The Brief
How AI Works 4 min read

Bad Bots Grew 124% in a Year. The Web Is Changing.

NAVION

Share

The internet has always had bots. What is changing, at a pace that most coverage underestimates, is where those bots are going and what they are doing when they get there. A new report from DataDome, drawing on more than 1 trillion web requests across more than 75,000 customer sites, offers one of the clearest pictures yet of how automated traffic is reshaping the online environment. The headline figure is striking: malicious bot traffic grew 124% between July 2025 and June 2026. That is nine times faster than human traffic grew during the same period.

The Bots Are No Longer Knocking at the Front Door

For years, the standard mental model of a bot attack involved the edges of a website: scrapers harvesting public content, crawlers indexing pages, automated tools probing for surface-level vulnerabilities. That model is now outdated.

According to the DataDome findings, bots are moving deeper into the architecture of the customer journey. Login pages, account creation flows, shopping carts, and payment endpoints are now primary targets. AI bots, specifically, are targeting login pages at eight times the rate recorded in the previous year’s report. This is not a marginal shift. It represents a fundamental change in what automated traffic is trying to accomplish.

Jérôme Segura, VP of threat research at DataDome, frames the challenge precisely: the question for businesses is no longer simply whether traffic is automated, but whether that automation is beneficial or harmful. Some bots are legitimate. Search engine crawlers, accessibility tools, and AI training agents all generate automated traffic with defensible purposes. The problem is that the infrastructure for distinguishing good automation from bad has not kept pace with the volume or sophistication of what is arriving.

Who Is Sending the Bots, and What Are They After?

The DataDome report identified 52.7 billion crawler requests from AI agents and large language models during the study period. More than 46% of those requests came from Meta-affiliated systems. OpenAI was the second-largest source, accounting for nearly 35% of the total. These figures reflect the scale at which AI companies are harvesting web content, whether for training data, retrieval systems, or other purposes.

The 185% increase in scraping activity fits this context. As AI systems require ever-larger datasets, the incentive to crawl and extract web content at scale grows accordingly. This is not inherently malicious, but it places significant load on websites that were not designed to handle it, and it raises unresolved questions about consent and compensation for content creators.

Separate from scraping, bot use for scalping, the automated purchase of tickets and high-demand items for resale, grew at nearly three times the pace of the previous year. Ted Miracco, CEO of cloud software platform Approov, describes the business consequence directly: scalping turns a company’s best customers into its angriest ones. The downstream effects include lower margins, damaged customer goodwill, and inventory disruption. These are not abstract risks. They are operational problems that affect revenue and reputation.

The protection gap is significant. DataDome tested 20,000 websites and found that 65.3% had no protection against the ten bot types included in the study. Only 2.4% of sites were fully protected, a figure that has declined from 8.4% in 2024 and from 2.8% in the most recent prior report.

What This Means Beyond the Security Conversation

The DataDome findings arrive alongside separate data from Cloudflare showing that bots already account for a majority of web traffic, with figures cited at 57.4% and rising to 62.5%. Taken together, these numbers raise a question that goes beyond cybersecurity: what does it mean for the web when most of its traffic is not human?

Segura is careful to push back on the more dramatic interpretation, sometimes called the “dead internet theory,” which holds that the internet is already dominated by automated content and bot-to-bot interaction with little genuine human presence. His data does not support that conclusion. Across DataDome’s customer traffic analysis, humans still generated 73.4% of requests, even as automated traffic grew at nine times the human rate.

The more precise concern is not that humans have disappeared from the web, but that the systems businesses use to serve those humans are increasingly under pressure from automated activity that was not anticipated when those systems were designed. Static, identity-based controls, the kind that check whether a user looks like a known bad actor, are no longer sufficient. Real-time decisions about what automated traffic to allow, and what to block, are becoming a baseline requirement rather than an advanced capability.

This is what most coverage of bot statistics misses. The numbers are alarming, but the structural implication is more important: the web’s security assumptions were built for a different era, and the gap between those assumptions and current reality is widening.

In Short

Malicious bot traffic grew 124% in a single year, nine times faster than human traffic. Bots are no longer targeting the edges of websites; they are reaching login pages, payment flows, and account systems. AI-affiliated crawlers from companies including Meta and OpenAI account for tens of billions of requests. Most websites remain largely unprotected. Humans still generate the majority of web requests, but the automated share is growing fast, and the tools businesses use to manage that traffic have not kept pace.

Based on reporting from Fast Company - Tech.

Written by

NAVION