The Storefront Is Becoming an API. Who Controls the Door?
AI agents are the new eCommerce shoppers. The edge decides who gets in.

The Storefront Is Becoming an API. Who Controls the Door?AI agents are becoming the new eCommerce shoppers. Amazon is blocking them and Macy's is letting them in. Either way, those decisions are enforced at the edge, across your WAFs, CDNs and bot tools, so retailers need visibility into agent traffic and one consistent policy for which agents get in.
The Storefront Is Becoming an API. Who Controls the Door?
Amazon is blocking AI shopping agents. Macy’s is inviting them in. Both moves point to the same shift in eCommerce - and to where that decision will ultimately be enforced.
For most of eCommerce’s history, the model was simple: the customer came to you. They searched for a product, clicked through to your site, browsed your catalog, compared options and checked out. SEO, advertising, conversion optimization and loyalty programs were all built around that journey.
AI agents are rewriting that model. The next “customer” reaching your site may not be a person at all, but an agent acting on someone’s behalf - one that can search for a product, compare prices, read reviews and, increasingly, complete the purchase without the shopper ever seeing your homepage.
Which raises a question every online business will eventually have to answer: if an agent sits between you and your customer, who controls that relationship?
Amazon is closing the door. Macy’s is opening one.
The market is already giving very different answers.
Amazon has blocked Meta’s Muse from shopping on Amazon.com, following similar restrictions on agents from Google, OpenAI and Perplexity. The logic is easy to follow. Amazon has spent decades building a direct relationship with its customers, and one of the world’s largest retail advertising businesses on top of it. Letting another company’s agent stand between Amazon and its shoppers puts both at risk.
Macy’s is taking the opposite approach. It recently went live with Google’s Universal Commerce Protocol (UCP), allowing approved AI agents to interact with its commerce infrastructure in a structured, sanctioned way.
These aren’t really opposing stories. They are two early data points in the same transition.
Every company that sells online will have to decide how it wants to deal with AI agents. Some will block them. Some will partner with them. Many will open certain parts of the business while keeping others closed. Most will land somewhere in the middle - and keep adjusting as the market moves.
From front door to API
This is the part of the shift that is easiest to underestimate.
For years, your website was the front door to your business. You controlled what customers saw, how they moved through the experience and what information they received along the way.
When an agent becomes the interface, that control shifts. The agent reaches your products, prices, inventory and content at machine speed, and the customer may experience your brand entirely through someone else’s interface.
That goes well beyond customer experience. It raises hard questions about data ownership, pricing, attribution, margins and the value of the customer relationship itself.
It also creates a new problem: not every agent knocking on your door has the same intent.
One may be acting for a real customer. Another may be a trusted commerce partner. A third could be a competitor scraping your prices. A fourth could be an attacker impersonating a legitimate agent.
To the infrastructure sitting in front of your application, those four requests can look almost identical.
The decision eventually reaches the edge
The headlines will keep focusing on partnerships, protocols and negotiations between retailers and AI companies. But every one of those decisions has to be enforced somewhere.
That somewhere is the network edge: the WAFs, CDNs, bot management systems and other controls sitting between the internet and your applications.
For a long time, the edge ran on a relatively simple idea: let real users through and stop bad bots.
AI agents break that idea. As explored in Same Game, New Rules: How Agentic Traffic Rewrote Bot Defense, AI browsers and agents now look almost identical to real users, undoing decades of bot-defense logic that depended on telling the two apart.
A retailer may want to allow one agent, rate-limit another and block a third. It may want to give a partner access to product data while stopping an unknown agent from scraping its catalog. And it will need to change those rules as its commercial relationships change.
In other words, the edge is no longer just a security layer. It is becoming the place where business decisions are enforced. Get it wrong in one direction and you leak data and margin. Get it wrong in the other and you block legitimate customers without ever seeing it in your application logs.
That is hard to manage when those decisions are spread across multiple WAFs, CDNs and bot platforms, each with its own rules, its own configuration model and its own partial view of the traffic.
What should companies be thinking about now?
Start with visibility. Before deciding which agents to allow or block, understand what is already reaching your properties. Which agents are there? How much traffic are they generating? What are they accessing? And which of them actually bring value to the business?
Treat agent access as business policy. It shouldn’t be decided by security alone. It sits between security, commerce, marketing, legal and product, and the business needs to decide which agents it wants to work with, and on what terms. This is exactly what played out at Merlin Entertainments, where giving security, marketing and eCommerce teams one shared view of the traffic turned the WAF from a conversion blocker into a growth enabler.
Enforce consistently. Once those decisions are made, they need to be applied the same way across the entire stack. A policy that exists on one CDN but not another isn’t really a policy. And even a single vendor can surprise you, as happened when Cloudflare “Log” rules started blocking production traffic.
Plan for change. New agents will appear, existing ones will change their behavior, and attackers will imitate trusted identities. Whatever policy you put in place today will need to evolve continuously, not once a year.
The next battle for eCommerce won’t be about websites
“Block everything” is unlikely to be a sustainable strategy. As agent-driven shopping grows, businesses will have to choose where they want to participate and where they don’t.
The question won’t simply be whether a company allows AI agents. It will be which agents it allows, what they can access, and how quickly it can change those decisions.
Amazon and Meta, Macy’s and Google: these are early signals. The bigger story is that the storefront itself is changing, from a place people visit into something agents access directly.
And when that happens, the edge becomes the door.
This is the problem Huskeys works on every day: helping security teams see, manage and enforce policy across the WAF, CDN and bot layers that make up that edge. Learn more about Network Edge Security Management.