The verification question retail cannot defer
On July 24, 2026, Fastly announced from Costa Mesa that it is joining Experian's Agent Trust ecosystem, a framework built to establish trusted identity, delegated authority, and transaction confidence for AI agents. For anyone running commerce infrastructure, the timing is the story. Autonomous agents are no longer a demo. They are beginning to browse, compare, and transact on a customer's behalf, and every one of those requests arrives at your systems looking a lot like ordinary traffic. The operational question is blunt. When an agent shows up at your checkout claiming to act for a human, do you actually know that it is authorized, or are you taking its word for it?
That question sits squarely with the CIO, because the failure modes are expensive on both sides. Reject legitimate agents and you lose a fast-growing sales channel to competitors who let them through. Wave through unverified ones and you invite fraud, unauthorized purchases, and disputes that land in your chargeback queue. Experian and Fastly are proposing that trust becomes a property you can check at request time, the same way you already check a card or a session token. We think that framing is the right one, because it turns a fuzzy governance worry into a concrete control point you can reason about and instrument.
What the Agent Trust ecosystem actually provides
The core of Experian's approach is an Agent Registry that maintains dynamic trust scores for what it calls Human to Agent Bound AI agents. The phrase matters. It describes an agent that is provably tied to a specific human principal who delegated authority to it, rather than an anonymous bot acting on its own account. A dynamic score means the trust signal moves over time as behavior and evidence accumulate, so a merchant is not stuck with a one-time binary allow or deny. Kathleen Peters, Chief Innovation Officer at Experian, frames the moment plainly: agentic commerce represents one of the most significant shifts in digital commerce since the rise of mobile.
For a retail technology leader, the useful mental model is credit-bureau logic applied to software agents. Experian has spent decades scoring the trustworthiness of parties to a transaction, and the ecosystem extends that discipline to a new kind of actor. The registry becomes a shared reference that many merchants and platforms can consult, which is what gives it leverage. A trust score is only worth acting on if it reflects behavior observed across the network rather than what one retailer happened to see. That network effect is the real asset here, and it is why an ecosystem model, with partners feeding and consuming signals, matters more than any single vendor feature.
Why the edge is the right checkpoint
Fastly's contribution is to move the verification decision to the network edge, evaluating agent identity and authorizing transactions before requests hit backend systems. This is an architectural choice with real consequences. Doing trust evaluation at the edge means unauthorized or low-scoring agents get filtered at the perimeter, so your order management, inventory, and payment services never spend cycles on traffic that was never going to be legitimate. It keeps the blast radius small and the latency budget intact, which matters when an agent may fire many rapid requests while comparison shopping across catalogs on a customer's behalf.
Jeff Alpen, VP of Fastly's Partner Ecosystem, puts the business need directly: as AI agents become an increasingly important channel for digital commerce, businesses need a way to distinguish trusted, authorized agents. The edge is where that distinction is cheapest to make. A programmable edge sees every inbound request first, before routing and before session logic, so it is the natural place to attach a trust check. We would rather reason about one enforcement layer that fronts all backends than bolt agent verification into each application service separately, where the logic drifts and coverage gets uneven across teams.
Fitting into the stack you already run
The detail that should reassure architects is integration rather than replacement. Fastly's programmable edge evaluates trust signals and integrates with existing APIs, authentication systems, and Know Your Agent technology such as Skyfire. That means the trust framework is designed to sit alongside the identity and authorization plumbing you already operate, not to demand a rip-and-replace of it. Agent verification becomes another signal in a decision you already make, layered onto session authentication and existing API gateways rather than duplicating them. For teams that have spent years hardening their auth stack, an additive model is the only one that stands a chance of getting deployed.
The Know Your Agent framing is deliberate and worth noting for governance. It echoes Know Your Customer obligations that retail and financial teams already understand, and it signals where regulation and audit expectations are likely to head as agents handle real money. Naming Skyfire as an example of the kind of technology the edge can integrate with tells you the intent is an open set of providers rather than a closed one. For a buyer, that lowers lock-in risk. You want the ability to swap or add verification providers without re-architecting the enforcement point, and an edge that treats trust as pluggable signals gives you that room.
The market forces making this urgent
The numbers cited alongside the announcement explain why this is a now problem. Salesforce says AI agents influenced 262 billion dollars in 2025 holiday sales, which puts agent-mediated buying well past the experimental stage. Imperva reports that 53 percent of web traffic is already automated, so more than half of what hits your endpoints is not a human with a browser. McKinsey projects that AI agents could drive up to 1 trillion dollars in U.S. commerce by 2030. Read together, these figures describe a channel that is large today and compounding, and a traffic mix where telling good automation from bad is becoming the central operational task.
We would caution against reading the automation figure as pure threat. A large share of that traffic is legitimate, and blanket bot blocking would throw away revenue and frustrate customers who deployed agents to shop for them. That is exactly why a scoring model beats a wall. The goal is not to keep automation out but to sort it, admitting authorized delegated agents while turning away the ones with no verifiable human behind them. The market context makes the case that this sorting problem is not optional. If half your traffic is automated and a growing slice of it is spending money, you need a defensible way to decide which agents to trust.
What this means for your roadmap
For the retail CIO, the practical takeaway is to treat agent trust as a first-class item in the 2026 to 2027 roadmap rather than a research topic. Start by mapping where agents already touch your stack, from product APIs to checkout, and where an unverified agent could currently complete a purchase. That inventory tells you how exposed you are today and how much of the problem an edge-level control could cover. Then evaluate whether your enforcement point should live at the edge, given the latency and blast-radius benefits, or whether you are willing to carry verification logic deeper in each service and accept the maintenance cost that brings.
The strategic read is that trust infrastructure for agents is consolidating into ecosystems and shared registries, and interoperability is becoming the deciding factor. A trust score gains value from the breadth of the network behind it, and an edge that can plug into multiple verification providers protects your optionality. Our advice is to favor approaches that keep verification pluggable and standards-friendly, so you are not betting your agentic-commerce channel on one vendor's registry. Fastly joining Experian's ecosystem is a signal that the market is organizing around this layer now. The leaders who instrument agent trust early will set the terms their competitors inherit.



