HUMAN BLOG

Evaluating AI Agent Trust: HUMAN’s Agent Trust Levels

Read time: 5 minutes

Aaheli Guhathakurta

September 2, 2026

Agentic AI, AI, E-commerce

For those seeking convenience, online shopping has never been easier. In just a few keystrokes, AI agents are browsing websites, logging into accounts, researching products, and completing transactions on behalf of humans. Since 2025, HUMAN has observed a 7,851% year-over-year growth in agentic AI traffic across the web. But threat actors are getting in on the act, too, testing credit cards, scraping content, probing login endpoints, and making fake accounts.

The question organizations face is a simple one with a complicated answer. Which online activities can you trust to be safely AI-driven?

Legacy tactics like filtering traffic by IP addresses and user-agent strings may no longer be sufficient to separate good traffic from unwanted traffic. Many AI agents don’t share their true identity and come from residential IPs, while self-declared identity can be malicious or inaccurate. In fact, HUMAN’s Satori research found that 5.7% of traffic presenting as an AI crawler or scraper user agent was spoofed, underscoring why declared identity alone cannot establish trust. Without a structured framework for evaluating agent identity, businesses are now left choosing between two bad options: block all automation or allow it all blindly.

HUMAN introduces a layer of visibility with Agent Trust Levels, a core component of AgenticTrust.

What Is an Agent Trust Level?

AI agents observed by HUMAN are assigned a Trust Level score, classified by high, medium, or low trust. This score is HUMAN’s assessment of how trustworthy a particular agent is, based on a continuous evaluation of its identity, behavior, and verification signals. These trust levels inform default agent permissions by giving organizations a principled foundation for setting policies on what actions agents are allowed to take. An agent with a High Trust Level may warrant broader access, while an agent with a Low Trust Level is often restricted or blocked from sensitive workflows (think account creation or payment card information). The framework makes risk-based governance easier to understand at scale.

AgenticTrust includes three intuitive Trust Levels:

The Makeup of Trust

In assigning a Trust Score, HUMAN evaluates agents across five dimensions:

As agentic behaviors adapt and new agents are introduced, HUMAN continuously monitors these dimensions and updates an agent’s Trust Level accordingly. 

High (H) Trust Level

HUMAN assigns a High Trust Level to agents that can be verified via cryptographic key on each request. Cryptographic verification eliminates spoofability and substantially strengthens an agent’s identity claim. ChatGPT, for example, exposes its key and makes it discoverable by services that need to verify its identity. 

Beyond cryptographic verification, HUMAN may assign High Trust Levels to agents with a strong record of consistent behavior and transparent self-identification.

High Trust is neither permanent nor guaranteed. If an agent begins behaving maliciously or stops identifying itself consistently, HUMAN may lower its Trust Level even if cryptographic verification remains in place.

Medium (M) Trust Level

By default, all agents start at a Medium Trust Level. Agents typically remain here when they lack cryptographic verification but otherwise declare their identities through other signals or private indicators.

Because these agents do not use cryptographic verification, there is a risk of false negatives. Agent providers can move up by strengthening their verification posture, or move down if behavioral problems emerge.

Low (L) Trust Level

Agents with a Low Trust Level are unverified, easily spoofable, or exhibit inauthentic activity.

An agent may be demoted to Low if it inconsistently declares its identity, never provides a private signal to HUMAN, or relies on user agents that can be easily abused. HUMAN also assigns Low Trust Levels to agents with previous evidence of abuse, limited market adoption, or that have been deprecated.

These agents can also generate false positives, incorrectly identifying legitimate activity as suspicious, further complicating their reliability for organizations trying to build policy around them.

How Agents Can Increase Their Trust Level

HUMAN periodically reviews them using the five dimensions above and updates an agent’s level as its posture changes.

Agent providers can strengthen their Trust Level by:

High Trust is earned by positive behaviors with strong verification..

Why Trust Matters

Trust levels give organizations actionable context for governing agentic traffic. Rather than treating all bots and AI agents the same, customers can configure policies based on the level of trust.

Organizations rely on these trust levels to configure agentic permissions for specific categories like, “Content and Products”, “Engage”, “Account Creation”, “Checkout”, “Rate Limit”, and more to best suit their brand’s risk tolerance. Trust levels support safe agentic commerce, granular permissioning, fraud reduction, and clear risk thresholds for different business needs.

The future of the agentic web is defined by which agents are the most trusted.

Ready to take control of agentic traffic on your platform? Learn more about AgenticTrust or request cryptographic verification to elevate your agent’s Trust Level with HUMAN.

Get visibility and control over AI agents and agentic browsers on your website.
Spread the Word