interface you defined and an interpretation an agent made up from your marketing pages.

A wall you're not allowed to build isn't a plan. A door you control is.

The one thing to remember

You can't keep AI agents out. You can decide what they get.

A federal appeals court just held that when an agent shops for a person, it is the person doing the accessing. Meanwhile AI-referred traffic is up 393 percent with 37 percent higher revenue per visit, and the sale still isn't closing inside the agent. Both facts point at the same piece of work: publish an interface, with a sign-in and limits you set.

This is a market briefing we run every cycle, tracking what's actually changing in agentic commerce so you don't have to piece it together yourself.

Five briefings ago the argument was that agents were starting to choose. Then the payment rails went live, then the shelves got graded, then the platforms started fixing the grade for their own customers. Now the last exit has been closed by a court, and the standard has moved into food and lodging where no platform vendor is coming at all. If you run your own systems, that is the bad news and the opening in the same sentence.

BeaconSpec exists for exactly this shift: making your business discoverable and transactable by AI agents over the UCP standard, instead of invisible to them.

See what we do  •  Read more articles

Related reading: Eleven thousand stores agents can read. Fifteen they can log into.


David Soden writes about agentic commerce, automation, and building durable technical systems for businesses. Photography via Pexels (David Guerrero, Mikhail Nilov, Jan van der Wolf); figures cited are drawn from the public reporting named above.