The problem

The bot majority: how automated traffic overtook people online

For most of the internet's history, the thing on the other end of a request was a person. By the most widely cited measure, that stopped being true in 2024.

BAD BOTS 40OTHER BOTS 13HUMANS 47
Share of web traffic, 2025. Thales Imperva Bad Bot Report 2026.

The numbers

The longest-running annual measurement comes from Imperva, now part of Thales. Its 2026 report found that automated traffic accounted for more than 53% of all web traffic in 2025, up from 51% the year before, leaving humans at 47%. The same series measured bad bots, meaning automation built to scrape, defraud or abuse, at 40% of traffic, up from 37% in 2024. It also found that 27% of bot attacks targeted APIs directly, skipping the visible website entirely.

The 2024 figure was a milestone. It was the first time in a decade that the series recorded more automated traffic than human traffic.

Why the estimates disagree

If you look at network-wide data, such as Cloudflare Radar, the share of bot traffic is lower, roughly a third of requests. Both can be right. Security vendors measure the traffic hitting the customers they protect, which is weighted toward login pages, checkout flows and APIs, exactly where automated abuse concentrates. A network-wide count includes enormous volumes of ordinary human browsing and video.

For anyone deciding whether to protect a channel, the attack-surface number is the relevant one. Your contact form, support inbox and sign-up page are not average pages. They are the pages automation is aimed at.

What changed: three kinds of automation

Good bots

Search crawlers, uptime monitors and feed readers. They identify themselves and mostly follow the rules.

Bad bots

Scrapers, credential stuffers, fake account factories, form spammers and click fraud. They disguise themselves as browsers, rotate through residential IP addresses and increasingly use AI to get past defences.

AI agents

The new category. An agent acts on behalf of a real person or company: it researches, fills in forms, books, buys and writes emails. An agent is not malicious by design. The problem is scale. One person with an agent can do the work of a thousand people with keyboards, and every channel priced for human effort is suddenly underpriced.

Why this matters beyond security teams

Most inbound channels were designed on an unstated assumption: that effort limits volume. Writing an email, filling in a form or submitting a job application took a person a few minutes, so nobody could send millions of them. Generative AI removed that limit for content, and agents removed it for actions. The channels stayed the same.

The result is not only fraud. It is noise at a volume that makes the channel useless: inboxes where no message is one-to-one, support queues where real customers wait behind automated tickets, and public consultations where the count of comments means nothing. See the channel map.

What to take from it

  • Assume any open inbound channel receives mostly automated traffic unless you have evidence otherwise.
  • Don't rely on the channel's own signals, such as a filled-in form or a well-written email, as proof of a person. Both are now free to produce.
  • Decide per channel what you actually need to know: that a person is present, that the sender is who they claim, or simply that the sender cares enough to pay a small cost. The five approaches compared.

Sources

  1. Thales Imperva, 2026 Bad Bot Report: Bad Bots in the Agentic Age
  2. Imperva, 2025 Bad Bot Report
  3. Cloudflare Radar, traffic and bot insights