Good and bad bots: verifying the AI agents that act for us

Good and bad bots: verifying the AI agents that act for us

In April 2025 I came across this TechCrunch article: Amazon's new AI agent will shop third-party sites for you.

Why does it deserve a post? We have a fair amount of clients that have communities or sites that require user registration and logon. One of the problems we encounter on a regular basis is DDoS attacks, Spam Attacks and other things generally generated by bots.  These attacks can bring down the site, fill it up with rubbish content or generally just waste the site owner's time fighting whatever is happening.  I would label these as bad bots, companies like Cloudflare and Akamai have services to stop these bots.  As a software developer we add in reCAPTCHAs (not my favourite option), honey traps, measure time to fill in the form and several other techniques to slow bots down or stop them entirely.  Let’s call these malicious bots “bad bots”.

AI Agents introduce a new problem, good bots.  They are trying to do a job for us, but are not human and will behave in the same way as a bad bot. A simple solution might be to track the IP addresses these bots are coming from. But that approach is flawed, after all, it’s entirely possible for a malicious AI agent to operate from a reputable platform.

To address this, I’d like to propose a decentralized identity and verification system for bots using Web3 principles. It would be along the same lines as ICANN registration for DNS being a separate registrar that allows bot creators to register their identities, declare their purpose and authenticate that they are genuine. This would allow platforms to distinguish between verified, trustworthy agents and potentially harmful or spoofed bots.

Imagine an AI bot called ProductOrderBot:

  • The creator registers it with a smart contract.

  • A verifiable hash of the bot’s core model is stored.

  • An NFT is minted and tied to the bot’s deployment.

  • Whenever someone calls the bot via an API, it sends its NFT address + DID signature.

  • Apps can check the smart contract or the NFT metadata to confirm it’s the real ProductOrderBot, not a knockoff.

There are other alternative ways to achieve the above, maybe using certificates.

As AI agents become more common, we’ll need new tools—not just to stop the bad bots, but to understand and verify the good ones. Web3 might just offer the framework we need.

The Online Safety Toolkit: 4 Roads' automated safety for Verint Community.

First published on LinkedIn on 7 April 2025.

Want to talk about any of this?

We build online communities, self-service and the software behind them. If something here is a problem you have, we would like to hear about it.

Let's chat

More insights

All insights