DataDome

DataDome Recognized as a Sample Vendor in the Gartner® Hype Cycle™ for Application Security, 2026

Table of contents
Last update: 8 Sep, 2026
|
min

We’re proud to share that DataDome has been recognized as a Sample Vendor in the Gartner® Hype Cycle for Application Security, 2026 report’s AI Agent Bot Management section, a brand innovation category introduced in this year’s edition.

Bot management has graduated, and according to us, that’s a significant step

In last year’s coverage, we noted that bot management had reached the “Plateau of Productivity,” with broad mainstream adoption already underway.

The Gartner Hype Cycle for Application Security, 2026 goes one step further, stating that “bot management and mobile application security testing have reached full maturity.”

We believe the Hype Cycle exists to track technologies as they move from novelty to necessity, and graduation from it means a category has completed that journey.

Bot management is no longer something organizations evaluate as an emerging capability. It’s an operational baseline, the same way firewalls and WAFs became table stakes years before most of us started working in security.

We believe this shift is a direct reflection of market forces we’ve observed firsthand. Sophisticated, adaptive bots proliferated. Attackers evolved their techniques. Organizations that had relied on CDN-level or rule-based protections faced repeated failures, which pushed the market toward specialized platforms built for behavioral detection at scale. Over time, best practices consolidated and adoption widened as the category matured.

That’s the good news. The harder news is that bot management’s graduation also exposes a gap: the infrastructure built for detecting bots and humans was never designed for what’s coming next.

Replacing bot management on the Hype Cycle is AI Agent Bot Management. According to the report, “AI agent bot management enables organizations to detect, identify, and classify AI agents accessing login flows, checkouts, forms, and similar interfaces; assess their risk, context, and potential intent; and enforce business and security policies governing permitted actions.”

We would like to point out that the definition doesn’t say block everything. It says detect, assess, classify, and enforce. That distinction matters enormously.

The report names a challenge we’ve been observing for months: “Existing bot management solutions can differentiate between bots and humans, but businesses now lack visibility into the type and intent of AI agent traffic.”

We’ve seen this gap firsthand. In a test of 698,214 reachable websites using a spoofed ChatGPT-style user-agent, 79.7% allowed the request through without blocking or challenging it. Separately, our research found that 80% of AI agents don’t use strong identity signals like published IP ranges, reverse DNS, or cryptographic authentication when visiting websites.

The gap isn’t theoretical. It’s widespread.

Why AI agents are fundamentally different from bots

Traditional bot management answered a binary question: is this traffic a bot or a human? AI agents force a more difficult question: What is this agent, who authorized it, and what is it actually trying to accomplish?

We believe this finding from the report captures precisely why the problem is so difficult: “Use of AI agents differs from traditional bots due to the broader range of actions that agents can carry out, but also because agents will all appear to be similar, coming from the same AI platforms — making it much harder to know the intent of the human user behind them.”

This is the core challenge DataDome’s Threat Research has been focused on. When agents from different use cases—a legitimate shopping agent, a competitive scraper, a credential-stuffing bot—all originate from the same handful of AI platforms and share the same infrastructure, user-agent strings and IP ranges stop being meaningful signals.

In our opinion, intent is invisible by default, which means organizations need a fundamentally different approach to surface it.

The identity dimension makes this even more complex. This is where the identity gap becomes most acute, and a finding in the report reinforces it: “There are currently no standardized methods for binding a human identity to an agent. Thus, if an agent is using a user’s credentials to access an account, the service provider cannot easily know whether the agent was sent by the genuine account holder.”

Since the start of 2026, DataDome has processed more than 30 billion AI agent requests, including 16.4 million attempts to impersonate a single AI platform in Q1 alone. In a test of nearly 700,000 websites, 79.7% allowed a spoofed AI agent request through without any challenge. The governance gap is not theoretical.

Why blocking everything is the wrong answer

Agentic commerce is accelerating faster than most security teams anticipated. AI agents are already researching products, booking travel, managing accounts, and completing purchases on behalf of real users. For digital commerce and financial services businesses, that traffic is legitimate, growing, and consequential.

In our view, the Hype Cycle for Application Security, 2026 surfaces a business risk that security teams too often overlook: “Mismanaging agents on customer-facing interfaces could have meaningful business consequences. For example, if agents from AI platforms are blocked, a digital commerce business may no longer appear in recommendations to users of that platform.”

We believe the organizations that will win in this environment are not the ones that block everything; they’re the ones that can make fast, accurate, policy-driven decisions: allow a verified shopping agent full access, restrict a scraper to public pages, block a credential-stuffing agent entirely. All in real time. All per endpoint.

Gartner’s report references capabilities like the ability to “assess the risk associated with that interaction based on agent type, actions being carried out, and an estimation of intent” and to “enforce policies such as allowing a given agent full access, permitting it to only navigate a certain path or see certain pages, or blocking it entirely.”

We believe this framing—assess, then enforce—maps directly to how organizations should be thinking about AI agent governance.

How DataDome approaches the AI agent challenge

We have been building toward this problem for some time, and we think the combination of behavioral detection, cryptographic identity, and granular policy enforcement is what separates meaningful AI agent governance from surface-level feature additions.

Detection at scale. DataDome’s multi-layered AI detection engine analyzes every request in real time across thousands of models, classifying traffic by type and intent—whether human, bot, or AI agent. Customers gain visibility into exactly who is interacting with their applications, at what volume, and with what behavioral patterns.

Cryptographic identity. On the identity side, DataDome supports Web Bot Auth, an IETF authentication standard that requires AI agents to attach a cryptographic signature to every HTTP request. Web Bot Auth currently verifies agents from ChatGPT, Amazon Bedrock AgentCore, and others.

In our opinion, this is the direction the entire industry is moving, and we see it reflected in the report’s reference, “Monitor the emergence and adoption of protocols and standards that can bind user identity and intent to an agent and be ready to adopt these in the future to make assessment of agents more deterministic and less probabilistic.” 

MCP coverage. For agentic flows built on the Model Context Protocol, DataDome protects MCP servers from malicious agent traffic, data exfiltration, credential abuse, and impersonation. MCP cybersecurity appears as a standalone Hype Cycle category for the first time in this year’s report—a signal, in our view, of how rapidly the new protocol surface is expanding and how urgently it needs to be secured.

Granular enforcement. Customers can allow verified agents full access, restrict them to specific paths, or block them entirely—per agent type, per endpoint, per business policy.

Protect your applications with DataDome

We believe every organization serving customers online needs a clear strategy for AI agent governance in 2026, not just because of security risk, but because the volume of legitimate agent traffic is growing fast, and the cost of mismanaging it goes in both directions.

DataDome protects websites, mobile apps, APIs, and MCP servers against malicious bots, fraud, and unauthorized AI agents across any infrastructure.

To see what’s actually interacting with your platform in real time, book a demo.

 

Hype Cycle for Application Security, 2026, Dionisio Zumerle, July 21, 2026

Gartner and Hype Cycle are registered trademarks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product, or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

DataDome
DataDome

Still exploring?

Start with an on-demand demo.