Blog AI and Agents · Beyond the Four Walls · Part 9
Who gets through the door: bot walls, verified agents and the new front desk
Banks, card networks and Cloudflare spent the last year building ways for an AI agent to prove who it is. Most local business websites are still checking everyone at the door the old way. Part 9 of Beyond the Four Walls.

Every gym has a front desk for a reason. Most people who walk in are members or guests. A few are not, and someone has to tell the difference without making the members wait.
Your website has a front desk too, though you may never have seen it. It is the security layer your web host or Cloudflare puts in front of your site, the thing that sometimes shows a "checking your browser" page or a box of traffic lights to click. For years it had one job: keep the bad bots out. Now a new kind of visitor is arriving. It is software, but it was sent by a real customer who wants to see your class schedule or book a facial. The old front desk cannot tell it apart from the bad bots, so it often turns it away.
This part is about who gets let in, and the new system the payments industry is building to answer that question properly.
The fight that made it public
On September 21, Amazon blocked Meta's new Muse assistant from shopping on Amazon.com. People using Muse saw a pop-up: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." As Adweek reported, one of Amazon's stated reasons was that Muse did not identify itself. Amazon said third-party agents "should operate openly and respect service provider decisions."
Strip away the brand names and the argument is simple. A store wants to know who is at the door. An agent in disguise gets treated like a shoplifter, even when it carries a real customer's order.
Eight days later, Federal Reserve Governor Christopher Waller gave a speech at Sibos in Miami titled Payments in the Age of AI Agents. He split agentic commerce into two models: agent assisted, where the assistant helps you search, and agent delegated, where you give it authority to shop and pay. Then he named the problem.
The biggest barrier to scaling agentic commerce, particularly the agent-delegated model, is building sufficient trust among buyers and sellers.
He listed three challenges: authentication, liability and fraud, and warned that fraud systems "calibrated to human behavior, may not translate well to agents." That is your website's front desk, described by a central banker.
Two kinds of door
There are two ways to decide who gets in.
The old way is the bot wall. It watches how a visitor behaves: how fast it clicks, what browser it claims to be, where its traffic comes from. If something looks automated, it shows a challenge page or a captcha. This works well against scrapers and credential stuffers. It also stops every honest agent, because an honest agent is, by definition, automated.
The new way is a signed request. The agent carries a cryptographic signature on every page request, a kind of tamper-proof name badge, and the website checks it against a public key the agent's operator publishes. The underlying standard, HTTP Message Signatures (RFC 9421), was published in 2024. An IETF working group called Web Bot Auth is now standardizing how bots and agents use it. Those specifications are still drafts, so expect details to move.
The bot wall
Judges visitors by behavior. Anything that looks automated gets a challenge page or a captcha. Bad bots are stopped, and so is the assistant a customer sent to book a class.
The verified door
Checks a signed badge on each request. A known agent acting for a real person can be let through to the schedule, while unknown traffic still meets the wall at login and checkout.
Who is building the badges
In the space of about fifteen months, almost every company that sits between a customer and a payment picked up the same idea.
| Date | Who | What they did |
|---|---|---|
| July 1, 2025 | Cloudflare | Began blocking AI crawlers by default that take content without permission, and asks every new domain upfront whether to allow them. Cloudflare says it manages traffic for about 20% of the web. |
| August 28, 2025 | Cloudflare | Launched signed agents, a category for agents directed by end users that sign their requests with Web Bot Auth. First members included OpenAI's ChatGPT agent and Block's Goose. |
| October 14, 2025 | Visa, with Cloudflare | Introduced the Trusted Agent Protocol, part of Visa Intelligent Commerce. A signed agent can tell a merchant its intent, whether the shopper already has a relationship with the store, and optionally payment details. Mastercard and American Express also said they would use Web Bot Auth. |
| September 22, 2026 | Six banks | NatWest, ASB, Bank of America, Capital One, Commonwealth Bank of Australia and ING published Building Trust in Agentic Commerce, voluntary principles on transparency, safety, privacy, choice and interoperability. |
| September 30, 2026 | Mastercard | Expanded Agent Pay with a score estimating how likely it is that an AI agent started a transaction, so issuers can approve legitimate agent purchases. It is rolling out for testing in the US. |
| October 6, 2026 | American Express | Released a free Business Playbook for Agentic Commerce and announced plans for Agent Purchase Protection covering errors by registered AI agents. Amex describes that protection as an intention, with terms still to come. |
Visa's announcement put the merchant's dilemma in one sentence. Visa's Jack Forestell said merchants "shouldn't have to choose between blocking bots and serving real customers." Skyfire, which Mastercard named as a partner, put the rule even more plainly: every agent that transacts for someone "should be identifiable, accountable and auditable."
A caution: much of this is new, in testing, or voluntary. The bank principles are not binding, Mastercard's score is in a US test, and Amex's protection has no published terms. What is settled is the direction. Good agents should carry a badge, and merchants should check it rather than block everything that moves.
What the businesses think
Merchants are paying attention, and they are not sure they can keep up. American Express surveyed 502 US business leaders in August, and consumers too.
Source: American Express Trendex: Agentic Commerce Edition, conducted by Teneo, August 2026, 502 business leaders and 2,005 consumers, via the Amex release
That gap between 52% and 15% matters for our industry. A class pack, a drop-in, a blowout or a first facial sits much closer to the everyday end than to a new refrigerator. The bookings our clients sell are exactly the size of purchase people say they will hand to an assistant first.
What we found on fitness and wellness websites
So we looked at our own industry. In October 2026 Sneeze It scanned 98 fitness and wellness brand websites to see what an agent meets when it arrives.
The good news first. Of the 82 sites whose robots.txt file we could read, none blocked the live AI assistants, the ones that fetch a page because a person just asked a question. Nobody in this group has deliberately shut the door.
The bad news is the front desk. 18 of the 98 sites sat behind a bot wall, the kind of challenge page an agent cannot get past. And of the 57 sites the scanner could read that had a way to book or get in touch, 30 put a captcha in the path that an agent cannot pass. That is the one page that matters.
Source: Sneeze It scan of 98 fitness and wellness brand websites, October 2026. The robots.txt figure covers the 82 sites with a readable file; the captcha figure covers the 57 readable sites with a booking or contact path.

The policy is open and the plumbing is closed. Nobody chose to turn agents away. A security setting did it for them.
Keep the lock on the safe, not the lobby
None of this means you should switch off your security. Login pages, member accounts, gift card balances and checkout are where fraud happens, and they should stay protected. The fix is to move the wall, not remove it.
Your schedule, prices, hours, locations and the first step of booking are the lobby. That is what a verified agent needs to see to recommend you, and it holds nothing a fraudster can steal. Your member login and payment page are the safe. Keep the strongest checks there.
One detail worth knowing: Cloudflare's free Bot Fight Mode protects the whole domain and, according to Cloudflare's own documentation, "cannot be customized, adjusted, or reconfigured via WAF custom rules." If that is what is running on your site, you cannot carve out the schedule page without changing the setup. That is a conversation for whoever manages your site.
- Find out who runs the front desk
Ask your web developer, agency or host: "Is our site behind Cloudflare or another bot protection service, and which mode is it in?"
- Ask what agents see
"Do verified bots and signed AI agents get through to our schedule and booking pages, or do they get a challenge page?"
- Move the challenge, do not delete it
"Can we keep bot challenges and captchas on login, account and payment pages, but not on the class schedule, pricing and first booking step?"
- Check the booking form
"Does our booking or contact form use a captcha? Is there an option that does not block AI agents, or can the platform handle bot screening instead?"
- Test it
Run the site through a free agent scan before and after the change, and keep the report.
If you missed the start of the series, Part 1 explains why the customer is starting to send software, and Part 2 covers robots.txt and the rest of the plumbing in plain English.
In Part 10 we open the full results: We scanned 98 fitness and wellness websites. Which brands an agent could actually book, where most sites fell down, and the handful of fixes that moved the most.
Sources
- Adweek, Trishla Ostwal, "Amazon Locks Out Meta's Muse in Agentic Shopping Standoff," September 21, 2026. adweek.com
- Federal Reserve Board, Governor Christopher J. Waller, "Payments in the Age of AI Agents," Sibos 2026, Miami, September 29, 2026. federalreserve.gov
- IETF, RFC 9421, "HTTP Message Signatures," Proposed Standard, 2024. rfc-editor.org
- IETF, Web Bot Auth working group charter and status. datatracker.ietf.org
- Cloudflare, "Cloudflare Just Changed How AI Crawlers Scrape the Internet-at-Large," press release, July 1, 2025. cloudflare.com
- Cloudflare Blog, "The age of agents: cryptographically recognizing agent traffic," August 28, 2025. blog.cloudflare.com
- Cloudflare, "Cloudflare Collaborates with Leading Payments Companies to Secure and Enable Agentic Commerce," October 14, 2025. cloudflare.com
- Cloudflare Docs, "Bot Fight Mode." developers.cloudflare.com
- Visa, "Visa Introduces Trusted Agent Protocol: An Ecosystem-Led Framework for AI Commerce," October 14, 2025. usa.visa.com
- NatWest Group, "Global banks collaborate on principles for trusted agentic commerce," September 22, 2026. natwestgroup.com
- Mastercard via Business Wire, "Mastercard Advances Agentic Commerce With New Trust and Intelligence Services," September 30, 2026. financialcontent.com
- American Express, "American Express Launches Playbook to Help Businesses Prepare for Agentic Commerce," October 6, 2026, including Trendex survey methodology. webwire.com
- FinTech Weekly, "Agentic Commerce Had Its Biggest Launch Month. Nobody Wants to Own the Risk.," October 4, 2026. fintechweekly.com
- Sneeze It, scan of 98 fitness and wellness brand websites, October 2026. Full results

