Experian said on Thursday, October 1, 2026 that DataDome has joined its Agent Trust ecosystem, attaching a system that evaluates what an AI agent does during a visit to a framework built to establish which verified person the agent represents. The release, issued from Costa Mesa, California, named no price, no availability date, no launch customer and no technical specification for the combined service.

In Short

Experian, a company that checks people's identities for banks and shops, has added a firm called DataDome to its group of partners that vet AI shopping assistants. Experian confirms which real person an assistant is working for, while DataDome watches what that assistant actually does on a website, so that one which has been hijacked or starts doing things it was never authorized to do can be spotted. If you run an online shop, the stated aim is that a genuine assistant buying for a real customer gets through without extra hurdles, while a fake or rogue one is stopped during the visit.

Who answers which question

The division of labor sits in the release's highlights. Experian's Human to Agent Binding connects a verified consumer, that consumer's device and the AI agent acting for them, establishing identity and what the companies call delegated authority. DataDome then assesses, according to Experian, whether the agent's actions align with legitimate business intent, letting trusted interactions continue while identifying behavior that may signal abuse. The companies label that second layer continuous intent verification.

Experian frames three questions behind the arrangement: who an AI agent represents, whether its behavior remains consistent with the authority it was given, and whether a business can make a trust decision at every step of an interaction. Identity binding answers the first. The other two are where DataDome comes in.

"Agentic commerce has the potential to reshape digital business, but it will only succeed if organizations can trust the AI agents acting on behalf of consumers," said Kathleen Peters, Chief Innovation Officer at Experian. "DataDome strengthens that ecosystem by adding continuous intent verification alongside Experian's trusted identity foundation, giving organizations greater confidence in every trust decision."

DataDome's account of the split was similar. "Experian's Human to Agent Binding establishes the trusted link between a verified consumer and the AI agent acting on their behalf. DataDome builds on that foundation by continuously assessing the agent's behavior and intent throughout the customer journey," said Aurelie Guerrieri, DataDome's Chief Marketing & Alliances Officer. The aim, she added, is to let trusted agents "transact without friction while stopping malicious or compromised agents in real time."

How the integration is described

DataDome integrates directly with Experian's framework, according to the release, using verified Know Your Agentsignals to inform its evaluation of each session. Experian adopted that label when it put Agent Trust into the market on April 30, 2026, presenting it as an extension of the know-your-customer obligations that already govern financial compliance. The October release states that organizations can strengthen trust within existing transaction flows without changing checkout experiences, adding operational complexity or re-architecting their technology stacks.

The operative word is continuous. DataDome evaluates agent behavior throughout each session and updates trust signals as activity evolves, according to Experian. A credential presented when a request arrives establishes who sent it. A session-long assessment asks something different: whether the sequence of requests that follows matches what was authorized. An agent bound to a verified shopper is not, by that binding alone, protected against being compromised mid-session, and it is that gap the two companies say they are closing.

The figures DataDome supplies

DataDome's company description carries the scale claims. Its multi-layered engine draws on thousands of models and 5 trillion signals a day to analyze the intent of every session in under 2 milliseconds, according to the company, protecting sites, apps, APIs and MCP servers. It says it stops more than 20,000 attacks every second, a rate equivalent to more than 1.7 billion a day. Named customers include Etsy, PayPal and SoundCloud.

None of those figures is audited in the release, which also leaves undefined what counts as a signal or as an attack. DataDome's own September research separately distinguished detected attempts from successful attacks, a distinction the boilerplate does not draw.

Two of the named customers sit close to the agent-facing side of retail. Etsy was among the five companies that co-developed Google's Universal Commerce Protocol, and PayPal agreed with Microsoft on January 8, 2026 to enable purchases inside Copilot. The release does not say whether any of the three will use the Experian integration.

Two names for one ranking

The release cites Forrester twice and names the evaluation two ways. The body text refers to The Forrester Wave for Bot & Agent Trust Management (Q2 2026); DataDome's boilerplate calls it The Forrester Wave: Bot and Agent Trust Management Software, Q2 2026. The body describes DataDome as a leader in bot and agent trust management, while the boilerplate calls it the leader. The release does not say how many vendors Forrester placed in its Leader category. HUMAN Security cited the same designation for the Q3 2024 edition, which was then titled Bot Management Software - so the addition of agents to the category's name is itself a measure of how quickly the market has moved.

What the release leaves out

Beyond the absence of pricing, dates and customers, the October text is silent on the mechanics that would let a merchant evaluate it.

It does not identify which Know Your Agent signals DataDome receives. The April design described two components by name: an Agent Trust Token issued in real time to validate identity and transaction fraud risk, and an Agent Registryholding a dynamic trust score for each registered agent. Neither appears in the October release. Whether DataDome reads a token, a registry score, a confirmation of binding or something else is not stated.

Nor does it describe the direction of the data flow. Experian's signals inform DataDome's evaluation, according to the release. Whether DataDome's session findings travel back to Experian is left open, and the question matters because the registry already claimed a behavioral role in April: an agent drifting from the patterns associated with its registered human could, under that design, see its score fall before a transaction completed. Is a session verdict from DataDome a new input to that score, or a separate decision taken on the merchant's side? The release does not say.

Two broader claims also sit without support. The highlights state that Agent Trust "now spans the full transaction lifecycle," and the opening paragraph describes the ecosystem as "the industry's open framework for trusted agentic commerce." The release points to no published specification, and, as the sections below show, several competing frameworks claim parts of the same territory.

Intent was already on the list

DataDome is not the first ecosystem member to claim intent. When Fastly joined on July 24, 2026, Experian said the edge provider would let organizations evaluate four properties of an inbound request before it reached origin servers: agent identity, delegated authority, intent and payment credentials. Cloudflare, one of three partners at the April launch alongside Visa and Skyfire, was described then as enforcing the trust layer at the edge of its network.

The October release mentions neither company. It does not explain how an intent judgment formed at the edge relates to one formed inside the session, or which takes precedence if the two disagree.

Placement offers part of an answer. DataDome's September report stated that roughly 60 percent of its customers operate behind a content delivery network with basic bot filtering switched on, with DataDome positioned downstream of that layer. Read together, the April, July and October announcements describe a sequence - identity bound by Experian, requests filtered at the edge, behavior evaluated after the request lands - without any of them setting it out in full. Experian itself said in April that its verification covered the agent, the person behind it and that person's intent to purchase. With Fastly in July and DataDome in October, three members of one ecosystem now describe themselves as assessing some part of what an agent intends.

The login page problem

DataDome's interest in the question is documented in its own data. The company's State of Bot & Agent Security Report 2026, published on September 22, 2026, drew on traffic from more than 75,000 customer sites between July 2025 and June 2026 and counted 52.7 billion AI agent and crawler requests over that period. In the first half of 2026, 605.6 million AI requests reached what the company calls high-risk endpoints: logins, forms, carts, payment flows and account creation. Login pages took 313.0 million of them. Monthly AI requests to login pages climbed from 11.9 million in January to 99.7 million in June.

That report argued that the endpoint alone cannot settle intent. A legitimate agent may sign in to retrieve an order or check a loyalty balance; an attacker uses the same page for credential testing and account takeover reconnaissance. Identity binding addresses one side of that ambiguity. Impersonation is the other. DataDome measured a 45 percent rise between February and July 2026 in traffic claiming a known agent's identity without being that agent.

Earlier DataDome research pointed the same way. In December 2025 one of its researchers asked Grok to fetch a single webpage and recorded 16 requests from 12 IP addresses, none of them identifying itself as an xAI or Grok agent. A March 2026 study co-produced with Retail Economics, AWS and Botify found that 79.7 percent of 698,214 live websites failed to block or challenge a spoofed ChatGPT user agent.

These are vendor figures, with the limits that implies. The September report contained two different first-half AI traffic totals, 29.65 billion and 29.02 billion requests, and its customer data describes sites that already pay to filter automated traffic. Its external benchmark was blunter. Of 21,491 heavily visited domains tested in June 2026, 65.3 percent stopped none of DataDome's 10 test bots, and 2.4 percent stopped all of them.

A crowded verification layer

Experian may describe Agent Trust as the industry's framework, but it is one of several competing for the same transaction. Cloudflare began working with Visa and Mastercard on October 24, 2025 on Visa's Trusted Agent Protocol and Mastercard's Agent Pay, both built on Web Bot Auth, a scheme in which an automated client signs its requests with a private key so a site can verify the sender rather than trust a self-declared user agent string. Cloudflare then published a registry format for discovering those keys at scale.

Payment networks went further. Mastercard and Google presented Verifiable Intent on March 5, 2026, a cryptographic record of what a user authorized an agent to do, backed at the outset by IBM, Adyen, Fiserv and others. On April 28, 2026, two days before Experian's own launch, the FIDO Alliance formed working groups on agentic authentication and payments, taking Google's Agent Payments Protocol and Mastercard's framework as starting points. HUMAN Security, which sells bot defense in the same category as DataDome, has offered AgenticTrust, which it describes as cryptographic verification of ChatGPT agent activity, since 2025.

Across these schemes the word intent carries at least two meanings. In Verifiable Intent it refers to a record of what the user authorized, fixed at the moment of authorization. In DataDome's usage it is an inference drawn from behavior while a session runs. The October release relies on the second meaning and does not say whether a Verifiable Intent record or a Trusted Agent Protocol signature would count among the signals DataDome reads.

The legal backdrop has shifted as well. On August 4, 2026, the Ninth Circuit vacated the injunction that had kept Perplexity's Comet browser out of Amazon accounts, treating the user rather than the agent's maker as the party accessing a site when the agent runs on the user's own machine. That removed one legal route merchants had relied on to keep third-party agents off their pages, and left technical controls carrying more of the load.

Five months, seven announcements

The DataDome agreement is the latest in a dense run. After the April 30 start with Visa, Cloudflare and Skyfire, Experian connected its Ascend Platform to the ServiceNow AI Platform on May 15, brought in Fastly on July 24 and paired with AUDIENCES on first-party data activation on July 30. In August it moved into OpenAI's assistant twice: authenticated credit score access for UK ChatGPT users on August 20, then a credit cards app inside ChatGPT on August 27.

Experian describes itself as a FTSE 100 company listed on the London Stock Exchange under EXPN, with 25,200 people across 33 countries and corporate headquarters in Dublin. The October release again cites an estimate that its identity verification and fraud prevention tools help clients prevent $15 billion to $19 billion in fraud losses each year - the same range used in April and in the Fastly announcement. It is Experian's own figure and comes without methodology.

Why this matters for the marketing community

Only about 2.1 percent of the AI requests DataDome analyzed by endpoint in the first half of 2026 reached high-risk pages, yet those are the pages where agentic AI meets revenue and measurement. Forms are lead capture, and DataDome counted 198.9 million AI requests to forms on customer sites over those six months. Bots that complete forms or fire events become invalid traffic in campaign reporting, if they are caught at all. DoubleVerify reported on July 29, 2026 that AI bots generated up to 10 times more clicks than humans in some unprotected campaigns. Cart pages are where retargeting pools are built, and agencies have described those pools filling with non-human visitors as CPMs climbed 20 percent.

The harder problem is classification rather than volume. HUMAN Security's April benchmark put agentic traffic growth at 7,851 percent in 2025 and found only a narrow margin separating benign automation from malicious activity, with patterns once treated as attack signatures - rapid navigation, programmatic form completion, automated checkout - now consistent with legitimate agent workflows. A system that ties an agent to a verified person and then follows its behavior through the session could, in principle, separate an authorized agent's checkout from scripted abuse.

Whether that separation reaches marketing systems is another matter. The release does not say whether DataDome's classifications leave the security stack - into analytics tools, ad platforms or conversion APIs - or whether an order completed by a bound agent is labelled as such downstream. Without that, an agent-placed purchase looks like any other in closed-loop retail media measurement, and an agent-completed lead form looks like any other lead.

The commercial dilemma DataDome set out in September remains. Blocking all AI traffic forfeits sales from legitimate agents; admitting all of it invites fraud and abuse. The Experian arrangement offers a third position: admit agents bound to verified people, then keep evaluating them. How many merchants adopt it will depend on terms neither company has published, and on whether shoppers delegate purchases to agents in meaningful numbers at all - a question analysts were already raising in October 2025 and which a year of infrastructure building has not yet settled.

Timeline

Summary

Who: Experian, the FTSE 100 data and technology company listed in London under EXPN with 25,200 people in 33 countries, and DataDome, a bot and agent trust management vendor whose named customers include Etsy, PayPal and SoundCloud. Kathleen Peters, Chief Innovation Officer at Experian, and Aurelie Guerrieri, DataDome's Chief Marketing & Alliances Officer, are the named spokespeople. Merchants, payment providers and the marketing teams whose measurement depends on separating human, bot and agent activity are affected.

What: DataDome has joined the Experian Agent Trust ecosystem. Experian's Human to Agent Binding links verified consumers, devices and AI agents; DataDome adds continuous intent verification, using Know Your Agent signals to evaluate whether an agent's behavior stays consistent with its delegated authority throughout each session. The release gives no pricing, availability date, launch customer or technical specification, names the Forrester evaluation it cites in two different ways, and does not say how DataDome's role relates to the intent evaluation Fastly took on in July or to Experian's own Agent Registry.

When: Experian issued the release on Thursday, October 1, 2026, five months after opening Agent Trust on April 30, 2026 and ten weeks after Fastly joined on July 24, 2026.

Where: The release was issued from Costa Mesa, California. Experian is headquartered in Dublin. No geographic limit on the integration was stated.

Why: AI agents increasingly reach login pages, forms, carts and payment flows, where a verified identity does not by itself show whether an agent is acting within what it was authorized to do or has been compromised. DataDome's own data recorded AI requests to login pages rising from 11.9 million in January 2026 to 99.7 million in June, and impersonation of known agents rising 45 percent between February and July. For marketers, the same traffic feeds lead forms, retargeting pools and invalid traffic filters, while a crowded field of identity schemes - from Web Bot Auth to Verifiable Intent - competes to define which agent signals a merchant trusts.