Bad Bots, AI Agents Push Deeper Into High-Risk Online Activity

Bad Bots and AI Agents Push Deeper Into High-Risk Online Activity DataDome research finds automated traffic is growing rapidly as bots and AI agents increasingly reach login, account and transactional environments.

Key Highlights

  • DataDome found bad bot traffic grew 124%, more than nine times the growth rate of human traffic.
  • AI agents are increasingly reaching login, account and transactional environments, raising fraud and account-security risks.
  • DataDome says organizations need to focus less on identifying bots and more on understanding the intent behind automated activity.

Automated traffic is not simply becoming more prevalent across the internet. Bots and AI agents are increasingly reaching login, account and transaction flows, putting automated activity closer to areas where malicious activity carries greater fraud and account-security risks.

That shift is among the key findings in DataDome’s "State of Bot & Agent Security Report, 2026 Edition." The new research found bad bot traffic increased 124% between July 2025 and June 2026, more than nine times the growth rate of human traffic. AI traffic increased 82.3% during the same period.

The report is said to be based on an analysis of trillions of requests across more than 75,000 DataDome customer sites, along with testing of more than 20,000 popular websites across 15 industries.

For security leaders, however, the location and behavior of that automated traffic may be more significant than its overall growth.

“The important shift is not simply that there is more automated traffic; it’s where that traffic is going,” Jérôme Segura, vice president of threat research at DataDome, told SecurityInfoWatch.

During the first half of 2026, AI agents generated 605.6 million requests to higher-risk areas including login pages, forms, shopping carts, payment flows and account-creation pages. Login pages accounted for 51.7% of that traffic, while AI-agent requests to login pages increased more than eightfold during the six-month period.

Segura said the numbers illustrate a transition from automation primarily associated with crawling publicly available content toward activity within authenticated and transactional portions of websites.

“Automated traffic, both legitimate and malicious, is moving from passive crawling into active participation in authenticated, transactional parts of the site,” he said. “It is showing up at account access, registration, cart and payment flows, where the consequences are fraud, account takeover and revenue loss rather than bandwidth costs.”

The shift means security strategies need to account for automated activity beyond public-facing pages. Segura said security leaders should assume login and API endpoints are already receiving significant automated traffic and ensure their protections extend to those areas.

Defenses struggle to keep pace

As automated activity expands, DataDome’s research also points to a substantial gap between evolving bot capabilities and the defenses deployed against them.

The company tested more than 21,000 popular websites against 10 types of bot and AI traffic and found 65.3% failed to block or challenge any of them. Only 2.4% blocked or challenged all 10. DataDome’s 2026 test was expanded to include spoofed AI agents and more advanced bot types, a methodological change that provides context for comparisons with previous years.

Segura attributes part of the protection gap to the speed at which attackers’ capabilities are developing.

“Attacker tooling has improved faster than defenses have,” he said.

Segura said AI is also accelerating the attacker side of that equation. Automated challenge solvers and AI-assisted development are helping make more sophisticated evasion techniques faster and cheaper to build, he said, while many organizations continue to depend on controls developed for an earlier generation of automated threats.

Those defenses can include IP reputation, user-agent filtering, robots.txt and static allowlists and blocklists. The limitations aren’t confined to sophisticated bots, either. According to DataDome, only 5.5% of the websites tested stopped every basic bot evaluated, while just 3.1% stopped every real-browser bot.

Organization size also provided little insulation. Segura said sites ranked among the top 1,000 by traffic had an unprotected rate of 64.4%, roughly comparable with smaller sites.

“Budget and scale are not helping,” he said. “Unprotected rates were essentially flat across company sizes.”

The findings suggest the challenge isn’t limited to organizations without substantial security resources. Instead, DataDome argues that widely deployed defenses are struggling to keep pace with changes in automated attack techniques.

AI complicates the question of identity

The rise of AI agents adds another dimension to the problem because automated traffic itself cannot simply be treated as malicious.

Some AI agents legitimately access websites on behalf of users, potentially retrieving information, navigating services or interacting with accounts. Malicious automation can target the same environments for credential testing, account takeover attempts and other forms of abuse.

At the same time, an AI agent isn’t necessarily what it claims to be.

DataDome found AI-agent spoofing increased 45% between February and July 2026. Segura also cited separate DataDome research finding that 80% of AI agents do not properly identify themselves.

That creates a problem for security systems that make decisions largely according to a visitor’s claimed identity.

More than seven in 10 websites in DataDome’s testing allowed a spoofed AI agent or crawler through without a challenge. Segura said DataDome believes sites that did stop such traffic frequently did so because a static rule recognized a known agent name, rather than because the system determined whether the visitor was actually the agent it claimed to be.

For security teams, the implication is that identifying traffic as human or automated is becoming less useful on its own.

“They need to stop asking ‘is this a bot or a human?’ and start asking ‘what is this visitor trying to do, and does it serve the business?’” Segura said.

Determining that intent requires more context than an identity label. Segura said organizations can combine verified agent identity with behavioral signals including the sequence of actions, sensitivity of the endpoint, request rate and volume and session context.

Organizations can also establish AI-agent access policies defining which agents are permitted, what they are allowed to reach and under what conditions. Those decisions will vary by organization because legitimate uses of AI agents will differ according to the business and the services it provides.

Managing automation rather than simply blocking it

That distinction becomes increasingly important as legitimate AI agents and malicious bots operate within many of the same online environments.

Segura noted that an AI agent accessing a login page could be acting on behalf of an authorized user, such as retrieving order information or other account data. Similar activity, however, could also be associated with credential testing or account takeover reconnaissance.

For security teams, Segura said, the challenge is therefore less about eliminating automated traffic and more about understanding its intent and determining which automation should be permitted.

“The goal is not to block automation,” he said. “Blanket blocking of AI traffic costs businesses visibility and revenue, and allowing everything through invites fraud. The task is identifying the wrong automation in real time while the right automation operates freely.”

About the Author

Rodney Bosch

Rodney Bosch

Editor-in-Chief/SecurityInfoWatch.com

Rodney Bosch is the Editor-in-Chief of SecurityInfoWatch.com. He has covered the security industry since 2006 for multiple major security publications. Reach him at [email protected].

Sign up for our eNewsletters
Get the latest news and updates