Why Layering a Specialist Bot & Agent Trust Solution With Your CDN Is Now Essential
When setting up a home theater, you start with a massive TV, right? 75-inch, minimum.
But crank the TV volume as high as you like, and the sound is likely going to leave you underwhelmed, whether you’re watching a movie or a football game. You need at least a quality soundbar, or even better, a full surround sound system.
Built-in speakers are fine for basic viewing. But for sound that matches the picture, you need to layer dedicated, best-of-breed products.
The same principle applies to cybersecurity. For years, enterprises have relied on their CDNs, with integrated WAFs and basic bot management, as a primary defense against automated traffic. That made sense when many threats were relatively simple and manageable with rules-based or rate-limiting-dependent approaches.
The reality today, however, is very different, and prominent analyst firms have explicitly recognized that in their latest research. In fact, Gartner recently wrote:
AI-powered bots, open-source tooling, and low-cost bots-as-a-service have made malicious attacks orchestrated by fraudsters easier, more sophisticated, and evasive. Basic bot solutions from CDN providers are no match, leading to overworked security teams and higher fraud costs.
The rise of agentic commerce traffic has shifted bot management from simply blocking threats to managing agent trust. AI agent and LLM crawler requests across DataDome’s network grew 82% from July 2025 to June 2026, for a total of 52.7 billion requests.
That means enterprises must now determine what an automated actor is trying to do, whether it should be trusted, how its behavior changes over time, and whether blocking it could harm business revenue, customer experience, or discovery.
The market is responding accordingly. The recently published Forrester Wave™: Bot And Agent Trust Management Software, Q2 2026 represents a meaningful shift in how the category is defined. Unlike in 2024, CDN and WAF providers are no longer included in this latest report. As I describe in more detail elsewhere, specialist vendors are now evaluated for their ability to analyze automated behavior, assess intent, and manage trust across bots and AI agents.
This new and important scope, agent trust management, includes AI agent trust use cases and isn’t typically included in many web application protection platforms today. That distinction matters. It signals that bundled bot mitigation is no longer seen as comparable to dedicated bot and agent trust management.
The result is a growing gap between baseline mitigation and advanced bot protection.
Gartner states:
In addition, Gartner continues by saying:
We believe that this is not a recommendation to abandon the CDN or WAAP platforms. It’s a recognition that the CDN should no longer be expected to solve every automated bot threat or agentic AI business interaction on its own.
Bundled does not mean specialized
Of course, CDNs and WAAP platforms remain essential enterprise infrastructure. They provide foundational capabilities across content delivery, DDoS protection, web application security, API protection, and other application security functions.
But breadth can come at the expense of depth. As CDN and WAF providers consolidate capabilities into unified platforms, they are designed to evaluate traffic broadly, not deeply. Specialist providers, by contrast, are built around the detailed, real-time analysis of automated behavior, identity, intent, and risk.
For more commentary, you can hear directly from Sandy Carielli, VP, Principal Analyst at Forrester, who recently discussed the topic alongside DataDome CEO Benjamin Fabre:
This is the dividing line. Traditional bot controls may classify traffic as human or automated, or good bot versus bad bot. Advanced bot and agent trust management must go further:
- Is this an authorized or legitimate AI agent?
- Does its intent or behavior match its stated identity?
- What is this agent attempting to do or access?
- Has its behavior changed, and does it still comply with business logic?
These decisions require specialized signals, continuous behavioral analysis, and granular intent-based policy controls. They are difficult to deliver as a checkbox feature inside a broad security platform.
Meanwhile, specialists like DataDome have expert threat research teams to help you stay in front of fast-moving attackers.
As Forrester says:
The implication for enterprise buyers is straightforward: do not assume that an existing CDN WAAP or bot mitigation service provides the depth needed to manage advanced bots, fraud, and AI agents. You can find more technical comparisons here.
Effective enterprise security architecture is layered
The most effective approach for most enterprises is not rip and replace but defense-in-depth with layering. A specialist bot and agent trust management platform can sit on top of that existing CDN architecture, providing deeper signals, real-time bot protection, and more precise trust decisions for agentic traffic, which may create the greatest business risk.
That deployment flexibility is important. Enterprises can leverage specialist protection where the business impact is highest, including login and account creation flows, checkout, ticketing, inventory, pricing, APIs, high-value content, and agent-facing experiences.
According to the 2026 State of Bot & Agent Security Report, AI agents made 605.6 million requests to high-risk endpoints in H1 2026 alone, with requests to login pages accounting for over 51% of that traffic. AI agents are increasingly targeting deeper into the customer journey.
The goal is not to block all automation. It is to distinguish valuable automation from harmful automation, then apply the right response to each. Some LLM-sourced requests and AI agents may support customer discovery. Some bots may be essential to business operations. Others may be attempting fraud, scraping, credential attacks, or abuse at a scale that traditional controls cannot reliably stop.
A new default for managing bot & agentic traffic
The market is moving away from the assumption that one broad security platform can provide sufficient depth for every use case. CDN-based application security remains a necessary baseline, but it is increasingly not the primary answer for advanced bot and agent trust management.
Forrester reflects on this approach:
The new enterprise security default should be layered.
Use your CDN and WAAP platform for foundational protection, and add a trust layer for advanced bot and agent traffic from a specialist. Many of our customers do just that: 60% use both CDN security and a DataDome trust layer.
Going back to my TV and speaker analogy: you want both in place for an amazing home theater. But how complicated is connecting a sound system with my 75-inch TV? Nobody needs that headache.
Fortunately, DataDome provides 80+ out-of-the-box integrations to your tech stack, including leading CDNs like AWS CloudFront, Akamai, Google Cloud, Cloudflare, Fastly, and more. DataDome is also a leading AWS CloudFront Ready partner with multiple competency designations, including the AWS Security Software Competency.
It’s easy to get set up quickly and deliver value fast. Book a demo to learn more today.
References:
[1] Gartner, Protect Web Applications From AI-Fueled Bot Attacks, 7 April 2026, Rajpreet Kaur.
[2] Gartner, Market Guide for Cloud Web Application and API Protection, 8 June 2026, Esraa ElTahawy, Adam Hils, Dale Koeppen.
[3] Forrester, The Forrester Bot And Agent Trust Management Software Landscape, Q4 2025, 15 June 2026, Sandy Carielli.
Gartner is a trademark of Gartner, Inc. and/or its affiliates.