AiGENTiA InsightsAgentic Economy
Agentic Internet and the Code of Business Conduct
30 August 2026
Commercial norms were written for actors with human limits — fatigue, attention, a working day. Agents have none of them, and the old code of conduct does not bind what it never anticipated.
This essay is still being written. The outline below is the argument it will make.
Every commercial code of conduct written over the last three centuries rests on an implicit physical premise: the entity on the other side of the transaction experiences fatigue, possesses limited attention, and operates within the bounds of a working day. Commercial contract law, trade custom, and corporate ethics guidelines were not designed to restrain pure malicious intent; they were designed to govern human actors whose natural constraints limit the speed, volume, and repetition of their actions.
Autonomous software agents possess none of these human boundaries. They do not sleep, they do not suffer cognitive strain, and they do not pay an operational penalty for initiating ten million micro-negotiations in a single second. The old codes of business conduct do not bind what they never anticipated.
The unwritten rules of business assumed a human body behind every desk
The legal foundation for automated commerce was laid decades ago under frameworks like Section 14 of the Uniform Electronic Transactions Act, codified in statutes such as Texas Business and Commerce Code Chapter 322 (UETA § 322.014). UETA established that a contract may be formed by the interaction of electronic agents even if no human actively reviews the transaction.
That framework answered a narrow question: whether automated electronic data interchange (EDI) orders were legally binding. It assumed static, deterministic software carrying out explicit, predictable human rules—such as an inventory system automatically reordering paper when stock drops below fifty units.
UETA did not anticipate generative, probabilistic agents capable of autonomous negotiation, micro-arbitrage, or continuous API polling across the Agentic Internet. Traditional business norms rely on soft friction. A vendor assumes that a prospective client asking for fifty custom quotes is constrained by the time it takes to draft an email. A broker assumes that a buyer submitting bids is paying an attention cost for every active position.
Existing contract law settles whether an automated transaction is legally enforceable; it does not protect a enterprise’s economic logic when an agentic counterparty uses zero operational friction to drain server compute, extract proprietary pricing structures, or lock up commercial inventory without completing a purchase.
Machine scale transforms benign commercial tactics into systemic attacks
The scale of machine interaction on the public internet has crossed a historic threshold. Automated machine traffic has officially surpassed human activity, representing 57.5% of all web requests compared to 42.5% for humans, driven by a 7,851% year-over-year surge in agentic AI requests according to Cloudflare Radar & Forbes Analysis and the Cloudflare Radar Platform.
Broader web traffic studies confirm that automated traffic now accounts for over 53% of overall web traffic, with malicious or unauthenticated bots comprising 37% globally. In high-velocity commercial sectors like travel and retail, bot traffic accounts for between 45% and 53% of all network activity, as detailed in the Imperva 2025 Bad Bot Report and Imperva AI Bot Traffic Analysis.
This transformation is not limited to passive web crawling; it is reframing commercial transaction pipelines. Analysts at Gartner project that autonomous AI agents will intermediate $15 trillion in B2B transactions by 2028, according to the MarketScale / Gartner Report on Zero-Click Commerce.
By that same year, autonomous AI agents are projected to outnumber human sales representatives 10-to-1, while 60% of commercial consumer brands will rely on agentic AI to execute direct, one-to-one customer interactions, as reported in the Gartner Press Release: AI Agents Outnumber Sellers and Gartner Press Release: Agentic AI in Marketing.
At the retail layer, Bain & Company forecasts that US agentic e-commerce will reach $300 billion to $500 billion by 2030, while McKinsey projects global orchestrated agent revenue will hit $3 trillion to $5 trillion, cited in the Commercetools Agentic Commerce Benchmark Report 2026.
When software agents operate at this magnitude without moral or physical limits, routine tactics become predatory. In the airline industry, unauthorized aggregators deploy automated agents to execute “seat spinning”—initiating ticket reservations and holding seat inventory right up to the payment step without settling the invoice.
By cycling holds across thousands of instances, agents trigger revenue algorithms to register artificial scarcity, forcing prices up so secondary market brokers can capture an arbitrage spread. Detailed investigations by Cequence AI and Imperva show how this strategy undermines core airline yield management without violating traditional network security protocols.
When two unmonitored agentic systems interact without human intervention, the absence of human operational boundaries can break price discovery entirely. On Amazon, two dynamic pricing algorithms selling an out-of-print biology textbook (The Making of a Fly) entered an unbounded feedback loop. One algorithm was programmed to continuously price its copy 27% higher than its competitor; the competitor’s algorithm was programmed to automatically match the lower market price.
Unchecked by human common sense, the agents escalated the textbook’s price to $23,698,655.93 plus $3.99 shipping before a human noticed weeks later, a phenomenon documented by the New Statesman. Software does not experience shame, nor does it step back to evaluate whether an outcome makes sense.
Instanced identity destroys the economic engine of corporate reputation
Defenders of traditional market discipline argue that existing corporate codes of conduct remain sufficient. They contend that reputation, credit ratings, and the prospect of repeat business will naturally deter abusive AI behavior.
This argument ignores the structural difference between a corporation and an instanced agent.
Human business conduct relies on identity stickiness. Building a reputable corporate brand takes years; destroying it carries immense financial friction. An AI agent is instanced. An operator can spin up ten thousand discrete sub-agents in milliseconds, assign each an ephemeral API key or proxy IP address, and burn those identities the moment an objective is met or an abuse filter is triggered.
Because an instanced sub-agent bears zero long-term reputational risk, the fear of brand damage ceases to function as a deterrent.
Traditional technical security controls fail for similar reasons. Systems administrators often rely on HTTP rate-limiting—restricting a single client IP to a fixed number of requests per minute—to maintain order. Rate-limiting restricts network request frequency, not economic intent or operational commitment.
An array of distributed sub-agents can comply with rate limits while systematically executing seat-spinning strategies, harvesting proprietary database models, or spamming micro-negotiation queues. The network traffic appears clean; the business logic is systematically compromised.
A code for software counterparties must enforce commitment at the protocol layer
A code of business conduct written for the Agentic Internet cannot rely on voluntary compliance, ethical norms, or legal post-mortems. It must enforce commercial rules programmatically at the point of interaction.
This structural shift is already taking shape across foundational web infrastructure. To prevent autonomous agents from hitting 5,000 separate web pages to evaluate a single consumer offer—burning origin server compute and HTML overhead—infrastructure providers are rebuilding content delivery.
Cloudflare introduced Markdown for Agents alongside a native implementation of HTTP 402 (“Payment Required”) titled Pay Per Crawl, documented in the Cloudflare Blog and Cloudflare Pay Per Crawl Documentation.
Instead of allowing free scraping under the assumption of fair use, web infrastructure now forces autonomous software agents to negotiate explicit machine-readable formats (Accept: text/markdown) and attach micro-payments directly to request headers before serving content.
At the tool integration layer, standards like Anthropic’s Model Context Protocol (MCP) establish open protocols for how autonomous software agents discover, authenticate, and execute actions across enterprise endpoints, as outlined in the Model Context Protocol Specification and Anthropic MCP Announcement.
Governments are beginning to enforce matching legal obligations. The European Union’s Regulation (EU) 2024/1689 (EU AI Act) explicitly mandates transparency obligations under Article 50, forcing deployers to ensure software agents self-identify during transactions and maintaining strict liability trails for automated decisions.
Significant legal and technical gaps remain. Courts have not settled liability frameworks for probabilistic LLM “hallucinations” during dynamic automated contract negotiations. If an autonomous buying agent misinterprets a prompt and commits to purchasing inventory at ten times market value, deployer liability remains legally ambiguous.
Furthermore, the market lacks a universally adopted cryptographic “Agent Provenance” standard—such as W3C Verifiable Credentials tailored for agents—that binds an ephemeral sub-agent to a verified financial principal in real time.
A modern code of business conduct for software counterparties must contain three explicit elements:
- Protocol-Bound Financial Commitments: Software agents cannot hold inventory, request bespoke pricing, or occupy negotiation queues without posting programmatic micro-bonds that are automatically forfeited if the agent abandons the transaction.
- Cryptographic Identity Attribution: Ephemeral sub-agents must present verifiable credentials linking their execution environment directly to a legally accountable corporate entity and a specific financial wallet.
- Machine-Readable Terms of Engagement: Terms of service can no longer exist solely as natural-language text in a footer. Commercial constraints—such as acceptable query volume, allowable micro-arbitrage bounds, and re-negotiation limits—must be served as machine-readable policy declarations that agents must parse and sign prior to access.
Defending enterprise logic against software buyers requires active economic friction
For enterprise leaders operating in a business-to-agent (B2A) or agent-to-agent (A2A) marketplace, waiting for legal reform is a terminal mistake. Companies trading against external software agents today must update their operating posture immediately.
We do not protect enterprise logic by blocking machine traffic; rather, we protect it by pricing machine intent.
First, convert passive web terms into active programmatic contracts. If your price discovery endpoints, inventory databases, or booking channels are accessible to agents, require API authentication backed by financial micro-stakes.
If an agent wants to query real-time pricing or initiate a transaction hold, require an HTTP 402 micro-payment or dynamic collateral deposit. This simple hurdle eliminates zero-cost seat spinning and high-frequency data harvesting overnight without turning away legitimate automated buyers.
Second, deploy an agentic operating posture on defense. Autonomous buyer agents will find every inconsistency in your pricing models, exploit legacy coupon logic, and exhaust human customer support channels if those channels are left open to machine queries.
Enterprise architectures must employ specialized agentic management systems that inspect incoming traffic for economic intent, enforce machine-readable rate and intent constraints, and negotiate directly with counterparty agents at wire speed.
Commercial norms were once enforced by human friction and corporate memory. On the Agentic Internet, they are enforced by code, micro-economics, and cryptographic verification.
The contract was written for a human world. The counterparty is software.