ANNUAL REPORT

State of Bot & Agent Security Report, 2026

This report combines an analysis of over a trillion requests across 75,000+ customer sites, as well as a test of more than 20,000 popular websites.

trillions

of requests analyzed

20,000+

popular websites scanned

75,000+

customer sites analyzed

ANNUAL REPORT

Executive summary & key findings

Automated traffic is changing rapidly. Between July 2025 and June 2026, bad bot traffic grew approximately 124%, more than 9x faster than human traffic, while AI traffic increased 82.3%. As automated activity becomes more sophisticated and increasingly targets high-value customer journeys, identity-based controls alone are no longer sufficient.

 

This report analyzes trillions of requests across 75,000+ customer sites, alongside tests of 20,000+ popular websites. Together, the findings show that automated traffic is becoming more active and valuable, while many businesses have not adapted their defenses quickly enough. Scraping remained the largest attack vector, accounting for 70.9% of bad bot traffic across DataDome’s customer base and increasing 185.2% during the study period. This growth may reflect an expanding AI data supply chain, in which data resellers and AI applications collect web content at scale.

 

DataDome detected 52.7 billion AI agent and LLM crawler requests during the study period. Meta-affiliated bots generated 46.3% of identified AI crawler traffic, followed by OpenAI-affiliated bots at 34.6%. AI agents are also reaching high-risk endpoints: during H1 2026, AI bot activity targeting login pages grew more than 8x.

 

At the same time, protection is falling behind. Among the 20,000+ websites tested, 65.3% had no protection against the 10 bot types in our assessment, while only 2.4% achieved full protection. Full protection has declined for the second consecutive year, from 8.4% in 2024 to 2.8% in 2025 and 2.4% in 2026, as attackers gain access to anti-fingerprinting tools, automated browsers, and low-cost bot-as-a-service platforms.

 

These trends reinforce the need for intent-based detection. Blocking all AI traffic can cost businesses revenue, while allowing everything through increases exposure to fraud and abuse. The key question is no longer, “Is this a bot or a human?” It is: “What is this visitor trying to do, and is it beneficial to the business?”

Key findings, what the data reveals

70.9%

Scraping is the fastest-growing attack vector

Scraping is the dominant and fastest-growing attack vector. Scraping accounted for 70.9% of bad bot traffic and increased 185.2% during the study period. One possible explanation is the growing AI data supply chain, in which third-party data resellers and applications building AI agents collect web data at scale for training, agent responses, and other AI services.

124%

Malicious automated traffic is growing much faster than human traffic

Bad bot traffic increased 124% over 12 months, over 9x the growth rate of human traffic over the same period.

290.7%

Scalping activity increased

with median daily volume nearly quadrupling. The sustained rise puts continued pressure on businesses to protect high-demand inventory and purchase flows from automated abuse.

52.7 billion

AI traffic is moving from passive crawling into active user journeys

DataDome detected 52.7 billion AI agent and LLM crawler requests across its customer base over 12 months, with total AI traffic increasing 82.3% during the study period. In H1 2026, AI agents generated 605.6 million requests to high-risk endpoints, including login pages, forms, carts, payment flows, and account-creation pages, with login pages accounting for 51.7% of that traffic.

>8x

Login-page targeting by AI agents increased more than 8x within H1 2026

Monthly AI bot requests to login pages rose from 11.9 million in January 2026 to 99.7 million in June 2026 across DataDome customer sites. Some of this activity may come from legitimate agents acting on behalf of users, but the same endpoint behavior can also resemble credential testing, account takeover reconnaissance, and form abuse.

34.5%

Account-related abuse is increasing across multiple attack paths

Fake account creation grew 34.5%, while credential stuffing remained cyclical rather than declining. Credential stuffing activity surged, dropped by nearly 90%, and later recovered to new single-day highs, showing how attackers can pause campaigns while refreshing credential lists or rotating infrastructure.

49%

Attackers continue to succeed with both simple and sophisticated tools

Simple bots accounted for 49% of sampled bad bot traffic, even though they made no effort to hide their automated nature. At the same time, 21.5% of sampled bad bot traffic representing "payload forgers" was caught using more advanced signals from WebAssembly (WASM) and our Virtual Machine.

45%

AI agent spoofing increased 45% between February and July 2026

User-prompted agents showed the sharpest category-level increase, rising from approximately 1.4% to 5.6%. This makes live AI assistants an increasingly important type of traffic to verify.

65.3%

20,000+ popular websites are completely unprotected against bots and AI agents

In the expanded 2026 test, 65.3% of tested websites stopped none of the 10 bot types, while only 2.4% stopped all of them. The directional trend in full protection has declined from 8.4% in 2024 to 2.8% in 2025 and 2.4% in 2026, although the 2026 test suite included additional spoofed AI agent and advanced bot types.

5.5%

The protection gap is visible even against basic automation

Only 5.5% of tested websites stopped every basic bot, and just 3.1% stopped every real-browser bot. These results show that the challenge is not limited to advanced attackers. Many websites remain exposed to the simplest forms of automation.