Managed Security Services, AI/ML, MSSP, MSP, API security

The next managed security service: Deciding which AI agents get in

COMMENTARY: AI agents are being used in business, but most still have no clear way to decide which agents should be trusted, what they should be allowed to access, or how those rules should change over time. That is where the managed service opportunity comes in. The tools can identify the traffic and enforce a policy, but someone still has to make the judgment call behind it. For MSSPs, this is about moving beyond simply blocking bad bots and helping customers manage agent access as an ongoing security function. It is practical, repeatable work, and it becomes more valuable as customers add more agents and more automated workflows.


For most of the last decade, bot defense was all about helping your customers answer two yes-or-no questions. Is that thing hitting your application a machine? If yes, do you want it there?

The product was there to catch bad traffic, and the better the catch rate, the better the renewal. Catching bad traffic is still part of the job, but it is becoming something every competent provider can deliver to roughly the same standard. What your business can compete on - what differentiates it and earns a margin - is permission.

From detection to permission

Automated traffic used to sort into two boxes: good bots to let in, bad bots to keep out. With the emergence of AI agents, there is now a third kind of automated traffic to deal with. When one of your customers' end users asks an AI assistant to compare flight prices across three airlines, the assistant doesn't open three browser windows; it calls three airline APIs on the user's behalf. When a procurement team uses an enterprise AI tool to pull supplier pricing, the tool fans out across vendor catalogs. When a sales rep asks their AI to research a prospect, the agent queries half a dozen SaaS platforms in the time it would have taken to log into one.

These agents behave like bots because they are bots. They retrieve data, submit forms, and call APIs. But the only thing separating a wanted AI agent from an unwanted one is whether a user asked it to act, and that intent isn't visible in the request.

The reflex in the channel is to treat this as a detection problem with a detection answer: sharper fingerprinting, better behavioral signals, a more capable product to put in front of your customer. That work matters, and it is not wrong; classification is where defense starts. But it is no longer where defense ends, because detection has run into a question it cannot answer. It can confirm that a request came from a bot, but it cannot tell you whether your customer wanted that bot there.

Why permission becomes a managed service

Here's where permission comes in. This is the work of deciding, for each customer, which automated agents may reach which systems, and on what terms, before the request arrives. Unlike detection, that work earns its margin from judgment, not labor. Each new customer you take on adds a set of access rules to maintain. It does not add a stream of alerts you have to staff.

Bot traffic is concentrated in the US. Thales's 2026 Bad Bot Report found the United States was the most targeted country for bot attacks last year, absorbing 59 percent of them, and the most targeted by AI bots specifically, taking 49 percent of that traffic. No other country comes close on either count. Automated requests now make up 53 percent of all internet traffic, and AI-driven attacks rose more than tenfold in a year.

The report also found something that should change how you price your time. Among declared, well-behaved AI - agents that identify themselves, close to nine percent of crawler sessions and almost eleven percent of fetcher sessions trip the same rules built to stop malicious bots. Each one is a legitimate agent; your rules are being treated as an attack. In a managed relationship, that misfire is not abstract. It is your customer's AI assistant getting blocked, your customer's complaint, and a support ticket with your name on it. The cost of getting permission wrong now lands on whoever manages the rules, and increasingly, that is you.

What's tricky is that permission has no default setting. So much is specific to each customer: what an API is for, what abuse looks like in their business, and which automated traffic is actually a paying user whose AI agent is acting for them (in other words, traffic you can't afford to block).

Deciding on permissions cuts across several functions - the application owner, the fraud team, sometimes the commercial side - and it changes as the customer's business changes. That is advisory and managed work, not a license, which is exactly why it is yours to own.

Doing this across many customers turns your scale into an advantage instead of a burden. A single enterprise can tune its own agent policy once and live with it. You are running the same decision across dozens of customers, which demands consistency, repeatability, and an explanation ready for each one. That consistency is the thing no single customer can reproduce alone. Get the platform underneath right and the practice scales.

Well, you might argue, customers buy products, not policy work, and they won't pay you to write rules. But this underestimates how buying is changing. The product that classifies traffic and enforces each allow-or-block decision is something you license and resell, as you always have. What a customer can't buy off the shelf is the decision behind it: which agents to permit for their business, configured correctly and kept current as that business changes. Detection isn't being replaced: it's still there, and now the decision sits on top of it. Resell the product alone and you compete on price, because every rival can license the same one. But own the decision, which is learned from a customer's traffic and refined as it changes, and you become hard to replace, because that understanding is specific to them and deepens the longer you hold the account.

Building this practice depends on three capabilities underneath it. Authorization starts with identification, so you need real-time visibility into which agents are reaching which applications and APIs. You need an identity that persists across sessions, so an agent stays known as it rotates addresses and fingerprints. And you need a human layer that tunes the policy and can explain every decision to a customer. This is the one thing automated detection cannot do alone. Together, that is a managed service with a platform behind it, and those platforms already exist. You are not waiting on technology to build this.

The new measure of value

For years, you proved your worth by how much you blocked: the catch rate, the volume of hostile traffic kept out. That number still counts. It's just table stakes now, because every competent provider catches traffic at roughly the same rate. What sets your price is how well you decide what to let through: which agents, into which systems, on whose authority, and why. Sell a customer a bot-blocking product and you've sold them a commodity, one that any rival can match line for line. Sell them the decision behind it, tuned to their traffic and defensible to their board, and you've sold them something no one else can replicate. That's not a product refresh. It's a managed service that gets stickier every year, because each new AI agent a customer adopts adds another decision to the set you already own.

You can license the visibility into which agents are reaching which systems, and the identity that persists as they rotate. The policies and the expertise behind them you build yourself, and that part you can start on right now. Run an agent audit on your three largest accounts: which automated traffic they already receive, which of it they want, and which of it they are currently blocking by mistake. Write one default agent policy you can adapt per account rather than drafting from scratch each time. Name one person who owns the allow decisions and can explain any of them to a customer.

The time to build AI agent authorization into your managed services is now, before customers begin asking which AI agents they can trust. The first one to ask won't wait while you work out an answer. They'll ask a provider who already has one.


MSSP Alert Perspectives columns are written by trusted members of the managed security services, value-added reseller and solution provider channels or MSSP Alert's staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Sammy Kinlaw

Sammy Kinlaw is VP Americas Channel Sales at Thales.

You can skip this ad in 5 seconds