Your customers brought an agent.
Your customers didn't wait for you to have a plan. Most of the agents on your site today are here to buy something on a real customer's behalf. The opportunity is letting them through. The work is telling the real ones from the ones that aren't.
20x more Muse in four weeks.
Meta shipped Muse free to US consumers on 8 September. In the four weeks that followed, daily Muse agent sessions across our network grew more than 20x, and Muse now outpaces every other agent we track. This is not a projection. It is what our customers' login pages recorded.

Nobody asked permission. There was no API to integrate and no standard to adopt. The agent opened a browser and used the login form that was already there, which means this arrived at your business whether or not you had a plan for it.
Three populations. One signature each.
Catching all three takes device, behavioral, and adaptive signals working together. Most vendors have one.
Self-disclosing good agents
Anthropic and OpenAI crawlers. Cryptographic signatures. Web Bot Auth.
They cooperate. They publish IP ranges and sign HTTP headers. Standards bodies and CIAM vendors are racing to serve this cohort.
Caught by: disclosure standards. The easy population.
Non-disclosing good agents
Muse. Instinct. Claude computer use. ChatGPT agent mode. Local agents on real laptops.
Operating on behalf of a real user, for legitimate purposes. They will never declare. The signal that gives them away is behavioral, not network.
Caught by: behavioral biometrics + Device ID.
Malicious agents
Account takeover. Fake accounts. Payment fraud. Scraping.
Cloud-hosted at scale. Spoofed devices, almost always impersonating Mac Chrome. Their tell is the spoofing itself: fingerprint mismatches and residential proxies.
Caught by: device spoofing detection + PoW.
Population Two is the one nobody planned for. It is also the one arriving by the hundreds of millions with a customer attached.
Where an agent runs decides how you catch it.
Populations tell you what it's for. Categories tell you where it runs, and each leaves a different fingerprint.
Cloud-hosted agents
ChatGPT. Anthropic API. Cloud-deployed crawlers and bots.
- Spoofed devices. Almost always impersonate Mac Chrome.
- Cloud infrastructure. Data-centre ASNs, residential proxies.
- Fingerprint mismatches. OS, UA, WebGL, canvas inconsistencies.
Device intelligence and Proof of Work invert the unit economics of cloud-scale automation.
Local browser agents
Atlas. Perplexity Comet. Custom Chromium forks.
- Static quirk detection. Claims Chrome, executes a forked engine.
- Chromium fork signals. Build flags, V8 timings, render anomalies.
- Behavioral biometrics. Click cadence, mouse trajectory shape.
Static quirk analysis and behavioral biometrics surface forked browsers even when the fingerprint looks clean.
Local OS-level agents
OpenClaw. Claude Cowork. Controllers driving real Chrome.
- Vision, reasoning, action loop. Screenshot, infer, click sequencing.
- Timing anomalies. Inhuman pauses, no fluid micro-motion.
- Device ID and biometrics. Real device, non-human interaction.
Persistent device identity and behavioral biometrics surface the agent even on a real device.
Every other vendor in this category talks about agent detection in the abstract. We can name the technique that catches each one, and it is shipped, not roadmap.
Two agents. Two ways of failing to be a person.
Neither announced itself. Both were caught by the movement alone.

Muse: the simulated hand
Muse tries to move like a person, and the attempt is the tell. The path wanders and doubles back, but the speed trace shows the same sawtooth spike again and again: instant acceleration, smooth decay, repeated with a regularity no hand produces.

Manus: no hand at all
Manus doesn't simulate anything. Start point to end point, one straight line, no correction and no overshoot. A person reaching for a target never travels in a perfect line, and never arrives without adjusting.
This is what Population Two looks like on a real device, with real credentials, at a login page that has no other reason to be suspicious.
Knowing it's an agent is the easy half
Detection answers one question: is something automated here. That answer is not much use on its own, because it is true of the customer's shopping assistant and the credential stuffing run in equal measure. Acting on detection alone is how businesses end up blocking the traffic they wanted.
Classification answers the question that follows: which agent is this, who is it working for, and is what it's attempting something you allow. That takes more than one signal source. Device intelligence places the machine. Behavioral biometrics read the hand. Network signals show where it runs. Adaptive challenges test what it can actually do. Read together, they resolve a session into something you can make a decision about.
Arkose Titan carries all four.
One agent name. One undifferentiated block of traffic. Allow it all or block it all, and most teams choose block, because there's nothing to tell the sessions apart.
Persistent device identity resolves the individual virtual machine behind each session, so one customer's Muse is a different object from another's. Your existing risk logic applies to agent traffic the way it already applies to people.
You never have to turn away good customers because one of them has a compromised agent.
None of them identify themselves. Each leaves a trail.
Every one of these is a customer trying to get something done. Naming them is how you let them.
Let the agents buy. Make the attackers pay.
Let the good agents buy
Agentic commerce only works if the agent can finish the transaction. Block it and the sale doesn't happen, and it never shows up as a loss, because the session simply ends. Visibility and classification let you open the door deliberately instead of leaving it shut by accident.
Make the attackers pay
The sessions trying to abuse you run on the same tooling. Adaptive challenges a model can't solve and compute costs that scale with risk make the attempt uneconomic, so the attacker gives up or hands control back to a human. Invisible to the customers you want.
One classification decision drives both, on one platform. That's the part competitors are missing. They built for one job or the other.
Four controls, built for a human at the keyboard.
Device trust.
The fingerprint belongs to the agent, not your customer. Hardware, IP, and geography you've never seen. It reads as takeover when someone is just buying something.
Velocity and geography.
Geo-impossibility rules assume a body in a place. A model can learn your threshold and sit underneath it.
Behaviour.
Still separates agent from human. Never separates a customer's agent from a fraudster's.
Authentication.
Credentials vaulted and injected at point of use. No typing, and in some markets a single consent sets a standing mandate with no fresh step-up.
Block this without deciding to, and your bot defence is making a revenue call on your behalf.
Frequently Asked Questions
What is agentic AI, and why does it matter for online security?
Agentic AI refers to AI systems like Muse, Instinct, Comet and Atlas that act autonomously on the web such as logging in and completing purchases on someone's behalf. Since malicious automation can look nearly identical technically, detection alone isn't enough anymore.
Are all AI agents a threat to my business?
No. AI agents fall into three populations: self-disclosing good agents that publish their identity and follow disclosure standards, non-disclosing good agents acting on a real customer's behalf, and malicious agents.
Why can't traditional bot detection tell good AI agents from bad ones?
Traditional detection answers "bot or human?" and both sides are now bots. Legitimate and malicious AI agents use the same automation technology with similar interaction patterns, so the real question is intent, not automation.
How is classifying an AI agent different from just detecting one?
Detection only confirms that traffic is automated. Classification evaluates an agent's intent to determine whether that automation is authorized, unknown or malicious, so it can be treated accordingly instead of blocked outright.