# Why customers discussed bot and agent trust tools
# What organizations are using these tools to solve
Account fraud is the most common use case mentioned by customer references. Close behind are web scraping and LLM scraping, and e-commerce fraud. Because the functional scope of bot and agent trust management spans multiple kinds of automated and agent-driven traffic, stakeholders outside security—digital teams, marketing, and commerce—often have a seat at the table when selecting and tuning a product.
# Agentic AI traffic is an emerging focus
Many customers have started—or plan to start—using these products to manage agentic AI traffic. They want three practical capabilities:
- Controls that limit what agentic callers can do on public-facing applications.
- Ways to detect when agent traffic maps back to a real human customer.
Those capabilities change how teams model application threats and who needs to be involved in protection decisions.
# Threat research and vendor responsiveness matter
Customers flag rapid changes in attacker techniques as a core operational challenge. They look for vendors that maintain active threat research teams so models keep pace with new attacks. Strong engineering and customer support matter too: customers accept occasional false positives or false negatives as long as the vendor responds quickly and helps tune protections or deploy model updates.
# Operational expectations and trade-offs
References describe an expectation that products will require ongoing tuning. That means buyers should plan for vendor-led updates and a support relationship that can act quickly when detection drifts. The practical implication: procurement decisions weigh product capability and the vendor's ability to deliver timely engineering and threat research support.
# Where to learn more
Forrester points readers to their Buyer's Guide: Bot And Agent Trust Management Software, 2026 for a deeper evaluation framework. The author will also present on adapting application threat modeling to include AI agent trust at Forrester's Security & Risk Forum in November 2026.
# What this means for buyers
If your organization faces account fraud, content scraping, or suspicious automated traffic, plan cross-functional evaluation teams that include security, marketing, and digital commerce. Expect an initial period of tuning and insist on vendor threat research and support SLAs that match your incident-response needs. If agentic AI traffic touches your applications, add provenance detection and action-control capability to your requirements list.