Ecommerce Insights

Digital shrink meets AI bots: protecting UK online stores without punishing shoppers

Cloudflare’s retail analysis citing the National Retail Federation’s 2025 report puts the pressure in numbers retailers already feel: **ecommerce fraud up 55%**, and **71%** of retailers seeing a sign

Cloudflare’s retail analysis citing the National Retail Federation’s 2025 report puts the pressure in numbers retailers already feel: **ecommerce fraud up 55%**, and **71%** of retailers seeing a sign

Retail “shrink” used to mean missing stock in a stockroom. Online, it looks like emptied carts that never checkout, scraped catalogues feeding rivals and LLMs, credential stuffing against customer accounts, and loyalty points drained by automation. The common thread is business-logic abuse, not only perimeter hacking.

Cloudflare’s retail analysis citing the National Retail Federation’s 2025 report puts the pressure in numbers retailers already feel: ecommerce fraud up 55%, and 71% of retailers seeing a significant rise in fraudulent returns. Separately, 85% of retailers say they are looking to AI to detect or prevent fraud — which raises a practical question for UK SMEs: where should that intelligence sit, and how do you avoid turning every checkout into a CAPTCHA obstacle course?

The new shape of automated threat

OWASP’s Automated Threats catalogue calls out denial of inventory (OAT-021): bots add high-demand SKUs to thousands of carts and never pay. Legitimate customers see “out of stock”; physical stock sits idle; peak demand passes; margin dies in markdowns. Cloudflare frames this as “phantom shrink” — loss that never shows as a chargeback but still destroys contribution.

Scraping has changed character too. In a September 2025 engineering post, Cloudflare reported that by mid-2025 nearly 80% of AI bot activity on its network was crawling for model training — a sharp rise year-on-year. Modern scrapers rotate residential proxies, mimic browsers, and follow plausible paths. A single request may look human against global traffic; against your store’s baseline, the behaviour is absurd: alphabetical product walks, zero cart interaction, sub-second dwell on every PDP.

Why one-size-fits-all bot scores are no longer enough

Classic signals (odd User-Agents, datacentre IPs) still catch lazy bots. They fail against residential-proxy fleets and AI-assisted agents. Cloudflare’s response has been twofold:

  1. Global fingerprinting — heuristics across HTTP/2 fingerprints, TLS Client Hello behaviour, and challenge-derived client signals; over a seven-day window their teams reported 11 billion requests linked to residential or commercial proxy networks in one snapshot they published.
  2. Per-customer behavioural models — baselines of normal for each zone, then anomaly detection. Early scraping detections flagged 138 million scraping requests in 24 hours across just five beta zones, with 34% of those requests not caught by prior bot-score logic alone.
Enterprise Bot Management exposes a Bot Score from 1–99 (`cf.bot_management.score`) for WAF rules, rate limits and Workers. Lower scores mean more likely automation. Verified good bots (search crawlers, monitoring) can still be allowlisted. The operational art is path-aware policy: stricter on login, add-to-cart and checkout; lighter on public browse — and challenges that use privacy-preserving Turnstile rather than endless picture puzzles.

Client-side and payment trust still matter

Not all shrink arrives as a bot swarm. Magecart-style skimmers and injected checkout scripts steal cards from the browser. Cloudflare cites Fossil’s use of Page Shield to monitor unauthorised script changes. Baymard’s abandonment research still finds 19% of users leaving because they did not trust a site with card details — trust UX and technical integrity are the same commercial problem.

UK Finance’s 2026 payments summary adds local colour: in 2025 online card spending grew 4% by volume but only 1% by value, with about 45.9 million adults (80% of UK adults) buying online. Wallets and one-click checkout are rising; so is the need for fraud controls that do not undo that convenience. IMRG’s 2026 outlook also flags AI-powered fraud growth as a margin risk for unprepared retailers.

A proportionate defence for UK SMEs

  • Map critical journeys: login, account create, add-to-cart, apply voucher, checkout, returns portal.
  • Rate-limit and score APIs as carefully as HTML — headless and mobile apps are soft targets.
  • Separate verified bots (SEO, uptime) from scrapers and hoarders.
  • Prefer invisible trust signals (Turnstile, device/session signals) over blanket CAPTCHAs.
  • Monitor inventory hold patterns and voucher abuse, not only HTTP 403s.
  • Keep human review for edge cases — false positives at checkout are self-inflicted shrink.

Why this matters for Clarity Growth

Clarity Growth designs ecommerce security as part of operations: Cloudflare bot and WAF policy, Shopify-compatible hardening, checkout integrity, and monitoring that protects margin without kneecapping paid traffic. For UK scale-ups heading into peak, bot management is stock and trust protection — not a bolt-on “IT ticket”.

Sources

  1. Cloudflare — Combating digital shrink with AI (theNET) — https://www.cloudflare.com/the-net/retail-digital-shrink-ai/
  2. Cloudflare Blog — Building unique, per-customer defenses against advanced bot threats in the AI era (23 Sep 2025) — https://blog.cloudflare.com/per-customer-bot-defenses/
  3. Cloudflare Docs — cf.bot_management.score — https://developers.cloudflare.com/ruleset-engine/rules-language/fields/reference/cf.bot_management.score/
  4. Cloudflare — Bot Management product overview — https://www.cloudflare.com/application-services/products/bot-management/
  5. Baymard Institute — 40+ UX Statistics (cart abandonment reasons) — https://baymard.com/learn/ux-statistics
  6. UK Finance — UK Payment Markets 2026 Summary — https://www.ukfinance.org.uk/system/files/2026-08/PaymentMarketsReport_2026Summary.pdf
  7. IMRG — Expectations for online trading in 2026 — https://www.imrg.org/blog/expectations-for-online-trading-in-2026/

Start with the friction. Build the capability.

Clarity Growth helps organisations identify, design and implement practical automation opportunities across existing systems and workflows.