Other AIs Are Talking to Your Shopping Agent. Who Pays for That?

Other AIs Are Talking to Your Shopping Agent. Who Pays for That?
AI shopping assistant accepting product queries and blocking unrelated bot requests to protect merchant credits.
Machine Visitor Policy: Who Pays When AIs Use Your Chat? | Alhena AI

Machine Visitor Policy: Other AIs Are Talking to Your Shopping Agent. Who Pays for That?

AI agents and scripts now run inference on your chat widget's budget. Here's a machine visitor policy to serve buyer-agents and stop paying freeloaders.

Key takeaways

A machine visitor policy is the set of rules your store uses to identify, answer and bill AI agents and scripts that use your on-site chat. Buyer-agents researching for real shoppers deserve structured, grounded answers. Freeloader conversations, where scripts use your widget as free LLM inference, should cost you nothing. Most brands have no policy at all.

Your chat widget was built for people. A shopper lands on a product page, asks whether the boots run narrow, gets an answer and buys. That is the conversation your AI budget was sized for.

That is not the only conversation happening anymore. Agentic browsers open your widget and ask questions on someone's behalf. Scripts open it too, but they are not asking about boots. They want a Python function, a marketing email or a summary of a PDF, and your model is doing the work on your bill. Without anyone deciding it, your on-site AI has become an API for other AIs.

This post covers the economics of that shift and a policy for handling it. It sets aside the security side (we covered prompt injection separately) and the support-routing side (also covered separately). The question here is simpler and more pressing for anyone who owns a P&L: when a machine talks to your shopping agent, who should pay?

Part one:

What is a machine visitor policy?

A machine visitor policy is a documented set of rules for how your on-site AI identifies, responds to, measures and bills conversations started by software rather than a person. It sits between your bot management at the edge and your AI vendor's billing, and it answers one question for every automated conversation: is this worth paying for?

Three more definitions are useful before we get to the numbers:

  • Buyer-agent: an AI agent or agentic browser acting for a real shopper, such as researching sizing, comparing specs or checking a return window before a purchase.
  • AI token freeloading: Akamai's term for routing outside workloads through a retailer's public-facing AI endpoints so that the retailer pays for the inference.
  • Freeloader conversation: one chat session where the visitor, human or script, uses your shopping assistant as a general-purpose LLM with no buying intent.
Part two:

How common are machine visitors in ecommerce right now?

Common, and growing faster than human traffic on every major dataset published this year.

47.9%
Share of AI bot traffic on Akamai's network that hit commerce
Akamai SOTI, July 2026
7,851%
Year-over-year growth in AI agent and agentic browser traffic, 2025
HUMAN Security, 2026
8x+
Rise in monthly AI requests to login pages, Jan to Jun 2026
DataDome, 2026
42%
Better conversion for AI-referred retail visits, March 2026
Adobe Analytics, April 2026

Akamai put commerce at the center of AI bot activity. Its July 2026 State of the Internet report, Securing the Agentic Storefront, found that commerce accounted for 47.9% of all AI bot traffic across Akamai's network from July to December 2025, and that AI bot traffic rose 19% year over year in 2025, driven mostly by retail. [1] Akamai also named AI token freeloading as one of three new threats to intelligent storefronts, describing threat actors who use scripts and bot networks to push their own processing or model-training queries through a retailer's public AI endpoints, "driving massive infrastructure costs and degrading performance." [2] One detail matters for the policy discussion: commerce organizations put more than 90% of their AI bot activity into a "monitor" category. [1] Most of the industry is watching this traffic, not deciding what to do with it.

HUMAN Security measured the agent side. Its 2026 State of AI Traffic & Cyberthreat Benchmark Report found that traffic from AI agents and agentic browsers grew 7,851% year over year in 2025, with retail and ecommerce taking 46.6% of all agentic traffic. Agentic browsers lean even more heavily toward shopping: 55.8% of their traffic went to ecommerce. [3] HUMAN's monthly tracker shows the trend continuing. In August 2026, ecommerce took back the top spot with 46% of agentic traffic, Perplexity's Comet browser produced 40.7% of all agent volume, and product and search routes reached a record 80% of agent activity. [4]

DataDome showed how deep these visitors now go. Its State of Bot & Agent Security Report 2026, covering more than 75,000 customer sites, counted 52.7 billion AI agent and LLM crawler requests in 12 months, with AI traffic up 82.3%. Monthly AI requests to login pages rose from 11.9 million in January 2026 to 99.7 million in June, an increase of more than eightfold. [5] These agents are no longer reading only your homepage. They reach the logged-in parts of the journey, which is where on-site chat usually lives.

Adobe explains why you can't simply block all of it. Adobe Analytics, in an April 16, 2026 report based on more than 1 trillion visits to US retail sites, found that AI-referred traffic grew 393% year over year in Q1 2026, and that in March 2026 those visits converted 42% better than non-AI traffic, "a new record high," reversing a year-earlier gap when AI traffic converted 38% worse. [6] Machine-mediated shoppers are now some of your best shoppers.

WatchCan AI Help Shoppers Visualize and Buy Furniture?This is the traffic you want more of: a shopper with a real buying question, and Alhena's AI shopping assistant helping them visualize furniture and decide what to buy.
Part three:

The three kinds of machine visitors (and why they need different answers)

Sorting machine traffic into "good bots" and "bad bots" falls apart once you look at the conversations. A more useful split is by intent and by who benefits.

1. Buyer-agents: your newest high-intent customers

A shopper asks Comet or ChatGPT, "Find me a waterproof trail shoe under $150 with a wide toe box and free returns." The agent visits your site, reads the PDP, maybe opens your chat and asks about the return window. A human with a credit card is at the end of that chain.

HUMAN's data says this is mostly research, not checkout. Agents concentrate on product and search pages, and in 2025 only 2.31% of agentic traffic touched checkout. [3] OpenAI's own course correction points the same way. After launching Instant Checkout in ChatGPT in September 2025, OpenAI wrote in a March 24, 2026 blog post that the first version "did not offer the level of flexibility that we aspire to provide," so it would let merchants use their own checkout while it focused on product discovery. [7] The buyer-agent's job is to collect facts. If your AI gives it vague, chatty or wrong ones, the agent drops you from the shortlist and never tells you.

2. Freeloaders: someone else's workload on your bill

This is the visitor who asks your skincare assistant to "write a 500-word cover letter" or "reverse a linked list in Python." Sometimes it's a curious person. Increasingly it's a script that has found a public endpoint which answers for free; CIO.com reproduced this kind of freeloading on Amazon's Rufus shopping assistant. [8]

The economics are skewed. In CIO.com's April 2026 reporting on token freeloaders, Nik Kale, a member of the Coalition for Secure AI (CoSAI) and ACM's AISec program committee, estimated that a normal "where's my order?" exchange runs 200 to 300 tokens, while a request to reverse a linked list in Python is "generating more than 2,000 tokens easy," which he called "roughly a 10x cost multiplier per session." The same CIO.com piece by Evan Schuman (April 9, 2026) put it bluntly: "Even if 5-8% of chatbot traffic consists of off-purpose or high complexity queries, that slice can consume a quarter or more of total inference spend." [8]

WatchHow Do Skincare Brands Use AI to Build Personalized Skincare Routines?The conversation your skincare assistant was built for: building a personalized routine for a real shopper, not writing a cover letter for a script. More on how this works in our post on the AI skincare routine builder.

3. The gray zone: scrapers and competitive intel

Between those two sit agents that are neither buying nor freeloading: price monitors, catalog scrapers and competitors' tools pulling your policy language. They ask legitimate-looking product questions at machine speed. Akamai's report notes that the same capabilities that power shopping assistants also power catalog scraping and price monitoring. [2] These visitors call for rate limits and data-exposure decisions, not structured product answers.

Human shopper Buyer-agent Freeloader Gray-zone scraper
IntentBuy for selfResearch or buy for a real personFree compute for unrelated workCollect your data at scale
Typical signalsHuman pacing, browsing context, cart activityAgentic browser fingerprints, signed requests (e.g., Web Bot Auth), crisp spec-style questionsOff-domain prompts (code, essays), long outputs, high volume from few sourcesHigh-frequency, repetitive product/price queries, no cart activity
How to respondFull conversational experienceShort, structured, grounded facts; clear links to PDP and policiesPolite deflection, no long generation, throttleRate-limit, cap detail, monitor
Who should payYou (it's a sale opportunity)You, as with any sales conversationNobody: zero cost to the merchantNobody: zero cost, contained at the edge
Part four:

Who pays for freeloader conversations? A simple cost model

Here is where finance leaders should pay attention. The point is not that tokens are expensive. They're cheap. The point is that most AI support pricing charges you the same for a freeloader as for a customer.

Illustrative assumptions (not Alhena data, not market averages)

  • A store runs 20,000 AI widget conversations a month.
  • The vendor charges $1.00 per conversation. That's a round number in the range of published per-conversation and per-outcome prices, such as Intercom Fin's $0.99 per outcome (a resolution, handoff or disqualification, charged at most once per conversation).
  • A freeloader conversation uses about 10x the tokens of a normal one, matching the 200–300 vs. 2,000+ token estimate cited by CIO.com. [8]
Automated/freeloader share Freeloader conversations per month Billed cost per month at $1.00 Annualized Share of total tokens consumed
5%1,000$1,000$12,000~34%
10%2,000$2,000$24,000~53%
20%4,000$4,000$48,000~71%

(Token share = freeloader share × 10 ÷ (human share + freeloader share × 10). At 5%, that's 50 ÷ 145 ≈ 34%, which matches the "quarter or more" range from CIO.com's sources.)

Two things stand out.

First, the bill is out of proportion to the compute. Even a long freeloader exchange with a few thousand tokens of retrieval context costs about a cent in raw inference at current small-model API prices (for example, OpenAI lists GPT-5.4 mini at $0.75 per million input tokens and $4.50 per million output tokens). Under a $1.00 per-conversation price, you pay something like 50 to 100 times the underlying cost for a conversation that produced nothing for your business.

Second, per-resolution pricing does not protect you. A freeloader who gets a working code snippet and leaves looks, to many resolution counters, exactly like a satisfied customer: one question, one answer, no escalation. The better your bot is at being "helpful," the more resolutions you are billed for.

So the policy question for vendors is not "can you detect bots?" It is "what does my invoice say when you do?"

Part five:

How to build a machine visitor policy in five steps

Step 1: Identify

Start at the edge. Your CDN or bot vendor already scores traffic, and cryptographic identity is arriving. Cloudflare's signed agents program, announced on August 28, 2025 in its post "The age of agents: cryptographically recognizing agent traffic," uses Web Bot Auth, built on the IETF's HTTP Message Signatures standard (RFC 9421), so agents like ChatGPT agent and Browserbase can prove who they are rather than relying on a spoofable user-agent string. [9] Pass those signals through to your chat layer. For the governance side of who decides what gets in, see our guide on who owns your AI agent access policy.

Step 2: Classify inside the conversation

Edge signals miss a lot, because a freeloader using a real browser looks human until it types. You need intent classification on every message: is this a product question you can answer, small talk, a request for a human, or an attempt to use the bot for something it isn't for? This is the job of how Alhena's GuardrailAgent classifies every message.

Step 3: Respond by visitor type

  • Buyer-agents: answer in short, factual, structured form, with specs, availability, price, shipping and return terms, plus links to the canonical page. Every fact should come from your catalog and policies, because agents repeat what you tell them. Grounded, retrieval-based answers matter more here than with any human.
  • Freeloaders: decline briefly, generate nothing long, and never let an off-domain request reach your most expensive model.
  • Gray zone: rate-limit at the session and source level, and decide deliberately how much catalog detail a high-frequency unknown agent gets.

The routing and verification details for agents contacting support, including order lookups and returns, are covered in our playbook on preparing your support stack for agentic traffic.

WatchHow to Test and Validate AI Agent Guidelines in Alhena AIA response policy only works if you can check it. This walkthrough shows how to test and validate AI agent guidelines in Alhena before they reach shoppers.

Step 4: Measure machine traffic as its own segment

Report automated sessions separately from human ones: volume, classification mix, tokens consumed and what they would have cost. If your vendor can't show you this split, you can't tell whether your "AI ROI" is real or inflated by bots.

Step 5: Bill fairly, and put it in the contract

Ask every AI vendor in writing: do you charge for bot-tricking, spam and irrelevant queries? For greetings? For failed answers? Then check a month of logs against the invoice. For the commercial reasoning behind this, read why credit-based pricing aligns vendor incentives and what counts as a meaningful conversation.

Machine visitor policy checklist

  • Bot and agent signals from the CDN/bot vendor are passed to the chat layer
  • Signed agents (Web Bot Auth) are recognized and logged separately
  • Every inbound message is classified by intent before an answer is released
  • Off-domain requests get a short, fixed response with no long generation
  • Buyer-agent answers are structured, grounded and link to canonical pages
  • Per-session and per-source rate limits exist for unknown high-frequency agents
  • Automated sessions are reported as their own segment, with cost-if-billed
  • The AI vendor contract states that bot, spam and off-purpose conversations are not billed
  • The policy has a named owner across CX, ecommerce and finance, reviewed quarterly
Part six:

How Alhena handles machine visitors

Alhena's approach turns the policy above into product defaults.

Every incoming message to Alhena's AI shopping assistant and AI Support Concierge is labeled by a dedicated GuardrailAgent before an answer is released. It sorts messages into six classes, including ANSWER_PRESENT, GENERAL_CONVERSATION and BOT_TRICKING_ATTEMPT, and the classifier runs in parallel with answer generation, so legitimate shoppers see no added latency. When a message is flagged as bot-tricking or out-of-domain abuse, the buffered answer is thrown away and the visitor gets the same neutral reply as a genuine knowledge gap, so a script learns nothing it can tune against.

The billing side follows the same logic. Under Alhena's published rules, spam, irrelevant queries and bot-tricking attempts cost zero credits, as do greetings, failed AI responses and human handoffs. The full list is in the nine interactions Alhena never charges for, and the rate card is on Alhena pricing. In practice, a freeloader conversation that would cost $1 or more elsewhere costs an Alhena merchant nothing. A buyer-agent asking a real product question gets a grounded answer and counts like any other meaningful sales conversation, which is where you want your budget going.

WatchHow Does AI Clienteling Work for Luxury Brands?Where your credits should go: Alhena working as an AI clienteling advisor for a luxury brand. See also six AI concierge workflows for luxury brands.

Because classification and billing come from the same system, the split between machine and human conversations shows up where finance will see it: on the invoice. As agent-to-agent commerce matures, that split becomes a line on your P&L, not a security footnote.

Frequently asked questions

What is a machine visitor policy?

A machine visitor policy is a store's documented rules for identifying, answering, measuring and billing conversations that software starts on its on-site AI. It separates buyer-agents acting for real shoppers from freeloaders and scrapers, and it sets a different response and cost treatment for each.

What is AI token freeloading?

AI token freeloading is Akamai's term, from its July 2026 commerce security report, for using scripts and bot networks to send outside workloads through a retailer's public-facing AI endpoints. The retailer pays for the inference, and performance can suffer for real customers.

What are freeloader conversations?

Freeloader conversations are chat sessions where a visitor uses a shopping or support assistant as a free general-purpose LLM, for example to write code or essays, with no buying intent. They often use far more tokens than normal support exchanges.

Should I block AI agents from my chat widget?

No, not across the board. Adobe found AI-referred retail visits converted 42% better than non-AI traffic in March 2026, so blocking every agent shuts out high-intent buyers. Identify and classify agents instead, answer buyer-agents with structured facts, and throttle or deflect freeloaders.

How do I tell a buyer-agent from a freeloader?

Combine edge signals with conversation intent. Buyer-agents often come from known agentic browsers or signed agents and ask focused product, price or policy questions. Freeloaders ask off-domain questions such as code, essays or translations, request long outputs, and tend to arrive in volume from few sources.

How much do bot conversations cost on per-resolution AI pricing?

Usually the same as a real customer conversation, because many resolution counters can't tell a satisfied shopper from a script that got its answer and left. At about $1 per conversation, 2,000 bot sessions a month adds about $24,000 a year, even though the raw inference cost is a few cents per session.

Does Alhena charge for bot traffic?

No. According to Alhena's published billing rules, spam, irrelevant queries and bot-tricking attempts consume zero credits, as do greetings, failed AI responses and human handoffs. Alhena's GuardrailAgent classifies each message before billing, so only meaningful conversations draw down credits.

How should my AI answer AI shopping agents?

Give short, factual, structured answers grounded in your catalog and policies: specs, price, availability, shipping and return terms, with a link to the canonical page. Agents pass your answers straight to shoppers, so accuracy and clarity matter more than conversational style.

The bottom line

Machine visitors are already a large and fast-growing part of ecommerce traffic, and your on-site AI is one of the places they stop. Some of them are bringing you customers. Some are spending your budget on their own work. Without a policy, you pay both the same. Write the policy, measure the machine segment, and make sure your AI vendor's invoice tells the difference.

Stop Paying for Freeloader Conversations

Alhena's GuardrailAgent classifies every message, and spam, irrelevant queries and bot-tricking attempts cost zero credits. Buyer-agents get grounded answers. Freeloaders cost you nothing.

Book a demoSee pricing

Power Up Your Store with Revenue-Driven AI