HUMAN Security stated in a blog post dated September 28, 2026 that Meta's Muse agent accounts for an average of 72% of daily AI-agent requests in its early observations, with daily request volume 5.2 times that of ChatGPT Agent, the next largest.
In Short
A security company that tracks web traffic says one new AI assistant from Meta now generates most of the requests that AI agents make to websites. That matters because advertisers, retailers and fraud teams count visits, carts and purchases, and an AI agent shopping for a person can be mistaken for a human or filed with malicious bots. What changes is the nature of the task: counting agent traffic is no longer enough, and HUMAN argues that telling the agents apart, and judging what each one does, becomes the main job.
What HUMAN measured
The figures come from a post by Julian Norton on HUMAN Security's blog, dated September 28, 2026 and described as early observations. According to HUMAN, Muse accounts for an average of 72% of daily AI-agent requests, and its daily request volume is 5.2 times that of the next largest agent, ChatGPT Agent. By September 27, daily Muse requests outnumbered those of all other measured agents combined by a factor of 2.34. Read as a ratio, that works out to roughly 70% of the day's requests, close to the 72% average.
A third comparison is more striking and less precise. HUMAN states that Muse reached, in two days, a request volume that took ChatGPT 11 months to achieve. The post names ChatGPT rather than ChatGPT Agent, gives no absolute volume and does not say which milestone is meant, so the claim cannot be matched against any outside series.
Much else is missing. The post offers no request counts, no sample size, no observation window and no definition of a request, which could mean a page load, an HTTP call or a session. The phrase "measured agents" appears to refer to those that HUMAN's AgenticTrust product identifies; the company says it verifies Muse and more than 30 other AI agents. Taken at face value, and assuming a common basis, a 72% share and a 5.2 times ratio would leave ChatGPT Agent with about 14% of daily agent requests and all remaining agents with about 14% between them. The post does not say the two figures share a basis, so that arithmetic is indicative only.
A free agent with a distribution network
HUMAN offers two explanations for the pace. The first is price. Most other AI agents, the post says, require a paid subscription for browser automation, whereas "Muse has a generous token limit on the free tier, includes an AI browser agent by default, and is designed for everyday consumers." The second is reach: Facebook, Instagram, Messenger and WhatsApp give Muse "an ability to scale that OpenAI and Anthropic lack", in the company's wording.
Adoption figures follow. By September 21, Muse had reportedly exceeded 2.5 million downloads and reached the top of U.S. app charts, according to the post, which does not name the source of the download count. Apptopia data cited by HUMAN indicates heavy overlap with Meta's existing apps: 95% of Muse's users are also Facebook users, and 63% are Instagram users. HUMAN frames the release as the first mass-market adoption of agentic AI and writes that "Muse will be many users' first experience of an agent browsing and acting on their behalf."
A share of agent requests is not, however, a share of web traffic, and the post supplies no bridge between the two. It recalls that HUMAN tracked a 7800% increase in agentic traffic in 2025, but a percentage rise says little without a starting volume. For a broader frame, Cloudflare data cited by Digiday and covered by PPC Land on September 8, 2026 put bots and AI agents above 50% of all web requests, a figure that covers automated traffic of every kind rather than agents alone.
Where the requests go
Among Muse requests, 84% target product and search pages, according to HUMAN. In what the post describes as a recent sample, Muse is 25% more likely than other AI agents to reach checkout pages. No absolute checkout rate, sample size or date range accompanies that comparison.
HUMAN's reading is that Muse follows the same discovery-to-purchase paths that businesses already measure, optimize and protect. Intent is where the company draws the line: "An agent researching products for a real shopper may be valuable. An agent that spoofs its identity, abuses an account, or attempts a fraudulent transaction is not." Counting both as undifferentiated bot traffic, or treating an agent session as a human one, "can distort conversion rates, funnel performance, attribution, and fraud signals", the post states.
Earlier HUMAN data offers a rough point of comparison. In its May 2026 report, covered by PPC Land in June, product and search routes made up 76.4% of agentic traffic, authentication 5.6% and checkout and payment 2.4%. Muse's 84% sits above that mix, although the two measurements differ in period and presentation. The same report listed Perplexity's Comet at a 47% share, with OpenAI's Atlas at 20.3% and the Claude Chrome Extension at 18.6%. The September post ranks ChatGPT Agent second and does not explain how its request-based ranking relates to the earlier share-based one.
Identification, not just counting
The post's policy conclusion is brisk. "The immediate need is accurate, real-time identification of this traffic, followed by governance that connects business policy to technical enforcement." It adds that 96% of CISOs cannot accurately quantify agentic traffic, a figure the text presents without describing the survey behind it.
On the technical side, the post names Web Bot Auth, which HUMAN supports, as a particular example of work on internet standards for identifying AI agents. Then comes the catch: "But most AI providers do not yet use these standards." Cloudflare put the protocol forward in May 2025, and it builds on HTTP Message Signatures, specified in RFC 9421, under which an agent signs its requests with a private key and publishes the matching public key where sites can fetch it. In Cloudflare's first proposal, bots send a Signature-Agent header that points to the endpoint hosting their keys, and Vercel, Shopify and Visa had implemented the scheme by the time of that November 2025 coverage. Whether Muse signs its requests is not stated in the post.
HUMAN says AgenticTrust identifies and verifies Muse and more than 30 other agents "using proprietary research or digital signatures that cannot be spoofed". The post does not specify which of the two methods covers Muse. The distinction carries weight because a self-declared user-agent string is trivial to copy. A DataDome test cited in a March 2026 report found that 79.7% of 698,214 sites did not block or challenge a spoofed ChatGPT user agent.
Once an agent is identified, the post says, activity determines policy. Organizations can allow automation that creates value and block what creates risk, with granular control over actions such as add to cart or log in, or rules on which agent is trusted. That model treats the agent's identity and its behavior as separate inputs, since the same agent can browse harmlessly on one visit and attempt a transaction on the next.
The legal and commercial backdrop
Whether a site can refuse an agent at all remains contested. On November 4, 2025, Amazon told Perplexity to stop Comet users from buying on its marketplace, arguing that the agents operate without transparency and evade detection. On August 4, 2026, the Ninth Circuit vacated the preliminary injunction that had kept Comet Assistant out of Amazon shopping accounts, reasoning that an AI agent is a tool and that the user is the party accessing Amazon's systems. The panel left Amazon free to set access rules through its terms of service.
For publishers and retailers, that backdrop means identification comes first and the allow-or-block decision second. HUMAN's own earlier work points the same way: its April 2026 expansion of Agentic Visibility delivers insights to marketing and commerce teams natively inside Adobe Experience Platform, covering the measurement of AI-driven traffic and the distinction between human, bot and agent activity.
Why the counts matter to marketers
Many measurement setups were built around two categories, people and bots. An agent acting for a logged-in shopper fits neither cleanly. Ad verification and analytics tools that sort visits into human and invalid traffic must decide where such a session belongs: it is automated, yet it is neither the fraud that filtering is meant to remove nor a person whose behavior a campaign set out to influence.
The practical effects reach several places at once. Conversion rates change when agent sessions that browse but never buy enter the denominator, and funnel reports change when agent sessions that reach checkout enter the numerator. Retargeting pools can fill with non-human visitors. GoFish reported that bot traffic on client sites rose 80% year on year and that the retargeting adjustments made in response raised cost per thousand impressions by an average of 20%, figures that Digiday published in September 2026.
The commercial setting deserves a note. HUMAN sells bot and agent detection, and the post closes with an invitation to book an AgenticTrust demo and to join a webinar on October 1 covering where Muse agents go, what they do and what consumer-grade agents mean for the holiday season. The numbers come from HUMAN's own platform, and the post cites no independent measurement of them. Whether other vendors and site operators see the same concentration is a question the post leaves open.
Timeline
- May 2025 - Cloudflare puts forward the Web Bot Auth protocol proposal, which uses HTTP Message Signatures to authenticate bot traffic
- October 30, 2025 - Cloudflare publishes a registry format for bot and agent authentication
- November 4, 2025 - Amazon sends Perplexity a legal demand to stop Comet users from making purchases on Amazon
- March 7, 2026 - Botify and DataDome data show 79.7% of 698,214 tested sites did not block or challenge a spoofed ChatGPT user agent
- April 9, 2026 - HUMAN publishes its 2026 State of AI report, stating that automation is growing eight times faster than human traffic
- April 21, 2026 - HUMAN expands Agentic Visibility to marketing and commerce teams inside Adobe Experience Platform
- June 4, 2026 - HUMAN publishes its May 2026 agentic traffic report, with Comet at a 47% share and a blocking rate near 9%
- August 4, 2026 - The Ninth Circuit vacates the preliminary injunction that kept Perplexity's Comet Assistant out of Amazon shopping accounts
- September 8, 2026 - Digiday reports Cloudflare data showing bots and AI agents above 50% of web requests
- By September 21, 2026 - Muse had reportedly exceeded 2.5 million downloads and reached the top of U.S. app charts, according to HUMAN
- September 27, 2026 - Daily Muse requests outnumbered those of all other measured agents combined by a factor of 2.34, according to HUMAN
- September 28, 2026 - HUMAN publishes the blog post on Muse traffic
- October 1, 2026 - HUMAN schedules a webinar on Muse and agent traffic, according to the post
Related PPC Land coverage
- AI agent traffic is up 8x - HUMAN Security now tells marketers why - April 26, 2026 coverage of HUMAN's Agentic Visibility expansion into Adobe Experience Platform and its State of AI report.
- AI agent traffic dips in May but blocking rates keep climbing - June 14, 2026 breakdown of HUMAN's May data on agent shares, sectors and routes.
- Cloudflare unveils registry format for bot and agent authentication - November 2, 2025 account of the Web Bot Auth registry format and early adopters.
- AI bots crawl retail sites 198x more than Google, new report warns - March 7, 2026 coverage of crawl ratios and a spoofing test across 698,214 sites.
- Amazon demands Perplexity stop AI shopping in Comet browser dispute - November 4, 2025 report on Amazon's legal demand over Comet purchases.
- Amazon loses injunction blocking Perplexity's AI shopping agent - September 13, 2026 coverage of the Ninth Circuit ruling on agent access.
- Half of web requests are bots as agency CPMs climb 20% - September 8, 2026 look at bot traffic shares and retargeting costs.
Summary
- Who: HUMAN Security, a cybersecurity company, in a blog post by Julian Norton; Meta, whose Muse agent is the subject; Apptopia, cited for user overlap data.
- What: HUMAN reports that Muse accounts for an average of 72% of daily AI-agent requests, runs at 5.2 times the volume of ChatGPT Agent, and outnumbered all other measured agents by a factor of 2.34 on September 27. Among Muse requests, 84% target product and search pages, and Muse is 25% more likely than other agents to reach checkout pages in a recent sample.
- When: The post is dated September 28, 2026, with data through September 27, a download milestone dated September 21 and a webinar on October 1.
- Where: Traffic observed by HUMAN's platform on the websites it protects; the post gives no geographic or sector breakdown, and cites U.S. app charts for downloads.
- Why: HUMAN argues that a free, consumer-oriented agent distributed through Meta's apps changes the composition of web traffic, and that businesses need to identify agents and govern their actions to protect conversion data, attribution and fraud signals. HUMAN also sells products for that purpose, and the figures come from its own data.
Discussion