Industry story
AI Agents Reshaping Ad Targeting: Non-Human Traffic Gains Legitimacy
agents ai-in-adtech attribution brand-safety measurement
Mark Zagorski of DoubleVerify has a provocative argument: AI agents — software that browses and buys on your behalf — are a new high-intent audience that advertising needs to reach and measure. Cloudflare says bot and agent traffic already exceeds human web traffic. But the Compute Pragmatist case is more convincing: agents pull structured product feeds and APIs, not ad-supported HTML, because rendering pages and parsing display ads is the expensive, wasteful path. The real fight isn't about measurement standards — it's about whether spend flows through the open web ad stack at all when a machine does the buying, or concentrates at the agent platform layer instead.
Analysis
Showing the shorter version.
AI Agents as an Ad Audience: A Measurement Story with Misaligned Incentives
Mark Zagorski, CEO of ad verification company DoubleVerify, published an op-ed arguing that autonomous AI shopping agents constitute a new high-intent "audience" that advertisers need to reach and measure. His evidence: a Cloudflare statistic showing bot and agent traffic has surpassed human web traffic. His conclusion: the ad industry needs new measurement standards for non-human buyers.
The incentive problem is visible immediately. DoubleVerify's revenue grows whenever a new measurement category gets declared mandatory — and Zagorski just declared one. The Cloudflare number also bundles together LLM training crawlers, indexing scrapers, and genuine purchase agents into one figure. Only the last group matters for this thesis, and consumer agents with real purchase authority are a small fraction of e-commerce today.
The core question Zagorski doesn't answer
The actual dispute isn't whether agents should be measured. It's whether agents transact by loading ad-supported web pages — where DoubleVerify operates — or by querying structured product feeds and APIs, where there are no ads to verify.
Inference economics point hard at the second path. Every agent product query is a paid call on hosted inference from platforms like OpenAI's Operator, Perplexity, or Google Gemini. When each query costs money, those platforms cache aggressively and pull clean structured data rather than rendering ad-supported HTML. Rendering a full page and parsing display ads is the expensive, wasteful path. The agent doesn't see your banner — it grabs a product feed and skips the ad call entirely. More agent activity does not mean more impressions; it means value concentrating at the inference platform layer, not at publishers or the ad stack.
If that's right, DoubleVerify isn't building measurement for a new audience. There's no ad-supported surface left to measure.
What actually needs solving now
The near-term problem is the opposite of what Zagorski describes. Existing fraud classifiers — built to detect invalid human traffic — will start flagging legitimate high-velocity agents as bots, triggering false-positive fires at premium publishers before any "new audience" product ships. The defensible near-term move is tuning those classifiers so real agents don't get misclassified and monetization doesn't break. That's a concrete service with clear value. "Reach agents as an audience" is not, because there's no agent-identity standard, user-agent strings spoof trivially, and no major platform is building the cross-vendor authentication handshake Zagorski's vision requires.
There's also an underappreciated fraud risk in the opposite direction: the moment any agent ranks on brand credibility, reviews, or sentiment to make purchase decisions, you've created a machine-speed incentive to poison exactly those signals. Faking a trustworthy brand profile for an agent to read is cheaper and faster than faking a human click. Existing brand-safety tooling has no adversarial model for this.
The prediction
No industry-wide agent-identity or authentication standard that DoubleVerify or peers can build a verification product against will be adopted by OpenAI, Google, or Perplexity before January 2027. Agents will keep transacting via structured feeds and APIs, not verified ad-supported page views.
The reason: building a cross-platform identity standard requires rival platforms to cooperate against their own cost and competitive interests, and none of them are currently moving toward a common agent-auth scheme. The first real event in this space won't be a working measurement category — it will be false-positive fraud flags on legitimate agents at scale.
Mark Zagorski, the CEO of DoubleVerify, wrote an op-ed arguing that autonomous AI shopping agents are a new "audience" — high-intent, non-human buyers that advertising has to learn to reach and measure. The hook is a Cloudflare stat: bot and agent traffic passed human web traffic last month. For anyone building or buying AI ad infrastructure, the real question is whether the open web ad stack gets reformed to serve agents, or routed around entirely.
Reversibility: Type 2 for now. Nobody has to bet the roadmap this quarter. But the standards choices being teed up — agent identity, authentication, measurement definitions — are Type 1 once they harden. Pick the wrong verification primitive and you're stuck with it.
What's actually being decided: Not "should we measure agents." It's "does spend flow through publishers and the ad stack at all when a machine does the buying, or does it concentrate at the agent platform layer." That's a monetization-topology question dressed as a measurement question.
Forcing function: Vague. The Cloudflare number is the only hard trigger, and it's a single-vendor read that mashes crawlers, scrapers, and genuine buyers into one scary figure.
The Skeptic. This is a verification vendor announcing that the world needs more verification. DoubleVerify's revenue grows every time a new measurement category gets declared mandatory, and Zagorski just declared one. Read the incentive before the argument. The Cloudflare figure conflates LLM training fetches and indexing crawlers with consumers who have a wallet — and consumer agents with real purchase authority are a rounding error on e-commerce today. The load-bearing claim is that agents will shop the ad-supported open web. They won't. They'll hit structured product feeds and APIs, where there are no ads to verify. For the PM: a company that sells ad-checking says ads now need a new kind of checking — maybe, but notice who profits from you believing it.
The Safety Lens. Zagorski treats trust as a ranking signal and waves at fraud in a footnote. That footnote is the whole game. The moment brand credibility, reviews, and sentiment become inputs a purchase agent ranks on, you've created a machine-speed incentive to poison reviews, fake authentication tokens, and manufacture trustworthy-looking brand profiles. A bad actor no longer fakes a human click — they fake a brand an agent trusts. Existing IVT and brand-safety tooling was built for human attention; it has no adversarial model for agent-to-agent deception, and no regulation touches it. For the PM: if a robot decides what to buy by reading reviews, the cheapest attack is to write the reviews the robot reads.
The Researcher. "Bot traffic exceeds human traffic" is a headline, not a finding. Traffic bundles four different things — crawlers, scrapers, training fetches, and genuine buyers — and only the last one matters for this thesis. The unanswered question is what fraction of agent traffic carries downstream purchase authority. Nobody has that number. And attribution is genuinely unsolved here: did the agent "see" an ad, or did it pull a structured feed that never touched the ad stack? That's not a viewability problem with a new coat of paint — it's a different causal question, and current attribution models can't answer it. For the PM: one dramatic number is crowding out the harder question of how many of those bots are actually shopping.
The Compute Pragmatist. Follow the inference bill. Every agent product query is a paid call on hosted inference — Operator, Perplexity, Gemini. When each query costs money, operators aggressively cache, compress, and pre-filter. That means agents pull structured schemas and MCP-style tool endpoints, not rendered ad-supported HTML — because rendering your page and parsing your display ads is the expensive, wasteful path. More agent spend does not mean more impressions. It means fewer, with the value concentrating at the platform doing the inference. For the PM: the robot doesn't load your webpage and see your banner — it grabs a clean data feed and skips the ads entirely.
The Enterprise Buyer. Put yourself in the seat of a CMO being sold an "agent audience" measurement product. What am I actually signing? There's no agent-identity standard, self-declaration is unaudited, and User-Agent strings spoof trivially. I can't buy indemnification against a category nobody can define yet. What I would pay for, today, is the opposite service: don't let my fraud filters torch legitimate high-velocity agents and tank my monetization. The near-term enterprise product isn't "reach agents" — it's "stop misclassifying them." For the PM: buyers won't sign a contract to reach an audience the vendor can't yet prove exists.
The tensions.
Zagorski versus the Compute Pragmatist is the whole fight: he assumes agents will browse — arrive at pages, evaluate, and be measurable like a fast human. Inference economics say they'll query — hit feeds and APIs and route around the page entirely. If the Pragmatist is right, DoubleVerify isn't building measurement for a new audience; there's no ad-supported surface left to measure.
The Skeptic and the Safety Lens agree the market is early but split on what to watch. The Skeptic says agent shopping is too small to matter yet. The Safety Lens says small doesn't mean safe — the attack surface (poisoned trust signals) is live the instant any agent ranks on credibility, regardless of volume.
And the Builder's warning from the earlier window sits underneath all of it: before any "reach agents" product ships, the fraud team's existing classifiers will start flagging real agents as bots. The first real-world event here isn't a shiny new audience. It's a false-positive fire drill at premium publishers.
What it hinges on: One fact settles most of this. Do consumer purchase agents transact by rendering ad-supported web pages, or by querying structured feeds and APIs? Everything Zagorski proposes assumes the former. The compute economics point hard at the latter. That's testable now — instrument your own inventory and watch how Operator, Perplexity, and Gemini agents actually fetch. If they're pulling schema.org and product feeds and skipping your ad calls, the "new audience" is real but unreachable through the ad stack, and the money moves to the platform layer.
What to de-risk before committing: Don't build to an agent-identity standard that doesn't exist. Do instrument agent fetch behavior on your own properties and tune fraud classifiers so legitimate agents don't get nuked as IVT — that's the concrete, defensible move with payoff regardless of how the standards war shakes out.
Prediction: No industry-wide agent-identity or authentication standard that DoubleVerify or peers can build a verification product against will be adopted by the major agent platforms (OpenAI, Google, Perplexity) before AdExchanger's next annual programmatic outlook in January 2027 — agents will keep transacting via structured feeds and APIs, not verified ad-supported page views.
Confidence: Medium — inference economics push agents to feeds, not rendered ad pages.
Why: Every agent query costs money, so operators cache and pull structured data rather than render ad-supported HTML — which means there's no shared incentive to build the cross-platform identity handshake Zagorski calls for, and no ad surface on the query path to verify. Standards like this need the platforms to cooperate against their own cost and competitive interests, and OpenAI, Google, and Perplexity have shown no move toward a common agent-auth scheme. The opposite outcome — a fast, adopted standard — would require rival platforms to align on identity plumbing in under six months, which nobody is currently building. The near-term reality is fraud-classifier false positives on real agents, not a working measurement category.
Revisit by 2027-01-31: We're right if no major agent platform has shipped an adopted, cross-vendor agent authentication standard usable by verification vendors, and agent commerce still runs mostly through feeds/APIs. We're wrong if two or more of OpenAI, Google, and Perplexity adopt a common agent-identity standard that DV or a peer ships a measurement product against.
Comments