Prompt Injection and Agent Impersonation: The Commerce Security Threats You Haven’t Locked Down Yet
Prompt injection and agent impersonation are two operational attack vectors targeting agentic commerce in 2026. DataDome tracked 16.4M spoofed Meta-ExternalAgent requests in two months alone. Here’s how both attacks work and what to do about them.
The Universal Commerce Protocol (UCP): What It Is and How to Implement It
UCP — co-developed by Google and Shopify — defines how AI shopping agents discover your catalog, negotiate terms, and execute purchases directly. Here is what it is, which platforms support it, how to implement it, and the fraud risk everyone is overlooking.
Visa TAP, Google AP2, and FIDO: The Agent Authentication Standards Reshaping Commerce in 2026
Visa TAP, Google AP2, and FIDO are each solving agent identity differently. Here’s how the three competing standards work, where they diverge, and what commerce sites should implement before agent-initiated orders become a major revenue channel.
Structured Data for AI Agents: The Schema.org Properties That Get You Recommended (or Skipped)
AI shopping agents and AI assistants read structured data, not marketing prose. Here are the Schema.org properties that determine whether your site gets selected or skipped — and the mistakes that cause agents to move on.
What Is Agentic Resource Discovery? How to Implement ai-catalog.json Before Your Competitors
On June 17, 2026, Google and ten major tech partners published the Agentic Resource Discovery spec. As of this writing, adoption is near zero — including among the companies that wrote it. Here is what ARD does, how ai-catalog.json works, and why moving early matters.
GA4’s New AI Assistant Channel: What It Tracks, What It Misses, and Why the Gap Matters
GA4 added a native AI Assistant channel on May 13, 2026, showing which humans clicked through from ChatGPT, Gemini, and Claude. But it can’t see the AI crawlers quietly shaping those answers. Here’s what you need to measure both.
AI Agent Access Control: The Tiered Framework Every Site Needs in 2026
Most sites treat all AI bots the same. This four-tier access control framework separates training crawlers, search agents, and shopping bots — giving each the right policy while protecting and monetizing your traffic.
llms.txt in 2026: What It Is, What It Actually Does, and How to Implement It
Google Lighthouse 13.3 now audits for llms.txt as part of its Agentic Browsing category. This guide explains what the standard is, what it realistically does in 2026, and six concrete steps to implement it for agent readiness.
The Agent-Ready Website Checklist: 10 Steps for 2026
Ten concrete steps to make your website agent-ready — from AI traffic baselines and crawler policy to structured data, MCP endpoints, and verification.
Inside the Agent Readiness Score: 5 sub-metrics that matter
The Agent Readiness Score is a number from 0 to 100 that summarizes how well a site can be read, verified, and transacted with by an autonomous AI. This is the methodology.
Why your site needs to be agent-ready
If your site is invisible to agents today, it will be invisible to a meaningful slice of buyers tomorrow. The math is changing fast.
What is the agentic web?
Half of the next decade's web traffic will be agents. Most sites can't tell any of them apart from humans. That's the agentic web problem in one sentence.