Bot & AI agent protection
benchmark in 2026
Key findings
What percentage of websites are protected against bad bots & AI agents?
In 2026, 65.3% of the 21,491 websites we tested were fully unprotected, meaning they failed to detect any of the bot types we deployed. Just 2.4% of sites achieved full protection.
This continues a troubling multi-year trajectory:
The decline in partial protection (from 36% in 2025 to 32.3% in 2026), combined with an increase in the fully unprotected rate, suggests that incremental or passive defenses are eroding in effectiveness. Sites that previously caught at least one bot type are now failing more consistently across the board.
The most direct explanation: bot tooling is getting better, faster than defenses are keeping up. The anti-fingerprinting bots we tested with in 2026 are meaningfully more capable than those deployed in prior years. As these tools proliferate, increasingly available through low-cost, low-code bot-as-a-service platforms, protection thresholds that held in 2025 are no longer sufficient.
This year’s methodology reflects that shift. We expanded our test suite to include spoofed AI agents and more sophisticated bot types, ensuring our findings accurately represent the threat landscape businesses face today.
Key takeaway: Full protection has now declined two years in a row. The gap between what websites deploy for defense and what attackers actually use is widening, not closing.
Which bot types do websites detect best and worst?
Detection rates vary across bot tiers, but remain low across the board. Across all 10 bot types, 65.3% of sites did not stop any test bot. Among those that did defend, protection is uneven and drops sharply as bot sophistication increases.
A few findings stand out.
Even the simplest bots get through on most sites. Only 5.5% of sites detected every Tier 1 bot — the category requiring the least sophistication to detect. Tier 3, which involves forged browser fingerprints at the network level, is stopped by just 5.5% of sites. Standard defenses — IP reputation, user-agent filtering, simple behavioral rules — are failing against even low-sophistication automation.
More sites are blocking spoofed AI bots than simple bots. Tier 2 has the highest detection rate of any tier: 29.3% of sites stopped at least one spoofed AI agent, and 14.1% stopped all of them. But this is not a sign of more sophisticated defenses. The more likely explanation is that publishers and content platforms added explicit rules for GPTBot, ClaudeBot, and similar user-agent strings, and spoofed versions of those bots get caught by the same rules, not because sites can detect the impersonation, but because the identity being spoofed was already on a blocklist.
These controls do not address attackers using unknown or custom agent strings. As more businesses begin allowing legitimate AI agents to access their sites, this weakness becomes more consequential. Static allowlists and blocklists cannot distinguish an authorized AI agent from a malicious bot impersonating one. Businesses need to verify agent identity and evaluate behavior and intent rather than rely on user-agent strings alone.
Identity-based trust is a widespread vulnerability. More than 7 in 10 sites allow a spoofed AI agent or crawler through without any challenge, simply because the request claims to be GPTBot, ClaudeBot, or a similar trusted identity. Tier 2 does have the highest “stopped all” rate of any tier at 14.1% — reflecting the growing number of sites that have added blanket AI-crawler blocks, typically through robots.txt enforcement or user-agent rules. But that protection has a critical ceiling: it works only against bots that announce themselves honestly. Any bad actor spoofing one of these identities could pass straight through.
Real-browser bots are the hardest to detect, and most sites blocking them may not be doing so for the right reasons. Only 3.1% of sites stopped every Tier 4 bot tested. Critically, sites stopped the cloaked and uncloaked real-browser builds at nearly identical rates, a difference of just 0.05 percentage points. This suggests most are applying an indiscriminate challenge to any browser-like request, rather than genuinely reading the automation signal.
Which region has the weakest bot protection?
The test distributes requests from three proxy locations — the United States, France, and Canada — to ensure results are not driven by IP-based geographic filtering. Detection results were broadly consistent across locations, confirming that the protection gaps identified are structural, not geography-specific.
Asia Pacific has the highest unprotected rate at 73.9%, followed by Europe at 66.7% and North America at 63.8%.
All major regions declined year-over-year. North America’s unprotected rate moved from 59.8% in 2025 to 63.8% in 2026. Europe went from 61.5% to 66.7%. Asia Pacific grew from 68.4% to 73.9%. Latin America’s unprotected rate also moved from 58.1% to 63.2%.
Key takeaway: No region is improving when it comes to overall protection. While there were some shifts between full and partial protection, every region saw a decline when the two categories are combined. In other words, fewer websites are stopping at least one of the bots tested, and more are allowing every test bot through. The most mature digital markets, North America and Europe, still have nearly two-thirds of websites fully unprotected.
Which industry is most vulnerable to bad bots & AI agents?
We grouped the tested websites into 15 industries. Protection levels vary significantly by sector, reflecting differences in business models, the value of assets at risk, and security maturity.
Telecommunications tops the least-protected list at 82.9% unprotected. Tech platforms follow at 77%, showing that broad digital reach does not automatically translate into strong bot protection.
Financial services rank third at 73.8% unprotected. Property, infrastructure & public sector follows at 71.9%, while Education rounds out the bottom five at 69.7% unprotected.
These results show that protection gaps are not limited to one type of business. Telecommunications and technology platforms face broad exposure, while financial services continue to carry significant risk despite the value of the data and accounts they protect.
For ranking purposes, protection was measured as the combined percentage of fully protected and partially protected for each site.
Marketplaces & classifieds are the most protected industry, with 47.7% of sites showing at least partial protection. Retail & e-commerce follow at 40.4%, making these the two strongest-performing categories.
Travel & hospitality ranks third at 38.5% combined protection, followed by Automotive & mobility at 37.9% and Food & beverage at 36.8%.
Marketplaces & classifieds are the strongest-performing category, but 52.3% of sites in the category remain unprotected. Even the best-performing industries therefore have a clear opportunity to improve detection across more advanced bot types.
Key takeaway: Protection is uneven across industries, but no category has reached a strong baseline. Unprotected rates range from 52.3% in Marketplaces & classifieds to 82.9% in Telecommunications. Consistent, behavior-based detection is needed across every sector, especially as attackers reuse the same automation tools across different business models.
Do bigger companies have better bot protection?
Protection levels show very little variation across company size tiers. One might expect large enterprises with substantial security budgets to significantly outperform small businesses. In 2026, the gap is narrow to the point of being negligible.
The largest companies (10,000+ employees) have an unprotected rate of 64.6%. This is worse than the very smallest businesses (62.7%). Large enterprises contend with the complexity of protecting vast and diverse digital infrastructures, often with fragmented tooling and legacy systems that create gaps.
Counterintuitively, the highest-traffic websites are not better protected. Sites in the top 1,000 by monthly traffic had a 64.4% unprotected rate, virtually the same protection rate as sites in the lowest-traffic tier tested.
High-traffic sites are more attractive targets. They host more users, more data, and more monetizable assets. Not having stronger defenses makes them disproportionately valuable to attackers.
Key takeaway: Neither company size nor traffic volume predicts protection quality in 2026. The most powerful websites on the internet are failing the same basic bot tests as the smallest.