Navigation
VIA Live ↗ Sellers → Buyers → The Pass → Consulting → Commentary → JOIN VIA →
← Commentary No. 11
Agent access

The web is learning to block your best customers

While VIA welcomes them with open arms

Akamai published its 2026 State of the Internet report this week. One line runs through all of it. Nearly half of all commerce traffic is now an AI bot.

Not fraud. Buyers.

The three biggest sources of that traffic are OpenAI, ByteDance, and Anthropic. Real people, shopping through an assistant that goes out and does it for them. This is the thing everyone said was coming. It is here, and it already accounts for half the traffic.

Then you read the rest of the report and the mood changes. Retail was the most attacked industry on the internet last year. It took 84% of all the application-layer denial-of-service traffic, close to three trillion attacks. There is a new category of fraud built on the same wave: hijacked assistants, stored cards drained, synthetic identities spun up by a language model to look like a real person.

Here is the trap. The good agents and the bad ones come down the same pipe. A retailer staring at its traffic cannot tell an Anthropic agent buying a gift for a real customer apart from a script emptying stored cards. Same requests. Same endpoints. Same card on file.

So the industry does the only thing its tools allow. It blocks.

Every defence retail has ever built assumes a human is on the other end. The CAPTCHA, the rate limit, the device fingerprint, the behaviour score. All of it exists to prove a person is present and reject whatever isn’t. Cloudflare and Akamai now sell agent-blocking as a feature.

Think about what that means. The wall goes up. The attacker, paid to look human, climbs over it. The real customer, arriving through an agent, gets stopped at the door. The web is teaching itself to reject the exact traffic that is its future, and calling it security.

The channel is breaking in both directions at once.

You do not fix this with a better wall. You cannot out-detect an adversary whose entire job is to look like your customer. Every improvement in detection is just the next target for the next synthetic identity. It is an arms race the merchant loses by definition, because the thing it is trying to keep out is indistinguishable from the thing it wants to let in.

So stop trying to tell them apart.

That is the whole idea behind VIA. We do not guess whether an agent is friend or fraud. We give every agent a name it cannot fake, and we make it pay to do business.

An agent on VIA carries a real identity and a reputation it has to protect. When it wants a brief, a quote, an offer, it pays for it. A few cents in USDC, settled agent to agent, with no card sitting behind a login for anyone to steal.

Watch what that does. A scraper will not pay to hit you a million times. A fraud ring will not build reputation it plans to burn. The economics do the filtering that detection never could. The attacker is priced out before it reaches anything worth taking. The real agent, the one buying for a real person, pays the toll without blinking and walks straight through.

No CAPTCHA. No guessing. No wall between you and the customer you actually want.

Akamai’s own security chief said the quiet part out loud. The customer, he said, is increasingly an AI agent acting on behalf of a human.

The largest network on earth is telling every brand that the buyer has changed, and the only thing it has to sell you is a taller wall.

The question is not how to keep agents out. It is whether you have a door built for them to come in.

We built the door. app.getvia.xyz

First published

On Substack in Thoughts from the Agentic frontline, 16 July 2026.

Richard Hobbs is founder and CEO of VIA Labs, building agentic commerce infrastructure in Singapore.