A five-level scale for how disciplined your organization is at detecting, classifying and controlling the AI agents now acting on your customers’ behalf.
Prepared for executive and board review
AI agents are already logging in, browsing, transacting and opening accounts on your platform, whether or not your business has a policy for it. The board-level question is not how much of this traffic to block. It is how quickly and confidently the business can tell which agents are acting for your customers and which are acting against them, and act on the difference in real time.
Maturity here is a revenue lever, not a compliance milestone. Companies that can answer that question quickly will say yes to agentic traffic as a channel while competitors are still deciding whether to block it.
The controls most companies rely on were built to answer one question: is this session automated? They were not built to answer the question agentic traffic actually poses: what is this agent trying to do, and should we let it? Treat every agent as a bot and you block your own customers. Treat every agent as a customer and you open the business to abuse at scale.
Fewer than one in four organizations can currently see the AI agents operating in their environment (Gravitee, State of AI Agent Security 2026). Visibility is the floor. Nothing above it is available to a business which cannot see the traffic in the first place.
| Level | Name | In one sentence |
| 1 | Initial | Agentic traffic is invisible inside general bot noise; nobody owns the problem. |
| 2 | Repeatable | Legacy bot rules are reused for agents, inconsistently, by whichever team bought the tool. |
| 3 | Defined | A documented, cross-functional policy classifies agent populations consistently across the business. |
| 4 | Managed | Agent trust runs as a measured program with real-time visibility and graduated enforcement. |
| 5 | Optimizing | Agent trust is a continuously improving, revenue-generating capability, not a security cost center. |
Arkose Labs' Agentic Trust Maturity Model answers on a five-level scale. The level names follow the maturity-model convention your engineering and risk teams already use; everything inside them is built for agentic traffic. Each level is assessed across the same five dimensions, so the result is a profile rather than a single number:
The five dimensions of agent trust maturity
Graduated enforcement is the part most often missing. Above Level 3 a business has more options than allow or block, including handing the decision back to a person when the call is wrong. Without that path back, every misjudged agent is a lost customer.
The market is concentrated at Level 1 and Level 2, which is expected rather than a failure. Purpose-built agent trust tooling, and the payment-network standards it works with, only began shipping in 2026, so the means of reaching Level 3 has barely existed long enough to adopt.
The gap shows up by name in the field, not only in survey data: a European retailer running agentic commerce in eleven countries where security ownership sits with a different team, an insurer with no policy for agentic payment automation, a betting operator with no authorization framework at all. This is what Level 1 looks like once agentic traffic reaches a company which has never named an owner for agent policy.
Levels 4 and 5 remain rare, concentrated among large payments, marketplace and travel platforms with the scale to justify a dedicated program. For most businesses the realistic near-term goal is Level 3, and it is reachable this year.
The companies moving fastest from here will not be the ones blocking the most agentic traffic. They will be the ones able to tell, with confidence, which agents are respecting the rules of the road.
Summarizes the full report, The Agentic Trust Maturity Model (Arkose Labs, 2026), which includes a crosswalk to NIST CSF 2.0 for security and risk teams. Companion asset: the interactive self-assessment, five questions to a profile with ten more to refine it.
© 2026 Arkose Labs. All rights reserved.