AI traffic becomes a new e-commerce variable
AI is reshaping e-commerce traffic, and security teams are being forced to move beyond the old question of whether to block crawlers. According to Akamai Greater China senior solutions manager Ma Jun, Akamai’s latest State of the Internet Security report shows that more than 17 trillion bot visits hit e-commerce sites in 2025, up 19% year on year. Asia-Pacific grew by more than 63%, making it the fastest-growing region.
The issue is not simply that bots are increasing. Ma said AI bots are behaving more like humans, with traffic peaking from Monday to Friday and briefly declining on weekends. The report also identified browser impersonation as a major bot technique, with related traffic reaching 750 billion visits.
Key figures include:
- More than 17 trillion e-commerce bot visits in 2025, up 19%;
- Over 63% bot growth in Asia-Pacific, linked to e-commerce scale, AI adoption and fragmented travel markets;
- 84% of Layer 7 DDoS attacks targeted e-commerce. A Layer 7 DDoS attack aims at the application layer, using large volumes of seemingly legitimate requests to disrupt services.
The good-bot/bad-bot model is no longer enough
Ma grouped current AI bots into four broad types: training bots, AI fetchers, AI search engines and AI agents. Training bots collect data to improve models. AI fetchers retrieve online information when users ask questions. AI search engines continuously crawl content to update indexes. AI agents go further by acting on behalf of users.
This changes the business meaning of crawler traffic. The same AI system may help a shopper find a product and complete a purchase, or it may repeatedly collect prices, inventory and product data without generating any transaction. For a retailer, one case creates business value; the other mainly creates cost.
That is why a binary allow-or-block model is becoming less useful. E-commerce platforms need policies based on identity, behavior and business impact. Trusted and useful AI traffic may be allowed, while unknown, abnormal or purely extractive traffic may need rate limiting, degradation or blocking. Bot management is shifting from a black-and-white decision to a spectrum of trust.
APIs move to the center of the attack surface
AI agents naturally interact with external systems through APIs. As companies open services and connect with partners, they also expose more API endpoints. An API is an interface that lets applications exchange data or invoke functions; weak authorization, excessive data exposure or poor validation can turn it into an attack path.
Ma cited data showing that in the fourth quarter of 2025, API attacks surpassed traditional web attacks overall for the first time. In Asia-Pacific, web attacks against e-commerce exceeded 200 billion, and 49% of them were API attacks.
Visibility remains a major gap. Akamai’s earlier survey found that 77.7% of CISOs said their organizations had created API inventories through technical or manual methods. But only about 22% could clearly answer which APIs contained sensitive data or which had authorization-bypass risks.
AI can make that gap more dangerous. Attackers can use AI to discover shadow APIs, meaning interfaces that the enterprise itself may not fully know or govern. In Ma’s view, API security in the AI era starts with visibility: companies need to know what APIs they have, what data they connect to, whether they involve loyalty points, member accounts or gifts, and whether they are exposed to leakage, injection or broken authorization.
New risks: chatbots, agents and tokens
As AI becomes part of e-commerce workflows, the attack surface expands to chatbots, agents and compute resources. Akamai uses the term Leak Faucet for a slow, low-volume and persistent distributed attack. Attackers may repeatedly interact with chatbots and use prompt injection to induce unwanted behavior, such as accepting refunds without returns, honoring expired coupons or exposing customer privacy. Prompt injection means crafting inputs that manipulate a model into ignoring its intended rules.
Agents create another class of risk. If consumers use agents for shopping, comparison and checkout, attackers may try jailbreaks or malicious prompts to make those agents access databases, call APIs or take unauthorized actions.
Token abuse is also a concern. When companies integrate model APIs into business systems, exposed interfaces or tokens can be stolen and used to consume the company’s computing resources. As a result, security objects now include not only servers, web pages and APIs, but also models, agents, MCP components and tokens.
Ma also mentioned efforts around identity verification for AI bots and agents, including Akamai’s work with ecosystem partners and Visa’s TAP, or Trusted Agent Protocol, as well as KYA-related mechanisms. The idea is to verify the agent first, then decide what it is allowed to do in a specific business scenario.
Security must return to business judgment
AI is also shortening the time between vulnerability discovery and exploitation. Ma cited Akamai data saying the median time from discovery to exploitation was more than two years in 2018, but has now fallen to 8 hours with AI assistance. This makes rapid discovery, judgment and response as important as blocking.
Akamai’s 18-month recommendations include improving asset and risk visibility, strengthening resilience through microsegmentation, multi-factor authentication, incident plans and communication mechanisms, and quantitatively analyzing the business impact of AI and AI bots. Microsegmentation divides systems into smaller security zones to reduce the blast radius when something goes wrong.
For e-commerce, false blocking is especially costly. During major promotion periods, legitimate traffic, attack traffic and AI traffic may surge at the same time. Overly aggressive rules can hurt performance, availability and conversion. The next phase of e-commerce security will not be about keeping all AI outside. It will be about knowing which AI represents real users, which APIs touch critical assets, and which agents can be trusted. The center of gravity is moving from perimeter defense to identity verification, behavioral judgment and business-aware decisions.




