Meta recently launched Muse, a personal AI agent that can sign in to your accounts, compare plans, fill a cart, and check out on your behalf. Within two weeks, Cequence saw traffic matching Muse at more than half of the customers it studied, and most of those businesses wouldn't have known, because Muse presents itself as an ordinary Chrome browser. Three weeks after Muse was launched, OpenAI launched Dots, always-on agents that keep working toward a user's tasks in the background long after the user has closed the app.
This traffic is automated, signs in with legitimate credentials, and by most legacy definitions is a bot. Usually, it is also a paying customer's assistant doing exactly what it was asked to do. Agent Trust, a new capability in Cequence Application and API Protection, is built to address this new type of visitor. Blocking these agents outright means turning customers away, and letting them through unchecked means trusting every agent, and every stolen agent token, by default.
The start of a new channel
Muse and Dots aren't outliers. They're part of a growing wave of personal agents from large platforms and startups alike, and customers are taking to them as a new way to do business. Salesforce estimates AI agents drove about 20% of 2025 holiday orders, roughly $262 billion, and Bain expects agents to handle 15 to 25% of retail sales by 2030.
The closest parallel is mobile, which also started as a curiosity and became the channel businesses couldn't afford to ignore. The difference is speed. Mobile matured over a decade, and most organizations had years to adapt. Agents are moving on a cycle measured in weeks. First-generation agents have rough edges, and early users and security researchers are already finding them, from agents taking unapproved actions to flaws in how agent credentials are protected. Those issues will be found and fixed in rapid iterations, and every iteration makes agents more capable and more trusted by the people using them. Businesses won't have the luxury of slow rolling their response.
Dots also introduces unique issues. Muse mostly acts while a customer directs it. A Dot works on standing goals while its user is elsewhere, so no one can assume the customer asked for any given request. OpenAI plans teams of Dots per user, which means one account may soon have several agents acting on it, each with its own pattern. And Dots connect to more than 4,000 apps, so a stolen agent credential opens far more doors than a stolen password.
Getting it wrong is costly in both directions. An organization that treats every agent as a bot will block its way out of a channel its customers are choosing, and those customers will send their agents, and their spending, somewhere else. An organization that simply lets all agents through is exposed to something far more capable than the bots it's used to. A bot follows a script. An agent reasons, adapts when it hits a wall, carries a customer's credentials, and can complete step-up authentication by itself. That's why security for this channel can't be an afterthought or a bolt-on.
What agent-ready security looks like
Before getting into capabilities, it's important to be precise about the outcome. An enterprise that's ready for agents should be able to:
- Know which agents are operating in its environment, whether they're calling customer-facing apps or internal ones.
- Understand what each of those agents is trying to accomplish.
- Determine whether an agent's activity breaches existing security controls, and adapt those controls as agent behavior evolves.
- When intent turns out to be harmful, act immediately, by blocking, rate-limiting, or challenging, without waiting on a manual investigation.
Each step depends on the one before it. You can't judge the intent of an agent you can't see, and you can't act decisively on intent you haven't established. The order is also deliberate: most agent traffic will be legitimate, so enforcement comes last and applies to the specific interactions that need it. Here's how each step maps to what Cequence delivers.
Step one: know which agents are in your environment
For outside agents calling the apps and APIs you expose, Agent Trust maintains a detected agent inventory: a live, deduplicated view of every agent in your traffic, including agents like Muse that don't uniquely identify themselves. Traffic from a single agent platform tends to behave like one managed fleet rather than thousands of independent browsers, which is how Cequence recognizes it as agentic even when it doesn't declare itself agentic. When an agent does present an identity, an issuer registry verifies it against the providers you trust, alongside Cequence's own Biometric Check.
The registry is protocol-agnostic. Skyfire, Visa's Trusted Agent Protocol, Google's AP2, and OpenAI and Stripe's ACP all take different approaches, and more are coming. Supporting a new framework means adding an issuer to the existing registry. Agents will run inside the enterprise too: OpenAI is already previewing specialist Dots with their own identities and credentials for company systems. For agents operating internally, Cequence AI Gateway gives you visibility into agents operating internally through agentic AI discovery.
Step two: understand what they're trying to do
An agent activity log records what each agent did, request by request, with identity context attached to every action. Behavioral analysis turns that record into intent. A purposeful assistant works through coherent, multi-step tasks, while a scraper sends requests to whatever it can reach. For always-on agents, the baseline has to follow the agent itself, since there may be no customer session to anchor it.
That judgment depends on context most security tools lack. Cequence discovers and inventories an organization's APIs as part of the platform, so it knows which endpoint handles login, which handles checkout, and which serves pricing and stock. Without that map, an agent completing a purchase and a bot enumerating accounts for malicious purposes can look uncomfortably alike.
Step three: check agents against your controls, and adapt to them
Identity tells you who an agent is. It doesn’t tell you whether the agent is staying within bounds, a point this summer's Hugging Face incident made explicitly and one we've explored in more depth. Agent Trust does both. Agent access policies key off verified identity, using the same policy priority and reporting model Cequence already applies to every other mitigation policy, while the engine behind Cequence Bot Management keeps evaluating every agentic session regardless of the credential it presented.
Behavioral fingerprinting, the signal that survives evasion, is what makes that second check meaningful. Cequence's Intent Graph builds an adaptive profile of how each agent behaves, and that profile separates the real agent from an impostor carrying a stolen token. If an attacker steals an agent credential and replays it from a script, the credential still checks out, but the behavior doesn't match. Controls need to evolve as well, since thresholds tuned for human customers and classic bots won't always fit agents. Because agent access policies live in the same policy engine and dashboards as the rest of your Cequence mitigation policies, adapting them simply requires an edit in a platform your team already works in.
Step four: act immediately, on the interaction rather than the agent
Blocking an agent is a blunt instrument. Stop Muse or Dots at the door and you've stopped every customer who relies on it. Usually, the problem is one specific thing an agent is doing.
Because Cequence fingerprints behavior at the transaction level, it can act on an interaction without acting on the identity behind it. Picture an agent that normally checks order status suddenly walking the catalog, pulling price and stock for every SKU. The platform flags those transactions as likely inventory scraping and lets you build a mitigation policy inline that takes effect immediately. You choose the response: block those transactions, rate-limit them, or allow and log them while you look closer. The agent keeps working for its customer. The scraping stops.
Some actions deserve a pause more than a verdict, such as changing the email on an account or sending an order to an unfamiliar address. OpenAI reached the same conclusion, keeping sensitive actions such as password changes with the user. For those moments, Agent Trust can challenge instead of block. With Biometric Check, the account holder confirms on their own device, with a hardware-bound biometric, whether they really meant for their agent to do this, which matters more when the agent acts while its user is away. If they didn't, the action stops, and you've learned something important about that session.
Agent Trust and Agent Personas: two sides of the same coin
Agent Trust governs agents you don't control. Most enterprises are also building agents of their own, and those need governance before they act. That's the job of Agent Personas in Cequence AI Gateway: a plain-language job description compiled into a scoped virtual endpoint, so an internal agent can reach only the tools, data, and models its role requires and nothing more.
Agent Personas are proactive, setting guardrails before your own agents act. Agent Trust watches what outside agents do once they arrive and corrects course when behavior drifts. However carefully an agent's builder scopes it, the business it visits still has to verify its behavior independently, and the agents your teams send into partner and internal systems still need limits of their own. Together they apply the same four steps to every agent in your environment, whoever built it.
Be ready for the agentic channel, not surprised by it
The instinct to block anything automated made sense when automation mostly meant attack. Applied to agents, it turns customers away. What replaces it is a sequence: see every agent, understand its intent, hold it to your controls, and step in only on the interaction that crosses a line. Doing that well depends on years of experience in behavioral detection across bot and API traffic, built into the same platform that already discovers and protects your APIs. It's also what lets an enterprise serve users of the next Muse or Dots safely and seamlessly.
Contact us to learn more about Agent Trust.




