For about thirty years, digital marketing has run on a quiet assumption. A pageview is a person. A click reflects some sliver of intent. A conversion means an actual human being handed over actual money. That assumption is now false often enough that treating it as true is starting to look reckless.
Sometime around 2025 or 2026, depending on whose telemetry you trust, automated traffic overtook human traffic on the open web. Imperva’s 2026 Bad Bot Report puts total automated activity at more than 53% of all web traffic in 2025, up from 51% the year before, with the human share continuing to shrink. Cloudflare, which sits in front of a massive slice of the internet’s infrastructure, recorded bots crossing 57.5% of web page requests in June 2026, which is more than a year ahead of the timeline its own CEO, Matthew Prince, had publicly predicted only a few months earlier. Imperva and Cloudflare disagree about exactly when the crossover happened. Neither disagrees that it happened.
There’s a decade old internet forum theory that finally has data behind it. “Dead internet theory,” once dismissed as a fringe conspiracy claiming most of what you see online isn’t human at all, has quietly become something closer to a measurement dispute among cybersecurity vendors rather than a joke. As Pitchbook fintech analyst Rudy Yang put it to Fortune, no single company can see the whole internet at once, so every one of these numbers is really a partial view stitched together from whatever slice of traffic that vendor happens to sit in front of. That caveat matters, because it means the truth is probably worse than any single report, not better.
For most people this is an unsettling curiosity to bring up at a dinner party. For marketers, advertisers, publishers, SEOs, and affiliate professionals, it is a full blown operational problem, because every discipline in this industry, from media buying to content strategy to affiliate management to basic analytics, was designed around the premise that the audience on the other end of a click is a human who might eventually buy something. That premise now needs an asterisk, and in some corners of the internet it needs a full rewrite.
This piece pulls together what the security vendors, ad verification companies, trade bodies, courts, and researchers tracking this in real time are actually finding, and what it means for anyone whose job is to reach real customers on a web that is increasingly built for machines.
Just how much of the internet is actually bots?
The numbers vary depending on who is measuring and how, but they all point the same direction, and the direction is up.
Imperva’s Bad Bot Report, now in its thirteenth year, is the longest running census of automated traffic in the industry. Its 2025 edition found bad bots, meaning the malicious kind built for scraping, fraud, and account takeover, made up 37% of all internet traffic on their own, with total automated traffic (the good bots plus the bad ones) crossing 51% for the first time since the report began. The 2026 edition pushed further still. Bad bots now sit around 40% of all traffic, total automated traffic has climbed to 53%, and parent company Thales says it blocked 17.2 trillion malicious bot requests globally over the year, a more than twelvefold jump in AI driven attacks compared to the year before, according to coverage of the 2026 report.
Cloudflare tells a similar story from a different vantage point. Because it sits in front of roughly a fifth of the entire web, its Radar data is one of the few datasets large enough to spot structural shifts as they happen rather than months later. By mid 2026, Cloudflare was recording bots at 57.5% of HTML page requests. More telling than the raw number is what kind of bot is driving the growth. It is not classic scraping anymore. According to HUMAN Security’s 2026 State of AI Traffic and Cyberthreat Benchmark Report, traffic from AI agents that actually take action on the web, meaning they click links, fill out forms, and complete tasks on someone’s behalf, grew 7,851% year over year. Traditional scraper traffic, the kind that just reads and copies, “only” grew 597% over the same period, which tells you where the real acceleration is happening.
Picture what that shift looks like from inside a marketing team. A campaign manager pulls up a dashboard on a Monday morning expecting to see the usual mix of organic visitors, paid clicks, and referral traffic. Increasingly, a meaningful chunk of what shows up in that dashboard never had a human anywhere near it. Some of it is benign, like a price comparison bot checking your product page for the fortieth time that week. Some of it is an AI agent quietly comparing your offer to three competitors on behalf of a real shopper who will never see your site directly. And some of it is outright fraud, engineered specifically to look like the first two categories so nobody bothers investigating it.
The rise of AI slop: when the content itself stops being human
Bot traffic is only half the story. The other half is what’s actually being published.
Digital agency Graphite has tracked the share of newly published English language web articles that are primarily AI generated, and the trajectory is genuinely startling. That figure jumped from roughly 10% in late 2022 to 36% within a year of ChatGPT’s launch, then 48% the year after that, before plateauing around 50% by 2026, meaning something close to half of everything newly written on the internet right now was primarily produced by a machine rather than a person. Ahrefs ran an independent check on nearly a million newly published pages and landed in a similar place, finding 74.2% contained detectable AI generated text, though most of that was human AI hybrid work rather than pure machine output with no editing at all.
The term for the low quality end of this flood, “AI slop,” escaped tech forums and went fully mainstream in 2025. It became common enough that Australia’s Macquarie Dictionary named it a word of the year for the year, which is as good a signal as any that the phenomenon had stopped being a niche complaint and started being a shared cultural experience. Media watchdog NewsGuard, which tracks unreliable news sources, found the number of websites that are primarily or entirely AI generated and presenting themselves as news outlets ballooned by more than 1,000% between May 2023 and mid 2024, crossing 800 sites. These aren’t hobby blogs. They exist specifically to harvest programmatic ad revenue by publishing thousands of keyword stuffed articles an hour, with no intention of anyone ever reading them closely.
Google has responded the way a search engine under siege responds: with algorithm updates, and a lot of them. In March 2026 the company ran what it described internally as a record fast spam update, completing in about twenty hours and aimed squarely at scaled content abuse and manipulative ranking schemes, according to reporting drawing on Google’s own search status dashboard. None of this has fully solved the problem, and it probably can’t, because the economics still favor the spammer. Publishing an AI written article costs close to nothing. Even a tiny click through rate on programmatic display ads makes the math work at scale, which means the incentive to flood search results with synthetic content isn’t going away just because a handful of algorithm updates make it slightly harder.
For content marketers, this creates a genuinely strange new competitive landscape. You are no longer just competing with other brands for a keyword. You’re competing with an army of AI generated pages that publish faster than any human team ever could, and a search engine that is simultaneously trying to reward genuine expertise while drowning in a flood of content specifically engineered to look like it.
The ad fraud economy marketers are quietly bankrolling
Bot traffic isn’t just a security headache sitting off to the side of marketing. In programmatic advertising specifically, it is a huge part of where the marketing budget actually goes.
The Association of National Advertisers, the leading U.S. trade body representing client side marketers, spent 2022 and 2023 tracking $123 million in real ad spend across 21 major advertisers all the way down to the individual impression. What it found reshaped how a lot of procurement teams think about programmatic media. Only 36 cents of every dollar that entered a demand side platform actually reached a real consumer, according to MarTech’s coverage of the study. Roughly 29 cents went to ad tech intermediary fees, and another 35 cents went to low quality media, including invalid traffic, made for advertising sites, and inventory that was never actually viewable or measurable. Extrapolated across the open web programmatic market at the time, that implied something like $22 billion a year in waste.
The ANA has kept tracking this quarterly through its Programmatic Transparency Benchmark, built in partnership with TAG TrustNet. The genuinely good news is that the trend is improving. Its Q3 2025 benchmark found marketers recovered $13.6 billion in working media value, with the share of spend actually reaching publishers rising to 47.1%, up 11 points since 2023, and 99.1% of programmatic spend landing in low risk, brand safe environments. But the improvement hasn’t erased the problem. The Q2 2025 benchmark still found $26.8 billion in wasted global media value annually, which is real money leaking out of real budgets even after years of cleanup effort across the industry.
Stack the broader fraud estimates on top and the scale gets harder to ignore. Juniper Research, an analyst firm that has tracked global ad fraud losses since 2017, has watched its own past projections repeatedly come in low. It forecast $68 billion in losses for 2022, and a trajectory heading toward $172 billion by 2028. Current 2026 estimates from various trackers cluster around $100 billion for the year alone. Fraud detection firm Fraudlogix, analyzing more than 105 billion ad impressions for its 2026 State of Ad Fraud Report, put the global invalid traffic rate at roughly 20.6%, meaning something close to one in five ad impressions served in 2025 wasn’t seen by a genuine, undisguised human being.
The technical vocabulary here comes from the Media Rating Council, working alongside the IAB, in guidelines that split invalid traffic into two tiers. General Invalid Traffic, or GIVT, covers known bots, spiders, and datacenter traffic that’s relatively easy to filter with a simple list. Sophisticated Invalid Traffic, or SIVT, covers hijacked devices, falsified location data, and bots specifically engineered to mimic human behavior closely enough that catching them requires real behavioral analysis rather than a blocklist. That distinction has real commercial teeth. DoubleVerify has reported that unprotected advertisers, meaning those running campaigns without pre bid or post bid fraud filtering, can see fraud and SIVT violation rates as high as 17%, and the company has specifically pointed to generative AI as a factor making it dramatically easier for fraudsters to fabricate convincing behavioral patterns that used to require real engineering skill to pull off.
What this actually looks like on the ground
Statistics like these can feel abstract until you see what they do to an actual small business owner’s bank account.
Fraud prevention firm ClickFortify documented one representative case involving a plumber in Phoenix who had run a solid business for twelve years mostly through word of mouth and yellow pages advertising. When that stopped working, he shifted a four thousand dollar monthly budget into Google Ads targeting emergency plumbing keywords. Traffic looked strong from day one. Calls didn’t follow. His daily budget was exhausted by mid morning, every single day. Assuming the problem was his own targeting rather than the traffic itself, he increased his monthly spend to six thousand dollars, funded in part by a business loan, and performance still didn’t improve. After six months and thirty thousand dollars spent, his cash reserves were gone. A separate case the same firm documented involved a business owner who discovered, only after a fellow business owner suggested she check her traffic sources, that 67% of her clicks were originating from a cluster of IP addresses tied to click farms she’d never heard of.
These stories illustrate a mechanic worth understanding, because it explains why fraud like this is so hard to catch in real time. Two distinct operations tend to be at work. Bot farms are networks of real or emulated devices, sometimes literal warehouses full of SIM equipped phones wired together, run from a central dashboard to fake clicks, app installs, and engagement at scale. Because genuine hardware and real mobile networks are involved, this kind of traffic slides right past basic IP based filters. Click farms work differently. They’re rooms of low paid human workers, often located in lower income regions, manually clicking ads and generating engagement that looks legitimate because, technically, it is a real person clicking. That person just has zero intent to buy anything from you. Security firm Opticks, analyzing two billion clicks across more than five hundred advertisers for its 2026 Ad Fraud Report, identified more than 416 million bot sessions, with close to 90% of those classified as outright malicious rather than benign crawler activity.

The damage compounds because most modern ad platforms lean on automated bidding, with Google’s Performance Max being the most commonly cited example, and automated bidding optimizes toward whatever signal it’s given, good or bad. Feed a Smart Bidding algorithm a stream of fraudulent conversions from a click farm and it will happily scale spend toward that exact pattern of fake behavior, essentially training itself to chase garbage more efficiently rather than correcting course. For a small business owner watching their daily budget vanish before lunch, none of this feels like an abstract industry statistic. It feels like their livelihood.
Affiliate marketing’s fraud problem is structurally different, and often worse
If programmatic display advertising bleeds money one fraction of a cent at a time, affiliate marketing loses it in much bigger bites, because the channel pays for results rather than exposure.
That’s the exact structural vulnerability Impact.com, one of the largest partnership management platforms, points to. A fraudulent display impression wastes a sliver of a CPM. A fraudulent affiliate conversion pays out a full commission, sometimes fifty dollars, a hundred dollars, or more, for a lead or sale that never actually happened. Fraud researchers at Fraudlogix estimate the affiliate channel loses roughly $3.4 billion a year to direct commission fraud, with fraudulent clicks accounting for something like 17% of all affiliate traffic and bots contributing roughly 24% of total affiliate channel activity. Some program level estimates suggest as many as one in four leads generated through affiliate campaigns are fake or badly qualified.
The tactics are specific to how the channel is built. Cookie stuffing, meaning silently dropping a tracking cookie onto a visitor’s browser without their knowledge so an affiliate gets credited for a purchase they had nothing to do with, still affects an estimated 5 to 10% of affiliate transactions. Click flooding manipulates last click attribution by firing off a huge volume of clicks to maximize the statistical odds of being the final touchpoint before a genuine, organic conversion happens anyway. And with 97% of brands now using AI in some form according to Impact.com’s own research, fraudsters have the exact same tooling available to them, meaning today’s fraudulent affiliate traffic can convincingly mimic human browsing patterns, rotate through residential IP addresses to appear geographically legitimate, and simulate realistic session lengths well enough to clear basic fraud filters without tripping a single alarm.
For affiliate managers, the useful detection signal usually isn’t found in the click data at all. It’s in what happens after the click. Legitimate paid channels typically convert somewhere around 8 to 12%. A partner suddenly sitting at 30% or higher, or a lead to call rate that quietly collapses weeks after a sale technically closed, is a far more reliable fraud signal than anything visible in a real time dashboard, according to fraud detection specialists at 24metrics, who describe a typical scenario where a top performing affiliate’s conversion rate doubles overnight, the numbers look beautiful for weeks, and then finance quietly flags a chargeback spike that reveals the whole thing was never real to begin with.
When your own dashboards start lying to you
Set fraud aside entirely for a moment. Bot traffic corrupts something even more basic, which is a marketer’s ability to trust the analytics sitting in front of them every single day.
“Dark traffic,” meaning visits Google Analytics can’t correctly attribute, often because a link got copied and pasted somewhere outside a browser rather than clicked, or because bot activity gets silently misclassified as direct traffic, has been a known distortion for years. Search Engine Journal has documented how this systematically undercounts channels like social and email while inflating “direct” traffic, which nudges marketers toward defunding channels that were actually working just fine.
What’s changed is the sheer scale of the automated traffic now feeding into that noise. A story reported by the Milwaukee Journal Sentinel captures just how disorienting this can get. Steve Robinson, founder of a digital advertising agency, was trying to reconcile a client’s banner ad numbers against Google Analytics data when the totals simply didn’t line up. Google was reporting 283 times more traffic than the number of ad impressions actually served on the sites in question. Digging into it, he eventually found that as much as 70% of the traffic Google Analytics reported for that client was being generated by bots, some malicious, some simply mundane automated tools scouring the web for shoppers, competitors, and price comparison engines. It was a big enough gap to undermine the entire basis on which his agency justified its own billing.
This isn’t a brand new problem wearing an AI costume. It’s an old, familiar problem getting structurally worse. Google itself built bot filtering options directly into Analytics specifically because, left unfiltered, a wave of automated traffic can create the illusion that a piece of content or a channel is performing well when it isn’t, leading to real editorial and budget decisions built on top of a completely false signal. For brand and content teams especially, the stakes here go beyond simple fraud losses. They’re about strategic self deception, meaning an entire content calendar quietly getting optimized around whatever bots seem to reward, rather than what real prospects actually respond to.
The AI crawler land grab
If 2023 and 2024 were mostly about search engine bots and generic scrapers, 2025 and 2026 have been defined by a new and far hungrier category: AI training and inference crawlers, deployed by every major AI lab to feed both model training and real time chatbot answers.
The scale involved is genuinely new. One investigation drawing on Cloudflare’s own network telemetry estimated AI crawlers were generating something like 50 billion requests a day by early 2026, and that’s only the traffic Cloudflare can positively identify. A meaningful share of AI driven scraping now disguises itself behind spoofed browser identities and residential proxy networks specifically to dodge detection. Individual crawler volumes have exploded to match. GPTBot requests rose 147% in a single year, and Meta’s crawler rose 843% over the same period, with total AI related bot traffic climbing more than 300% between January 2025 and March 2026, per an analysis published on Coronium’s data blog.
Cloudflare’s own published research adds a detail that should matter enormously to publishers and content marketers. The traffic these crawlers send back in referrals isn’t remotely close to what they take. In a detailed breakdown of what it calls crawl to refer ratios, Cloudflare found Anthropic’s crawler fetching roughly 38,000 pages for every single visitor it referred back to a site as of mid 2025, OpenAI at roughly 887 to one, and Perplexity around 118 to one. Compare that to Google’s traditional search crawler, which Cloudflare separately measured at roughly five crawls for every referral it sends back. In plain terms, AI companies are extracting content at a wildly higher rate than they’re sending readers, and therefore revenue, back to the people who actually made it.
Publishers have started fighting back at the infrastructure level. In mid 2025, Cloudflare became the first major internet infrastructure provider to switch AI crawler blocking on by default for every new domain on its network, alongside launching a marketplace called Pay Per Crawl that lets site owners charge AI companies a micropayment for every page fetch, or block them outright if they’d rather not deal with it at all. Dotdash Meredith CEO Neil Vogel welcomed the shift at the time, framing it as finally giving publishers the ability to work only with AI partners willing to strike genuinely fair arrangements rather than simply taking whatever they wanted. By August 2025, more than 2.5 million sites had chosen to fully disallow AI training crawlers altogether, and that trend has continued hardening rather than softening, with sites increasingly moving from partial blocks to full ones on crawlers like GPTBot, CCBot, and Google Extended. As of July 2026, Cloudflare pushed even further, rolling Pay Per Crawl into a broader Pay Per Use model designed to charge AI firms based on the value their content actually creates rather than simply charging per fetch, motivated in part by Cloudflare’s own finding that over half of all AI crawler traffic was just repeatedly refetching pages that hadn’t changed since the previous visit.
For content marketers and publishers, the practical calculation here has gotten genuinely difficult. Blocking AI crawlers protects bandwidth, server costs, and intellectual property. It can also mean disappearing entirely from the AI powered answer engines, including ChatGPT, Perplexity, and Google’s own AI Overviews, where a growing share of prospective customers now begin their research before they ever type a traditional search query.
The courtroom has become a marketing battleground
None of this is playing out only in dashboards and vendor reports. Some of the most consequential fights over how AI companies get to use the web are happening in federal courtrooms right now, and the outcomes will directly shape what marketers and publishers are legally allowed to do about it.
The New York Times filed suit against OpenAI and Microsoft in December 2023, alleging the companies trained ChatGPT on millions of the paper’s articles without permission or compensation. As of mid 2026 the case remains very much alive, currently in discovery before the Southern District of New York. A judge largely denied the defendants’ motion to dismiss back in April 2025, letting the core copyright claims proceed, and the case has since produced a genuinely bizarre side battle over ChatGPT user logs, with the Times initially seeking access to 120 million user conversations to determine whether ChatGPT routinely reproduces its copyrighted reporting nearly verbatim. It’s widely considered the single most consequential test yet of whether training an AI model on copyrighted journalism qualifies as fair use, and its outcome will likely shape licensing norms across the entire publishing industry.
An even more current fight broke out over agentic commerce specifically. Amazon sued Perplexity in November 2025, accusing the startup’s Comet browser and its built in AI shopping agent of accessing customer accounts and placing orders without proper authorization, in some cases by disguising the automated agent as a regular human user browsing in Chrome. A federal judge sided with Amazon in March 2026, granting a preliminary injunction after finding the retailer had presented strong evidence of unauthorized access. Then, just days ago as of this writing, the Ninth Circuit Court of Appeals overturned that injunction, ruling that it was Perplexity’s users, not Perplexity the company, who were technically the ones accessing Amazon’s systems, since the agent only acted when a real person directed it to. The case is far from over, but the arguments made during the appeal hearing get at something genuinely new in commercial law. One judge on the panel, weighing how a law written in 1986 should apply to software acting on a person’s behalf, asked the courtroom point blank: “Does an AI agent ever have intent?”
That is not a rhetorical flourish. It’s the exact question every advertiser, affiliate network, and retailer is going to have to answer eventually, because the entire architecture of digital marketing, from attribution models to fraud detection to basic advertising law, was built around the assumption that a click reflects the intent of the person who made it. Nobody has fully worked out yet what a click means when the thing clicking is software.
Zero click search and the vanishing organic funnel
Even where AI crawlers aren’t the direct culprit, their output is reshaping the single largest channel most marketing teams still depend on: organic search.
The most rigorous data here comes from the Pew Research Center, which tracked actual browsing behavior rather than survey responses, drawn from 900 U.S. adults across nearly 69,000 real Google searches in March 2025. The findings were stark. When a search produced an AI Overview, users clicked through to a traditional result only 8% of the time, compared to 15% when no AI summary appeared, roughly half as often. Even more strikingly, users clicked on a source cited inside the AI summary itself in just 1% of visits. Pages featuring an AI Overview were also more likely to end the browsing session entirely, happening on 26% of those pages compared to 16% of traditional results pages.
The prevalence of that experience has been climbing fast. Semrush’s own tracking found AI Overview appearances roughly doubling between February and March 2025 alone, and by the first quarter of 2026 a large scale study covering nearly 22 million searches found roughly a quarter of all Google queries triggering an AI Overview. Bain and Company’s February 2025 consumer research put a real number on the downstream business impact, estimating that organic web traffic has declined somewhere between 15% and 25% across many sectors as a direct consequence of AI mediated search, with B2B software categories seeing click through declines as steep as 30% in some cases since AI Overviews launched broadly.
For SEO and content teams, this genuinely changes which metric matters most. Ranking first no longer reliably means visibility, and visibility no longer reliably means a click. There is at least one silver lining worth mentioning. Data cited across multiple industry analyses suggests the smaller number of visitors who do click through from an AI tool tend to convert at meaningfully higher rates than traditional organic visitors, and brands that get cited by name inside an AI Overview see a real lift in both organic and paid click through on that same query. The strategic implication most analysts are converging on is that raw traffic as a KPI is being partially replaced by something closer to citation and presence, a genuinely new discipline sometimes called AI search optimization or answer engine optimization, distinct from classic SEO in ways the industry is still figuring out.
Agentic commerce: when the customer is a piece of software
The newest wrinkle, and arguably the one with the least mature tooling built around it so far, is agentic commerce, meaning AI agents that don’t just answer questions but actually shop, compare, and in some cases complete purchases on a real person’s behalf.
Industry data suggests this is moving from novelty to meaningful volume quickly. The IAB found that 38% of consumers already use AI when shopping, with 80% expecting to lean on it even more going forward, primarily to compare options and narrow down decisions rather than to complete full checkouts, at least for now. Ogilvy North America’s head of innovation, Kaare Wesnaes, described the shift bluntly: once someone decides they need something, they’ll no longer open ten tabs or read 20 reviews before buying. Instead they’ll ask an agent to do all of that comparison work for them and simply bring back a recommendation they trust. Gap Inc’s chief technology officer Sven Gerjets put the marketing implication even more directly, noting that brands need to show up not just in search engines, but in answer engines, in a sentiment shared via LinkedIn and covered by eMarketer.
The problem, as retail focused analysts have bluntly pointed out, is that most merchant infrastructure and attribution systems simply weren’t built for a customer that isn’t a person actively clicking through a browser. Early data suggests agent driven traffic can convert dramatically worse than traditional affiliate traffic when a retailer’s product feed and checkout architecture hasn’t been made agent ready, a gap researchers tend to attribute to infrastructure readiness rather than any lack of underlying consumer demand.
For affiliate marketers and performance advertisers, this raises a genuinely open question the industry hasn’t solved yet. What does a click or a referral even mean when the entity doing the clicking is software acting on stated human preferences rather than a person’s own finger on a mouse? Analysts at commerce infrastructure firms are candid that reliable attribution for agentic commerce is likely still eighteen to twenty four months away from actually maturing, which means brands investing in this channel right now are largely operating on faith rather than any measurable return on investment, a striking inversion for a discipline, affiliate and performance marketing, that has always taken particular pride in being the most measurable form of advertising that exists.
What the industry is actually doing about it
None of this is happening in a vacuum. A real infrastructure has emerged to push back, even if it’s still very much playing catch up.
Standards bodies have done the unglamorous but genuinely essential work of building shared vocabulary and accreditation. The Media Rating Council’s Invalid Traffic Detection and Filtration Guidelines, developed jointly with the IAB and the Trustworthy Accountability Group, give the industry the GIVT and SIVT framework referenced throughout this piece, and MRC accreditation has effectively become a practical requirement for any verification vendor advertisers are expected to trust with real budgets.
Verification vendors, including DoubleVerify, HUMAN Security, Integral Ad Science, Fraudlogix, and channel specific tools like TrafficGuard and Fraud Blocker for paid search, now sit about as close to mandatory infrastructure as optional tooling ever gets in modern media buying, offering pre bid filtering that blocks suspect inventory before a bid is even placed, and post bid monitoring that flags and credits back fraud that slipped through anyway.
Infrastructure providers are actively rewriting the rules of engagement between publishers and AI companies. Cloudflare’s shift toward blocking new domains against AI crawlers by default, and its evolving Pay Per Crawl and Pay Per Use marketplace, represent the first serious attempt at making AI companies actually pay for the content they’ve been extracting largely for free. As of mid 2026, major labs including OpenAI, Anthropic, Google DeepMind, and Meta had not yet broadly adopted the payment mechanism, which means publishers who opt in mostly see their content simply blocked rather than monetized in practice today.
Trade bodies are pushing for structural accountability rather than settling for slightly better filtering. The ANA’s ongoing Programmatic Transparency Benchmark is explicitly designed to give advertisers the log level data and direct contract leverage needed to demand better supply chain behavior from DSPs and SSPs, rather than simply accepting waste as an unavoidable cost of doing business in programmatic media.
A practical playbook
Given everything above, a handful of concrete practices show up consistently across the sources cited here as genuinely reducing exposure, regardless of which channel you’re working in.
- Insist on log level data and direct contracts wherever possible. The ANA’s own research is unambiguous that advertisers with direct relationships to DSPs, SSPs, and verification vendors, and real access to raw impression level data rather than platform summarized dashboards, recover meaningfully more working media value than those relying on black box reporting alone.
- Treat MRC accreditation as a floor, not a differentiator. If a verification vendor isn’t accredited for SIVT specifically, and not just GIVT, it is only catching the obvious, easy fraud and leaving the sophisticated fraud to slip right through.
- Look past the click to what happens afterward. In both affiliate and paid search fraud, the most reliable tell isn’t the click or the lead itself. It’s what happens after: refund rates, call to close rates, session depth, and customer lifetime value. Fraud is increasingly engineered to convincingly fake the first touch and then fail at literally everything downstream of it.
- Segment AI referred traffic separately in your analytics rather than lumping it in with classic organic search. Traffic arriving via ChatGPT, Perplexity, or an AI Overview citation behaves differently, often converting at a meaningfully different rate, than traditional organic search traffic, and treating them as one bucket obscures both the threat and the opportunity sitting inside that segment.
- Decide deliberately, not by accident, on AI crawler access. Blocking AI crawlers protects your content and your infrastructure costs, but it can also reduce your visibility inside AI mediated discovery. Allowing them without any compensation effectively donates your content to a competing distribution channel for free. Cloudflare’s per crawler allow, charge, or block controls, and similar tools from other providers, at minimum turn this into a conscious business decision rather than an accident of whatever the default setting happened to be.
- Budget for both the fraud losses and the fraud tooling. Spending on ad fraud detection and prevention is itself growing sharply industry wide, a signal that treating verification as a genuine line item, rather than optional overhead you’ll get to eventually, is quickly becoming standard practice among serious advertisers.
The bottom line
The web that marketing as a discipline was originally built to navigate, one made of pages, clicks, sessions, and conversions all traceable back to an actual person, is being overlaid by a second web made of scrapers, agents, fraud rings, and AI intermediaries that don’t behave like people and increasingly can’t be filtered out using yesterday’s tools. Treating this as purely a security or IT problem is a mistake. It’s a marketing measurement problem first and foremost, because every budget decision, every attribution model, and every conversation about what’s actually working now runs on data that is meaningfully less trustworthy than it was even two years ago.
Nothing in any of the sources gathered here suggests this trend is reversing anytime soon. What they do suggest is that the gap between marketers who treat traffic quality as a first class metric, worthy of the same rigor as CPA or ROAS, and those who still don’t, is going to keep widening. The bots aren’t going anywhere. The AI agents are only going to get more capable and more numerous. The only real choice left for anyone running a budget is how seriously their organization decides to actually measure all of it, starting now rather than after the next quarter’s numbers come back looking strange.

I manage ClickBaton.com and ROIpad.com our product positioning intelligence platform. I am always open to new partnerships, collaboration and speaking directly with founders who are looking to test our products. Please feel free to connect with me on linkedin.