Skip to content

Security1 publisher3 min readPublished

Ecommerce absorbs 44.8% of the POST requests Akamai traced to verified AI crawlers

A GET asks a site for a page and a POST tells it to act, so the change Akamai measured over 30 days puts verified AI bots on the request type behind store logins, carts and checkouts. Akamai did not break those requests down by action; retailers have that in their own logs.

The Watch · Security desk

Illustration accompanying Ecommerce absorbs 44.8% of the POST requests Akamai traced to verified AI crawlers

What happened

  • Akamai says it has watched verified AI crawlers, ChatGPT among them, move from reading pages to sending high-frequency POST requests, based on a 30-day analysis of traffic to its global customers.
  • Model Context Protocol traffic made up 4.1% of the AI bot POST transactions, and Akamai has built a rule that tracks MCP traffic across the systems it protects.
  • Asked what the Mythos model found in Akamai's own software, Winterfeld said agreements with Mythos and Akamai's own policies prevent the company sharing the data.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Bot rules written for page reads now govern requests that open sessions and change carts, so any client that passes as a verified agent gets to write, not just read.
  • constraint A store cannot read its own checkout exposure off the 44.8%; that comes out of its own request logs.
  • decision Stores now pick between blocking verified agents and losing the answer-engine visibility Akamai advises optimising for, or admitting a request class that can log in and buy.

A crawler that only sends GET requests reads pages. A client that sends POST requests writes: it opens sessions, changes carts and submits orders [4]. An allow rule keyed to a verified crawler's identity, written when the concern was scraping and search ranking, now covers that class of request.

Akamai's Ryan Gao, who leads its Threat Intelligence Services, was asked how a retailer separates a legitimate AI shopping agent from a bot posing as one [18]. He said it comes "[t]hrough combining techniques like generative engine optimization (GEO) with specialized bot tracking, monitoring transactional shifts (GET vs. POST behaviors), and adaptive behavioral analytics for evasion tactics and nonhuman identity and schema validation. These are constantly evolving." [7] Each of those is something a retailer builds and tunes against its own baseline. Steve Winterfeld, Akamai's advisory CISO, said the advice for retailers is to "ensure AI bot visibility and apply a well-informed security strategy for governance". The same answer carried the deadline: retail is approaching holiday season [10].

Akamai describes the measurement only as a 30-day analysis of its global customers [19]. Ecommerce was 44.8% of the AI bot POST transactions in that window and travel reached 30% in a single month [2][3]. If both shares are counted against the same total, those two verticals are 74.8% of the POSTs, leaving roughly a quarter spread across everything else [16]. MCP, the Model Context Protocol that connects models to outside databases, code and APIs, was 4.1%, about one POST transaction in 24 [5][17].

The figure a store would price its risk with is which endpoint those POSTs hit. Winterfeld was asked which actions the requests perform most often, with logins, cart additions and checkouts offered as the options. He answered in categories: "We are seeing a wider variety of transaction types, including a consistent rise in non-GET requests from some of the verified AI crawlers for training and searching." [8][9] Akamai has also built a rule that tracks MCP traffic across the systems it protects. What has that rule detected, and how many MCP endpoints are reachable without authentication? Gao did not give a count. He named unsanctioned services running without proper authentication and potential PII exposure as the primary risks [6].

Akamai joined Anthropic's Project Glasswing and got early access to the Mythos model to hunt for critical flaws in its own software [11]. On what Mythos found, how many findings were critical and how quickly they were fixed, Winterfeld said: "Due to agreements with Mythos, and our own security policies, we cannot share this data. We continue to leverage the data to find and fix issues, but they are not public." [12] The company argues AI can cut vulnerability discovery from weeks to hours while enterprise patch cycles lag, and recommends runtime protection, edge controls or segmentation until a patch lands [13]. It also says the majority of AI-generated exploits, a majority it does not quantify, will still be stopped by edge protections, east-west segmentation and DDoS prevention [14].

For one store, the usable part of a 30-day industry sample is its own log: POST requests filtered by verified-agent identity, matched to the endpoints they reached. That work has to happen before peak trading, which Winterfeld put weeks away [10].

What to watch

  • Whether Akamai publishes the action-level split of AI bot POSTs, separating logins from cart additions and checkouts, before peak retail trading.
  • Whether the MCP tracking rule Akamai built yields a count of MCP endpoints reachable without authentication.
  • Whether any retailer reports fraud traced to a client impersonating a verified AI agent on a POST endpoint.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories