Malicious bot traffic rose 124% between July 2025 and June 2026, more than nine times faster than human traffic, according to DataDome, which analyzed automated activity across more than 75,000 customer sites.
The company’s 2026 State of Bot & Agent Security Report also found that AI-related traffic rose 82.3% during the same period. DataDome analyzed more than a trillion requests and separately tested more than 20,000 popular websites.
Scraping remained the largest category of malicious bot activity. It accounted for 70.9% of bad bot traffic and increased 185.2% over the year. DataDome said one possible explanation is the expanding AI data supply chain, in which third-party data resellers and companies building AI applications collect web content at scale. The report presents that as a possible connection, not a confirmed cause.
AI agents are also reaching parts of websites beyond publicly accessible content pages. In the first half of 2026, DataDome recorded 605.6 million AI agent requests to login pages, forms, carts, payment flows and account-creation pages. Login pages accounted for 51.7% of that traffic, with monthly requests increasing from 11.9 million in January to 99.7 million in June.
But DataDome cautions against treating all of that activity as malicious. A legitimate AI assistant helping someone shop can generate requests that resemble automated credential testing or other abusive activity. That makes intent increasingly important when websites decide what to allow or block.
The report found other forms of automated abuse rising as well. Scalping activity increased 290.7%, while fake account creation grew 34.5%. Credential-stuffing activity fluctuated sharply, dropping nearly 90% after a major spike before later climbing to new daily highs.
Sponsored. Journalists, PR pros and communicators: the fall cohort of AI for Media starts October 13, six live Tuesday sessions with Pete Pachal plus two 1:1 coaching calls. Code AISEARCH500 takes $500 off the $1,500 price for anyone who found the course through AI search, a bigger discount than is offered anywhere else.
DataDome tested how well websites could detect and block automated traffic. In a controlled assessment, the company sent 10 types of bot and spoofed AI-agent requests to 21,491 websites, ranging from basic automation to more advanced browser-based bots.
The results showed large gaps in defenses: 65.3% of the sites blocked none of the 10 test types, while just 2.4% blocked all of them.
The report covers websites broadly, not publishers specifically. But separate data show why news organizations are watching automated traffic closely. DataDome recorded 17.7 billion AI agent requests in Q2 2026, much of it from Meta-affiliated crawlers. Separately, Cloudflare’s CEO has said bots now outnumber human visitors across traffic seen on its network. The figures come from different datasets and are not measurements of the web as a whole.
Publishers are also testing responses beyond blocking. Time is selling ads on markdown pages built for AI crawlers, treating some automated traffic as a potential audience rather than only a threat.
DataDome’s point is simpler: websites need better ways to tell useful AI agents from abusive bots. As automated traffic moves into login, account and payment flows, the old human-versus-bot distinction is no longer enough.







