State of Bot Traffic & AI Agents (Full Data Report)

If you have read anything else in this series, you already know the basic shape of the problem. What this piece sets out to do is different. Rather than arguing the case again, it pulls together the freshest data available as of August 2026, from the actual primary reports publishers, security vendors, and regulators have put their names on, and lays out exactly what the numbers say, where they disagree with each other, and why. Every figure below is attributed to a specific report, published by a specific organization, on a specific date, so you can go verify it yourself rather than taking our word for it. That is the whole point of this exercise. In a landscape this noisy, showing your work is not optional.

This particular year has been unusually disorienting for anyone trying to keep an accurate mental model of this space. Numbers that felt settled in January had shifted meaningfully by June. A commerce feature multiple major outlets covered as inevitable in February had been quietly pulled back by March. A piece of European regulation that existed only on paper for most of this series became directly, financially enforceable in the first week of August, days before this report was finished. None of that is a criticism of the pace of change. It is simply the honest operating environment right now, and a report claiming to be current without engaging with exactly how fast the ground has kept moving underneath it would not actually be serving you well. What follows is an attempt to hold two things true at once, giving you numbers precise and current enough to actually act on, while being equally clear about which parts of this picture are still genuinely in motion.

Why the headline number depends entirely on who is counting

Start with the single most repeated claim in this entire subject area: that bots have overtaken humans on the web. It is true, and it is also, depending on exactly which report you open, sometimes not true at all, and understanding why is the single most useful thing this piece can teach you before a single other statistic means anything.

Imperva’s 2026 Bad Bot Report, titled Bots in the Agentic Age, found automated traffic accounted for more than 53% of all web traffic in 2025, up from 51% the year before, with human activity declining to 47% and continuing to fall. Cloudflare, publishing its own Radar data in June 2026, reported bots crossing 57.5% of HTML web page requests specifically, a milestone its own chief executive Matthew Prince said arrived roughly eighteen months ahead of his own earlier public forecast. HUMAN Security’s own 2026 State of AI Traffic and Cyberthreat Benchmark Report lands in a similar range. And yet an independent tracker analyzing Cloudflare’s own Radar feeds on a rolling basis throughout Q2 2026 reported something noticeably different: bot traffic sitting at 33.2% of all HTTP requests for the full April through June quarter, with humans still comfortably ahead at 64.8% of total web traffic as of a June 2026 snapshot pulled directly from the same underlying Cloudflare data source the 57.5% figure came from.

Both numbers are real. They are simply measuring different things. The 57.5% figure describes HTML page requests specifically, a narrower and more crawler heavy slice of total web traffic, pulled from a shorter, faster moving rolling window. The 33.2% figure describes all HTTP requests across Cloudflare’s entire network, including the vast ocean of API calls, image loads, script fetches, and other non page traffic that never shows up in a simple page request count, measured across a full calendar quarter rather than a rolling seven day snapshot. Neither is wrong. They answer genuinely different questions, and any report, including the one you are reading right now, that quotes a single bot traffic percentage without specifying exactly what traffic category and time window it covers is asking you to trust a number without giving you enough information to actually evaluate it. That is worth remembering every single time you see this statistic cited anywhere, including in marketing material from companies, including bot detection vendors, that benefit from the scarier sounding version.

What every major tracker does agree on, regardless of methodology, is the direction and the trend line. The same independent Q2 2026 analysis that found the more conservative 33.2% figure also found the underlying share had climbed from 30.4% a year earlier, a real and measurable increase however you slice the denominator. And a separate, striking data point from that same tracker deserves attention on its own merits. Comparing full Q2 2025 against full Q2 2026, the share of crawler requests that actually succeeded fell from 80.5% down to 49.2%, while requests met with a 4xx block response more than tripled, rising from 10.2% to 35.8%. Whatever the exact bot percentage turns out to be, the web has spent the past year fighting back against automated traffic considerably harder than it did the year before, which is arguably the more important story buried underneath the more viral headline number.

The 2026 baseline, from the source reports themselves

With that methodology caveat firmly in place, here is what the primary annual and quarterly reports actually found, cited directly rather than through secondary aggregation.

Thales, Imperva’s parent company, frames its 2026 findings around a genuine structural shift rather than a single number. Automated traffic reached 53% of all observed internet activity in 2025, split between 40% classified as bad bots and 13% as benign automation like legitimate search indexing. Financial services experienced the highest attack volume of any single industry, accounting for 24% of all bot attacks and a striking 46% of all account takeover incidents in 2025, according to coverage of the report published by Help Net Security. The same report identifies APIs as the dominant modern attack surface, with 27% of all bot attacks and, in a separate figure specific to more advanced, sophisticated attacks, as much as 44% targeting API endpoints directly rather than traditional web pages, meaning attackers are increasingly bypassing the user interface entirely and talking straight to the backend systems behind it.

Travel has emerged as a genuinely distinct case study within this data, and the trajectory is dramatic enough to be worth walking through on its own. Imperva’s research found the travel industry became the single most attacked sector in 2024, absorbing 27% of all bot attacks industry wide, up from 21% the year before, representing a 280% rise in bot attacks targeting the sector between January 2022 and December 2024 alone. The specific tactics driving that surge have real names inside the industry now. Seat spinning holds airline seats or hotel rooms in a cart right up to the final payment step without ever completing the purchase, deliberately manipulating dynamic pricing algorithms and inventory counts along the way. Fare scraping lets a competitor or a price comparison engine harvest real time pricing data at a volume no human researcher could ever match. And straightforward ticket scalping, the same phenomenon covered in depth in our companion piece on enterprise bot defense, continues to account for a meaningful share of the total.

HUMAN Security’s own 2026 benchmark report grounds these industry level statistics in a specific, real customer example that is worth sitting with. One financial news publisher on HUMAN’s network, already a heavily targeted scraping victim throughout 2025 at a rate hovering just under half of its total web traffic, saw that rate climb further still, reaching almost two thirds of its total web traffic attempting a scraping attack by February 2026. Read that number slowly. For a portion of that period, on that specific publisher’s own infrastructure, scraping attempts were not a meaningful minority of traffic. They were closer to the majority of everything hitting the server. The same report found attempted account takeover rates against financial services businesses rose 39% year over year, with the most heavily targeted individual businesses in that sector seeing over a third of all login traffic represent an active account takeover attempt, and one banking and insurance provider specifically enduring an eight month long, sustained attack during which twelve to fifteen percent of all login attempts on its platform were part of that single ongoing campaign.

Two additional sectors round out the industry picture worth knowing. Education has quietly become a significant category of its own, with online course registration systems, assignment platforms, and exam portals now common targets, and a striking 92% of the automated activity hitting that sector classified as basic, unsophisticated bots rather than advanced automation, a pattern researchers at bot analytics firm STCLab suggest points toward students themselves using easily accessible, off the shelf automation tools rather than organized criminal operations. Regionally, Hong Kong and Indonesia each accounted for 24% of bot attacks within the Asia Pacific region specifically, the highest concentration of any single markets in that region, a pattern researchers tie directly to those economies’ unusually heavy reliance on digital financial services and API driven infrastructure, the exact combination that shows up repeatedly across this report as the strongest predictor of where bot activity concentrates.

The AI agent surge is not evenly distributed, and the picture just shifted again

Zoom in specifically on AI driven traffic rather than bot traffic broadly, and the most current available data shows a landscape that looks meaningfully different than it did even six months ago.

Bot management vendor DataDome’s Q2 2026 AI Traffic Report, covering April through June 2026 and published in mid July, found AI agent traffic surged 45% quarter over quarter, with the company’s own network processing 17.7 billion AI agent requests in Q2 2026, up from 12.2 billion in Q1 of the same year. The more interesting story sits underneath that headline growth figure. Meta, not OpenAI or Anthropic, now dominates the category. Meta’s external agent crawler grew 74% quarter over quarter, climbing from 3.1 billion to 5.3 billion requests, while a second Meta crawler, its web indexer, grew even faster at 163% quarter over quarter, rising from 1.4 billion to 3.75 billion requests. In June 2026 alone, Meta’s web indexer briefly overtook its external agent crawler in monthly volume for the first time, a shift DataDome’s own researchers read as evidence Meta is investing heavily in real time answering capability rather than purely long term model training.

Not every AI crawler is growing at the same pace, and one specific data point complicates the simple narrative that AI bot traffic only ever goes up. ChatGPT’s own user triggered fetcher, the specific bot that retrieves a live page in response to a real person’s real time question, actually visited websites 6% less in Q2 2026 than it had in Q1, according to that same DataDome analysis. That is not necessarily bad news for publishers. It may instead reflect a genuine shift in how OpenAI’s product routes traffic, sending fewer raw fetch requests while, as separate data covered below shows, delivering more valuable referral traffic per visit than before. The clear practical lesson for anyone managing a site’s crawler policy in the second half of 2026 is that a one size fits all approach, treating every AI bot as an equivalent threat or an equivalent opportunity, is now measurably wrong, since the individual crawlers behind these aggregate numbers are behaving in genuinely different, fast changing ways from each other.

There is real money attached to getting this distinction right. Adobe’s own Q2 2026 AI Traffic Report, built on Adobe Analytics data across its US retail client base, found AI referred traffic to US retailers grew 393% year over year in the first quarter of 2026 alone, having peaked at an extraordinary 1,151% year over year growth rate in December 2025 during the prior holiday season. That is a genuinely new, genuinely large channel appearing inside retail analytics within the span of about a year, and it is growing fast enough that treating it as a rounding error inside a broader organic traffic report, rather than breaking it out and tracking it deliberately, is already a meaningful strategic mistake for any retailer sitting on that data today.

A quieter, more technical development sitting underneath these numbers is worth flagging for anyone building infrastructure right now, even though it has not yet produced a headline statistic of its own. DataDome’s Q2 2026 analysis specifically calls out the emergence of the Model Context Protocol, the increasingly standard mechanism AI systems use to connect directly to external tools and data sources, as a newly measurable category of network traffic in its own right, sitting somewhere between a traditional crawler and a traditional user triggered fetch. Traffic arriving through this channel does not fit neatly into the training, search, or browsing categories this report and its companion piece on blocking AI crawlers both rely on, and tracking it as its own distinct category, rather than folding it into whichever existing bucket seems closest, is likely to become genuinely necessary infrastructure work over the next few quarters rather than an optional refinement.

Agentic commerce met reality in 2026, and reality won

Few areas of this entire subject moved faster or more visibly in 2026 than agentic commerce, the idea of an AI agent shopping and buying on a real person’s behalf, and the story is considerably messier and more interesting than the smooth, inevitable narrative most coverage of the topic told at the start of the year.

OpenAI moved first and moved fastest. Its Agentic Commerce Protocol, an open standard co developed with Stripe and released on September 29, 2025, defined how an AI agent could interact directly with a merchant’s catalog, pricing, and checkout systems, introducing a payment mechanism called a Shared Payment Token that let an agent initiate a real transaction without ever directly handling a customer’s card details. On February 16, 2026, OpenAI relaunched its consumer facing shopping feature as Buy It In ChatGPT, expanding to more than one million Shopify merchants alongside major brands and adding PayPal as a compliant payment partner, charging merchants a transaction fee that, combined with standard payment processing costs, landed around 9.2% total, roughly a third of what Amazon charges third party sellers on its own marketplace.

Then, in March 2026, OpenAI pulled the feature back. The company’s own public explanation was that the checkout experience did not offer the level of flexibility the company aspired to provide, a notably understated way of describing what industry reporting characterized as a genuinely rough launch. Fewer than thirty of Shopify’s millions of merchants had actually gone live with the feature by the time it was pulled, and Forrester principal analyst Emily Pfeiffer, covering AI and commerce for the research firm, offered a blunt read on the broader moment that goes well beyond OpenAI specifically, telling one reporter plainly that nobody has figured it out yet, but everyone has FOMO. OpenAI’s own pivot away from owning the entire transaction reflects something genuinely important about how real customers actually behave, not just a technical setback. Reporting on the shift found that shoppers using ChatGPT to research and compare products still overwhelmingly preferred to complete the actual purchase somewhere they already had a saved account, a stored payment method, and an order history they trusted, rather than checking out cold inside a chat window.

Google took a visibly different path with its own Universal Commerce Protocol, launched in January 2026 alongside a genuinely large founding coalition that included Shopify, Etsy, Wayfair, Target, Walmart, Visa, Mastercard, and Stripe itself. Rather than pursuing OpenAI’s model of owning checkout directly, Google’s protocol was built explicitly to let an agent build a multi item cart, pull real time catalog and pricing data, and link a shopper’s existing loyalty or membership identity, while handing the actual transaction back to the merchant’s own checkout flow. Retailers have responded to this fork in strategy with a fork of their own. Walmart, after its own early integration into ChatGPT’s native checkout underperformed, pivoted to embedding its own AI assistant, internally named Sparky, directly inside the ChatGPT conversation instead of relying on OpenAI’s infrastructure, while keeping the actual transaction anchored inside Walmart’s own systems, and the company has reported ChatGPT is now driving roughly twice as many new customers as its traditional search acquisition channels. Amazon, meanwhile, has quietly built the single largest agentic shopping deployment in the entire industry using its own infrastructure rather than any open protocol at all. Its in app assistant Rufus reportedly reached roughly 250 million customers in 2025 alone, with users found to be 60% more likely to complete a purchase after interacting with it, internal company estimates reportedly projecting more than ten billion dollars in incremental annualized sales and upward of seven hundred million dollars in indirect operating profit tied directly to the feature. Amazon has since gone further with a feature called Buy For Me, which lets its own shopping agent complete a purchase directly on a third party brand’s website from inside the Amazon app whenever Amazon itself does not carry a given product, a genuinely striking detail given that Amazon separately sued Perplexity in late 2025 over the exact same underlying behavior, an AI agent placing an order on Amazon’s own site on a user’s behalf, when it was a competitor’s agent doing it rather than Amazon’s own.

The market built to fight back is scaling just as fast

Every statistic in this report describing the scale of the problem has a mirror image on the defense side, and the money flowing into that defense market is itself a useful, independently verifiable signal of how seriously the businesses actually living with this problem are taking it.

Market research firm Fortune Business Insights values the global bot security market at 1.05 billion dollars in 2025, projecting growth to 1.27 billion dollars in 2026 alone and, over the following eight years, all the way up to 5.67 billion dollars by 2034, a compound annual growth rate above 20%. Web security specifically, covering the detection tools that analyze browser fingerprints, mouse movement, and session behavior directly on a business’s own website, accounts for roughly 46% of that total spend today, the single largest segment within the category, ahead of dedicated API protection and mobile app specific tooling. That growth trajectory is not evenly distributed either. The firm’s own sector breakdown points specifically to banking and financial services, ecommerce platforms defending pricing and inventory data, and media and ticketing platforms fighting persistent scalping as the categories driving spend fastest, which lines up almost exactly with the industry attack data cited earlier in this report from an entirely different set of sources. When the attack data and the defense spending data, pulled from unrelated research firms using unrelated methodologies, point at the same handful of industries independently of each other, that convergence itself is a meaningful signal worth taking seriously.

The pattern is not confined to consumer retail either. On the business to business side, Alibaba’s own AI sourcing platform, Accio, offers an early look at how fast this can scale once genuine product market fit clicks into place. The platform passed one million users within roughly five months of its early 2025 launch and had exceeded two million users by August of the same year, adding deep research and increasingly automated sourcing workflow features along the way, a trajectory suggesting agentic buying may end up moving faster in procurement heavy business contexts, where the research and comparison work an agent automates is especially time consuming for a human, than it has in the more publicly visible consumer shopping space covered above.

The AI generated half of the web is no longer a future prediction

While the commerce side of this story played out in courtrooms and product launches, the content side of the web quietly crossed a threshold that deserves its own moment of attention. Analysis from growth agency Graphite, tracking a sample of roughly sixty five thousand English language articles and cited in reporting by Axios, found that by late 2024 the volume of newly published AI generated articles had already reached rough parity with human written output, a trend line that has continued climbing through 2025 and into 2026 rather than leveling off. This is not a claim about quality, and plenty of that AI assisted content is genuinely well edited and useful. It is a claim about sheer volume, and it means that anyone competing for attention, search visibility, or AI citation in 2026 is doing so inside a content ecosystem where roughly half of everything newly published was primarily machine written, a genuinely new competitive reality that did not exist even three years earlier.

The regulatory response has finally, actually arrived

For years, the honest answer to what happens legally when a bot lies about being human was, in most jurisdictions, largely nothing. That answer changed meaningfully in 2026, and the most significant single development landed just days before this report was written.

Article 50 of the European Union’s AI Act became enforceable on August 2, 2026, imposing a direct, mandatory disclosure duty on any chatbot serving European users, regardless of where the company operating it is headquartered, alongside a parallel requirement that AI generated images, audio, video, and text be marked as such. Penalties for noncompliance reach fifteen million euros, or three percent of a company’s total worldwide annual revenue, whichever figure is larger, a threshold clearly designed to be meaningful even against the very largest technology companies rather than functioning as a rounding error line item. In the United States, the pattern looks different but the direction is the same. No single comprehensive federal law has passed, but the state level pace has been genuinely fast. Legal tracking firm Law360 reported 27 states actively pursuing chatbot specific legislation as of April 2026, with the Future of Privacy Forum separately tracking 98 distinct bills across 34 states and three federal proposals, and a full 25 state level AI laws passed in 2026 alone, 19 of them in the single month of March. California, Maine, New Jersey, Utah, and Colorado already have chatbot disclosure requirements actively on the books and enforceable today, and the Federal Trade Commission has made clear, through its existing authority under Section 5 of the FTC Act, that failing to disclose AI involvement in a commercial interaction can independently qualify as a deceptive practice even in states with no chatbot specific statute at all.

The FTC has backed that position with real enforcement rather than leaving it purely theoretical. A health supplement company that used chatbots designed to impersonate human doctors, recommending products to customers without disclosing the AI’s involvement at all, was hit with a settlement requiring a 2.3 million dollar penalty alongside mandatory consumer refunds, and current published FTC guidance puts the maximum civil penalty for AI content disclosure violations at 53,088 dollars per individual violation as of 2026, with the agency’s own enforcement action volume up roughly 40% in 2025 over the year before. None of this regulatory activity directly targets the crawler and click fraud side of the bot traffic problem this series has focused on most closely, and it is worth being precise about that distinction rather than blurring two related but genuinely different issues together. These new rules govern whether a human being is told they are talking to AI. They do not yet govern whether a business is told its own traffic or ad clicks are fake. But both threads are clearly part of the same broader reckoning, a growing, increasingly codified legal recognition that automated, non human activity dressed up to look human carries real costs, and that pretending otherwise is no longer something regulators are willing to simply let slide.

Beyond the chatbot disclosure rules covered above, a parallel track of state level regulation is tightening around automated decision making more broadly, and it is worth knowing this second track exists even though it sits slightly outside this report’s core focus. Colorado’s AI Act began phased enforcement in 2026, imposing algorithmic discrimination duties specifically on high risk automated decisions in areas like employment and housing. New York State has expanded its own framework through the RAISE Act alongside new synthetic performer disclosure requirements, while New York City’s Local Law 144, requiring bias audits for automated employment decision tools, remains one of the most actively enforced local AI regulations anywhere in the country. Taken together with the chatbot disclosure rules, the throughline across all of this new regulation is consistent. Lawmakers at every level of government spent 2026 deciding, in a way they clearly had not by the end of 2025, that automated systems interacting with real people carry real legal obligations, and that treating disclosure as optional is no longer a defensible position regardless of which specific corner of automation a business happens to operate in.

What still does not work, updated for the current moment

Our earlier piece on enterprise bot defense covered in depth why even the most expensive, most sophisticated commercial protection available still lets a meaningful amount of bot traffic through, and that core argument has not changed or softened in the months since. What is worth updating here is the specific, current shape of that gap, because it has shifted in a genuinely interesting direction.

The web, in aggregate, is fighting back harder than it was a year ago, and the data on crawler success rates cited earlier in this report proves it directly. A crawler request that succeeded roughly four times out of five in the second quarter of 2025 succeeded barely half the time by the same quarter in 2026, while outright 4xx blocks more than tripled over the same period. That is real, measurable progress, and it did not happen by accident. It reflects the widespread adoption of exactly the tools and techniques covered elsewhere in this series, default AI crawler blocking, managed bot detection rules, and far more aggressive rate limiting than was common even eighteen months ago. At the same time, the nature of what is getting through that tightening net has shifted in a way that should genuinely concern anyone still thinking about this problem purely in terms of blocking known, named crawlers. Agentic browsing traffic, the kind generated by a real person directing a genuinely legitimate AI tool inside their own logged in browser session, does not need to evade a single one of these defenses, because there is functionally nothing fake about the underlying request for a detection system to catch. As agentic commerce and agentic browsing both continue their rapid growth through the rest of 2026, an increasing share of the traffic that matters most, the traffic a business most wants to understand and measure accurately, sits in exactly that ambiguous, genuinely legitimate, genuinely hard to categorize middle ground.

What this actually means going into the rest of 2026

Pulling the full picture together, a few practical conclusions hold up across every data source cited in this report, regardless of which specific percentage or methodology you personally find most convincing.

The scale of automated traffic is large enough, and confirmed by enough independent, disagreeing methodologies, that treating it as a marginal edge case in your own reporting is no longer defensible for a business of any real size. Exactly how large depends entirely on what you are measuring and over what window, which means the specific question worth asking is never simply how much of my traffic is bots, but rather which traffic, measured how, and compared against what baseline. Industry matters enormously, and a generic, one size fits all bot percentage pulled from an unrelated sector tells you very little about your own specific exposure, whether you are running a travel booking platform staring down seat spinning and fare scraping, a financial services business absorbing nearly half of all industry wide account takeover attempts, or a content publisher watching AI referral traffic grow at a rate that dwarfs anything organic search delivered even during its strongest years. Agentic commerce is genuinely real and growing fast, but 2026 proved decisively that the smooth, fully automated, fully disintermediated version of that future arrived considerably later and messier than most 2025 predictions assumed, with real customer behavior, real infrastructure limitations, and real trust concerns all pushing back hard against the more breathless version of the narrative. And the legal and regulatory ground underneath all of this is moving for the first time in a way that carries real financial teeth, even if, as of today, that regulatory attention is aimed more squarely at AI disclosure to consumers than at the click fraud and crawler abuse problem most of this series has focused on.

None of this resolves into a single, tidy percentage worth memorizing and repeating at your next planning meeting. What it resolves into instead is a genuinely more sophisticated, more current picture than the one most teams are currently operating from, built on primary sources rather than recycled headlines, and specific enough to your own industry and your own infrastructure to actually inform a real decision rather than just a talking point.

Translated into role specific terms, a marketer running paid acquisition should treat AI referred traffic as its own distinct, separately tracked channel starting now rather than later, given the 393% growth figure cited above and the meaningfully different conversion behavior that traffic tends to show. A developer or infrastructure lead should assume crawler policy is no longer a set once, forget forever configuration task, given how much individual crawler behavior shifted quarter to quarter even within the single six month window covered most closely in this report. An affiliate or partnership manager should watch the agentic commerce space closely without over investing in any single protocol yet, since as of this writing the industry itself has not settled on one standard, and the businesses moving fastest, Amazon most visibly, are largely doing so with proprietary infrastructure rather than the open protocols receiving most of the public attention. And anyone in a compliance or legal adjacent role should treat the AI disclosure regulations covered above as active, not upcoming, given that the largest single piece of that regulatory framework became enforceable in the same week this report was published.

Common questions this data answers directly

A few specific questions come up often enough, in comment sections and in client conversations alike, that they deserve direct, sourced answers pulled straight from the data above rather than a vague gesture back toward the general topic.

What percentage of web traffic is actually bots in 2026. The honest answer is that it depends entirely on what you are measuring. Across all HTTP requests over a full quarter, independent tracking of Cloudflare’s own Radar data puts the figure at roughly 33% as of Q2 2026. Measured specifically as HTML page requests on a faster moving rolling basis, Cloudflare’s own headline figure crossed 57.5% in June 2026. Imperva’s broader annual methodology, covering the full 2025 calendar year, found 53%. All three are internally consistent and correctly sourced. None of them is the single universal answer, because no single universal answer exists.

Is agentic commerce actually working yet in 2026. Partially, and unevenly. Amazon’s own in house agent, Rufus, is a genuine, large scale commercial success by the company’s own reported figures. OpenAI’s attempt to own checkout directly inside ChatGPT was pulled back within weeks of a wider relaunch after real customers showed a strong, consistent preference for completing purchases inside merchant environments they already trusted. Google’s more infrastructure focused approach through its Universal Commerce Protocol is still in its early adoption phase as of mid 2026. The technology works. The consumer trust and checkout experience side of the equation is still visibly catching up.

Which industries should be most worried about bot traffic right now. Based on attack volume specifically, financial services leads at 24% of all bot attacks industry wide. Based on the rate of increase and the proportion of total traffic affected, travel has overtaken retail as the fastest growing target, driven specifically by seat spinning, fare scraping, and ticket scalping. Any business running meaningful API infrastructure, regardless of industry, should treat itself as a high priority target, given that API endpoints now absorb over a quarter of all bot attacks and as much as 44% of the more advanced ones.

Is the bot traffic problem actually getting worse or is defense catching up. Both, measured on different axes, and that is not a contradiction. The raw volume of automated traffic, and the sophistication of the most advanced attacks, both continued climbing through 2026 by every measure in this report. At the same time, the proportion of that traffic actually succeeding against a defended target fell sharply over the same period, from roughly four in five crawler requests succeeding to fewer than half. The correct read is not that the problem is shrinking. It is that the fight has become considerably more active on both sides at once, which tends to look like progress and regression simultaneously depending entirely on which specific metric you happen to be watching that week.

Does blocking AI crawlers actually work. Partially, and the trend is genuinely improving. Full quarter data comparing Q2 2025 against Q2 2026 found crawler request success rates falling from roughly 80% down to under 50%, with outright blocks more than tripling over the same period, meaning the web collectively is getting measurably better at this. It does not work at all against agentic browsing traffic operating through a real, legitimate, logged in human session, since there is no fake signal for a detection system to catch in the first place.

Treat this report the way you would treat any single snapshot of a subject moving this fast, as an honest, well sourced picture of a specific moment rather than a permanent conclusion. The single most reliable prediction contained anywhere in this piece is that a meaningful share of the specific figures above will already look somewhat dated by the time enough months have passed for the next major report to land, and that the businesses that come out ahead through that continued churn will be the ones treating this as an ongoing measurement discipline rather than a topic to research once and consider settled.

Sources and methodology

Every statistic in this report is drawn from a named, dated, publicly available report or a piece of journalism directly covering one, rather than from an unattributed aggregator repeating a number with the original source stripped away. The primary reports referenced throughout include Imperva’s 2026 Bad Bot Report, Bots in the Agentic Age, published by Imperva and its parent company Thales in April 2026, HUMAN Security’s 2026 State of AI Traffic and Cyberthreat Benchmark Report, DataDome’s AI Traffic Report for the second quarter of 2026, published in July 2026, Cloudflare’s own Radar data on bot and crawler traffic as reported through its June 2026 public statements and independently tracked on a rolling basis by third party analysts, and Adobe’s Q2 2026 AI Traffic Report drawn from Adobe Analytics retail client data. Regulatory figures are sourced directly from the text and effective dates of Article 50 of the European Union’s AI Act and from contemporaneous legal and compliance industry tracking of United States state level legislation and Federal Trade Commission enforcement actions current as of publication. Where two credible sources disagreed on a figure, both are presented explicitly with their differing methodology explained, rather than silently choosing whichever number told the more dramatic story. Given how quickly this specific landscape continues to move, treat every figure in this report as accurate as of its cited publication date, and expect the underlying numbers to keep shifting in the months ahead exactly as they have shifted in every quarter covered here.

Leave a Comment