
There is a lost sale that will never appear in your analytics.
No abandoned basket. No bounce. No error in Monday's funnel report. A shopper asked an AI assistant to find running shoes in their size, under £100, delivered by Friday.
The AI shopping agent goes looking, reaches your store, meets a challenge page from your bot protection, and moves on to a competitor.
The customer never knew you existed. Your team never knew you lost them.
As AI-powered product discovery becomes more common, retailers need to optimise not only for human shoppers but also for AI shopping agents that compare products, interpret structured data and recommend where customers should buy.
Salesforce data shows AI influenced roughly 20% of global online orders during Cyber Week 2025, and traffic from AI agents is the fastest-growing part of that. That traffic is already at the door. The question is what your storefront does when it arrives.
A mid-year ecommerce health check asks whether a person can buy from you.
Every one of those questions matters. Everyone assumes a human shopper using a browser. But an AI shopping agent behaves differently. It reads your product data, decides in milliseconds whether you are a credible answer, and either includes you in its recommendation or does not. There is no second impression.
Before any of that happens, it must get through your front door. Which is where security stops being purely a security question.
Retailers are under sustained attack. 80% of retailers report at least one successful cyberattack in the past year, and 68% say business downtime is the most likely outcome when one lands.
A Web Application Firewall (WAF) exists to decide which non-human traffic gets through. That decision used to be straightforward, because non-human traffic was either malicious or a verifiable, well-behaved crawler. Today, a growing proportion of it is an AI shopping agent acting for a genuine customer.
Tune the WAF too loosely and you increase security risk. Tune it too tightly and you may disappear from AI-generated recommendations.
“The big agents can now cryptographically prove who they are, and the major CDNs can verify that at the edge. But checking those signatures is something a retailer must switch on and the long tail of agents' signs nothing. So legitimate agents get challenged, and nothing tells you it happened. From the WAF's point of view, the rule worked exactly as intended." Suraj Gurung, CTO, The Commerce Team Global
Bot protection, challenge pages, rate limits and downtime can prevent legitimate AI shopping agents from accessing your storefront.
Thin product descriptions, missing structured product data, and critical detail buried in images or JavaScript make it difficult for AI shopping agents to confidently recommend your products.
Commerce and PayPal research found 64% of UK shoppers are interested in trying Agentic AI shopping. Shoppers will happily let an agent find a product. Handing over payment is a different matter. That makes the moment an agent passes the customer back to your checkout one of the most important in the journey, and if it breaks, so does the sale.
Agent readiness is not a performance problem wearing a new name. It combines structured product data, crawl accessibility, API reliability and security configuration, which is why it often falls between multiple teams.
Four questions worth asking your team before peak 2026
Storefront Next reached General Availability in Salesforce's June 2026 B2C Commerce release and now included in every B2C Commerce SKU, built for exactly this shift.
“Before you plan for agentic commerce, find out what your store does today when an agent arrives. If you don't know the answer, that's the point. Most monitoring platforms were never designed to tell you." Suraj Gurung, CTO, The Commerce Team Global