On July 27, 2026, the Federal Trade Commission announced a $300,000 settlement with Elite Events and Tickets LLC, a ticket broker that used automated systems to purchase millions of dollars worth of tickets to more than 2,400 events. The company operated under the name “Smart Scalpers” and maintained a website at smartscalpers.com. The name was accurate.
Elite Events used 75 separate accounts to buy 277 tickets to a single Metallica concert at Virginia Tech University between September 2024 and March 2025. The ticket seller limited purchases to six tickets per buyer. Elite Events spent between $50 and $270 per ticket and resold them for $100 to $400 each. The company employed hundreds of agents, many based abroad, to operate multi-session browsers, generate thousands of unique virtual credit card numbers, and use IP proxy services to make purchases appear to originate from different consumers in different locations.
The FTC’s Director of the Bureau of Consumer Protection, Christopher Mufarrige, said: “Consumers should be able to purchase tickets to events without having to contend with bad actors who drive up prices and make it harder for fans to see their favorite artists and athletes.”
This case was brought under the Better Online Ticket Sales Act, known as the BOTS Act, which makes it illegal to circumvent security measures designed to enforce ticket purchase limits. The settlement imposes more than $10.7 million in civil penalties, partially suspended to $300,000 due to the defendants’ inability to pay the full amount.
The Elite Events case is about ticket scalping. But the enforcement logic it establishes has direct implications for agentic commerce, and the timing could not be more consequential.
The Technology Gap Between Scalper Bots and AI Shopping Agents Is Closing
Consider what Elite Events actually did. The company used automation to:
- Create hundreds of fake accounts with fictitious names, addresses, and phone numbers
- Generate thousands of unique virtual credit card numbers
- Use IP proxy services to mask the origin of purchases
- Deploy multi-session browsers to run parallel purchasing operations
- Employ human agents abroad to oversee the automated purchasing process
Now consider what a modern AI shopping agent does. ChatGPT Work, with GPT-5.6, can browse Amazon, compare products across retailers, and execute purchases. Amazon’s Project Moonraker, backed by $100 million, is building Alexa into an autonomous shopping assistant. Google’s Gemini integrates purchasing into its assistant. These agents operate across multiple sessions, use sophisticated browsing techniques, and can be deployed at scale.
The technological overlap is unmistakable. Both scalper bots and AI shopping agents use automation to interact with commerce platforms in ways that exceed human speed and volume. Both can create sessions that appear to originate from different users. Both process platform data and act on it without human review of each transaction.
The difference is intent. Elite Events used automation to corner inventory and resell at a markup. An AI shopping agent uses automation to help a consumer find the best product at the best price. But intent is not a technical signal. Platform security systems cannot distinguish between a bot purchasing 277 tickets for resale and an AI agent purchasing 277 products for 277 different users who happen to share similar tastes.
This distinction problem will define the next phase of agentic commerce regulation.
Why the BOTS Act Framework Cannot Scale to Agentic Commerce
The BOTS Act was passed in 2016 to address ticket scalping. It prohibits circumventing security measures that enforce purchase limits on ticketing websites. The law is narrow. It applies specifically to ticket sales, not to general e-commerce.
But the enforcement logic of the Elite Events case reveals principles that will need to scale to broader commerce:
Purchase limit circumvention is the core offense. Elite Events was penalized not for buying tickets, but for bypassing the technological controls that ticket issuers put in place to enforce fair access. Amazon and other marketplaces have analogous controls: purchase quantity limits, account verification requirements, anti-bot detection systems. When an AI shopping agent makes purchases on behalf of multiple users from a single IP address, or uses multiple sessions to complete transactions in parallel, it may trip the same anti-bot defenses that caught Elite Events.
The platform defines the rules. Under the BOTS Act, the legality of an automated purchase depends on whether the platform’s security measures were circumvented. This means the platform is the arbiter of what constitutes legitimate versus illegitimate automated purchasing. For ticketing, this is straightforward: Ticketmaster sets a six-ticket limit, and any automated system that bypasses that limit is violating the law. For general e-commerce, it is far more complex. Amazon’s terms of service prohibit certain forms of automated access, but enforcement is inconsistent, and the platform has commercial incentives to allow some forms of agent-driven purchasing while blocking others.
Individual liability applies. The FTC held Elite Events’ owners, Kevin McKerley and Aaron Fera, personally liable. They are permanently prohibited from engaging in the circumvention activities outlined in the complaint. If the same principle is applied to AI shopping agents, the developers and operators of agents that circumvent platform controls could face personal liability. This has implications for every company building agentic commerce infrastructure.
The Hopper Precedent: When the AI Platform Is the Deceiver
The Elite Events case is about a third party using automation to exploit a platform. The Hopper case, settled by the FTC on July 2, 2026, for $35 million, is about the platform itself using AI to deceive users.
Hopper, an AI-powered travel booking app, showed users a “total price” that was not the total price. It pre-selected optional fees and hid them below the fold. Its own employees knew the deception was happening. Internal communications referenced in the FTC complaint include an employee saying: “To me, the problem here is that we’re tricking users.” The company’s own internal testing showed that if the fees were adequately disclosed and unselected by default, most consumers would decline them.
Hopper is an AI platform. It uses machine learning for price prediction and recommendation. The deceptive pricing was embedded in an AI-mediated user experience. When a user asked Hopper’s AI to find the best deal, the AI presented manipulated pricing as if it were the complete picture.
Together, the Hopper and Elite Events cases define the two trust failure modes in agentic commerce:
- Platform-side deception (Hopper): The AI platform itself manipulates the data presented to users, and the AI processes this manipulated data as if it were accurate.
- Agent-side exploitation (Elite Events): Third parties use automation to exploit platform systems, distorting inventory access and pricing for legitimate users.
Both failure modes produce the same outcome: consumers receive worse outcomes than they would in a transparent, non-manipulated marketplace. And both failure modes are amplified when AI agents operate at scale.
EU Regulation Is Already Moving
While the FTC enforces existing laws against individual cases, the European Union is building a proactive regulatory framework that applies to AI-mediated commerce directly.
As reported by Bloomberg and confirmed by The Verge on July 29, ChatGPT search and Roblox have been designated under the EU’s Digital Services Act as Very Large Online Platforms, having surpassed 45 million monthly active users in the bloc. This designation imposes content moderation obligations, transparency requirements, and risk assessment duties. ChatGPT search will need to comply as soon as August 2026.
This is the first time an AI assistant’s search and recommendation function has been subject to DSA-level regulation. The implications for agentic commerce are significant. When ChatGPT search recommends a product, that recommendation is now subject to EU content moderation rules. If the recommendation is based on manipulated reviews, deceptive pricing, or sponsored placement presented as organic ranking, it may constitute a DSA violation.
The EU is treating AI-mediated product recommendations as a form of content that requires regulatory oversight. The FTC is treating platform deception and bot scalping as enforcement targets under existing law. Together, these regulatory frameworks are converging on a single conclusion: automated commerce needs trust infrastructure that does not currently exist.
The Trust Infrastructure Gap
Here is the structural problem. Agentic commerce is scaling. ChatGPT Work has shopping capabilities. Amazon is building autonomous purchasing into Alexa. Google Gemini integrates commerce. Meta is experimenting with commerce in messaging. Millions of consumers will use AI agents to make purchasing decisions in the next 12 months.
The trust infrastructure to support this scale does not exist. AI agents currently consult the marketplace’s own data: Amazon’s star ratings, search rankings, sponsored placements, and review counts. This data is commercially manipulated. The marketplace profits from the manipulation. The agent processes the manipulated data as structured input. The consumer receives a confident recommendation based on corrupted data.
The Elite Events case shows what happens when platform purchase limits are circumvented by automated systems. The Hopper case shows what happens when the AI platform itself is the source of deception. The EU DSA designation shows that regulators recognize AI-mediated commerce needs oversight.
What is missing is a structural trust layer that sits between the AI agent and the marketplace, providing data that the marketplace cannot manipulate.
What Trust Infrastructure Looks Like
Trust infrastructure for agentic commerce needs four components:
Independent review verification. Not Amazon’s star rating, which blends authentic reviews with fake and incentivized reviews. A filtered assessment that removes suspected fake reviews, detects review incentivization patterns, and recalculates ratings based on verified, authentic reviews only. Products should be scored on review quality, not review volume.
Independent price verification. Not Amazon’s “Was Price” or “List Price,” which are set by sellers. Actual transaction prices over 30, 60, and 90 day windows, tracked by a third party with no commercial stake in the purchase decision. An AI agent should be able to tell a user: “The reference price was set 12 days ago. The actual 90-day average price is $39.99, not the $79.99 ‘regular price’ displayed.”
Independent quality ranking. Not Amazon’s search ranking, which blends organic signals with paid placement. A quality-based ranking that reflects product performance, durability signals, and competitive comparison. Products should appear because they earned their position, not because a seller paid for visibility.
Agent-native access. This verification layer must be accessible to AI agents through a standard protocol. The Model Context Protocol (MCP), now supported across major AI platforms, provides the technical infrastructure. Agents should be able to query a trust provider before finalizing a recommendation, the same way a human consumer might check a second opinion before making a major purchase.
GoBuy’s Role
GoBuy is building this infrastructure. The MCP server at gobuy.ai/api/mcp provides AI agents with product intelligence that does not come from the marketplace.
The Smart Score (0-100) is calculated from review quality, not quantity. Fake reviews are filtered before the score is computed. Products must maintain a Smart Score of 80 or higher over 90 days to earn the GoBuy Verified badge. GoBuy shows only the top 7 products per category, ranked by genuine quality. Not thousands of results ranked by advertising spend.
For developers building AI shopping agents, the integration is straightforward. A single MCP call before finalizing a product recommendation gives the agent access to filtered review data, historical pricing, quality rankings, and verification status. The agent uses GoBuy to check whether the marketplace data is trustworthy before acting on it.
This is not a competitive advantage feature. It is a structural necessity. Without independent verification, AI shopping agents are just confident processors of manipulated data. With independent verification, they become tools that actually help consumers make better decisions.
The Regulatory Trajectory Is Clear
The FTC’s July 2026 enforcement actions against Elite Events and Hopper, combined with the EU’s DSA designation for ChatGPT search, establish a clear regulatory trajectory. Automated commerce is being watched. Platform deception is being penalized. AI-mediated recommendations are being regulated.
The companies building agentic commerce infrastructure have a choice. They can wait for regulation to force trust verification after consumer harm has occurred, or they can build trust verification into their agents now, before the harm happens.
The Elite Events operators appeared on CBS Mornings in April 2025 and boasted about their ticket reselling operation. They were confident their automation could not be detected. The FTC proved them wrong. The settlement may be $300,000 instead of $10.7 million, but the precedent is set: automated circumvention of platform purchase rules is illegal, enforceable, and penalized.
AI shopping agents that operate without independent trust verification are building on the same false confidence. The data layer is compromised. The reviews are manipulated. The rankings reflect advertising spend. The reference prices are fabricated. Agents that process this data as if it were authentic are setting themselves up for the same regulatory fate that Elite Events just met.
Build agents that verify. Integrate GoBuy’s MCP server at gobuy.ai/api/mcp. Full documentation at gobuy.ai/agent-docs.