← All posts

How top US retailers are responding to AI shopping agents

We audited 51 of the largest US online retailers. None has a way for a verified AI agent to buy, and 37 block shopping agents by accident.

AIbillions teamOct 2, 20266 min read

None of the 51 largest US online retailers we audited has a way for a verified AI agent to complete a purchase. Some ban agents outright, some let them browse but stop them at the cart, and two are starting to welcome them into checkout.

AI agents are learning to shop, and the payments industry is moving fast to let them pay. In July, the Linux Foundation launched the x402 Foundation with Visa, Mastercard, Stripe, Google and dozens of others agreeing a standard for how AI agents transact.

This research looks at the other side of that shift: how the stores themselves are responding. We reviewed the published access rules of 51 major US retailers, drawn from the NRF Top 100 and the major marketplaces. The picture is not a uniform wall. It is a spectrum, and it is moving quickly.

Key findings

Only 11 of the 51 retailers have taken a deliberate position on AI agents, and those 11 are split between restricting, limiting and welcoming them. Not one has a route for a verified agent to buy.

Five positions, moving in opposite directions

Where retailers have taken a deliberate position on AI agents, they are heading in opposite directions. Most have not taken one at all.

The largest group is the most telling. Nearly three-quarters of the set block shopping agents by accident. Their rules were written years ago for a different problem, and a well-behaved agent shopping on a customer's behalf gets caught in the same net as a scraper.

Three retailers sit closest to agent-ready. Pottery Barn, West Elm and Williams-Sonoma publish an llms.txt file that tells agents how to navigate their sites. Guidance is not verification, though, and all three still block checkout.

Browsing is about access. Buying is about trust.

Zero of 51 retailers has built a route for a verified agent to complete a purchase. Opening checkout to all automated traffic is not the fix, because it lets bad bots in along with good agents.

A verified-agent route needs three things:

  1. The agent presents a credential proving which real person it is acting for.
  2. The retailer can check that credential at the point of sale.
  3. Both sides know what the agent is permitted to do, such as a spend limit or a single order.

Today's tools, robots.txt and terms of service, can only say yes or no to a type of traffic. They cannot tell a legitimate agent from a bad one. That is why the retailers who have decided are split: the ones welcoming agents are making a bet, and the ones holding back are waiting for a way to tell friend from foe.

“Payment is being solved in public, and identity is being left in the dark. Most of the retailers in our audit have not made a decision about AI agents at all. They are running rules written for scrapers, and an agent shopping on a customer's behalf gets caught in the same net. Those who have decided are split because there is no reliable way to tell a legitimate agent from a bad one. As checkout moves from a person at a browser to an agent acting on their behalf, the trust layer has to move with it.” Evin McMullen, co-founder and CEO, Billions Network

Methodology

We reviewed the publicly stated access rules of 51 major US retailers, drawn from the NRF Top 100 and the major US online marketplaces. The audit was conducted in August 2026, with sources verified through 2 September 2026.

What we measured. For each retailer we reviewed robots.txt directives and relevant published terms or policies. We classified how each treats AI agents at the two stages that matter for shopping: creating an account or signing in, and reaching the cart or checkout.

The AI user-agents we checked. OpenAI (GPTBot, OAI-SearchBot, ChatGPT-User), Anthropic (ClaudeBot, anthropic-ai, Claude-User), Perplexity (PerplexityBot, Perplexity-User), Google (Google-Extended, GoogleAgent-Shopping), Meta (Meta-ExternalAgent, meta-externalfetcher), plus Amazonbot, Applebot-Extended, Bytespider and CCBot. Where a site's rules distinguished training and search crawlers from interactive shopping agents, so did we.

How we classified each retailer.

  • Explicitly restricts AI: names and blocks AI agents in robots.txt, or prohibits automated or agent access in its terms.
  • Permits AI browse, blocks checkout: allows AI agents to browse but disallows account and checkout paths.
  • Permits AI agents including checkout: explicitly grants AI shopping agents access that extends to checkout.
  • Incidental blocking: no AI-specific rules, but standard older bot rules still disallow account or checkout paths to any automated client.
  • No robots block on cart or checkout: does not restrict those paths in robots.txt at all.

What “agent-ready” means. A dedicated path for a verified, authorised AI agent to transact. General permission for an AI agent to reach checkout does not qualify on its own.

How to replicate it. For any retailer, open [domain]/robots.txt and its published terms, then check how automated and AI-agent access is treated at account and checkout. Every classification in the dataset below records the evidence used, so each can be checked against the retailer's own rules.

Caveats. robots.txt and terms of service are stated policies, not proof of technical enforcement; we report what each retailer declares. This is a dated snapshot, and policies change. It is a directional sample of 51 retailers, not a census.

Full dataset: all 51 retailers

Every retailer in the audit, with the evidence behind its classification. No retailer is agent-ready, so that column is left out. Sources verified through 2 September 2026.

Resources

The full audit materials are open for anyone to review, cite or replicate.

  • Dataset: all 51 retailers: one row per retailer, with its classification and the robots.txt or terms-of-service evidence behind it.
  • Methodology note: what we measured, the AI user-agents checked, how each retailer was classified, how to replicate the audit, and its caveats.

About Billions Network

A store that wants to admit good agents and keep bad ones out needs to know who is behind each one. Billions is an identity and trust layer for the agent economy. It proves a person is real and unique without exposing their personal data, then binds that proof to the AI agents acting on their behalf, so an agent can pay, be verified and build reputation with an accountable human behind it. Built on the Privado ID stack, its verification has been used by banks including HSBC and Deutsche Bank.

Media contact: Evin McMullen, co-founder and CEO of Billions Network, is available to walk through the dataset and findings.

Citing this research: Billions Network, “How top US retailers are responding to AI shopping agents,” audit conducted August 2026.

Get this in your inbox

Product news, agent-commerce research and the occasional deep dive.