The New Analytics Blind Spot: AI Traffic & AI Agents That Shop Without Visiting Your Site

This blog was originally published on March 3, 2025 and updated on July 22, 2026.

Is That "Web Visitor" an Agent or a Human? 

Back in January 2025, OpenAI’s Operator became the first true "AI agent" to hit the market, available to ChatGPT Pro users. We ran an early experiment to see how it would show up in GA4, and the results were strange enough that we wrote about them in the original version of this blog.

A lot has changed since then. Operator itself is gone: OpenAI deprecated it on July 17, 2025, eventually folding its capabilities into the broader ChatGPT agent experience. Its successor on the browser side is ChatGPT Atlas, a native Chromium-powered browser for Mac OS that launched in late 2025.

More importantly, this is no longer a one-agent problem. What was a single product to track in early 2025 is now a multi-vendor field, and the analytics challenge we described for OpenAI's Operator applies to all of them.

So here's where we started, what we learned, and what's changed since our original testing.


The Current Players in the AI Agent Space

As of July 2026, the current players in this space are: 

  • ChatGPT Atlas (OpenAI): Launched in fall 2025 as a native Chromium-powered browser for Mac OS, with agent mode available to paid tiers. Atlas is effectively Operator's successor: the same underlying capability, now built directly into the browser instead of shipped as a standalone product, with a built-in virtual browser for completing tasks on a user's behalf.
  • Perplexity Comet: Launched summer 2025 on Windows and Mac, followed by Android in November 2025 and iOS in March 2026. Built on the Blink Chromium engine, with a native sidebar assistant capable of automating tasks and completing purchases.
  • Google Project Mariner: Available to Google AI Ultra subscribers in the U.S. since 2025, with its agentic capabilities being folded into the Gemini API and AI Mode in Search. Google has said it plans to bring Mariner's agentic features into search-driven tasks like event tickets, restaurant reservations, and local appointments, working with partners including Ticketmaster, StubHub, Resy, and Vagaro.
  • Claude Cowork (Anthropic): Rolled out widely to paid tiers in mid-May 2026, integrated into the Claude desktop app. It operates within a dedicated local folder to manage files and execute multi-step workflows autonomously.

Each of these has different detection characteristics, and each is growing its user base quickly. As you'll see below, the problem has also expanded well beyond asking "can we detect a visit?" to "can we even see the transaction at all?"


Our Original Test: OpenAI's Operator Showed Up in GA4 as Bing/Organic

We tested Operator on our Seerinteractive.com website, expecting GA4 to track it as direct traffic or (possibly) referral traffic from ChatGPT. Instead, it showed up as Bing/organic traffic. 

That raised a bigger question at the time: how do you accurately track an AI agent's traffic?

What We Expected vs. What Actually Happened

Usually when web activity isn't human controlled, GA4 logs it as direct traffic (if no referral data was present) or filters it out entirely as bot activity. Our test visits from Operator consistently appeared as Bing/organic, which was unexpected.

We learned that this was a nuance of agentic traffic more broadly. If you told Operator to go visit a site like seerinteractive.com, it showed up as direct traffic (with a source medium of direct / (none)).

But if you told it to go find Seer’s website, it behaved how a person would: it searched, and because ChatgGPT and Bing had a partnership, it searched using Bing. From there, it would click on an organic result or an ad, meaning your traffic could show up as Bing/organic or Bing/cpc.  

We ran through a series of diagnostic checks—browser type, version, OS, user agent, and more—but none of them reliably distinguished Operator traffic from normal user sessions. 

The Trap: To Catch an Agent, We Ran an Experiment

To understand how GA4 classified Operator traffic, we set up a controlled experiment. 

Our hypothesis was that Operator would carry a unique user agent string that would give it away. If we were right, we planned to add a custom dimension for User_Agent in Google Tag Manager (GTM) and GA4. This could help us distinguish agent visits from human ones with a high degree of accuracy.


The Plan: How We Tracked Operator Activity on Our Site

Selected Low-Traffic Pages – We mimicked a user session on pages with minimal daily visitors to isolate our test activity from real traffic. 

Launch Operator Sessions – We had Operator visit the selected pages and click on CTA buttons that would trigger our key events under controlled conditions. 

✔ Tracked GA4 Session IDs – We planned to capture both Client ID and Session ID from the GA4 payload in the developer console's Network tab to identify the Operator session(s) during the test. We expected to see a series of sessions for each page Operator visited, but thankfully that wasn't the case.

Analyzed Source/Medium – We wanted to determine whether GA4 labeled the source of traffic as direct, none, or potentially ChatGPT/Operator referral.


The Headache: What Got in Our Way

  • Operator runs on Chromium – When we launched a session from our Windows laptop, we quickly learned Operator runs on a Chromium browser, which we hadn't planned for.
  • We couldn’t open the developer console in Operator – We'd planned to pull the Client ID and Session ID straight from the dev console's payload tab, but couldn't get Operator to open it. Instead, we had to identify the session after the fact using the Session ID in GA4 tied to our test activity.
  • User agent mismatch – To our surprise, we learned that Operator identified itself as a Linux operating system using Chrome. 
  • The traffic source / medium wasn't consistent – Agents are good at mimicking human behavior. Tell one to go directly to a URL, and it shows up as direct traffic. Tell it to go find a company and browse their offerings, and it behaves like a person would, running a search and clicking on an organic result or an ad.


The Solution: How CHEQ Helped Identify Our Operator Activity

The day after our test, while we were waiting for the GA4 data to fully process, we got an email from our friends over at CHEQ.ai. The CHEQ tag on our site had identified our single Operator session almost instantly, and we learned CHEQ's Threat and Traffic Intelligence Team had already been detecting and classifying this kind of activity in the background. 

While we ran our isolated test on Seerintereactive.com, CHEQ was analyzing thousands of attributes about visitors, browsers, networks, and devices across the million-plus domains they monitor daily. CHEQ built a reliable fingerprinting method using common attributes, user-agent and OS signals, and cybersecurity testing patterns. 

Back-testing against historical data, CHEQ found no sessions matching this pattern before January 2025, confirming the fingerprint was unique to Operator.

Full Disclosure: CHEQ is a Seer partner. We work with them and refer our clients to them because, unlike most of the vendors mentioned above, they work with marketers and security teams.

What's changed since Operator was discontinued: CHEQ, along with vendors like Human Security and DataDome, has since built updated detection for Atlas, Comet, and Mariner. But that detection requires active configuration. If you're using one of these tools, you need to explicitly tell it to recognize and allow legitimate agentic browsers through, rather than assuming it'll happen on its own.


Key Findings, Then and Now

Then: Some Operator AI-Agent showed up as Bing organic or paid traffic. A steady, unexplained increase in Bing traffic might not have been humans visiting your site…it could have been AI agents.

Now: That underlying pattern (where agents that have to search for a site route through Bing) turned out to be a real, generalizable signal about how agents behave when they don't have a direct URL. But the specific fingerprint we relied on to catch Operator, a Linux OS presenting as Chrome, was unique to that one product and is now obsolete. ChatGPT Atlas, Operator's successor, presents a completely standard Chrome user agent string and blends into human traffic by default.


The AI Traffic Challenges That Analytics Teams Are Facing Today

It's no longer a question of whether AI agents will become a meaningful share of your website traffic. For many sites, they already are.

Human Security documented a 6,900% year-over-year increase in automated agentic network activity in its late-2025 technical briefings. During Cyber Five 2025 (Black Friday through Cyber Monday), overall agent traffic grew 28% compared to the prior five days, and agent traffic specifically targeting ecommerce sites surged 144%.

As agent traffic rises, teams are facing new analytics and tracking challenges on multiple fronts. 

Analytics Problem #1: Multiple Failure Modes

The analytics problem itself has also split into two genuinely different failure modes, and it's worth understanding both if you're trying to track down which agents are hitting your site.

Failure Mode A: Invisible Crawlers. Think GPTBot, ClaudeBot, and similar. These request raw HTML and move on. They don't execute JavaScript, so your GA4, Adobe, or Amplitude tags never fire. These visits are entirely invisible to client-side analytics and only detectable through server logs. They're not distorting your data; they simply aren't in it.

Failure Mode B: Agentic Browsers. Think Atlas, Comet, Mariner, and Cowork. Just like real users, these run full Chromium engines, fire your tags, click buttons, add items to carts, fill out forms, and abandon sessions. GA4 counts every one of these sessions as a real visitor, generating events that look exactly like human behavior. Left unchecked, that traffic can quietly train your ad platforms on non-human intent signals and corrupt your optimization efforts.

Legacy techniques like CAPTCHAs, IP blocking, and user-agent filtering remain largely ineffective against AI agents because they're engineered to look like real users​. And you don’t want to block all AI traffic indiscriminately, since LLMs still need to index your site to find answers and train their models (and some of that traffic is genuinely valuable). 

Analytics Problem #2: Off-Website Transactions

There's now a third layer the original experiment and blog didn't touch at all: commerce happening off your website entirely.

This may be the most structurally disruptive shift since Operator first launched. The question you have to answer has become more complex: "how do we measure revenue when agents complete purchases without ever visiting the website, or doing so in ways we've never had to account for?"

OpenAI, Google, and major ecommerce platforms like Shopify are now building ways for people to complete purchases directly inside an AI chat, without ever landing on the merchant's website. The chat interface handles the browsing and checkout experience, while the payment and order still process through the merchant's own systems behind the scenes.

That means you have no tracked website session or GA4 hit, and no attribution chain. The transaction and the revenue are real, but it's invisible to standard analytics because the customer never technically "visited" the site at all.

This isn't a hypothetical, either. Platforms that support this kind of in-chat checkout are already reporting meaningful, fast-growing volume of traffic and orders coming from AI tools. Every one of these orders is invisible to a standard GA4, Adobe, or Amplitude setup. There's real revenue flowing through a channel your analytics stack was never built to see.

How Analytics Teams Can Adapt to These Changes

  1. Understand the mix of humans, bots, and AI agents, and separate the two failure modes. Traditional bot filters won't catch agentic browsers, and server logs are the only way to see invisible crawlers. Segment traffic sources to get a clearer picture of real user behavior versus automated interaction, and build separately for the two problems.
  2. Recognize and adapt to AI-driven noise in analytics. Agentic browsers can inflate engagement, artificially depress bounce rates, and distort session duration. Consider AI-agent detection and filtering in your analytics stack (bot management tools, log file analysis, behavioral pattern tracking), and build new traffic classifications into your reporting for human visits, AI-assisted visits, and agent-driven API calls.
  3. Consider the impact on traditional metrics and KPIs. Conversion rates, click-through rates, and attribution models can all be skewed by unaccounted-for AI interactions. Agents can trigger events that look like conversions (such as adding to cart or filling out forms) without representing real purchasing intent. Track AI-assisted conversions separately from human conversions.
  4. Adapt SEO and digital marketing strategies. Search and discovery keep shifting toward AI-driven agents, meaning traditional search metrics may decline as more users rely on AI-powered recommendations. Optimize for AI crawlers (GPTBot, ClaudeBot, and others) in addition to traditional SEO, and treat agents as a distinct new referral source requiring their own tracking and attribution logic.
  5. Build visibility into agentic commerce, not just agentic traffic. This is the new addition: get visibility into orders placed through in-chat checkout. If your clients sell through Shopify, Etsy, or similar platforms, orders are already flowing through ChatGPT and Gemini that will never appear in your website analytics. That data lives in the merchant's order management system, not your analytics platform. Build the reporting bridge between the two now, before the volume makes the gap impossible to ignore.

Key Takeaway: Marketers and analytics professionals must evolve their measurement strategies to differentiate between human engagement and AI interactions. Now, they also have to account for AI-driven revenue that never touches their analytics stack. That means refining methodologies, updating KPIs, and building new tracking mechanisms to ensure reliable insights in an AI-powered digital landscape.


 

What You Should Do Next

If you’re a marketer wondering how your business will identify and understand AI traffic and AI-driven revenue to your digital assets, you’re not alone. Our original recommendations still hold true, but we've updated them based on the current state of agent traffic:

  • Identify AI-referral traffic using custom channel groupings. Not to brag, but we at Seer have been encouraging you to track AI traffic since 2023 when we first wrote about this topic. Set up an AI-search traffic channel in your analytics account. Whether you use Google Analytics, PiwikPro, or Adobe Analytics, we have you covered, and our regex formula can get you monitoring AI traffic today. 
  • Reframe your “When to Care” threshold. It's early days...but we've always believed in giving practical advice you can act on. Our colleague Teresa wrote about this in Analyzing AI Overview Data w/ Paid Conversions: Finding When to Care, which digs into assessing when AI-generated search experiences meaningfully impact a business, with a focus on revenue over visibility. We originally suggested a 5–10% traffic threshold for AI agents; that number has already been crossed for many sites, particularly in ecommerce. A more useful question today: what percentage of your Shopify or Etsy orders in the last 90 days originated from an AI service? That number is measurable right now, and it's almost certainly not zero.
  • Use a tool like Known Agents to understand AI-agent traffic volume. We're still in relatively early days for AI-agent detection, but tools like Known Agents are proving useful. Their client-side and server-side tracking gives you real-time analytics on AI agents, bots, and crawlers interacting with your site, including automatic robots.txt generation, protection against content scraping, spoofed-agent detection, and alerts for bot-driven traffic spikes. While the tool is limited in what it can tell you about an agent's actual session activity, it's a strong first layer for knowing which agents and bots are hitting your site, so you can prioritize where to focus.
  • Update your bot detection configurations. The original Operator fingerprint is obsolete. Vendors like CHEQ, Human Security, and DataDome have updated their detection for Atlas, Comet, and Mariner, but this isn't automatic. You need to actively configure these tools to recognize and allow legitimate agentic browsers onto your site, rather than blocking them by default.
  • Add server-side tagging. Invisible crawlers are only detectable server-side; client-side analytics will never surface them. Server-side tagging has moved from an advanced practice to a baseline requirement for anyone serious about measuring the real human-to-agent traffic mix.
  • Develop behavioral anomaly flags in your analytics setup. Bot detection vendors will always be playing catch-up to brand-new agents that haven't hit their fingerprint databases yet. In the meantime, there are a few directional signals you can build today: sessions with revenue events but near-zero duration; key-event completions missing their usual prerequisite steps (add-to-cart with no view-item, purchase with no add-to-cart); and direct landings on checkout URLs. None of these prove agent activity on their own, but together they're the best proxy available right now.
  • Get visibility into orders placed through in-chat checkout. If your clients sell through Shopify, Etsy, or similar platforms, orders are already flowing through ChatGPT that never touch your analytics. That data exists, it just lives in the merchant's order management system. Build the reporting bridge between order data and analytics data now, before the volume makes the gap too big to ignore.
  • Expect the most robust solutions to keep coming from bot detection vendors. Detecting agents (and understanding what they actually do once they land on your digital properties) remains a genuinely hard problem, even for experienced analysts. Watch for continued development from companies like CHEQ, Human Security, DataDome, Kasada, and Imperva, who remain at the forefront of bot and fraud detection. 

The agentic landscape is moving faster than almost anything else in digital analytics right now. We'll keep tracking how these tools evolve and report back with what we learn.  If you want to follow along, subscribe to our newsletter for the latest from the Seer team. 

If you’re running into similar challenges, let us know—this is very likely part of a larger measurement problem the whole industry is working through together. We want to hear from you!

John Lovett

VP Analytics

John Lovett is the Vice President of Analytics at Seer Interactive, where he leads the analytics practice with a focus on AI-assisted measurement and data strategy. With 20+ years in digital analytics, John is the author of The Big Book of KPIs and Social Media Metrics Secrets and past President of the Digital Analytics Association.

We love helping marketers like you.

Sign up for our newsletter for forward-thinking digital marketers.