ANNUAL REPORT

Takeaways &
recommendations

The 2026 data demands a new approach to detection

The 2026 data tells a consistent story: the gap between what most websites deploy for defense and what attackers actually use is widening. Only 5.5% of sites stopped every basic bot — the lowest-sophistication attack in the test set. For real-browser bots, that figure drops to 3.1%. The tools enabling these attacks — from fingerprint-spoofing frameworks to bot-as-a-service platforms — are increasingly accessible and affordable. Defenses that cannot stop simple bots will not stop the fraud and abuse that follows.

 

The challenge in 2026 is not only about stopping more bots, but making better decisions about all automated traffic. Traffic type alone is no longer a reliable signal. An AI agent hitting a login page could be an authorized customer tool or an attacker running a credential stuffing campaign. The security question is no longer “is this a bot or a human?” It is: “What is this visitor trying to do, and does it serve my business?”

 

Intent-based detection answers that question by evaluating not just who or what is making a request, but what it is trying to accomplish — using signals like behavioral sequencing, endpoint sensitivity, rate and volume patterns, and session context. The goal is not to block automation. As AI agents become active participants in commerce, productivity, and research workflows, the right automation should operate freely. The task is identifying and stopping the wrong automation in real time.

Key recommendations

Implement intent-based detection, not just bot detection. Traffic type alone does not determine risk. AI agents, good bots, and human users all generate web requests. The security decision is not whether a visitor is automated — it is whether the automation is authorized, behaving consistently with its declared purpose, and targeting appropriate endpoints. Detection systems that classify based on identity signals alone (user-agent, IP, header patterns) will continue to miss the majority of modern threats.

 

Extend protection to high-risk endpoints, especially APIs and login flows. Login endpoint targeting by AI agents grew more than 8x (735.8%) across H1 2026. Forms, APIs, and cart flows are increasingly touched by automated traffic — both legitimate and malicious. Protection that covers the homepage and misses the login page, checkout flow, mobile apps, or a Model Context Protocol (MCP) endpoint is incomplete. Access control policies for AI agents need to be applied with the same rigor as access control for human users.

 

Test your bot and AI agent defenses. Tool presence does not equal effective protection. Security teams should test their own sites to understand what actually gets through. DataDome makes this easy to do anytime for free. Test your site

 

Define your AI agent access policy. AI agents will interact with your website whether or not you have a policy for them. The question is whether those interactions are governed. A published AI agent access policy — specifying which agents are permitted, what they can access, and under what conditions — gives your security team the criteria to classify traffic as authorized or unauthorized, and gives legitimate AI systems the information they need to operate appropriately.

Why DataDome?

Traffic you can trust

 

DataDome delivers real-time bot and agent trust management, giving businesses complete visibility and control over all traffic — human, bot, or AI. 

 

Acting as a traffic control plane, DataDome’s multi-layered AI engine leverages thousands of models and 5 trillion signals daily to analyze intent and stop fraud in under 2 milliseconds — letting legitimate users through seamlessly.

 

Key platform capabilities:

 

  • Intent-based detection in real time: DataDome evaluates behavioral intent — not just identity — to distinguish authorized automation from malicious activity
  • Full-journey coverage: Protection across web, mobile, API, and MCP server endpoints
  • Industry-leading accuracy: Less than 0.01% false positive rate, ensuring legitimate users and authorized AI agents are never incorrectly blocked

See it for yourself

If this report raises questions about your own exposure, there are two ways to find out where you stand.

 

Test your site’s defenses for free. See exactly which bot and AI types get through, and where your protection gaps are.

 

Talk to our team to see how DataDome works across your full traffic environment, including web, mobile, API, and MCP endpoints.