Experian said on Thursday, October 1, 2026 that DataDome has joined its Agent Trust ecosystem, attaching a system that evaluates what an AI agent does during a visit to a framework built to establish which verified person the agent represents. The release, issued from Costa Mesa, California, named no price, no availability date, no launch customer and no technical specification for the combined service.
In Short
Experian, a company that checks people's identities for banks and shops, has added a firm called DataDome to its group of partners that vet AI shopping assistants. Experian confirms which real person an assistant is working for, while DataDome watches what that assistant actually does on a website, so that one which has been hijacked or starts doing things it was never authorized to do can be spotted. If you run an online shop, the stated aim is that a genuine assistant buying for a real customer gets through without extra hurdles, while a fake or rogue one is stopped during the visit.
Who answers which question
The division of labor sits in the release's highlights. Experian's Human to Agent Binding connects a verified consumer, that consumer's device and the AI agent acting for them, establishing identity and what the companies call delegated authority. DataDome then assesses, according to Experian, whether the agent's actions align with legitimate business intent, letting trusted interactions continue while identifying behavior that may signal abuse. The companies label that second layer continuous intent verification.
Experian frames three questions behind the arrangement: who an AI agent represents, whether its behavior remains consistent with the authority it was given, and whether a business can make a trust decision at every step of an interaction. Identity binding answers the first. The other two are where DataDome comes in.
"Agentic commerce has the potential to reshape digital business, but it will only succeed if organizations can trust the AI agents acting on behalf of consumers," said Kathleen Peters, Chief Innovation Officer at Experian. "DataDome strengthens that ecosystem by adding continuous intent verification alongside Experian's trusted identity foundation, giving organizations greater confidence in every trust decision."
DataDome's account of the split was similar. "Experian's Human to Agent Binding establishes the trusted link between a verified consumer and the AI agent acting on their behalf. DataDome builds on that foundation by continuously assessing the agent's behavior and intent throughout the customer journey," said Aurelie Guerrieri, DataDome's Chief Marketing & Alliances Officer. The aim, she added, is to let trusted agents "transact without friction while stopping malicious or compromised agents in real time."
How the integration is described
DataDome integrates directly with Experian's framework, according to the release, using verified Know Your Agentsignals to inform its evaluation of each session. Experian adopted that label when it put Agent Trust into the market on April 30, 2026, presenting it as an extension of the know-your-customer obligations that already govern financial compliance. The October release states that organizations can strengthen trust within existing transaction flows without changing checkout experiences, adding operational complexity or re-architecting their technology stacks.
The operative word is continuous. DataDome evaluates agent behavior throughout each session and updates trust signals as activity evolves, according to Experian. A credential presented when a request arrives establishes who sent it. A session-long assessment asks something different: whether the sequence of requests that follows matches what was authorized. An agent bound to a verified shopper is not, by that binding alone, protected against being compromised mid-session, and it is that gap the two companies say they are closing.
The figures DataDome supplies
DataDome's company description carries the scale claims. Its multi-layered engine draws on thousands of models and 5 trillion signals a day to analyze the intent of every session in under 2 milliseconds, according to the company, protecting sites, apps, APIs and MCP servers. It says it stops more than 20,000 attacks every second, a rate equivalent to more than 1.7 billion a day. Named customers include Etsy, PayPal and SoundCloud.
None of those figures is audited in the release, which also leaves undefined what counts as a signal or as an attack. DataDome's own September research separately distinguished detected attempts from successful attacks, a distinction the boilerplate does not draw.
Two of the named customers sit close to the agent-facing side of retail. Etsy was among the five companies that co-developed Google's Universal Commerce Protocol, and PayPal agreed with Microsoft on January 8, 2026 to enable purchases inside Copilot. The release does not say whether any of the three will use the Experian integration.
Two names for one ranking
The release cites Forrester twice and names the evaluation two ways. The body text refers to The Forrester Wave for Bot & Agent Trust Management (Q2 2026); DataDome's boilerplate calls it The Forrester Wave: Bot and Agent Trust Management Software, Q2 2026. The body describes DataDome as a leader in bot and agent trust management, while the boilerplate calls it the leader. The release does not say how many vendors Forrester placed in its Leader category. HUMAN Security cited the same designation for the Q3 2024 edition, which was then titled Bot Management Software - so the addition of agents to the category's name is itself a measure of how quickly the market has moved.
What the release leaves out
Beyond the absence of pricing, dates and customers, the October text is silent on the mechanics that would let a merchant evaluate it.
It does not identify which Know Your Agent signals DataDome receives. The April design described two components by name: an Agent Trust Token issued in real time to validate identity and transaction fraud risk, and an Agent Registryholding a dynamic trust score for each registered agent. Neither appears in the October release. Whether DataDome reads a token, a registry score, a confirmation of binding or something else is not stated.
Nor does it describe the direction of the data flow. Experian's signals inform DataDome's evaluation, according to the release. Whether DataDome's session findings travel back to Experian is left open, and the question matters because the registry already claimed a behavioral role in April: an agent drifting from the patterns associated with its registered human could, under that design, see its score fall before a transaction completed. Is a session verdict from DataDome a new input to that score, or a separate decision taken on the merchant's side? The release does not say.
Two broader claims also sit without support. The highlights state that Agent Trust "now spans the full transaction lifecycle," and the opening paragraph describes the ecosystem as "the industry's open framework for trusted agentic commerce." The release points to no published specification, and, as the sections below show, several competing frameworks claim parts of the same territory.
Intent was already on the list
DataDome is not the first ecosystem member to claim intent. When Fastly joined on July 24, 2026, Experian said the edge provider would let organizations evaluate four properties of an inbound request before it reached origin servers: agent identity, delegated authority, intent and payment credentials. Cloudflare, one of three partners at the April launch alongside Visa and Skyfire, was described then as enforcing the trust layer at the edge of its network.
The October release mentions neither company. It does not explain how an intent judgment formed at the edge relates to one formed inside the session, or which takes precedence if the two disagree.
Placement offers part of an answer. DataDome's September report stated that roughly 60 percent of its customers operate behind a content delivery network with basic bot filtering switched on, with DataDome positioned downstream of that layer. Read together, the April, July and October announcements describe a sequence - identity bound by Experian, requests filtered at the edge, behavior evaluated after the request lands - without any of them setting it out in full. Experian itself said in April that its verification covered the agent, the person behind it and that person's intent to purchase. With Fastly in July and DataDome in October, three members of one ecosystem now describe themselves as assessing some part of what an agent intends.
The login page problem
DataDome's interest in the question is documented in its own data. The company's State of Bot & Agent Security Report 2026, published on September 22, 2026, drew on traffic from more than 75,000 customer sites between July 2025 and June 2026 and counted 52.7 billion AI agent and crawler requests over that period. In the first half of 2026, 605.6 million AI requests reached what the company calls high-risk endpoints: logins, forms, carts, payment flows and account creation. Login pages took 313.0 million of them. Monthly AI requests to login pages climbed from 11.9 million in January to 99.7 million in June.
That report argued that the endpoint alone cannot settle intent. A legitimate agent may sign in to retrieve an order or check a loyalty balance; an attacker uses the same page for credential testing and account takeover reconnaissance. Identity binding addresses one side of that ambiguity. Impersonation is the other. DataDome measured a 45 percent rise between February and July 2026 in traffic claiming a known agent's identity without being that agent.
Earlier DataDome research pointed the same way. In December 2025 one of its researchers asked Grok to fetch a single webpage and recorded 16 requests from 12 IP addresses, none of them identifying itself as an xAI or Grok agent. A March 2026 study co-produced with Retail Economics, AWS and Botify found that 79.7 percent of 698,214 live websites failed to block or challenge a spoofed ChatGPT user agent.
These are vendor figures, with the limits that implies. The September report contained two different first-half AI traffic totals, 29.65 billion and 29.02 billion requests, and its customer data describes sites that already pay to filter automated traffic. Its external benchmark was blunter. Of 21,491 heavily visited domains tested in June 2026, 65.3 percent stopped none of DataDome's 10 test bots, and 2.4 percent stopped all of them.
A crowded verification layer
Experian may describe Agent Trust as the industry's framework, but it is one of several competing for the same transaction. Cloudflare began working with Visa and Mastercard on October 24, 2025 on Visa's Trusted Agent Protocol and Mastercard's Agent Pay, both built on Web Bot Auth, a scheme in which an automated client signs its requests with a private key so a site can verify the sender rather than trust a self-declared user agent string. Cloudflare then published a registry format for discovering those keys at scale.
Payment networks went further. Mastercard and Google presented Verifiable Intent on March 5, 2026, a cryptographic record of what a user authorized an agent to do, backed at the outset by IBM, Adyen, Fiserv and others. On April 28, 2026, two days before Experian's own launch, the FIDO Alliance formed working groups on agentic authentication and payments, taking Google's Agent Payments Protocol and Mastercard's framework as starting points. HUMAN Security, which sells bot defense in the same category as DataDome, has offered AgenticTrust, which it describes as cryptographic verification of ChatGPT agent activity, since 2025.
Across these schemes the word intent carries at least two meanings. In Verifiable Intent it refers to a record of what the user authorized, fixed at the moment of authorization. In DataDome's usage it is an inference drawn from behavior while a session runs. The October release relies on the second meaning and does not say whether a Verifiable Intent record or a Trusted Agent Protocol signature would count among the signals DataDome reads.
The legal backdrop has shifted as well. On August 4, 2026, the Ninth Circuit vacated the injunction that had kept Perplexity's Comet browser out of Amazon accounts, treating the user rather than the agent's maker as the party accessing a site when the agent runs on the user's own machine. That removed one legal route merchants had relied on to keep third-party agents off their pages, and left technical controls carrying more of the load.
Five months, seven announcements
The DataDome agreement is the latest in a dense run. After the April 30 start with Visa, Cloudflare and Skyfire, Experian connected its Ascend Platform to the ServiceNow AI Platform on May 15, brought in Fastly on July 24 and paired with AUDIENCES on first-party data activation on July 30. In August it moved into OpenAI's assistant twice: authenticated credit score access for UK ChatGPT users on August 20, then a credit cards app inside ChatGPT on August 27.
Experian describes itself as a FTSE 100 company listed on the London Stock Exchange under EXPN, with 25,200 people across 33 countries and corporate headquarters in Dublin. The October release again cites an estimate that its identity verification and fraud prevention tools help clients prevent $15 billion to $19 billion in fraud losses each year - the same range used in April and in the Fastly announcement. It is Experian's own figure and comes without methodology.
Why this matters for the marketing community
Only about 2.1 percent of the AI requests DataDome analyzed by endpoint in the first half of 2026 reached high-risk pages, yet those are the pages where agentic AI meets revenue and measurement. Forms are lead capture, and DataDome counted 198.9 million AI requests to forms on customer sites over those six months. Bots that complete forms or fire events become invalid traffic in campaign reporting, if they are caught at all. DoubleVerify reported on July 29, 2026 that AI bots generated up to 10 times more clicks than humans in some unprotected campaigns. Cart pages are where retargeting pools are built, and agencies have described those pools filling with non-human visitors as CPMs climbed 20 percent.
The harder problem is classification rather than volume. HUMAN Security's April benchmark put agentic traffic growth at 7,851 percent in 2025 and found only a narrow margin separating benign automation from malicious activity, with patterns once treated as attack signatures - rapid navigation, programmatic form completion, automated checkout - now consistent with legitimate agent workflows. A system that ties an agent to a verified person and then follows its behavior through the session could, in principle, separate an authorized agent's checkout from scripted abuse.
Whether that separation reaches marketing systems is another matter. The release does not say whether DataDome's classifications leave the security stack - into analytics tools, ad platforms or conversion APIs - or whether an order completed by a bound agent is labelled as such downstream. Without that, an agent-placed purchase looks like any other in closed-loop retail media measurement, and an agent-completed lead form looks like any other lead.
The commercial dilemma DataDome set out in September remains. Blocking all AI traffic forfeits sales from legitimate agents; admitting all of it invites fraud and abuse. The Experian arrangement offers a third position: admit agents bound to verified people, then keep evaluating them. How many merchants adopt it will depend on terms neither company has published, and on whether shoppers delegate purchases to agents in meaningful numbers at all - a question analysts were already raising in October 2025 and which a year of infrastructure building has not yet settled.
Timeline
- Q3 2024 - HUMAN Security cites a Leader placement in The Forrester Wave: Bot Management Software
- 2025 - HUMAN Security offers AgenticTrust for cryptographic verification of ChatGPT agent activity
- October 2025 - Analysts question the commercial viability of AI shopping agents
- October 24, 2025 - Cloudflare, Visa and Mastercard begin work on Trusted Agent Protocol and Agent Pay, built on Web Bot Auth
- October 30, 2025 - Cloudflare publishes a registry format for bot and agent authentication
- December 11, 2025 - DataDome documents a single Grok request generating 16 requests from 12 IP addresses
- January 8, 2026 - PayPal and Microsoft enable purchases inside Copilot
- March 5, 2026 - Mastercard and Google present Verifiable Intent
- March 7, 2026 - Retail Economics, AWS, Botify and DataDome find 79.7 percent of 698,214 sites fail to challenge a spoofed ChatGPT user agent
- April 9, 2026 - HUMAN Security's benchmark puts 2025 agentic traffic growth at 7,851 percent
- April 28, 2026 - FIDO Alliance forms working groups on agentic authentication and payments
- April 30, 2026 - Experian opens Agent Trust with Visa, Cloudflare and Skyfire as ecosystem partners
- May 15, 2026 - Experian connects its Ascend Platform to the ServiceNow AI Platform
- Q2 2026 - Forrester names DataDome a Leader in its Bot and Agent Trust Management evaluation
- July 24, 2026 - Fastly joins the Agent Trust ecosystem, evaluating agent identity, delegated authority, intent and payment credentials at the edge
- July 29, 2026 - DoubleVerify reports AI bots generating up to 10 times more clicks than humans in some unprotected campaigns
- July 30, 2026 - Experian pairs with AUDIENCES on first-party data activation
- August 4, 2026 - The Ninth Circuit vacates the injunction keeping Perplexity's Comet out of Amazon accounts
- August 20, 2026 - Experian opens authenticated credit score access for UK ChatGPT users
- August 27, 2026 - Experian places a credit cards app inside ChatGPT
- September 2026 - Agencies report retargeting pools filling with non-human visitors as CPMs climb 20 percent
- September 22, 2026 - DataDome publishes its State of Bot & Agent Security Report 2026, counting 99.7 million AI requests to login pages in June
- October 1, 2026 - Experian says DataDome has joined the Agent Trust ecosystem to add continuous intent verification
Related PPC Land coverage
- Experian launches Agent Trust to verify humans behind AI shopping - The April 30, 2026 framework DataDome has joined, including the Agent Trust Token and Agent Registry.
- Fastly gains Experian agent checks as 53% of web traffic turns automated - The July edge integration that already listed intent among the properties evaluated before a request reaches origin.
- Full bot protection drops to 2.4% of popular websites, DataDome finds - DataDome's September report on AI traffic to login pages, spoofing and site defenses.
- Experian and ServiceNow tie up to push agentic AI past the pilot stage - The May integration placing Experian identity decisions inside enterprise workflows.
- Experian puts credit card offers inside ChatGPT through partner lenders - Experian's August move to render card offers inside OpenAI's assistant.
- ChatGPT users in the UK gain their 1250 Experian credit score - The authenticated credit score product that preceded the US card app by a week.
- Experian pairs with AUDIENCES to close 72% activation gap - The July first-party data partnership in the same run of announcements.
- Cloudflare partners with Visa and Mastercard to secure AI agent shopping - The Trusted Agent Protocol and Agent Pay schemes built on signed requests.
- Cloudflare unveils registry format for bot and agent authentication - How signing agents' public keys are discovered and validated at scale.
- Mastercard and Google's new trust layer could reshape how AI buys for you - Verifiable Intent, the payment-side record of what a user authorized an agent to do.
- FIDO Alliance forms working groups to lock down AI agent payments - Standards work on agentic authentication seeded by AP2 and Verifiable Intent.
- AI agents caught masquerading as humans to bypass website defenses - DataDome's Grok investigation into spoofed user agents.
- AI bots crawl retail sites 198x more than Google, new report warns - The March 2026 joint report including DataDome's 698,214-site spoofing test.
- AI agents are now buying things - and fraud looks identical - HUMAN Security's benchmark on how little separates agent workflows from fraud.
- HUMAN Security launches open-source MCP server for AI threat analysis - Background on AgenticTrust and signature-based verification of ChatGPT agent traffic.
- Ninth Circuit frees Perplexity's shopping agent from Amazon's hacking claim - The ruling that narrowed retailers' legal tools against third-party agents.
- Half of web requests are bots as agency CPMs climb 20% - Buy-side accounts of automated visitors in retargeting audiences.
- DoubleVerify: ad fraud drops 41% in North America, 45% in EMEA - AI bot click volumes in unprotected campaigns.
Summary
Who: Experian, the FTSE 100 data and technology company listed in London under EXPN with 25,200 people in 33 countries, and DataDome, a bot and agent trust management vendor whose named customers include Etsy, PayPal and SoundCloud. Kathleen Peters, Chief Innovation Officer at Experian, and Aurelie Guerrieri, DataDome's Chief Marketing & Alliances Officer, are the named spokespeople. Merchants, payment providers and the marketing teams whose measurement depends on separating human, bot and agent activity are affected.
What: DataDome has joined the Experian Agent Trust ecosystem. Experian's Human to Agent Binding links verified consumers, devices and AI agents; DataDome adds continuous intent verification, using Know Your Agent signals to evaluate whether an agent's behavior stays consistent with its delegated authority throughout each session. The release gives no pricing, availability date, launch customer or technical specification, names the Forrester evaluation it cites in two different ways, and does not say how DataDome's role relates to the intent evaluation Fastly took on in July or to Experian's own Agent Registry.
When: Experian issued the release on Thursday, October 1, 2026, five months after opening Agent Trust on April 30, 2026 and ten weeks after Fastly joined on July 24, 2026.
Where: The release was issued from Costa Mesa, California. Experian is headquartered in Dublin. No geographic limit on the integration was stated.
Why: AI agents increasingly reach login pages, forms, carts and payment flows, where a verified identity does not by itself show whether an agent is acting within what it was authorized to do or has been compromised. DataDome's own data recorded AI requests to login pages rising from 11.9 million in January 2026 to 99.7 million in June, and impersonation of known agents rising 45 percent between February and July. For marketers, the same traffic feeds lead forms, retargeting pools and invalid traffic filters, while a crowded field of identity schemes - from Web Bot Auth to Verifiable Intent - competes to define which agent signals a merchant trusts.
Discussion