logo
|
Blog
    BotManager

    2026 Bad Bot Report: The Threat of AI-Powered Bots

    Bots now account for 53% of web traffic. Explore the 2026 Thales Bad Bot Report and how BotManager protects APIs and critical infrastructure.
    Daniel(원재인)'s avatar
    Daniel(원재인)
    Sep 15, 2026
    2026 Bad Bot Report: The Threat of AI-Powered Bots
    Contents
    AI Bots Are Reshaping Internet TrafficHow AI Is Changing Bot Attack Trends1. The Line Between Good Bots and Bad Bots Is Blurring2. Bots Are Targeting APIs and Accounts Directly3. Bots Continue to EvolveHow Should Businesses Manage AI-Powered Automation?

    AI Bots Are Reshaping Internet Traffic

    Machines now generate more internet traffic than humans.

    According to the 2026 Thales Bad Bot Report*, human activity accounts for only 47% of global web traffic. The remaining 53% comes from automated traffic generated by bots.

    Of all internet traffic, good bots—including search engine crawlers and site-monitoring tools—account for 13%. Meanwhile, bad bots performing malicious activities such as hacking, data theft, and service disruption account for 40%.

    Traffic Type

    Share of Internet Traffic

    Human Traffic

    47%

    Bot Traffic

    53%

    How AI Is Changing Bot Attack Trends

    Types of Bot Attacks
    Types of Bot Attacks

    Advanced and moderate bot attacks are becoming increasingly adaptive and persistent. With the help of AI, attackers can adjust access patterns and timing and quickly change their attack strategies.

    At the same time, AI has lowered the barrier to entry for simple bot attacks. Even attackers with limited technical expertise can now operate automated systems at scale. While individual attacks may not be highly sophisticated, large volumes of simple bot traffic can create persistent infrastructure load and operational disruption.

    In real-world service environments, these attack types often work together. Large-scale simple bot attacks continuously consume infrastructure resources, while advanced and moderate bots target high-value workflows such as authentication, reservations, and payments.

    Organizations therefore need to understand how bot attacks are evolving and adapt their defenses accordingly.

    1. The Line Between Good Bots and Bad Bots Is Blurring

    Bot security used to be relatively straightforward. Search engine crawlers such as Googlebot were considered “good bots,” while automated tools used by attackers were classified as “bad bots.”

    The widespread adoption of AI agents and large language models (LLMs), however, is breaking down this distinction.

    AI agents can access websites on behalf of users, search for information, shop, make reservations, and perform other tasks. Embedded in browsers, search platforms, and enterprise tools, they increasingly interact directly with applications and APIs.

    As a result, automated behavior that might previously have been considered suspicious is now becoming part of legitimate internet activity.

    AI traffic can broadly be divided into two categories:

    • AI Crawlers: Systematically explore websites and APIs to collect data for model training. Unlike traditional crawlers, they may interact with dynamic content, follow complex data paths, and extract both structured and unstructured content at scale.

    • AI Fetch Agents: Retrieve specific content in response to user requests. Rather than broadly indexing content, they focus on targeted retrieval and can extract specific information from web pages, APIs, or databases.

    The challenge becomes clearer when we look at how this supposedly legitimate AI traffic behaves.

    Detection Type

    AI Crawlers

    AI Fetch Agents

    Bad Bot Detection

    8.8%

    10.8%

    Customer-Defined Rules

    11.9%

    7%

    DDoS Rules

    4%

    0.53%

    According to the report, 8.8% of AI crawler traffic and 10.8% of AI fetch-agent traffic triggered bad-bot detection rules. This means that AI-driven traffic is already exhibiting behavioral patterns similar to malicious automation.

    Customer-defined rules were also triggered by 11.9% of AI crawler traffic and 7% of AI fetch-agent traffic. This suggests that many organizations either do not want certain AI bots crawling their sites or prefer to control how that traffic is allowed to interact with their services.

    The fact that 4% of AI crawler traffic triggered DDoS-related rules further highlights the potential for AI-driven activity to develop into disruptive or aggressive traffic patterns.

    An even greater challenge is that this analysis covers only identifiable AI clients. There may be significantly more AI-driven automated traffic operating without being recognized as such.

    It is becoming increasingly difficult to determine intent when traffic appears to come from a legitimate AI agent but is actually scraping valuable business data without authorization or placing excessive load on infrastructure.

    For businesses, the ability to distinguish approved AI traffic from unverified automation using validated headers, customized policies, and behavioral controls is becoming increasingly important.

    2. Bots Are Targeting APIs and Accounts Directly

    In 2025, 27% of all bot attacks targeted API endpoints.

    Modern bots are increasingly designed with an API-first approach, allowing them to interact directly with backend services without going through the user interface.

    Analysis of API attack traffic shows that data leakage and business logic attacks are the most common.
    Analysis of API attack traffic shows that data leakage and business logic attacks are the most common.

    API attacks can have a direct business impact through activities such as data leakage, business logic abuse, remote code execution, and remote file inclusion. Excessive API calls generated by AI agents are also becoming an important security concern for developers and security teams.

    These attacks are particularly concentrated in high-value industries where successful abuse can generate direct financial returns.

    • Financial Services: The industry accounted for 24% of all bot attacks, while 46% of account takeover (ATO) attacks targeted financial services.

    • E-commerce and Travel: Attackers increasingly exploit business logic rather than simply attacking infrastructure. Examples include continuously scraping competitors’ pricing data or adding products to shopping carts without any intention to purchase, creating artificial stock shortages. These activities can negatively affect both revenue and customer experience.

    Strengthening API security therefore requires more than infrastructure-level protection.

    Organizations also need behavior-based monitoring at API endpoints, including control over authentication, data access, payment activity, access permissions, and request patterns.

    3. Bots Continue to Evolve

    Bad bots are evolving rapidly with the help of AI.

    • 41% of bad bot attacks impersonate Google Chrome to bypass basic security controls. Android Browser impersonation also accounts for 17%, demonstrating that mobile traffic continues to be used as a disguise for automated activity.

    • Attackers continue to hide behind residential static IP addresses and mobile proxy networks, allowing malicious traffic to blend naturally into legitimate user traffic.

    • Traditional defenses such as CAPTCHA are also being bypassed at scale.

    If your bot defense still relies primarily on static rules such as IP blocking or simple rate limiting, sophisticated automated attacks may already be slipping through.

    Defenses need to evolve alongside changing bot behavior.

    How Should Businesses Manage AI-Powered Automation?

    Blocking every bot is neither realistic nor beneficial for business growth.

    The more important challenge is to build a system that can distinguish between automation that supports your business and malicious bots that exploit it—and manage both in real time.

    • Protection must extend beyond web pages to critical infrastructure such as backend APIs and authentication systems through multi-layer access control.

    • Organizations should be able to analyze attacks and respond with AI assistance, even without dedicated security specialists.

    • Alongside predefined rules, intelligent defenses should dynamically adapt to changes in attacker behavior.

    This is where BotManager, developed by traffic management specialist STCLab, can help.

    BotManager uses a multi-layer architecture across the client side, server side, and CDN to improve the detection of malicious bots and macros. It also uses AI-powered analysis and policy recommendations to help optimize bot detection and response.

    Most importantly, organizations can apply a wide range of behavioral policies to detect and block abnormal access attempts in real time.

    In an era where machines generate more than half of all internet traffic, businesses need the ability to understand the intent behind traffic and control it in real time. This capability is becoming essential to protecting both customer trust and business performance.

    Before malicious bots consume your service resources—and before unnecessary infrastructure costs and damaged customer trust begin to accumulate—build a stronger standard for security in the AI era with BotManager.

    Explore BotManager →

    *This article is based on the 2026 Thales Bad Bot Report: Bad Bots in the Agentic Age.

    Share article
    Contents
    AI Bots Are Reshaping Internet TrafficHow AI Is Changing Bot Attack Trends1. The Line Between Good Bots and Bad Bots Is Blurring2. Bots Are Targeting APIs and Accounts Directly3. Bots Continue to EvolveHow Should Businesses Manage AI-Powered Automation?

    STCLab Inc.

    RSS·Powered by Inblog