Your Conversion Rate Now Counts Machines. Is Your CRO Program Ready?

Your Conversion Rate Now Counts Machines. Is Your CRO Program Ready?
Ecommerce dashboard showing steady human conversion rates and falling blended rates as AI agent traffic grows.
Denominator Drift: AI Agents Are Skewing Your Conversion Rate | Alhena AI

Your Conversion Rate Now Counts Machines. Is Your CRO Program Ready?

Agentic browsers fire your analytics tags like shoppers. Learn how denominator drift distorts conversion rate and A/B tests, and how to measure humans.

What is denominator drift? Denominator drift is the slow, silent change in who your analytics counts as a visitor. AI agents that render pages and fire tags like a person now sit inside the session counts that every conversion rate, engagement metric and A/B test divides by. Your numerator (human orders) can hold steady while your denominator fills with machines. The metric moves even though your shoppers didn't.

For most of the last decade, "bot traffic" was a security team's problem. It was a marketing team's problem too, when referral spam hit, but it was rarely a CRO problem, because the bots that mattered most either announced themselves or never ran your tracking code. That arrangement is ending. The newest visitors to your product pages run a full Chromium browser, execute your JavaScript, scroll, click and leave. Your dashboard records every step of it as a person.

This post is for heads of ecommerce and CRO and analytics leads. It explains the mechanism, introduces a simple model for fixing the maths, and gives you a playbook to start with this quarter.

Part one:

Why crawlers never broke your dashboards (and agents do)

The old automation mostly came in two kinds, and neither one wrecked your conversion rate.

Declared crawlers never reached the tag. Googlebot, Bingbot, GPTBot, ClaudeBot and PerplexityBot identify themselves in their user-agent strings. The AI crawlers largely fetch raw HTML without executing JavaScript, so they never fire a client-side analytics tag at all. Snowplow's analysis puts it plainly: non-browser agents fetch content from their own servers with identifiable user-agents and stay invisible to traditional analytics, showing up only in server logs. Googlebot does render JavaScript, but it is on the known-bot list, which brings us to the second protection.

Known bots were filtered. GA4 automatically excludes traffic from known bots and spiders, using Google's own research plus the IAB/ABC International Spiders and Bots List. You can't switch that filter off, and you can't see what it removed. It only works on bots that say who they are.

Agentic browsers break both assumptions. Snowplow's January 2026 analysis notes that in-browser agents such as Perplexity Comet, ChatGPT Atlas and Dia run JavaScript and inherit the user's session. When Atlas browsed, it presented a standard Chrome user-agent identical to a human visitor's, so the IAB list didn't catch it. HUMAN Security's own agent profiles say the same of Comet and Claude for Chrome: both present as ordinary Chrome or Chromium traffic at the network layer.

The honest caveat is that headless-browser bots have always leaked into analytics. What's different now is scale: HUMAN's 2026 benchmark, published March 26, 2026, found automated traffic grew 23.5% year over year in 2025 against 3.1% for human traffic, and that the new traffic is legitimate: it arrives from real consumer products that people install on purpose. Google has also added Auto Browse, a Gemini-powered agent inside Chrome that clicks, scrolls and fills forms in dedicated tabs, for AI Pro and Ultra subscribers in the US.

How big is the browser-agent slice?

HUMAN Security's April 2026 State of Agentic Traffic benchmark, published May 4, 2026 by its Satori Threat Intelligence Team, found that browser-based agents, "led by Perplexity's Comet and OpenAI's Atlas," accounted for roughly 71% of observed activity among the top ten agents. Comet led at 48.12%, followed by Atlas at 21.33%, the Claude Chrome extension at 17.33% and ChatGPT Agent at 8.55%.

The mix keeps shifting. OpenAI sunset the standalone Atlas browser on August 9, 2026 and folded browsing into the ChatGPT desktop app and a Chrome extension. By July 2026 HUMAN had Claude's Chrome extension at 24% of agentic traffic, ahead of Atlas at 15.5%. The lesson for analytics teams: don't build your detection around one product name. The brands change every quarter. The behaviour doesn't.

What agents do on your site: browse a lot, buy a little

HUMAN's 2026 State of AI Traffic & Cyberthreat Benchmark Report, published in March 2026 and covering 2025, found that 77% of agentic AI activity landed on product and search pages. Only 8.8% hit account pages, about 5% authentication flows and 2.3% checkout pages.

77%
Agent activity on product and search pages
HUMAN Security, 2025 data
8.8%
Agent activity on account pages
HUMAN Security, 2025 data
~5%
Agent activity on authentication flows
HUMAN Security, 2025 data
2.3%
Agent activity on checkout pages
HUMAN Security, 2025 data

Read that carefully. The 2.3% is a share of agent activity by page type, not a conversion rate. But the shape is exactly what distorts CRO maths: agents pile into the pages you optimise hardest (PDPs, search, collections) and rarely reach the pages where revenue gets counted. HUMAN's monthly data keeps confirming the pattern. In June 2026, 79% of agentic activity sat on product and search routes, while checkout and payment flows held at 2.34%.

Volume is growing fast from a small base: HUMAN says agentic traffic "currently measures in the millions of requests per month" against the trillions of interactions it processes weekly, and training crawlers still made up 67.5% of AI-driven traffic in 2025. HUMAN measured agentic AI traffic growing 7,851% year over year in 2025, and noted that agentic browsers concentrate heavily in ecommerce, which took 55.8% of browser-agent traffic.

Part two:

The Three Denominators model

Most CRO programs divide by one number: sessions. That worked when sessions meant people. A more accurate program keeps three denominators side by side and watches the gaps between them.

The Three Denominators model holds that every ecommerce metric should be reported against three nested bases: sessions (everything your tag recorded), human sessions (sessions with no agent signals) and buyer-capable sessions (human sessions plus agent sessions acting for a real shopper who can actually complete a purchase).

Denominator What it includes What it's for
1. SessionsEvery session your analytics tag recorded, human or notCapacity planning, load, total reach
2. Human sessionsSessions with no agent signals (no valid Web Bot Auth signature, no known agentic-browser traits, no behavioural agent flags)Human UX, engagement and conversion benchmarks
3. Buyer-capable sessionsHuman sessions plus agent sessions tied to a real shopper who can transact (e.g., signed, delegated agents that reach cart or checkout)Revenue forecasting and channel economics in an agentic world

Denominator drift is the widening gap between Denominator 1 and Denominator 2.

When that gap grows month over month, every rate built on Denominator 1 is quietly losing accuracy.

The human-verified conversion rate is orders from human sessions divided by human sessions. It is the conversion rate your CRO program should optimise, benchmark and report, because it measures the experience you actually designed for. Keep the blended rate for finance reconciliation. Just stop using it to judge UX changes.

Part three:

Illustrative arithmetic: how the rate moves when you remove agents

The numbers below are illustrative arithmetic, not Alhena network data. They show the mechanism. The magnitude on your site will differ.

Imagine a store whose human shoppers convert at a steady 2.2% all year, while agent sessions (mostly research agents) convert at 0.5%. Here is what happens as agents grow from 3% to 12% of sessions.

Month 1 Month 6
Total sessions100,000100,000
Agent sessions (0.5% CR)3,000 → 15 orders12,000 → 60 orders
Human sessions (2.2% CR)97,000 → 2,134 orders88,000 → 1,936 orders
Blended (reported) conversion rate2.15%2.00%
Human-verified conversion rate2.20%2.20%

The dashboard shows a 7% relative drop in conversion over six months. A team looking only at the blended number would start "fixing" checkout, rewriting PDPs or blaming a theme update. Nothing about the human experience changed. The denominator did.

The same drift hits engagement metrics. Snowplow flags the case directly: a rising bounce rate can send you into page work you don't need when the real human bounce rate is lower and agents are driving the change.

Part four:

The A/B test problem: uneven agent share across arms

Randomisation is supposed to protect experiments from this. On average it does. In practice there are at least four ways agents can land unevenly across arms:

  • 1. Session-level or cookieless bucketing. Many agents don't keep cookies between tasks, so they get re-bucketed on every visit. If one arm triggers more retries (a slower render, a broken element the agent can't parse), it collects more agent sessions.
  • 2. The variant changes agent behaviour. Move the price into a JavaScript-only widget and agents may reload, loop or bail in ways that inflate that arm's session count.
  • 3. Ramped allocations. If you raise a variant from 10% to 50% mid-test while agent share is climbing week over week, the later-ramped arm soaks up more agents.
  • 4. Asymmetric filtering. If a bot filter flags high-engagement sessions and the variant raises engagement, you've removed different populations from each arm. Optimizely's documentation names third-party bots as a common cause of sample ratio mismatch.

Here is a worked example of what that does to a decision.

Illustrative arithmetic, not Alhena data. A 50/50 test, 50,000 sessions per arm. Agents convert at 0.3% in both arms. The variant genuinely improves human conversion from 2.40% to 2.50%, but it also draws a larger share of agent sessions.

Control Variant
Sessions50,00050,000
Agent share6% (3,000)14% (7,000)
Agent orders (0.3%)921
Human sessions47,00043,000
Human orders1,128 (2.40%)1,075 (2.50%)
Blended conversion rate2.27%2.19%
Result on blended dataVariant "loses" by 3.6%
Result on human-verified dataVariant wins by 4.2%

The session counts are equal, so a standard sample ratio mismatch check passes. The composition is what's broken. You would kill a winning variant and never know.

The reverse also happens. If agents cluster in control, a neutral variant looks like a winner. This is why checking total traffic split isn't enough anymore. You need to check agent share per arm.

Part five:

Why blocking agents is the wrong fix

The tempting response is to block anything that looks automated. There are three reasons not to.

Some agents carry buyers. HUMAN's 2.3% checkout share is small, but it is real transacting activity, and HUMAN's own agentic commerce guidance warns that most agents act for real users, so blocked product pages send them to another merchant. Alhena's cohort research found that LLM-referred shoppers converted at 2.68% from October 2025 to April 2026, ahead of Google Ads at 1.87%. That's the same ecosystem these agents come from.

Your bot tools probably can't tell good from bad anyway. DataDome's State of Bot & Agent Security Report 2026, published September 22, 2026, tested 21,491 popular websites in June. It found 65.3% blocked none of its 10 test bot types and only 2.4% blocked all of them. That is a test of site protection, not analytics, but it shows how rough the line between "allowed" and "blocked" is. Hydrolix's State of AI Bots in 2026 survey of 300 enterprise leaders found that only 33% said their WAF or bot tool blocked more than half of AI bot traffic in the past 12 months.

Leaders underestimate the problem. Hydrolix's June 3, 2026 report on the same survey found respondents estimate AI bots generate "approximately 17%" of their traffic. Imperva's 2026 Bad Bot Report measured automated traffic at more than 53% of all web traffic in 2025, with malicious bots at 40%, figures Hydrolix itself repeats in the same report. These measure different things (one company's AI bots versus all automation on the web), and Hydrolix itself cautions against subtracting them. But the direction is clear: most teams think their machine exposure is smaller than it is.

Segment, don't block.

Keep agents on the site, keep them out of your human metrics, and measure them as a channel of their own.

Part six:

How to find agent sessions: the signal stack

No single signal catches everything. Stack them from most to least certain.

1. Cryptographic identity (Web Bot Auth)

Web Bot Auth builds on RFC 9421 HTTP Message Signatures. The agent signs each request, and you verify it against a public key directory published at /.well-known/http-message-signatures-directory. OpenAI's allowlisting documentation says ChatGPT's Cloud browser signs outbound requests with a Signature-Agent value of "https://chatgpt.com". Cloudflare's Signed Agents programme launched with ChatGPT agent, Goose, Browserbase and Anchor Browser. The IETF webbotauth working group adopted draft-ietf-webbotauth-httpsig-protocol-00 on September 1, 2026. Treat a valid signature as proof. Don't treat a missing signature as proof of a human. HUMAN's profile of Atlas notes it had no public signed identity, and consumer agentic browsers generally don't sign.

2. Known agentic-browser traits

These are product-specific markers such as injected page elements, extension IDs or Perplexity-specific headers. HUMAN's September 2026 agent-detection research gives concrete examples: Genspark injects a genspark-float-bar element into every page it opens, and Manus loads a "Manus Helper" Chrome extension. HUMAN also found every agent it analysed runs on Selenium, Playwright or Puppeteer, "most commonly Playwright."

3. Behavioural signals

HUMAN's research found ChatGPT Agent moved its cursor in perfectly straight lines and in exact 0.25-pixel increments. Timing that is too even and paths with no hesitation are the kind of patterns event-level data can reveal and aggregated reports can't.

4. Server-side and edge logs

These are the only place non-JavaScript agents appear. Alhena's Black Friday analysis of what AI shopping agents read covers that side: most agents never run your JavaScript, so their demand is under-counted. This post covers the opposite problem, the agents that do run it and inflate your human metrics. You need both views.

Part seven:

The human-verified CRO playbook

A practical sequence for CRO and analytics leads:

  • 1. Add an agent flag at collection. Capture signature headers at the edge or server and pass a session-level agent_signal dimension (signed / trait / behavioural / none) into your analytics and warehouse.
  • 2. Stand up the Three Denominators report. Show sessions, human sessions and buyer-capable sessions side by side, weekly. Chart the gap between the first two. That gap is your denominator drift.
  • 3. Re-baseline your KPIs. Recompute the last 12 months of conversion rate, bounce rate and PDP engagement on human sessions where the data allows. Expect some "declines" to turn out flat.
  • 4. Make the human-verified conversion rate the CRO north star. Report the blended rate to finance, and use the human-verified rate for UX and merchandising decisions.
  • 5. Add an agent-share balance check to every experiment. Alongside the usual SRM test, run a chi-square test on agent-flagged sessions per arm. Flag any test where agent share differs by more than a pre-set threshold.
  • 6. Bucket by durable identity, not session. Where you can, assign by a stable fingerprint or user ID. That keeps cookieless agents from re-randomising on each visit.
  • 7. Pre-register which denominator decides the test. Write it into the test plan before launch, so no one picks the flattering one afterwards.
  • 8. Treat agents as a channel with its own funnel. Track agent sessions to cart, agent sessions to checkout and agent-carried revenue separately. Some variants will help humans and hurt agents (for example, JavaScript-only pricing), and you should know when that trade-off is happening.
  • 9. Audit your bot rules quarterly. Agent products launch, rename and shut down within months (Atlas lasted about nine). Rules keyed to product names go stale fast.
Part eight:

Where Alhena fits

This is a measurement problem, and it takes first-party data joined to outcomes. Alhena runs on-site shopping and support agents across a cohort of roughly 310 retail brands and about 190 million visitors. Its 310-brand LLM traffic study describes how that data joins arrival channel to checkout in a single system. Alhena's AI search revenue attribution guide and its published measurement methodology explain the joins: traffic classified by source and matched to cart and checkout events by visitor fingerprint. The AI A/B testing guide covers deterministic test and control assignment for the chat experience itself.

That setup is what lets Alhena measure how agent-flagged sessions behave next to human ones, in chat and at checkout, and how much a brand's conversion rate moves once they're removed. If you're weighing the AI Shopping Assistant as a conversion surface, the CRO chat platform checklist is a good place to start. Alhena AI Visibility covers the upstream question of whether AI engines recommend you at all.

Key takeaways

  • Denominator drift is the growing share of machine sessions in the base your metrics divide by. It can move your conversion rate with no change in human behaviour.
  • Declared crawlers rarely reached your analytics tag. JavaScript-executing agentic browsers do, and they look like Chrome.
  • Agents concentrate on product and search pages (77% of agentic activity in 2025, per HUMAN) and rarely reach checkout (2.3%).
  • Use the Three Denominators model: sessions, human sessions, buyer-capable sessions.
  • Optimise the human-verified conversion rate, and check agent share per arm in every A/B test.
  • Don't block agents wholesale. Segment them, measure them, and sell to the ones that carry buyers.

FAQ

Do AI agents show up in Google Analytics 4?

Some do. Declared crawlers like GPTBot mostly don't execute JavaScript, so they never fire the GA4 tag. Agentic browsers such as Perplexity Comet and Claude for Chrome run JavaScript and present standard Chrome user-agents, so GA4 usually counts them as ordinary sessions.

Does GA4 filter AI agent traffic automatically?

Only if the agent is on the known-bot list. GA4 excludes known bots using Google's research and the IAB/ABC International Spiders and Bots List. Agentic browsers that look like regular Chrome aren't on it.

What is a human-verified conversion rate?

It's orders from human sessions divided by human sessions, with any session carrying agent signals excluded. It measures how well your site converts the people you designed it for.

Can AI agents skew A/B test results?

Yes. If one arm receives a larger share of agent sessions, its blended conversion rate falls even when humans convert better. The total traffic split can look perfectly balanced while the arms are made up differently. Check agent share per arm, not just total sessions.

Should I block AI agents from my ecommerce site?

Usually not wholesale. Some agents act for real shoppers and reach checkout, and blocking them hands those sales to competitors. Segment agent sessions out of human metrics instead, and track them as their own channel.

What is Web Bot Auth?

It's an IETF-track standard, built on RFC 9421 HTTP Message Signatures, that lets an agent prove who it is by signing its requests. OpenAI signs ChatGPT's Cloud browser requests this way, and Cloudflare verifies signed agents at the edge. Many consumer agentic browsers don't sign yet.

How much of ecommerce traffic is AI agents?

It varies by site and by how you count. HUMAN measured agentic traffic growing 7,851% year over year in 2025 from a small base. Imperva put all automated traffic at more than 53% of web traffic, which includes crawlers and bad bots, not just shopping agents. Measure your own share with an agent flag in your data.

Power Up Your Store with Revenue-Driven AI