It’s An Agent’s World: Customer Insights From The Bot And Agent Trust Management Software Wave
One of the best parts about authoring a Forrester Wave is getting to speak to customer references. Every vendor in the Wave connects me with customers that talk about how they use the product, what they like, and what they wish was better. While a lot of that goes into evaluating vendors during the Wave process, those customer conversations are chock full of additional insights that go well beyond their relationship with the vendor. During the Forrester Wave™: Bot And Agent Trust Management Software, Q2 2026, I spoke with customer references who shared their thoughts on key use cases, the emergence of AI agent trust, expectations around service and support, and the importance of threat research. Some of what I learned was that:
- Bot and agent trust management software is a multi-use case tool. Customers most commonly aimed their bot and agent trust management software at account fraud, but web and LLM scraping and eCommerce fraud were close behind. The overall breadth of use cases that bot and agent trust management support means that multiple stakeholders outside of security will have an interest in the product. Security leaders will want to collaborate with their marketing, digital, and eCommerce counterparts to make the most of these tools.
- Understanding inbound agent behavior and intent is top of mind. A majority of the customers I spoke with have started or are about to start applying their vendor’s product to AI agent trust management, hoping to gain better visibility to and control of inbound agentic traffic. Look to bot and agent trust management tools to understand the provenance of AI agent traffic hitting your applications, to set controls on what actions these agents can or cannot perform, and to understand when these agents tie back to a real human customer.
- A responsive threat research team will help keep your tool in tune. Malicious bot and agent operators evolve their attack techniques quickly and adapt to new protections. Therefore, buyers prioritized bot and agent trust management vendors that maintain strong threat research teams to keep up with the latest threats and strong engineering and support teams that help update models, help customers tune protections, and respond to new attacks quickly. Some customers acknowledged the occasional false positives or false negatives, but they were willing to accept them so long as the vendor was responsive and could quickly update or tune models to improve detection.
For a deeper dive, please check out the recently published Buyer’s Guide: Bot And Agent Trust Management Software, 2026. I also hope to see you at Forrester’s Security & Risk Forum in November, where I will be talking about how to adapt your application threat modeling program to account for AI agent trust.