The Rise of the Machine: Unpacking DataDome’s 2026 State of Bot & Agent Security Report

The digital landscape is undergoing a structural transformation, one characterized by a staggering surge in automated traffic that threatens to eclipse human interaction on the web. On September 22, 2026, cybersecurity firm DataDome released its State of Bot & Agent Security Report 2026, a comprehensive analysis that serves as a sobering wake-up call for publishers, retailers, and digital marketers alike. By synthesizing traffic data from over 75,000 customer websites alongside a rigorous external audit of more than 21,000 high-traffic domains, the report exposes a critical vulnerability: the vast majority of the modern web is effectively defenseless against sophisticated, automated agents.

Main Facts: The Automation Tsunami

The headline figures from the report are startling. Between July 2025 and June 2026, "bad bot" traffic—software designed for scraping, credential stuffing, and fraud—surged by 124%, growing at a rate nine times faster than human traffic. While human participation in web requests remains the majority at roughly 73%, the remaining 26.5% is dominated by a complex ecosystem of good bots, malicious scrapers, and a rapidly expanding cohort of Artificial Intelligence (AI) agents.

Perhaps most alarming is the report’s external benchmark. DataDome deployed 10 distinct test bots against 21,491 of the most visited domains on the internet. The result: 65.3% of these sites failed to block or even challenge a single one of the test bots. Only a meager 2.4% managed to intercept all 10, a decline from the 8.4% recorded just two years prior. This suggests that as bot technology advances toward more human-like, "agentic" behavior, defensive measures are failing to keep pace.

Chronology: A Year of Escalation

The data reveals a clear trajectory of increasing bot activity throughout the 12-month study period:

  • July 2025: Human traffic share sits at 77.9%, with bad bots accounting for 9.9%.
  • Late 2025: AI agent traffic begins a steady climb, averaging 3.89 billion monthly requests.
  • February 2026: A critical inflection point. Human traffic hits a low of 70.7%, while bad bot activity peaks at 20.3%.
  • March–April 2026: Security incidents spike. DDoS traffic hits a record 2 billion requests in a single day in April; credential stuffing, while flat on an annual basis, shows intense, cyclical bursts of activity.
  • May–June 2026: AI traffic reaches a fever pitch, with 6.6 billion requests in June alone. The report concludes with an external benchmark test conducted throughout June, revealing the widespread failure of standard domain protections.
  • July 2026: Post-study data indicates that AI spoofing—where malicious actors masquerade as legitimate crawlers like ChatGPT or ClaudeBot—continues to rise, with spoofing rates for user-prompted agents reaching 5.6%.

Supporting Data: The Anatomy of a Threat

DataDome’s methodology relies on three distinct datasets: anonymized customer traffic (trillions of requests), a filtered analysis of 52.7 billion AI-specific requests, and an external benchmark test.

The Rise of the AI Crawler

The report highlights a significant shift in the AI ecosystem. Meta-affiliated bots dominate the landscape, accounting for 46.3% of AI traffic, followed by OpenAI at 34.6%. Interestingly, Google’s reported share remains low (0.4%), a discrepancy the report attributes to Google routing AI traffic through its existing, well-established "Googlebot" infrastructure rather than deploying new, distinct crawlers.

The Vulnerability of High-Risk Endpoints

The most dangerous trend is the migration of AI traffic toward "high-risk" endpoints. While 97.9% of AI requests target public content, the remaining 605.6 million requests targeted login pages, checkout flows, and account creation forms. Login page traffic, in particular, exploded by 735.8% between January and June 2026. This is a critical area for account takeover (ATO) fraud, as agents can automate the testing of compromised credentials at an industrial scale.

The Spoofing Epidemic

Identity in the age of AI is increasingly fragile. Malicious actors are frequently spoofing the headers of legitimate bots. DataDome found that 80% of AI agents do not correctly identify themselves, and the rate of traffic claiming to be a known agent—without actually being one—rose by 45% in the latter half of the study. This renders simple "allow-lists" based on user-agent names obsolete.

Official Responses and Industry Context

While the report is a product of a vendor seeking to promote its own "intent-based" security solutions, it aligns with broader industry warnings. The report notes that traditional CDN-based filtering is no longer sufficient. Because DataDome sits downstream of most CDN layers, their figures represent a "conservative lower bound" of the actual bot volume hitting the web.

Other industry players have echoed these concerns. Cloudflare’s 2026 threat reports have highlighted that up to 94% of login attempts on their network are bot-driven. Furthermore, legal bodies have begun to intervene; in March 2026, a US court blocked the Perplexity AI "Comet" browser from accessing Amazon accounts, citing the Computer Fraud and Abuse Act—a landmark decision that underscores the legal volatility of AI-driven web interaction.

Implications: The New Marketing and Security Reality

For businesses, the report suggests a paradigm shift in how they must measure their digital footprint.

The Marketing Conundrum

For marketers, the proliferation of bots creates a "pollution" problem. When automated agents—or even legitimate AI crawlers—fill out lead forms, click on ads, or trigger tracking pixels, they skew campaign data. Invalid traffic (IVT) is now a primary threat to marketing budgets. With 75.6% of marketers estimating they lose budget to bots, the report validates the urgent need for dedicated IVT tools that can distinguish between human intent and automated noise.

The Security Mandate

The report concludes that the binary "human vs. bot" question is dead. Organizations must now ask, "Is this visitor beneficial to my business?" This requires a move toward intent-based detection. Effective security must now encompass:

  1. Behavioral Sequencing: Analyzing how a visitor moves through a site rather than just checking their ID.
  2. Endpoint Sensitivity: Applying stricter controls to login, payment, and form pages than to informational content.
  3. Governance: Establishing clear, published policies for AI agents, effectively creating a "digital handshake" that defines the terms under which AI is permitted to crawl a site.

The Trade-off

DataDome acknowledges a commercial tension: aggressively blocking all automated traffic risks losing SEO visibility and legitimate AI-driven traffic, but a permissive policy invites fraud. The recommendation is a nuanced, granular approach to access control. As the report notes, "Businesses that hard-block all AI traffic will lose revenue, and businesses that allow everything through will face fraud and abuse."

Ultimately, the 2026 DataDome report paints a picture of a web that is increasingly populated by non-human actors. For the average webmaster, the era of relying on simple filters is over. The new reality demands a sophisticated, intent-aware infrastructure capable of verifying not just who is visiting, but why they are there—and whether their presence adds value or creates risk. As the digital and physical worlds become more intertwined through AI agents, the security of these automated gates will define the future of the internet economy.