DataDome

Key Takeaways From Our Conversation With Forrester on the State of Bot & Agent Trust Management

Table of contents

Two years ago, most security teams weren’t thinking about agentic traffic. Today, it’s one of the fastest-moving topics in enterprise security—and the decisions organizations make about it are no longer just security decisions. They’re also business ones.

The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026 reflects that shift. Forrester expanded the category for this evaluation, recognizing that bot management alone no longer captures what organizations need to manage. The category itself changed, and the evaluation had to change with it.

To unpack the report’s findings, DataDome co-founder and CEO Benjamin Fabre sat down with guest speaker Sandy Carielli, VP, Principal Analyst at Forrester, who authored the evaluation. DataDome was named a Leader in the Wave, receiving the highest score in the Current Offering category of all evaluated vendors.

Their conversation covered why the category evolved, how Forrester’s evaluation criteria changed to reflect it, what enterprise customers are prioritizing right now, and where the threat landscape is headed. Here are DataDome’s key takeaways.

 

Why the category evolved from bot management to bot & agent trust management

For years, the bot management market operated on a simple question: is this traffic human or not? Sandy Carielli has covered this space for most of that time, watching the question evolve from “bot or not” to “good bot, bad bot, or human.” But over the past year, even that framing stopped being enough.

“It became very obvious over the last year or so that a lot of automated traffic wasn’t necessarily originating from a bad place or even from a non-human place,” Sandy explained. “It was a human that would go into ChatGPT and say, ‘Hey, I want to find information, I want you to do this.’”

That shift from autonomous bots to human-initiated agents is exactly why Forrester renamed and expanded the category to Bot and Agent Trust Management. The new name reflects a new reality: automated traffic is increasingly tied to real people, real intent, and real business relationships. You can’t just cut it off.

Scraping is a good illustration of why intent is now at the center of how Forrester evaluates this market. A web scraper used to be a clear sign of trouble—someone stealing your data, undercutting your pricing, or harvesting your IP. But what if that scraper is an LLM indexing your site so your content surfaces the next time someone asks Claude a relevant question?

“If an LLM is coming in and scraping your traffic, is that always a bad thing?” Sandy asked. “Maybe that is going to help push up your search results If you just say all scrapers are bad, that’s a problem.”

This marks a move from security-first to trust-first—and it’s exactly what agent trust management is designed to address.

Why bot and agent trust management is now a business imperative

The cost of getting bot and agent trust management wrong has changed.

“We always used to talk about security in terms of bottom line,” Sandy said. “This is a top-line problem now.”

She pointed to a B2B example from her research: a company used an AI agent to scrape supplier pricing information and place orders based on what it found. One supplier blocked the agent, and the orders stopped coming.

On the consumer side, the stakes are just as high. A retailer that blocks agentic traffic could be cutting off information to customers who might otherwise complete a purchase down the line.

This changes who needs to be at the table. The security team can’t make these calls in isolation. Marketing, e-commerce, fraud, and revenue teams all have a stake in how agentic traffic is handled. While Sandy has been advocating for cross-functional collaboration to address attacks (or fraud) in this space for years, the urgency has shifted considerably.

“It’s no longer just a security problem. It now becomes a requirement for the security team to be collaborating with the rest of the business to understand the intent of what they’re trying to do with the applications. Who are they trying to serve? What customers are they trying to reach? What is the goal?” Sandy said.

Budget ownership is shifting too. Sandy noted that while security still holds the line item in many organizations, she’s increasingly speaking with CTOs, e-commerce leaders, marketing leads, and fraud teams that care about the impact of bot and agent traffic. The buyer profile is getting wider.

What raised the bar in this Wave’s evaluation criteria

Every Forrester Wave evolves, but the 2026 edition introduced some meaningful changes to how vendors are evaluated.

One new addition was use-case-specific criteria. Rather than evaluating bot management capabilities broadly, Forrester broke out distinct criteria for account trust and protection, AI agent trust, marketing analytics assurance, and transaction assurance. Sandy said she found that certain vendors focused more on certain use cases than others, which matters a great deal for buyers who need to match a solution to their specific exposure.

Intent visibility got its own spotlight too. In previous evaluations, intent was folded into reporting or UI criteria, assessing things like whether a dashboard told you the likely purpose of an attack. This time, Sandy pulled it out as a standalone dimension.

“I really looked explicitly at what is the intent of the traffic, what is the intent of the customer,” she explained. “I broke that out as a specific thing to look at because that is so important now and really needs to be highlighted.”

Attack and user analytics became a formal criterion for similar reasons. Budgets are tighter, and more stakeholders are now part of the buying conversation. Being able to show that a platform is reducing fraud losses, improving conversion, and protecting top-line revenue is increasingly what gets the budget approved.

"If you can actually justify your spend on the product by showing how you are able to increase your top line or reduce your bottom line, that becomes really important."
Sandy Carielli
VP, Principal Analyst at Forrester

Why CDN and WAF vendors were excluded from the evaluation

One of the more significant structural changes to this Wave was the removal of CDN and WAF vendors from the evaluation scope entirely. Sandy described it as a two-pronged decision.

The first part is about platformization. CDN and WAF providers are increasingly moving toward consolidated platforms that bundle multiple capabilities—WAF, bot detection, API security—under one roof. In doing so, they view traffic differently than dedicated bot and agent trust management vendors.

The second part is about signal depth. Evaluating agentic intent requires a level of detail that these platforms aren’t built to provide.

“They don’t have the same level of signal,” Sandy noted. “I really wanted to focus on those vendors that were able to focus more on the agentic traffic and really getting the level and depth of signal to evaluate the intent.”

The result is a Forrester Wave™ that draws a clearer line between broad security platforms and specialists. For organizations trying to get serious about agent trust management, the distinction matters.

What Forrester is hearing from customers right now

One of the most valuable parts of Forrester’s Wave process is the direct customer interviews. Sandy spoke with 22 enterprises for this edition, and the signals she picked up are worth paying attention to.

The biggest one: 13 of those 22 customers said they were already investigating AI agent trust as a use case. That’s more than half, for a capability that was barely being discussed a year ago.

Account trust and protection remains the top use case for customers, but web and LLM scraping and transaction assurance are close behind. Organizations are realizing, often faster than they expected, that agentic traffic isn’t a future problem.

Customers also told Sandy they want visibility, not just decisions. Even when they’re relying on their vendor to handle detection and enforcement, they want access to the underlying data.

“They really wanted to understand what the traffic is doing, what do the attacks look like, what do the profiles look like, what is the intent."
Sandy Carielli
VP, Principal Analyst at Forrester

That appetite for shared intelligence is driving another trend: the expansion of the platform user base inside large enterprises. Security teams, fraud teams, marketing teams, and business ops all want a window into the same data, they just have different questions to answer with it.

Those are the signals that stood out most. 

Where the threat landscape is headed and what leaders need to do now

Sandy introduced a concept in her report that’s worth understanding now, before it becomes a widespread problem: intent hijacking.

Say you’ve evaluated an agent, decided to trust it, and let it operate. But what happens if that agent’s behavior changes, either because someone tampered with it, or because it drifted on its own? The traffic looks the same. The session looks familiar. But the intent has shifted.

“As a customer, I want to know when that happens, because I may need to make the decision: this agent isn’t behaving the right way anymore, the intent has changed, I can no longer afford the same level of trust,” Sandy explained.

This is why continuous assessment matters as much as initial classification. Trust isn’t something you grant once. Do you still trust this agent that you trusted last week? Do you still trust this agent that you trusted an hour ago? Has the intent changed? It should be an ongoing measurement, not a one-time gate.

Looking further out, Sandy expects the composition of web traffic to keep shifting, suggesting that the proportions of agentic versus human versus bot traffic will change. She also raised the possibility that organizations might start creating different versions of content or site experiences optimized for agents versus humans. If that happens, correctly identifying who’s asking becomes essential.

Governance around trust needs to catch up, too. Sandy’s view: security doesn’t drive these decisions on its own anymore. It’s still a contributor, but it’s the business that’s going to drive the decision-making in terms of what customers they want, who is trusted, and who is prioritized.

The same logic applies to emerging protocols like MCP. Sandy drew a direct parallel to the API security lessons of the last decade:

"The business is going to do what it needs to do to make money. So our job as security professionals is to understand the business goals and then figure out what guardrails we can apply in order to best allow them to meet those goals in a safe way. If we say no, what's going to happen is they're going to do it anyway."
Sandy Carielli
VP, Principal Analyst at Forrester

Sandy’s parallel to API security is instructive. The industry eventually got its arms around APIs—not by blocking them, but by understanding them well enough to make smart decisions about access. The same process is now underway for agentic traffic, and the Wave is a practical tool for organizations trying to navigate it.

View The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026

Sandy’s full evaluation goes even further than what we covered here. The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026 goes deeper on vendor methodology, use-case criteria, and what separates the leaders in this space.

DataDome was named a Leader, receiving the highest scores possible in 12 criteria, the most of all evaluated vendors. Access the report here.

DataDome
DataDome

Still exploring?

Start with an on-demand demo.