January 2026 Summaries
5 posts from Datadome
Filter
Month:
Year:
Post Summaries
Back to Blog
AI agents are increasingly prevalent on websites, with significant implications for businesses in terms of both opportunities and risks. As AI-enhanced browsers and agentic commerce frameworks emerge, understanding and managing AI traffic becomes crucial. The DataDome Global Bot Security Report 2025 highlights a substantial increase in AI traffic, with a majority targeting form and login pages, reflecting a growing consumer reliance on AI for shopping. Businesses must identify which AI agents are accessing their sites, understand their intent, and develop policies to manage them effectively, including decisions on what actions to allow or block and how to enforce these policies technically. Additionally, privacy and compliance must be addressed, particularly concerning sensitive data access and server-side privacy controls. Organizations are encouraged to assess the revenue impact of AI agent traffic and explore monetization opportunities while ensuring that marketing, product, and security teams align on strategy. Technical readiness involves having structured data and APIs that meet machine-time latency requirements, as well as infrastructure capable of handling traffic spikes. Security measures should detect malicious behavior and protect against agent impersonation. Cross-functional coordination is vital, with shared success metrics and a clear understanding of both opportunities and risks associated with AI agents, as outlined in the comprehensive Agentic Commerce Guide.
Jan 30, 2026
1,073 words in the original blog post.
The Model Context Protocol (MCP) is an open protocol that facilitates secure connections between AI agents and external tools, databases, and business systems, but it also introduces significant security risks. These risks primarily arise from two types of attacks: prompt injection and tool poisoning, both of which exploit AI models' inability to distinguish between legitimate and malicious instructions. Prompt injection involves embedding hidden commands in user inputs or external data that AI agents execute, while tool poisoning places malicious instructions within tool metadata, compromising every session that uses the affected tool. Traditional security measures, such as bot detection, are ineffective against these threats, which operate through legitimate and authenticated channels. Effective prevention requires a multi-layered approach, including input validation, least-privilege permissions, tool registry governance, and continuous monitoring, with real-time intent analysis being the most effective defense strategy. Solutions like DataDome’s MCP Protection offer real-time evaluation of requests' origins, intents, and behaviors before they reach MCP servers, highlighting the necessity of evaluating behavioral intent alongside identity.
Jan 30, 2026
257 words in the original blog post.
AI agents like ChatGPT, Perplexity, and Claude are transforming the travel industry by automating the booking process, which offers travel companies opportunities for improved conversion rates and customer experiences but also poses significant cybersecurity challenges. These AI-driven tools help consumers navigate the complexities of travel planning, such as fluctuating prices and coordinating multiple reservations, but the same capabilities can be exploited for malicious activities like data scraping and fraud. This dual challenge requires a shift from traditional bot detection to intent-based trust management, distinguishing between legitimate AI activity and harmful automation. Companies like DataDome are providing solutions to protect travel platforms from these threats, emphasizing the need for real-time behavioral analysis and trust scoring to enable secure and effective agentic commerce. Successfully navigating this shift will allow travel brands to enhance their competitive edge, maintain strong partnerships, and preserve customer trust in an increasingly automated market.
Jan 29, 2026
1,125 words in the original blog post.
Google's Universal Commerce Protocol (UCP) is set to revolutionize AI-driven shopping by providing a standardized open-source framework co-developed with major retailers and payment providers, aiming to unify fragmented agent frameworks and payment systems. Launched in January 2026, UCP simplifies the integration process for merchants by offering a single integration point for AI platforms, leveraging Google's extensive Merchant Center infrastructure to support its adoption. However, the real challenge lies in managing trust and security, as traditional fraud prevention measures are inadequate against the rapid pace and scale of agentic commerce. As agentic commerce is projected to generate trillions in global revenue, the need for effective fraud detection and agent trust management becomes critical. While UCP has significant industry backing, it competes with other protocols like the Agentic Commerce Protocol (ACP) developed by OpenAI and Stripe. The future success of agentic commerce hinges on building a comprehensive trust layer that ensures secure and trustworthy interactions, regardless of the protocol or the nature of the agents involved.
Jan 26, 2026
1,450 words in the original blog post.
AI agents are transforming online shopping by autonomously performing tasks such as browsing products, comparing prices, reading reviews, and completing transactions without direct human interaction, a phenomenon known as agentic commerce. This development presents businesses with both opportunities, such as increased revenue and reach, and challenges, including privacy concerns, security threats, and marketing strategy shifts. Organizations need to develop a comprehensive understanding of the AI agents accessing their sites, including their purposes, the business value they offer, and the potential risks they pose. Key considerations include ensuring machine-readable catalogs, maintaining fast and reliable APIs, and aligning cross-functional teams to create an effective agent strategy. By proactively addressing these challenges, businesses can leverage AI agents to gain a competitive advantage while protecting user privacy and data security.
Jan 14, 2026
1,091 words in the original blog post.