The chicken-and-egg problem for agentic commerce is largely solved. Today, any consumer in the US or Canada with a Meta account can spin up a Muse agent, which can use browser automation to scrape any merchant website. Because supply and demand arrive together, Meta will likely market Muse extensively for holiday gifting and travel planning.

Doing nothing means agents will revert to web-scraping. The limitations of scraping will result in agents taking a long time to accomplish their task, using a lot of tokens. 

The message to merchants was once, “Get UCP or ACP ready for a Gemini or OpenAI pilot.” It’s changed to, “Take control of your agentic checkout now before volume spikes during the holiday season.”

The shift from LLM chatbots to AI personal assistants

People are quickly adopting AI personal assistants, such as Muse, Instinct, and Grok Bot. The Muse app has logged more than 2.5 million downloads since its debut earlier this month, surpassing ChatGPT as the leading iOS free app within 10 days.

Unlike a standalone LLM, which only generates text in response to a prompt, assistants like Instinct and Muse take their time, and are proactive in their investigations and communications. They also store vault items, like your logins, 2FAs, and even your credit card numbers. Consumers talk to these tools through WhatsApp or iMessage, the way they would a human personal assistant. The assistant goes away, thinks, and acts on its own before returning a result, sometimes several minutes later. 

And as adoption grows, consumers will increasingly attempt to complete purchases through their assistants. 

Forter is already seeing these assistants make orders, with transactions from Instinct and Grok Bot up over 250% since the first week of September, and transactions from Muse up 42% in just two days. Unlike the gated LLM agentic commerce pilots, such as Gemini, merchants are effectively opted-in to the mass-market agentic commerce pilots. These assistants will attempt agentic transactions on your site regardless of whether you’ve optimized for them. 

This evolution has implications for the delicate balance between customer experience and risk protection. How do you ensure a seamless customer experience for those using these assistants, while also protecting yourselves from the fraud that will come with this new shopping channel?

Forter’s agentic experiment

One of our engineers downloaded different personal assistants to conduct a side-by-side experiment to understand the customer experience of ordering with these assistants. He tested across web-scraping models as well as different agentic protocols available via headless checkout, ordering a red dress, timing it and counting the number of tokens used.

So, what is headless checkout?

Headless checkout is an agentic protocol approach that separates the actual payment processing (handled via backend APIs) from the interface a customer sees, so an AI assistant purchase can be completed without going through a merchant’s website. This contrasts with web-scraping models, where the AI assistant goes through the same flow as a consumer shopping directly on the website. 

In the experiment, protocols beat scraping by roughly 10x in time and 5x in tokens, with API calls taking 1 to 16 seconds vs. scraping taking 4 to 6 minutes. Offering every protocol at once was measurably slower than offering one, and no two agents chose the same transport.

Additionally, the experiment found that discovery documents let merchants influence agent selection, and also shape how agents route around ambiguity and inconsistencies, flag machine-readable text as a potential injection vector, and handle untrusted data.

Though web-scraping models have significantly improved from the early days of Operator, this experiment demonstrates how they are still not the optimal path. It’s compute-heavy for merchants to serve and degrades the human browsing experience when operating at scale. It’s also error-prone, with agents getting stuck or declined, burning huge amounts of LLM tokens, and abandoning journeys.

Striking the right balance before the holiday peak

Commerce is one of the first high-value verticals where the impact of these AI assistants will show up at scale. Those who take control of agentic checkout will deliver a better, safer experience to end customers. Those who don’t will risk failed checkout attempts, poor customer experience, higher web serving costs — all leading to lost revenue.

If you want to provide a seamless checkout experience for these assistants (and their end customers), while still protecting your business from fraud, headless checkout is a programmatic, scalable, and higher-performing method. With headless checkout, the payment user interface is separated from backend processing, so you can build custom experiences while reusing the same underlying fraud and payment logic.

Take control of your agentic checkout 

Forter helps merchants both protect themselves from fraud perpetuated by these AI assistants, and promote a seamless customer experience with headless checkout. 

Forter’s Fraud Management solution identifies and makes a risk decision on AI assistant traffic, separating legitimate assistants from attempted fraud and abuse.

And if you have yet to configure headless checkout, Forter’s Agentic Orchestration lets you run any protocol and define which products a personal assistant can buy, where it can ship them, at what price – and whether that assistant gets to transact with you at all — with identity, tokenization, payment and security as one system across every order. 

Contact [email protected] to start now.

Published on September 24, 2026   •  
4 minute read   •  
Author: Forter Team