ANNUAL REPORT

Bot & AI agent protection
benchmark
in 2026

Key findings

3.1

What percentage of websites are protected against bad bots & AI agents?

In 2026, 65.3% of the 21,491 websites we tested were fully unprotected, meaning they failed to detect any of the bot types we deployed. Just 2.4% of sites achieved full protection.

Overall bot and AI traffic protection levels
Unprotected 65.3%
Partially protected 32.3%
Fully protected 2.4%
Unprotected — 65.3% 65.3% Partially protected — 32.3% 32.3% Fully protected — 2.4%

This continues a troubling multi-year trajectory:

Protection levels: 2024, 2025, 2026
Unprotected
Partially protected
Fully protected
Fully protected: 8.4%
Partially protected: 26.4%
Unprotected: 65.2%
2024
Fully protected: 2.8%
Partially protected: 36%
Unprotected: 61.2%
2025
Fully protected: 2.4%
Partially protected: 31.3%
Unprotected: 65.3%
2026

The decline in partial protection (from 36% in 2025 to 32.3% in 2026), combined with an increase in the fully unprotected rate, suggests that incremental or passive defenses are eroding in effectiveness. Sites that previously caught at least one bot type are now failing more consistently across the board.

The most direct explanation: bot tooling is getting better, faster than defenses are keeping up. The anti-fingerprinting bots we tested with in 2026 are meaningfully more capable than those deployed in prior years. As these tools proliferate, increasingly available through low-cost, low-code bot-as-a-service platforms, protection thresholds that held in 2025 are no longer sufficient. 

This year’s methodology reflects that shift. We expanded our test suite to include spoofed AI agents and more sophisticated bot types, ensuring our findings accurately represent the threat landscape businesses face today.

Key takeaway: Full protection has now declined two years in a row. The gap between what websites deploy for defense and what attackers actually use is widening, not closing.

3.2

Which bot types do websites detect best and worst?

Detection rates vary across bot tiers, but remain low across the board. Across all 10 bot types, 65.3% of sites did not stop any test bot. Among those that did defend, protection is uneven and drops sharply as bot sophistication increases.

Average detection rate by tier tested
11.4%
21.8%
5.5%
13.3%
Tier 1: Basic bots
Tier 2: Spoofed AI agents & crawlers
Tier 3: Disguised bots
Tier 4: Real browsers

A few findings stand out.

Even the simplest bots get through on most sites. Only 5.5% of sites detected every Tier 1 bot — the category requiring the least sophistication to detect. Tier 3, which involves forged browser fingerprints at the network level, is stopped by just 5.5% of sites. Standard defenses — IP reputation, user-agent filtering, simple behavioral rules — are failing against even low-sophistication automation.

More sites are blocking spoofed AI bots than simple bots. Tier 2 has the highest detection rate of any tier: 29.3% of sites stopped at least one spoofed AI agent, and 14.1% stopped all of them. But this is not a sign of more sophisticated defenses. The more likely explanation is that publishers and content platforms added explicit rules for GPTBot, ClaudeBot, and similar user-agent strings, and spoofed versions of those bots get caught by the same rules, not because sites can detect the impersonation, but because the identity being spoofed was already on a blocklist. 

These controls do not address attackers using unknown or custom agent strings. As more businesses begin allowing legitimate AI agents to access their sites, this weakness becomes more consequential. Static allowlists and blocklists cannot distinguish an authorized AI agent from a malicious bot impersonating one. Businesses need to verify agent identity and evaluate behavior and intent rather than rely on user-agent strings alone.

Identity-based trust is a widespread vulnerability. More than 7 in 10 sites allow a spoofed AI agent or crawler through without any challenge, simply because the request claims to be GPTBot, ClaudeBot, or a similar trusted identity. Tier 2 does have the highest “stopped all” rate of any tier at 14.1% — reflecting the growing number of sites that have added blanket AI-crawler blocks, typically through robots.txt enforcement or user-agent rules. But that protection has a critical ceiling: it works only against bots that announce themselves honestly. Any bad actor spoofing one of these identities could pass straight through. 

Real-browser bots are the hardest to detect, and most sites blocking them may not be doing so for the right reasons. Only 3.1% of sites stopped every Tier 4 bot tested. Critically, sites stopped the cloaked and uncloaked real-browser builds at nearly identical rates, a difference of just 0.05 percentage points. This suggests most are applying an indiscriminate challenge to any browser-like request, rather than genuinely reading the automation signal.

3.3

Which region has the weakest bot protection?

The test distributes requests from three proxy locations — the United States, France, and Canada — to ensure results are not driven by IP-based geographic filtering. Detection results were broadly consistent across locations, confirming that the protection gaps identified are structural, not geography-specific.

 

Asia Pacific has the highest unprotected rate at 73.9%, followed by Europe at 66.7% and North America at 63.8%.

Bot protection by region in 2026
Unprotected
Partially protected
Fully protected
Asia Pacific
73.9%
23.3%
2%
Europe
66.7%
30.8%
2%
North America
63.8%
34.2%
2%
Latin America
63.2%
33.9%
2%

All major regions declined year-over-year. North America’s unprotected rate moved from 59.8% in 2025 to 63.8% in 2026. Europe went from 61.5% to 66.7%. Asia Pacific grew from 68.4% to 73.9%. Latin America’s unprotected rate also moved from 58.1% to 63.2%.

Change in regional protection, 2025 vs. 2026
2025 unprotected
2026 unprotected
58.4%
64.9%
North America
61.6%
66.7%
Europe
68.7%
75.1%
Asia Pacific
56.7%
63.2%
Latin America

Key takeaway: No region is improving when it comes to overall protection. While there were some shifts between full and partial protection, every region saw a decline when the two categories are combined. In other words, fewer websites are stopping at least one of the bots tested, and more are allowing every test bot through. The most mature digital markets, North America and Europe, still have nearly two-thirds of websites fully unprotected.

3.4

Which industry is most vulnerable to bad bots & AI agents?

We grouped the tested websites into 15 industries. Protection levels vary significantly by sector, reflecting differences in business models, the value of assets at risk, and security maturity.

Protection levels by industry
Unprotected
Partially protected
Fully protected
Telecommunications
82.9%
15.9%
1.2%
Tech platforms
77%
21.5%
1.5%
Financial services
73.8%
24.2%
2%
Property, infra & public sector
71.9%
27.5%
0.6%
Education
69.7%
28.8%
1.5%
Business & professional services
69%
29.8%
1.2%
Media & entertainment
66.3%
31.9%
1.8%
Healthcare
65.7%
33.7%
0.6%
Gaming & gambling
64.3%
32.6%
3.1%
Ticketing
64.2%
33.7%
2.1%
Food & beverage
63.1%
35.7%
1.1%
Automotive & mobility
62.1%
36.4%
1.5%
Travel & hospitality
61.5%
37.2%
1.3%
Retail & e-commerce
59.7%
38.4%
2%
Marketplaces & classifieds
52.3%
43.8%
3.9%
Least protected industries
Unprotected
Partially protected
Fully protected
Telecommunications
82.9%
15.9%
1.2%
Tech platforms
77%
21.5%
1.5%
Financial services
73.8%
24.2%
2%
Property, infra & public sector
71.9%
27.5%
0.6%
Education
69.7%
28.8%
1.5%

Telecommunications tops the least-protected list at 82.9% unprotected. Tech platforms follow at 77%, showing that broad digital reach does not automatically translate into strong bot protection.

Financial services rank third at 73.8% unprotected. Property, infrastructure & public sector follows at 71.9%, while Education rounds out the bottom five at 69.7% unprotected.

These results show that protection gaps are not limited to one type of business. Telecommunications and technology platforms face broad exposure, while financial services continue to carry significant risk despite the value of the data and accounts they protect.

Most protected industries
Unprotected
Partially protected
Fully protected
Food & beverage
63.1%
35.7%
1.1%
Automotive & mobility
62.1%
36.4%
1.5%
Travel & hospitality
61.5%
37.2%
1.3%
Retail & e-commerce
59.7%
38.4%
2%
Marketplaces & classifieds
52.3%
43.8%
3.9%

For ranking purposes, protection was measured as the combined percentage of fully protected and partially protected for each site. 

Marketplaces & classifieds are the most protected industry, with 47.7% of sites showing at least partial protection. Retail & e-commerce follow at 40.4%, making these the two strongest-performing categories. 

Travel & hospitality ranks third at 38.5% combined protection, followed by Automotive & mobility at 37.9% and Food & beverage at 36.8%. 

Marketplaces & classifieds are the strongest-performing category, but 52.3% of sites in the category remain unprotected. Even the best-performing industries therefore have a clear opportunity to improve detection across more advanced bot types.

Key takeaway: Protection is uneven across industries, but no category has reached a strong baseline. Unprotected rates range from 52.3% in Marketplaces & classifieds to 82.9% in Telecommunications. Consistent, behavior-based detection is needed across every sector, especially as attackers reuse the same automation tools across different business models.

3.5

Do bigger companies have better bot protection?

Protection levels show very little variation across company size tiers. One might expect large enterprises with substantial security budgets to significantly outperform small businesses. In 2026, the gap is narrow to the point of being negligible.

Bot protection by company size
Unprotected
Partially protected
Fully protected
10K+
64.6%
33.7%
1.7%
5K-10K
65.9%
31.9%
2.2%
1K-5K
63.9%
34%
2.1%
501-1K
65.1%
32.5%
2.4%
201-500
66.6%
31.7%
1.7%
51-200
65.6%
32.3%
2.1%
11-50
65.1%
32.6%
2.3%
1-10
62.7%
34.1%
3.2%

The largest companies (10,000+ employees) have an unprotected rate of 64.6%. This is worse than the very smallest businesses (62.7%). Large enterprises contend with the complexity of protecting vast and diverse digital infrastructures, often with fragmented tooling and legacy systems that create gaps.

Counterintuitively, the highest-traffic websites are not better protected. Sites in the top 1,000 by monthly traffic had a 64.4% unprotected rate, virtually the same protection rate as sites in the lowest-traffic tier tested.

Bot protection by website traffic tier
Unprotected
Partially protected
Fully protected
Top 50K–100K
64.4%
32.8%
2.8%
Top 10K–50K
65.6%
32.2%
2.2%
Top 1K–10K
65.8%
31.6%
2.6%
Top 1,000
64.4%
32.7%
2.9%

High-traffic sites are more attractive targets. They host more users, more data, and more monetizable assets. Not having stronger defenses makes them disproportionately valuable to attackers.

Key takeaway: Neither company size nor traffic volume predicts protection quality in 2026. The most powerful websites on the internet are failing the same basic bot tests as the smallest.