Retailers have spent years refining digital commerce around the familiar assumption that a human shopper is the one clicking, comparing, adding to cart, and checking out. That assumption is now starting to break.
A new class of AI shopping agents can search across sites, test promotions, rebuild baskets, and complete transactions on a customer’s behalf through the same front-end experiences people use every day. As that behavior scales, the risk is not limited to fraud in the traditional sense. It’s also operational disruption caused by software that follows instructions too literally, too quickly, and with no real understanding of downstream consequences.
Transmit Security, an identity security company co-founded in 2014 by CEO Mickey Boodaei, has been focused on the question of digital trust for years, and that focus is becoming newly relevant as agentic commerce moves from theory into live retail environments.
The Retail Stack Was Built for Human Behavior
The core problem is not that every AI agent is malicious. In many cases, it is the opposite. An agent told to “find the best price” may interpret that task by trying endless combinations of items, promo codes, shipping options, and cart states until it finds a lower total. It may add the same item to thousands of carts in seconds, abandon and rebuild sessions repeatedly, or behave in ways that look abusive even when no attack was intended.
The visible web has long been designed around a person sitting in front of the screen, moving step by step through a workflow. AI agents challenge that model because they can navigate websites, fill in forms, and execute actions for users, introducing traffic and behavior patterns that many existing fraud and bot controls were never built to interpret correctly.
Why This Is an Identity Problem, Not Just a Bot Problem
Boodaei sits at the intersection of identity, authentication, and fraud prevention rather than treating them as separate disciplines. The company’s Mosaic platform is positioned as an end-to-end identity security platform spanning authentication, fraud prevention, orchestration, identity verification, and threat detection and response.
Mosaic supports enterprise-grade access security, session controls, audit logging, authentication, user management, and identity fraud detection. In the era of AI agents, this support is especially impactful given that the question is no longer whether a user successfully logged in once. The harder question is what should happen after access has already been granted and behavior starts to drift.
Authorization Is Becoming the Real Fault Line
Once a consumer allows an agent to act on their behalf, the system may recognize the session as legitimate even if the path the agent takes is unpredictable.
An agent may hallucinate the route to a goal, misread a checkout flow, exploit a discount structure by trial and error, or complete a purchase the customer did not mean to authorize in that form.
The challenge for retailers is telling the difference between a helpful autonomous assistant, a misbehaving agent, and a malicious actor hiding inside what appears to be an approved session.
Fraud stacks often assume human input at every stage. Traditional signals such as device fingerprinting, behavioral biometrics, and bot detection become less reliable when agents operate from cloud infrastructure or act instead of the end user.
The Liability Question No One Has Solved Yet
This shift also creates a liability problem the market has not resolved. If an AI agent completes an order that a shopper did not intend, who owns the mistake? The consumer may argue they never meant to buy that item, quantity, or configuration. The merchant may see a valid session and a completed transaction. The agent provider may say the system acted within broad instructions.
That ambiguity is not a niche edge case, but rather likely to become a recurring issue as consumers grow more comfortable delegating shopping and payments to AI tools.
Transmit Security frames the issue in similarly practical terms, pointing to a future in which banking, shopping, and bill pay are increasingly delegated to AI-powered agents, with fraud and abuse moving at machine speed when something goes wrong.
Agentjacking Raises the Stakes
A particularly important wrinkle is what Transmit Security has identified as “Agentjacking.” In this scenario, a malicious instruction is slipped into an agent’s session and then treated as legitimate because it occurs inside an already authorized interaction. That makes it different from older perimeter-based attack models.
The compromise does not necessarily begin with a stolen password or a visibly hostile login attempt. Instead, the abuse can emerge from inside a trusted flow, after the customer and system have already accepted the presence of the agent.
For retailers and financial institutions alike, that means trust can no longer be a one-time event. It has to be reassessed continuously, based on context, behavior, and whether the current action still aligns with expected intent.
Where Identity Security Enters the Agentic Commerce Debate
As AI agents begin to move from novelty to infrastructure, Transmit Security is exposing a gap that many businesses have not yet fully articulated. A user can be verified, a session can be authorized, and damage can still unfold inside that trust boundary. That is the real shift. In the agentic economy, risk is increasingly shaped by what happens after access has already been granted.
Seen through that lens, Boodaei and his team are helping draw attention to a problem that is likely to define the next phase of online commerce. Automation does not need malicious intent to create disruption. It only needs permission, speed, and enough freedom to improvise. Retailers must adapt by getting better at reading behavior in context, assessing trust continuously, and responding before cart manipulation, discount abuse, and session-level interference become a routine cost of doing business online.



