Forrester Bot & Agent Trust Management: Why AI Agent and Bot Trust Management is Now Essential

The new norm is AI agents and bot trust management. AI agents can now browse, research, buy, scrape, and complete tasks on behalf of real people, making the old ‘bot or human’ approach far too simple.

That’s why bot management has changed into bot and agent trust management. The focus, according to Forrester, is understanding what kind of automated traffic is interacting with your business, what it is trying to do, and whether it should be trusted. Read on to find out more.

Why Bot Management Had to Evolve Into Bot and Agent Trust Management

Forrester expanded the category from bot management to bot and agent trust management because you’re not just analyzing whether it’s human traffic or not. That just doesn’t cover the scale of online traffic. The issue is now what kind of automated traffic it is (who it is) and what it is trying to do.

Principal analyst at Forrester Research, Sandra Carielli, explained that the change came from the increase in human-initiated AI agents, which is when a real person asks ChatGPT (or another agent) to browse, retrieve information, or complete tasks on their behalf.

Most of you have probably done this thousands of times. ChatGPT (or Gemini, if you’re rogue) has become our new Google.

Automated traffic isn’t automatically ‘bad,’ but a scraper could still be harmful and help surface content in AI answers or support discovery journeys. And that’s the big issue.

The category therefore moved from security-first thinking to trust-first thinking. You don’t have to think ‘block all bots,’ but decide what should be trusted, allowed, limited, or blocked.

Forrester covers both agent and bot trust management in its The Forrester Wave™ reports, listing DataDome as the leader for strength of offering and strength of strategy. Datadome is the leader of this new bot and agent trust management category in general, embracing the trust-first approach, helping businesses assess intent and regain control of traffic, whether it’s human, bot, or agent.

Why CDN and WAF Vendors Are No Longer Enough on Their Own

Forrester excluded CDN and WAF vendors from the Q2 2026 Wave report because the evaluation focused on specialist bot and agent trust management capabilities, and CDN and WAF vendors don’t meet every criterion.

Platformization was a big reason. CDN and WAF vendors increasingly bundle WAF, bot detection, and API security together, but that doesn’t necessarily provide the depth needed for agent trust decisions.

Signal depth was also a reason for exclusion. Carielli said these platforms don’t have the same level of signal required to assess agentic intent properly.

It’s not that broad infrastructure tools aren’t useful, but agentic traffic requires more granular analysis than traditional perimeter tools were designed to provide, which is exactly what DataDome provides.

Where the Threat Landscape Is Headed

One of the most important concepts from the Forrester discussion is intent hijacking. An agent may initially appear trustworthy, but its behavior can change during the session or over time.

Cariell’s point is that trust can’t be granted once and forgotten, and that businesses need continuous assessment, not just one-time identification or allowlisting.

She also expects the composition of web traffic to keep shifting. Agentic, human, and bot traffic should continue to rebalance over time, but for now, agentic and bot traffic is just below 50% of the total internet traffic. It’s crazy to think we’ve come that far as to almost be taken over by bots.

Another future-facing point is that businesses may eventually create different site experiences or content paths for humans and agents, which makes correct identification even more important.

Relatively new protocols such as Model Context Protocol (MCP) reinforce that organizations will need better governance around agentic access, permissions, and trust rather than relying on legacy bot rules alone. DataDome again excels here. It provides real-time security and traffic visibility specifically designed to protect MCP server infrastructure against modern AI-driven threats.

How DataDome Helps Organizations Manage Bot and Agent Trust

DataDome was listed as a leader in Forrester’s latest Q2 Wave Report for a reason. Its Agent Trust capability is designed to identify, classify, score, and govern AI-agent traffic interacting with digital properties in real time. Their system can spot AI bots in milliseconds, so it really is ‘real-time.’

What sets DataDome apart is that it’s a governance model rather than a blunt allow/block model. It focuses on visibility, real-time decisions, and policy control over AI traffic.

A core feature is the Agent Trust Score, a dynamic 0–100 score assigned to each AI agent. It is based on:

  • Identification strength
  • Behavioral intent
  • Reputation
  • The included endpoint-level control is an excellent feature, meaning an agent could be allowed to browse products and complete purchases but blocked from account creation. It’s exactly the type of balance and control we’ve been talking about.

    The new norm is AI agent and bot trust management. Not every bot or AI agent is a risk, but finding systems that allow businesses to trust which ones are safe or not is essential. Whether we do find a balance between AI agents, bots, and human traffic is yet to be seen, but for now, a more holistic approach is essential.

    Previous post Should You Upgrade Your PC or Replace It?
    Next post TVRem App for iPhone: Turn Your iPhone Into a Smart TV Remote