HUMAN Security observed agentic traffic across its defence platform rise 209.7% month on month in September. That is a meaningful visibility and research signal, but it is not evidence of global market share, purchase intent or revenue. The same dataset shows activity concentrated in discovery routes rather than payment. Marketing teams should therefore make their offers machine-readable and useful to agents while keeping consent, access and transaction controls firmly intact.
What the September observation does—and does not—show
HUMAN Security’s 5 October State of Agentic Traffic report describes traffic observed across its Human Defense Platform, not all web activity. In that observed mix, Meta Muse accounted for 40.3%, ChatGPT Agent 28.6%, Perplexity Comet 9.4%, Codex Browser 7.7% and Claude Chrome Extension 7.1%. These are shares of the report’s observed agentic traffic—not global market shares, audience shares or a leaderboard for commercial value.
For marketers, the useful headline is not which name came first. It is that agent-mediated visits can surface before a conventional lead, branded search, assisted conversion or sale is visible in reporting. The work is to separate that early signal from an agent’s research session, a human’s confirmed demand and a completed, authorised outcome. Our earlier look at AI-agent visitors and the emerging second web [blocked] offers complementary context for that shift.
| Observed September signal | Share of observed agentic traffic | What it can reasonably suggest |
|---|---|---|
| E-commerce destinations | 60.4% | Agents are reaching retail endpoints in this dataset |
| Product and search routes | 81% | Discovery and research dominate route activity |
| Checkout and payment routes | 2.4% | Route visits should not be equated with completed transactions |
HUMAN says the distribution supports a research-and-discovery interpretation more than transaction completion. That matters because a catalogue page visited by an agent might represent a comparison task, an attempted workflow, monitoring, testing or an automated request. It is not, on its own, a customer commitment.
From traffic to demand: use a four-layer measurement model
Treat an agentic request as an observed access event first. Then ask what can actually be verified. A practical measurement model has four layers:
- Crawler and security data: Identify the request, its technical characteristics, policy outcome and the page or API reached. This is operational telemetry, not demand.
- Agent research session: Where detection and consent permit, group related requests into a declared or verified agent session and record the task stage: discovery, comparison, account access or purchase attempt. Do not infer a human identity or motive merely from a user-agent string.
- Human demand: Count an explicit, attributable human action: a form submission, a call request, a logged-in preference, a consented hand-off or another defined qualification event. Decide and document the rule before reporting it.
- Completed value: Record value only when the business’s existing controls confirm an authorised conversion, such as a validated booking, contract or settled transaction. Reconciliation, cancellation and fraud rules still apply.
This avoids a tempting but weak funnel in which every detected agent page view becomes ‘intent’. It also helps marketing, product, analytics and security teams speak about the same journey without merging their evidence. For a useful counterweight, see our analysis of consumer inertia and margin resilience in an agent-led market [blocked]: agent capability does not automatically remove the conditions that make people trust, switch or buy.
Agent Experience Optimisation: an editorial operating discipline
Agent Experience Optimisation is our editorial label, not a term or claim made by HUMAN Security. It describes the discipline of designing a site so a legitimate agent can accurately discover, interpret and progress through information, while the organisation preserves the controls that require human authority.
Make the decision path legible
Give product, service and content pages stable names, precise descriptions, eligibility details, current availability, clear owners and unambiguous next steps. Use structured data where it faithfully represents visible information; do not use markup to claim capabilities, reviews or availability that the page does not substantiate. Explain the difference between exploratory information and actions that need sign-in, verification or human approval.
This is not a licence to remove friction everywhere. Clear boundaries are part of a good experience. A retailer might expose product attributes and delivery constraints for research, while requiring an approved identity, consent and a review step for account changes or payment. The policy questions explored in our piece on a retailer’s agent-access policy [blocked] are therefore marketing questions as well as security questions.
Connect visibility to control
Instrument routes by purpose—search, product detail, content, account, authentication, basket and checkout—then compare observed agent activity with human outcomes without attributing one to the other by default. Maintain allow, challenge, rate-limit and deny decisions appropriate to the route. Record why a sensitive action was permitted or refused, and provide a review path for exceptions.
Identity is central here. A browser-like request is not proof that an agent is authorised to act for a customer, and an agent assertion is not a substitute for consent. Our guide to operational identity and delegation for AI agents [blocked] examines the governance behind that distinction. Where teams are building agent-ready journeys in Google’s ecosystem, our Gemini agentic AI service [blocked] is relevant context—not a shortcut around security or customer approval.
Design for a human decision at the right moment
Good paths can answer factual questions quickly, disclose limitations plainly and offer a clean hand-off when a decision becomes personal, contractual or financial. Keep the commercial rule simple: agents draft and a person signs. That protects the customer and gives the business a defensible point at which demand, consent and value can be evidenced.
Methodology and limits: read the signal carefully
This article’s figures come from HUMAN Security’s October 5 report, which says its data reflects agentic traffic observed across HUMAN Sightline Cyberfraud Defense during September 2026. Its identification method combines behavioural signal analysis, user-agent attribution and publisher-level integration where available. Sector and route classifications reflect destination endpoints, not the operator’s intent.
Those boundaries are material. The report is a network observation, not a census of internet use; it cannot establish global market share. A route category cannot reveal whether an agent had a purchase mandate, whether a person completed the task, or whether a request produced revenue. Detection coverage, traffic controls, publisher mix and newly available visibility can all influence what is observed. HUMAN also notes that passed and blocked requests rose; a request being seen, allowed or blocked is not equivalent to an engaged visitor or a qualified lead.
Use the findings as a prompt to inspect first-party logs, consent records, analytics definitions, fraud controls and CRM outcomes. Do not benchmark a business against the reported agent shares as if they were a forecast. If you publish an internal dashboard, label the data source, observation window, detection confidence, route taxonomy and the difference between sessions, people and completed value.
An operational checklist for marketing, security and product
- Define your events: document separate fields for detected agent request, verified session, human hand-off, authorised conversion and realised value.
- Map the routes: inventory search, product, content, account, authentication, basket, checkout and payment endpoints; assign an owner and permitted action to each.
- Improve the evidence: keep offers, specifications, availability, policies and contact routes clear, current and consistent across pages and structured data.
- Protect sensitive steps: require appropriate identity, consent, fraud checks and human approval before account, contractual or payment actions.
- Review exceptions: give teams a way to investigate blocked legitimate activity without silently weakening controls.
- Report honestly: show agent traffic alongside—not inside—human conversion reporting until attribution is proven under your agreed definition.
What to do next
The immediate opportunity is not to chase agent traffic as a vanity metric. It is to make the path from answer to evaluated option to approved action easier to understand and safer to operate. Integrated.Social can help assess the content, technical and measurement foundations through our SEO, AEO and GEO service [blocked]. If you want a practical starting point, request a free AI growth audit [blocked]; it is a conversation, not a performance promise.
Frequently asked questions
Does a rise in agentic traffic mean that demand has risen?
No. A rise in observed agentic traffic can indicate more automated access to routes that support research, discovery, monitoring or attempted actions. It does not establish the number of people behind those sessions, their authority to purchase, or a change in revenue. Treat it as an early operational and visibility signal, then validate demand through explicit human actions and your own qualified conversion definitions.
Why are product and search routes more useful than checkout routes in this report?
They show where observed activity was concentrated, not what each operator intended. HUMAN reported 81% of observed September activity on product and search routes, compared with 2.4% on checkout and payment routes. That pattern supports a research-and-discovery interpretation. It does not prove that product-route visitors will buy, nor that checkout-route requests resulted in authorised, completed transactions. It is a directional route-pattern signal, not a commercial-funnel measurement.
What is Agent Experience Optimisation?
Agent Experience Optimisation is Integrated.Social’s editorial term for making legitimate agent journeys clearer, more accurate and appropriately governed. It combines accessible information, truthful machine-readable content, explicit route purposes and controls for identity, consent and sensitive actions. It is not a HUMAN Security product or a claim that optimisation causes conversion. Its purpose is better evidence and safer hand-offs between automated research and human decisions.
Should we allow every AI agent to access our site?
No. Access should be determined by route risk, verified behaviour, contractual and customer requirements, and the action requested. Informational pages may need a different policy from account, inventory, basket, checkout or payment routes. Maintain controls that can allow, challenge, rate-limit or deny requests, and review them with security and product owners. Convenience should not override consent, authorisation or transaction safeguards.
How should we report agent-assisted conversions?
Start with separate measures rather than a blended conversion rate. Report observed agent requests and sessions with source, detection confidence and route category; report human hand-offs with consent and attribution rules; and report completed value only after the usual validation, reconciliation and fraud checks. Link records only where your lawful data and measurement design permit it. This preserves a defensible distinction between assistance, demand and outcome.
About Modi Elnadi
Modi Elnadi [blocked] is the founder of Integrated.Social and writes about practical AI visibility, search and growth systems for organisations that need evidence before adoption. His perspective here is deliberately cross-functional: content should be easy to evaluate, measurement should distinguish signals from outcomes, and technical progress should not bypass customer consent or accountable human approval.










