Remember (if you can) how web security was 15 years ago, things were relatively simple. You set up a firewall, block suspicious IP addresses, write a few basic rules, and call it a day.
Now? It’s messy.
Your APIs are dealing with a massive influx of AI agents, agentic browsers, LLM crawlers, and custom automated tools, some of which represent genuine business, and others that cause harm. It’s a massive headache. If you block all automated traffic, you shut the door on legitimate customer transactions.
But, let those same agents run wild without oversight, and you get hit with scraping spikes, massive cloud bills, inventory hoarding, and outright fraud.
This exact dilemma is why Forrester retired the old “bot management” moniker in their Q2 2026 Wave report. The new playground is called “Bot and Agent Trust Management Software”.
The bottom line? We have to evaluate the actual intent of incoming traffic.
DataDome’s play for real-time intent visibility
DataDome secured the highest score in the Current Offering category for Q2 2026. In fact, they managed to sweep the maximum possible score in all 12 criteria, particularly standing out in areas like AI agent trust management, intent visibility, innovation, and rapid adoption. They’ve been talking about intent-based detection since way back in early 2025.
They look at the behavior across the entire session to determine if an AI assistant is checking out a cart or if a malicious script is brute-forcing logins. We are seeing them roll out features like Priority Protect, which essentially works as a virtual waiting room that helps you prioritize human buyers and allow authorized AI agents to complete checkouts. This stops you from blocking good bots that are trying to spend money.
On top of that, their management console lets you use generative AI to summarize report takeaways.
The counter-offensive: Kasada
Kasada approaches the problem by trying to make the platform invisible. Their setup basically aims to make life hell for attackers by dynamically changing the client-side code so bots can’t reverse-engineer it. They’ve introduced AI Agent Trust and Account Intelligence, which maps out connections between users, devices, IPs, and active sessions. This is all visualized beautifully in their Graph Explorer.
Strong performers with specialized focus areas
Arkose Labs leans into identity and credential protection with their Arkose Titan platform. They deploy invisible proof-of-work challenges alongside their classic visual challenges to slow down bot runners, driving up the computing cost for attackers until they simply give up. Their big win is what they call “telltales”: clear, explainable indicators tied to their detection models that show why a request was flagged.
Then again, some advanced users might find the managed service model a bit too hands-off when they want to make rapid, self-service configuration changes.
CHEQ took a different path by acquiring Deduce to bolster their identity fraud capabilities, building on their historic strength in marketing and ad fraud prevention. If you are deeply integrated with tools like Adobe and want to make sure your marketing attribution data isn’t being skewed by headless browsers, CHEQ offers a massive library of marketing and e-commerce integrations. On the security side, though, their explainability is a bit rough around the edges – you’ll find yourself staring at cryptic numerical reason codes in the dashboard that require a decoder ring to understand.
Netacea stands out by running exclusively on the server side, focusing on behavior analysis of API calls and backend traffic. This is useful for stopping scrapers from cloning your inventory, and they even let you register upcoming “hype sales” so their SOC team can monitor the surge.
The downside is their pricing structure, which is complex with onboarding fees, platform fees, usage bands, and support costs.
Scaling up with the contenders: hCaptcha and Google
If privacy is your team’s absolute, non-negotiable priority, hCaptcha is a fascinating option. Run by Intuition Machines, they focus on keeping data localized and letting you run “private learning,” which shows how different data enrichments alter detection without shipping your raw logs off to a third-party server. They are technical and API-first, though their management console is historically clunky and feels like it was designed by engineers, for engineers.
And then we have Google. They are in the middle of rebranding and leveling up reCAPTCHA Enterprise into Google Cloud Fraud Defense. If your infrastructure is already buried deep within the Google Cloud Platform (GCP) ecosystem, it makes sense to leverage it, but it is basic.
Google has some glaring gaps in the agentic era. Their out-of-the-box library of AI agents is currently non-existent, while their basic reporting on intent only breaks out detailed traffic data for the top four AI agents. If you want granular visibility into why a specific crawler is scraping your pricing API, Google’s dashboard is going to leave you squinting.
- DataDome (Leader): Under two milliseconds to spot intent. They swept up 12 top scores in the Wave—covering agent trust, intent visibility, innovation, and rapid onboarding. Priority Protect keeps checkouts open for real buyers. The console lacks internationalization though.
- Kasada (Leader): No CAPTCHAs, which is a massive relief. Their Graph Explorer maps out sessions, devices, IPs, and user accounts so you can spot anomalies. Their team manages the day-to-day tuning—great for offloading work—but you won’t get much dashboard customization.
- Arkose Labs (Strong Performer): They raise computing costs for hackers using silent proof-of-work checks and puzzles. “Telltales” use AI to summarize exactly why a request looked shady. If you want deep self-service tweaks, their heavily managed model will feel too restrictive.
- CHEQ (Strong Performer): Built to stop automated junk from wrecking your marketing attribution and ad spend. They bought Deduce to help with identity fraud and they integrate directly with Adobe. The catch is staring at cryptic numeric codes trying to guess why someone got blocked.
- Netacea (Strong Performer): They ignore client-side JavaScript entirely, focusing on server-side behavior. Excellent for catching scrapers, and they let you register upcoming hype sales. Prepare for billing headaches—they charge for onboarding, platforms, usage, and support separately.
- hCaptcha (Contender): Built for the privacy-obsessed. “Private learning” lets you run model training without throwing raw customer logs at third-party servers. The API-first approach is powerful, but the clunky, engineering-heavy UI feels like something designed in a dark basement.
- Google (Contender): They are turning reCAPTCHA Enterprise into Google Cloud Fraud Defense—handy if you are already buried in GCP bills. The dashboard supports hundreds of languages, but you don’t get an out-of-the-box agent library and the basic reporting is highly bare-bones.





