Akamai launches AI agent traffic security framework
Mon, 15th Jun 2026 (Today)
Akamai has introduced a security framework to manage AI agent traffic, aimed at businesses that need to verify whether automated requests should be allowed to act.
Built into its Bot & Agent Control products, the framework combines identity checks, traffic monitoring and enforcement at the network edge. It targets merchants, publishers and other organisations facing a rise in automated requests from AI agents acting on users' behalf.
The launch reflects a broader industry focus on whether an AI agent can be tied to an authorised human user and whether its behaviour can be trusted. That question has become more urgent as agents begin to shop, retrieve content and carry out tasks previously completed directly by people in browsers or apps.
Akamai's model is built around six areas: verified identity, user-linked authentication, trust analysis, edge enforcement, content monetisation and traffic visibility. It is working with several partners to connect those elements.
One part of the framework focuses on agent identity in commercial transactions. Akamai is working with Visa on the Trusted Agent Protocol and with Skyfire and Experian on the Know Your Agent framework, intended to let agents declare identity, origin and intent while linking them to the platforms they use and the users they represent.
The approach is designed to help businesses distinguish between a legitimate AI shopping assistant and a malicious bot that may appear similar when it first connects to a website. It also aims to provide an audit trail for transactions carried out by software acting for a person.
Visa said agent identity will be a basic requirement if automated commerce is to expand.
"Without trusted identity and explicit permissioning, AI agents cannot participate in commerce at scale," said Rubail Birwadker, Senior Vice President, Head of Growth Products and Partnerships, Visa. "Visa's Trusted Agent Protocol provides the identity layer that defines how agents are authenticated, authorized, and trusted at the transaction level so businesses and consumers can transact with confidence."
Experian described the issue as one of transparency and accountability in AI-led interactions.
"AI agents are quickly becoming part of digital commerce, but trust will determine how far and how fast adoption grows," said Kathleen Peters, Chief Innovation Officer at Experian. "With the Experian Agent Trust framework, we are helping businesses bring more transparency and accountability to AI-driven interactions by verifying identities, assessing risk, and strengthening confidence in every transaction. Our collaboration with Akamai and other ecosystem leaders reflects the industry's shared commitment to building a secure foundation for agentic commerce that consumers and businesses can trust in real time."
Skyfire, which is also involved in the identity effort, said commercial use of agents depends on a recognised trust layer.
"AI agents can't participate in the economy without trusted identity and the ability to transact," said Amir Sarhangi, Chief Executive Officer and Co-Founder, Skyfire. "Skyfire provides that foundation - enabling agents to authenticate, operate within policy, and access global payment rails. With Akamai, we're bringing that trust layer to the edge, so enterprises can securely enable trusted agents without re-architecting their existing systems."
Identity checks
Another element covers the hand-off between a human user and an AI agent. Integrations with identity providers including Auth0 and Ping Identity allow organisations to apply existing checks such as behavioural analysis and multi-factor authentication to the agents their customers use.
The idea is that a company should not rely only on a session or browser signal when an agent is involved. Instead, it should be able to assess who the agent represents, what it is permitted to do and whether its actions match the user's established profile.
"AI agents introduce a new trust challenge because session-based trust alone is no longer sufficient. Organisations need to understand who they represent, what agents are allowed to do, and how their actions are governed in real time," said Loren Russon, Vice President, Product Management, Ping Identity. "By combining Ping's Runtime Identity capabilities with Akamai's edge enforcement and visibility, enterprises can extend identity and access controls to AI-driven interactions with stronger accountability and oversight."
Akamai said the framework also moves beyond a simple allow-or-block approach. Its trust analysis layer is intended to assess interactions across browsers, bots and agents on a spectrum, helping organisations decide which requests support commercial goals and which may signal fraud, abuse or operational risk.
Publisher model
For publishers and content owners, the system also addresses how AI agents access and pay for web content. Partnerships with TollBit and Skyfire support models in which access can be negotiated and charged on a pay-per-request basis.
That could give media groups and other content businesses a way to distinguish between ordinary visitors, beneficial agents and scraping activity, while also setting commercial terms for machine-driven access to material on their sites.
The framework is tied to Akamai's traffic analysis tools, including TrafficPeak, which can provide a view of how human users, useful AI agents and malicious bots interact with websites over time. Security teams and business managers can then use that data to adjust access rules and revenue strategies.
At the infrastructure level, enforcement happens at the edge of Akamai's distributed network, allowing decisions on incoming requests to be made quickly without shifting checks to a central system.
Patrick Sullivan, Vice President, Chief Technology Officer of Security Strategy, Akamai, said the goal is to give businesses a way to tie identity to decision-making as automated interactions increase.
"AI agents are replacing clicks, acting and handling commerce for us. For that to work, businesses need to recognize not just the agent, but who is behind it and what it's trying to do," said Sullivan. "We've built this so that identity informs visibility, visibility drives trust, and trust powers the decisions that let companies safely grow and monetize these new AI interactions. We're giving businesses the confidence to open their doors to AI without compromising security."