DataDome on September 22, 2026 published its State of Bot & Agent Security Report 2026, which combines traffic from more than 75,000 customer sites between July 2025 and June 2026 with a June 2026 test of 21,491 of the most visited domains on the web. Of those domains, 65.3 percent let every one of the company's 10 test bots through without a block or a challenge.

In Short

A company that sells protection against automated website traffic tested more than 21,000 widely visited websites and found that about two in three did nothing to stop any of its fake visitors, while roughly one in 40 stopped all of them. On its own customers' sites, it also saw AI tools hitting login pages more than eight times as often in June as in January, which is where account theft and fraud usually start. For marketers and publishers, it means more of the visits, clicks and form fills in your reports may come from software, and a visitor calling itself ChatGPT or ClaudeBot may be something else entirely.

Three datasets from one vendor

The report, previously published under the name Global Bot Security Report, draws on three bodies of data, according to its methodology section. The first is anonymised traffic across DataDome's customer base between July 2025 and June 2026. The second is a filtered view of that same traffic covering AI agents, agentic browsers and large language model crawlers, which amounts to 52.7 billion requests. The third is an external benchmark in which DataDome sent automated requests to the homepages of heavily trafficked websites across 15 industries during June 2026. Domains that were unreachable during the testing window were dropped, leaving a final sample of 21,491, up from 16,948 in the 2025 edition.

According to DataDome, the rename reflects a change in what the company sees on the network. "Bots and AI traffic now represent two distinct and growing challenges that organizations need to understand together," the report states.

The document is inconsistent about its own scale. The executive summary describes "over a trillion requests" across customer sites, while the methodology section and the company's web version refer to "trillions of requests." Neither gives a precise figure.

Several caveats sit in the fine print. Attack vector figures count detected attempts, not successful attacks, and a request can be classified as an attack even when DataDome blocked it before completion. Approximately 60 percent of DataDome customers operate behind a content delivery network with basic bot filtering switched on, and because DataDome sits downstream of that layer, the company describes its automated traffic figures as "a conservative lower bound." There is a further limitation the report does not address: the customer dataset describes sites that pay a vendor to filter automated traffic, a population that may attract, or already expect, more attacks than the wider web. All of the figures below are vendor-supplied and have not been independently audited.

Bad bots outgrew people ninefold

Between July 2025 and June 2026, total traffic across DataDome customers grew 23.7 percent and human traffic grew 13.2 percent, according to the report. Bad bot traffic grew 124.0 percent, which is where the headline claim of "more than 9x the rate of human traffic growth" comes from. AI traffic grew 82.3 percent. Good bots grew 1.3 percent.

Across the full period, humans accounted for 73.41 percent of requests, bad bots for 15.42 percent, good bots for 9.93 percent and AI agents for 1.25 percent. That puts automated traffic at roughly 26.5 percent of the total, or more than one request in four. The monthly picture moved faster than the annual averages suggest. Human share fell from 77.9 percent in July 2025 to a low of 70.7 percent in February 2026, then settled between 71.3 and 71.8 percent through the first half of 2026. Bad bots absorbed almost all of that shift, climbing from 9.9 percent of traffic in July 2025 to a peak of 20.3 percent in February 2026 before easing to approximately 17.6 percent in the second quarter.

The figures sit well below the network-wide numbers that have circulated this year. Cloudflare Radar data put bots at 57.4 percent of HTML web traffic in the week ending June 5, 2026, against 42.6 percent from humans. The gap is largely methodological. Cloudflare measures at the network edge, while DataDome measures traffic that has already passed through a CDN filter on the sites of its own customers.

Scraping dominates on volume, scalping grows fastest

Scraping accounted for 70.9 percent of all bad bot traffic across DataDome's customer base and grew 185.2 percent over the 12 months, according to the report. DDoS traffic followed at 12.7 percent, then spamming at 7.9 percent and credential stuffing at 6.7 percent. Fake account creation, payment fraud and vulnerability scanning each made up 0.6 percent or less, and scalping was the smallest category at 0.2 percent.

The report's key findings page describes scraping as "the fastest-growing attack vector." Its own growth chart does not support that label. Scalping grew 290.7 percent over the same period, with median daily volume nearly quadrupling, which places it well ahead of scraping on rate of growth. Scraping leads on volume, not on pace.

DataDome offers a hypothesis for the scraping surge rather than a finding. According to the report, "one possible explanation" is an AI data supply chain, in which third-party data resellers and applications building AI agents collect web data at scale for training and agent responses. The company notes that this activity "does not always identify itself as an AI crawler" and can run on conventional scraping infrastructure, which would mean the effect of AI on web traffic may be larger than the traffic carrying an AI label suggests.

Other vectors behaved differently. DDoS traffic grew 39.9 percent on a steadier upward path and peaked above 2 billion requests in a single day in April 2026. Spamming rose 44.9 percent in a series of waves. Fake account creation grew 34.5 percent, with attackers commonly using browser automation frameworks such as Playwright and Chrome DevTools Protocol.

Credential stuffing tells a different story. Net volume was flat, down 1.1 percent across the year, but the annual figure hides a cycle. Activity surged through summer 2025, dropped by nearly 90 percent over the following three months, recovered fully by early 2026 and reached new single-day highs in April. DataDome's interpretation is that attackers run intense campaigns, go dark "likely to refresh credential lists and rotate infrastructure," and then return at full scale.

Simple bots still get through

For the first time, DataDome classified a sample of bad bot traffic by sophistication. The analysis covered more than 1.5 billion bad bot requests over 30 days in 2026. Simple bots, which trigger WebDriver signals exposed by Selenium and basic ChromeDriver automation, made up 49 percent, or 735.2 million requests. Average bots, built on Playwright and Chrome DevTools Protocol, accounted for 29.5 percent, or 443 million. Advanced bots represented 21.5 percent, or 322.2 million requests, which the report labels "payload forgers" detected through WebAssembly and virtual machine signals.

Why would anyone still run a bot that makes no attempt to hide? The benchmark supplies the answer. According to the report, simple bots evade detection on an average of 88.6 percent of websites tested. "Attackers continue using them because they continue to work," the report states.

The techniques rarely mix at the top end. Simple and advanced signals overlapped in only 0.01 percent of volume, which DataDome reads as different actors running different toolchains. Simple and average techniques overlapped more often, with 4.4 percent of the sample showing both WebDriver and Playwright signals in the same campaign window, a pattern the company interprets as attackers starting with basic automation and escalating when detection looks likely.

52.7 billion AI requests, with Meta ahead of OpenAI

AI agent and crawler traffic totalled 52.7 billion requests over the 12 months, according to the report: 23.06 billion in the second half of 2025 and 29.65 billion in the first half of 2026. Monthly volume averaged 3.89 billion from August through December 2025, reached 4.11 billion in January 2026, dipped to 3.45 billion in February and then climbed to 6.36 billion in May and 6.6 billion in June. AI traffic's share of all requests rose from 1.2 percent in July 2025 to 1.7 percent in June 2026. DataDome projects that the category is "on pace to exceed 79.2 billion annual requests by 2027" if growth continues, a projection rather than a measurement.

The attribution by company for the first half of 2026 is concentrated. Meta-affiliated bots generated 46.3 percent of identified AI traffic, OpenAI 34.6 percent, Huawei's PetalBot 5.3 percent, Amazon 5.3 percent, Anthropic 3.5 percent and Perplexity 2.8 percent. ByteSpider, attributed to TikTok, came in at 1.4 percent, Google's Gemini and Vertex agents at 0.4 percent and DuckDuckGo at 0.3 percent. DeepSeek, Manus, Mistral AI, Microsoft Copilot and Apple each accounted for less than 0.1 percent. DataDome's taxonomy covers more than 100 named agents and crawlers.

Meta's lead rests on two crawlers. Meta-ExternalAgent generated 8.54 billion requests and Meta-WebIndexer 5.30 billion, according to the report, and Meta's AI traffic rose 164.9 percent between January and June 2026. The two totals add up to 13.84 billion, marginally more than 46.3 percent of the 29.65 billion half-year figure, a gap the report leaves unexplained.

The OpenAI entry contains a naming problem. The report lists the company's portfolio as ChatGPT-User, "ChatGPTBot" and "OpenAI-SearchBot." OpenAI's documented crawlers are GPTBot and OAI-SearchBot, and the report itself uses those correct names in its spoofing section a page later.

Google's small share has an explanation. According to DataDome, Google routes AI agent traffic through existing Googlebot infrastructure rather than deploying separate LLM crawlers, and Gemini can draw on Google's search index and cached content without sending a fresh request to every site. The company concludes that Google's "actual AI footprint on the web is likely much larger" than 0.4 percent. Google added Google-Agent to its crawler documentation on March 20, 2026 as a user-triggered fetcher, a category that sits apart from its main crawler.

Two smaller sources moved quickly. DuckDuckGo's AI bot traffic rose 423 percent in the first half of 2026. Perplexity's Comet browser accounted for 12.2 percent of Perplexity-attributed bot traffic, with PerplexityBot at 78.2 percent. That is a different measure from HUMAN Security's May 2026 benchmark, which put Comet at 47 percent of all observed agentic traffic.

One internal figure does not reconcile. Section 2.1 of the report puts first-half 2026 AI traffic at 29.65 billion requests, while section 2.4 analyses "29.02 billion AI bot requests" for the same January to June period. The report does not explain the 630 million request difference.

Half of sensitive AI traffic lands on login pages

Of the 29.02 billion AI requests DataDome analysed by endpoint in the first half of 2026, 97.9 percent went to general content such as homepages and informational pages. The remaining 605.6 million reached what the company calls high-risk endpoints: login pages, forms, carts, payment flows and account creation.

Login pages took 313.0 million of those requests, or 51.7 percent. Monthly AI requests to login pages rose from 11.9 million in January 2026 to 99.7 million in June, an increase of 735.8 percent. Forms received 198.9 million requests, or 32.8 percent. Cart, payment and account-creation endpoints together received 93.9 million, or 15.5 percent, split between payment flows at 6.4 percent, carts at 6.3 percent and account creation at 2.8 percent.

The mix has shifted sharply against the 2025 edition. Login share rose from 23 percent to 51.7 percent, forms fell from 64 percent to 32.8 percent, payment flows rose from 2 to 6.4 percent, carts from 5 to 6.3 percent and account creation from 2 to 2.8 percent. The report stresses that form traffic did not fall in absolute terms; it grew more slowly than the rest. The 2025 shares as published add up to 96 percent, and the report does not account for the remaining four points. Its monthly chart also shows total high-risk traffic peaking in May, driven by a spike in form requests, before falling back in June even as login volume kept climbing.

What is all that login traffic? DataDome does not claim to know. Legitimate agents may log in to retrieve order information, check loyalty balances or manage account data for a user, according to the report, while the same endpoint is valuable to attackers running credential testing, account takeover reconnaissance and session abuse. The report's position is that endpoint type alone cannot establish intent.

Other measurements converge on the same pressure point. HUMAN Security's 2026 benchmark, released on April 9, found that authentication flows made up 4.95 percent of agentic activity and account pages 8.82 percent, with checkout at 2.31 percent. Cloudflare's 2026 threat report stated that 94 percent of login attempts across its network originate from botsand that 63 percent of logins involved credentials already compromised elsewhere. The legal status of agents logging in for users is itself contested: a US court blocked Perplexity's Comet browser from Amazon's accounts in March 2026, treating agentic access under the Computer Fraud and Abuse Act.

A name proves nothing

AI agent spoofing, meaning traffic that claims a known agent's identity without being that agent, increased 45 percent between February and July 2026 across all tracked agents, according to DataDome. The company splits the agents into three groups. User-prompted agents such as Perplexity-User and ChatGPT-User rose from approximately 1.4 percent spoofed to 5.6 percent. Search and answer bots such as OAI-SearchBot and Meta-ExternalAgent went from approximately 1.9 percent to 4.7 percent. Crawlers and indexers, including ClaudeBot, PerplexityBot, GPTBot, Meta-WebIndexer and Google-CloudVertexBot, rose from approximately 3.2 percent to 5.7 percent.

Those category numbers need care. The report says they represent "the combined rates of the agents shown in each group, rather than a traffic-weighted pooled rate." Each category rose by far more than 45 percent, roughly fourfold, two-and-a-half-fold and 1.8-fold respectively, and the report does not state how the 45 percent aggregate was calculated or whether it measures spoofed volume or a rate. The comparison also runs to July 2026, one month past the June 2026 end of the study window used elsewhere in the report.

By volume, Meta-ExternalAgent was the most impersonated identity, with 16.4 million spoofed requests in February and 12.7 million in July. ChatGPT-User ranked second in February with 8 million, and ClaudeBot second in July with 4.1 million. At the individual level, PerplexityBot had the highest spoofing rate in February at 2.4 percent, while Perplexity-User led in July at approximately 5.1 percent.

The classification of Meta-ExternalAgent as a search and answer bot differs from how Meta describes it. Meta's webmaster documentation presents the crawler as collecting data to train foundation models and to index content directly, which places it closer to DataDome's crawler category.

The spoofing data extends work DataDome has published before. A March 2026 report co-authored with Retail Economics, AWS and Botify found that 79.7 percent of 698,214 live websites did not block or challenge a spoofed ChatGPT user agent, and the new report repeats that study's finding that 80 percent of AI agents do not properly identify themselves. In December 2025, DataDome researchers documented a single Grok query triggering 16 requests from 12 IP addresses under spoofed user agents. More recently, GreyNoise reported on August 28, 2026 that scanners on 824 addresses forged 13 AI crawler names to hunt credential files.

89.4 million referrals, mostly from ChatGPT

In the other direction, DataDome counted 89.4 million AI-referred visits to customer sites between January and June 2026, according to the report. ChatGPT generated 83.4 percent of them, Gemini 7.9 percent, Perplexity 4.8 percent, Copilot 2.2 percent and Claude 1.5 percent, with Grok and all other sources at 0.1 percent each. Monthly referrals peaked at 19.1 million in March 2026 and held at approximately 13 to 14 million a month through mid-2026.

The report does not set referrals against automated requests, but the arithmetic is simple. Set against the 29.65 billion AI requests for the same half-year, the 89.4 million referrals work out to roughly one referred visit for every 330 AI requests. That is not a pure crawl-to-referral ratio, because the request total includes user-prompted agents acting on a person's behalf. It nonetheless sits inside the range Cloudflare documented on July 1, 2026, from 118 to nearly 50,000 crawls per referral depending on the operator.

The company-level asymmetry is sharper. Meta generated 46.3 percent of AI bot traffic yet does not appear as a named source in the referral breakdown at all; at most it sits inside the 0.1 percent "other" line. OpenAI, at 34.6 percent of bot traffic, produced 83.4 percent of referrals. Google, at 0.4 percent of bot traffic, produced 7.9 percent of referrals through Gemini.

ChatGPT's dominance of referrals contrasts with its declining share of visits to AI assistants themselves. Similarweb data published on June 11, 2026 put ChatGPT at 52.7 percent of worldwide generative AI website traffic, down from 76.4 percent a year earlier. The two measures are different quantities, a distinction drawn in coverage of Demandbase data showing ChatGPT referrals to B2B sites up 303 percent in a year: visits to an assistant and outbound clicks from it follow different product decisions. IAB Australia guidance published in July 2026 had already cited earlier DataDome data putting ChatGPT at 80 to 88 percent of AI referral traffic.

Two in three tested sites stop nothing

The benchmark routed requests through residential proxies in the United States, Canada and France, so that sites could not simply filter by IP reputation. Each homepage received 10 bot types across four tiers, according to the methodology:

  • Tier 1, basic bots (two types): raw requests with minimal or generic headers.
  • Tier 2, spoofed AI agents and crawlers (four types): forged headers for Google's crawler, ChatGPT, GPTBot and ClaudeBot.
  • Tier 3, disguised bots (one type): forged TLS handshake patterns and HTTP/2 behaviour of a real browser, without running one.
  • Tier 4, real browsers (three types): automated Chrome or Firefox engines equipped with anti-detection techniques.

A site counted as fully protected only if it blocked or challenged all 10. In 2026, 65.3 percent were unprotected, up from 61.2 percent in 2025. Partial protection fell from 36 percent to 32.3 percent. Sites that stopped all 10 made up 2.4 percent, against 2.8 percent in 2025 and 8.4 percent in 2024.

Results by tier undercut the idea that basic defences are in place. Only 5.5 percent of sites detected every Tier 1 bot, and the same share stopped the Tier 3 bot. Tier 2 had the highest detection rate: 29.3 percent of sites stopped at least one spoofed AI agent and 14.1 percent stopped all four. DataDome attributes that to blocklists. Publishers that added rules for GPTBot and ClaudeBot catch spoofed versions of those names as a side effect, "not because sites can detect the impersonation." The flip side is that more than seven in 10 sites let a spoofed AI agent or crawler through without challenge, and a bot using an unknown agent string passes the same blocklists untouched. Only 3.1 percent of sites stopped every Tier 4 real-browser bot, and cloaked and uncloaked builds were stopped at rates just 0.05 percentage points apart, which the report reads as sites challenging any browser-like request indiscriminately rather than reading the automation signal.

The year-on-year decline carries a caveat the report acknowledges. The 2026 suite added spoofed AI agents and more sophisticated bot types, and the sample grew by more than 4,500 domains. A harder test lowers the fully protected share whether or not site defences changed, and the report itself calls the trend "directional." DataDome's explanation for the decline is that anti-fingerprinting frameworks, automated browsers and low-cost bot-as-a-service platforms are improving faster than defences.

Regions, sectors and size

Every region recorded a higher unprotected rate than in 2025. Asia Pacific rose from 68.4 to 73.9 percent, Europe from 61.5 to 66.7 percent, North America from 59.8 to 63.8 percent and Latin America from 58.1 to 63.2 percent. Results were broadly consistent across the three proxy locations, according to the report.

Telecommunications was the least protected industry, with 82.9 percent of sites unprotected, followed by tech platforms at 77 percent, financial services at 73.8 percent, property, infrastructure and public sector at 71.9 percent, and education at 69.7 percent. Marketplaces and classifieds performed best, with 47.7 percent showing at least partial protection, though 52.3 percent remained unprotected. Retail and e-commerce followed at 40.4 percent, travel and hospitality at 38.5 percent, automotive and mobility at 37.9 percent, and food and beverage at 36.8 percent. Media and entertainment sits in the middle of the 15-industry chart; the report gives no figure for it in the text.

Scale made little difference. Companies with more than 10,000 employees had an unprotected rate of 64.6 percent, worse than the smallest businesses at 62.7 percent. Sites in the top 1,000 by traffic were unprotected at 64.4 percent, virtually the same as the lowest traffic tier.

Why the numbers reach media budgets

Most of this lands in places marketers already pay for. Forms are lead capture, and the report names lead fraud and form abuse among the risks attached to the 198.9 million AI requests that reached forms in six months. Bots that fill in forms or trigger events become invalid traffic inside campaign reporting. DoubleVerify reported on July 29, 2026 that AI bots generated up to 10 times more clicks than humans in some unprotected campaigns, and a Lunio survey found only 5.3 percent of marketers run a dedicated invalid traffic platform while 75.6 percent estimate losing budget to bots.

Cart activity feeds audiences. Kinsta measured AI crawlers sending 3.75 million requests to a single WordPress shopping cart page in 24 hours, and agencies have described retargeting pools filling with non-human visitors as CPMs climb 20 percent. The DataDome figures on cart and payment endpoints, 93.9 million requests combined with payment share tripling, sit on the same pages those pools are built from.

Referral measurement is shifting too. Google Analytics added a dedicated AI Assistant channel on May 13, 2026, which classifies the kind of ChatGPT and Gemini referrals DataDome counted. The report adds a caveat analytics tools cannot see: AI-referred visitors "arrive with session context that may be invisible to standard analytics," because the assistant may already have retrieved and summarised the destination page before the click.

Account security is the other exposure. Advertising accounts sit behind login pages like any other, and Google Ads began requiring passkeys for sensitive account actions from July 15, 2026, a control aimed at attackers who already hold a valid password.

What DataDome proposes

The report's central argument is that the question has changed. "The key question is no longer, 'Is this a bot or a human?'" according to the company's summary. "It is: 'What is this visitor trying to do, and is it beneficial to the business?'" The closing section phrases the second half slightly differently, as "does it serve my business?" DataDome also frames the commercial trade-off directly: "Businesses that hard-block all AI traffic will lose revenue, and businesses that allow everything through will face fraud and abuse."

The recommendations follow from that. The report calls for intent-based detection using behavioural sequencing, endpoint sensitivity, rate patterns and session context; protection extended beyond the homepage to login flows, checkout, mobile apps, APIs and Model Context Protocol endpoints; testing of existing defences, on the grounds that "tool presence does not equal effective protection"; and a published AI agent access policy stating which agents are permitted and under what conditions. DataDome figures cited in the IAB Australia guidance showed MCP traffic rising from negligible levels to peaks near 500,000 requests a day.

The recommendations are also a sales argument. DataDome sells intent-based bot and agent protection, the benchmark test is offered as a free tool on the company's website, and the report closes with product claims, including a false positive rate below 0.01 percent, that the document does not substantiate.

Timeline

Summary

Who: DataDome, a bot and fraud protection company, published the report. The data covers more than 75,000 DataDome customer sites and 21,491 high-traffic domains tested externally. The AI traffic analysis attributes requests to Meta, OpenAI, Huawei, Amazon, Anthropic, Perplexity, TikTok's ByteSpider, Google, DuckDuckGo and others. Publishers, retailers, advertisers and any business running login, form or checkout pages are affected.

What: The State of Bot & Agent Security Report 2026 finds bad bot traffic grew 124 percent against 13.2 percent for human traffic, scraping made up 70.9 percent of bad bot traffic, and AI agent and crawler requests reached 52.7 billion. AI requests to login pages rose from 11.9 million in January 2026 to 99.7 million in June. In the external test, 65.3 percent of sites stopped none of 10 test bots and 2.4 percent stopped all of them, while more than seven in 10 let a spoofed AI agent through. Several internal inconsistencies, including two different first-half AI traffic totals and an unexplained 45 percent spoofing aggregate, are noted above.

When: DataDome published the report on September 22, 2026. Customer traffic covers July 2025 to June 2026, the AI endpoint and referral analyses cover January to June 2026, the spoofing comparison runs from February to July 2026, and the website test took place in June 2026.

Where: Customer data spans DataDome's global customer base. The website test used residential proxies in the United States, Canada and France and reports results for Asia Pacific, Europe, North America and Latin America across 15 industries.

Why: Automated traffic increasingly reaches pages tied to money and accounts rather than public content, and identity signals such as user agent strings no longer separate legitimate AI agents from impersonators. For marketers, the same traffic flows into lead forms, retargeting pools, analytics and invalid traffic filters, while publishers deciding which AI crawlers to admit depend on names that can be forged.