One of the best parts about authoring a Forrester Wave™ is getting to speak to customer references. Every vendor in the Wave evaluation connects me with customers who talk about how they use the product, what they like, and what they wish was better. While a lot of that goes into evaluating vendors during the Wave process, those customer conversations are chock-full of additional insights that go well beyond their relationship with the vendor. During The Forrester Wave™: Bot And Agent Trust Management Software, Q2 2026, I spoke with customer references who shared their thoughts on key use cases, the emergence of AI agent trust, expectations around service and support, and the importance of threat research. Here’s what I learned:

  • Bot and agent trust management software is a multi-use-case tool. Customers most commonly aimed their bot and agent trust management software at account fraud, but web and LLM scraping and e-commerce fraud were close behind. The overall breadth of use cases that bot and agent trust management supports means that multiple stakeholders outside of security will have an interest in the product. Security leaders will want to collaborate with their marketing, digital, and e-commerce counterparts to make the most of these tools.
  • Understanding inbound agent behavior and intent is top of mind. A majority of the customers I spoke with have started or are about to start applying their vendor’s product to AI agent trust management, hoping to gain better visibility into and control of inbound agentic traffic. Look to bot and agent trust management tools to understand the provenance of AI agent traffic hitting your applications, set controls on what actions these agents can or cannot perform, and understand when these agents tie back to a real human customer.
  • A responsive threat research team will help keep your tool in tune. Malicious bot and agent operators evolve their attack techniques quickly and adapt to new protections. Therefore, buyers prioritize bot and agent trust management vendors that maintain strong threat research teams to keep up with the latest threats, as well as strong engineering and support teams that help update models, help customers tune protections, and respond to new attacks quickly. Some customers acknowledged the occasional false positives or false negatives, but they’re willing to accept them as long as the vendor is responsive and can quickly update or tune models to improve detection.

For a deeper dive, please check out the recently published Buyer’s Guide: Bot And Agent Trust Management Software, 2026. I also hope to see you at Forrester’s Security & Risk Forum in November, where I will be talking about how to adapt your application threat modeling program to account for AI agent trust.

Share