Somewhere in your bot-management settings there's a switch that decides whether AI agents can reach your site at all. Most companies never touch it on purpose. That's the actual problem - not which setting is right, but that nobody decided.
In short
The evidence points one direction: AI-driven traffic converted 42% better than non-AI traffic in March 2026 (Adobe Analytics), a reversal from converting 38% worse a year earlier, and Shopify measured AI-attributed orders growing 11x over the same stretch. Blocking that traffic protects you from bad bots and throws away your best new segment in the same motion. The better move is to tell them apart and measure the good ones - not leave the decision to a default setting.
Landscape as of September 2026
Why this decision keeps getting made by accident
Bot-management tools ship with aggressive defaults, because most automated traffic historically was scraping, credential stuffing, or ad fraud - blocking it was the safe call. Nobody updated that default for a world where a meaningful share of "bot-shaped" traffic is now an AI agent buying something on a customer's behalf. So the block happens by inheritance, not by decision, and it stays that way until someone asks why AI referral numbers look wrong.
What blocking actually costs you
You lose the segment converting best. Adobe Analytics measured AI-driven traffic converting 42% better than non-AI traffic in March 2026 - a reversal from a year earlier, when the same comparison ran 38% worse. Shopify measured AI-attributed orders up 11x from January 2025 to March 2026. Whatever the exact number is for your business, the direction is not close.
You can't tell good agents from bad ones with a blunt rule. A rule broad enough to stop scraping and credential stuffing is broad enough to stop a legitimate shopping agent too - the underlying signals overlap. See how agent detection actually works for why "block anything bot-shaped" isn't a real filter.
You stay blind either way. Blocking doesn't just stop agents from acting - it stops you from ever seeing that they tried, which means you can't even quantify what you're giving up.
What measuring actually requires
This is the part that gets skipped in the "just allow it" version of this advice: agent traffic breaks the tracking most companies already run. A large share of agent-driven purchases happen through direct API calls that never load a page or fire a script - the exact mechanism covered in full here. Measuring agents properly means moving the capture point server-side, not just changing a firewall rule. It's a real engineering project. It is also a bounded one, and the alternative - flying blind on your fastest-growing, best-converting segment - is the more expensive path.
Common questions
Won't blocking AI agents just protect us from bad bots?
A blanket block can't tell the difference between a scraper stealing your prices and an AI agent about to buy from you - both often arrive with similar signals. The blunt version of blocking throws away the second group along with the first, and the data says the second group is now unusually valuable.
Is agent traffic actually worth anything, or is this hype?
Adobe Analytics measured AI-driven traffic converting 42% better than non-AI traffic in March 2026 - a full reversal from a year earlier, when it converted 38% worse. Shopify measured AI-attributed orders growing 11x from January 2025 to March 2026. Those are the two biggest named measurements available; treat the trend as real and the exact number for your business as something to measure, not assume.
If we choose to measure instead of block, what does that actually require?
Mostly a shift from client-side to server-side capture, because a large share of agent activity - especially API-driven purchases - never loads a page or runs a script that a pixel can catch. It is an engineering project, not a settings toggle, but it is a bounded one.
Can we do both - block the bad ones and measure the good ones?
That is the actual recommendation, not a compromise. The point of building real agent classification is exactly so you can keep blocking scrapers and abuse while letting verified, high-intent agents through and counted. Blanket rules in either direction are the thing to avoid.
Find out what your current setting is actually doing.
A short review of your bot-management posture against your real traffic - what's being blocked, what that's worth, and what changing it would take.