Automated Traffic Now Exceeds Humans, Reshaping Internet Security and Digital Economy

For the first time in the history of the web, bots generate more internet traffic than humans. According to Imperva's 2024 Bad Bot Report, automated traffic now accounts for 49.6% of all web requests, while human traffic has fallen to just 50.4% — its lowest level in a decade. The shift marks a turning point that experts say will reshape security, advertising, and the very nature of online interaction.
The trend is driven by artificial intelligence. Since the launch of ChatGPT in late 2022, the number of bots scraping the web to feed AI language models has exploded. "The automation will soon surpass the proportion of internet traffic coming from humans, changing the way organizations approach security," warned Nanhi Singh, head of application security at Imperva.
Not all bots are harmful. Imperva breaks web traffic into three categories: human (50.4%), good bots like Google's search crawlers (17.6%), and bad bots (32%). That last figure rose 2 percentage points in a single year. Bad bots include tools that steal account credentials, scrape content without permission, and manipulate online inventories.
The geography of bot attacks is uneven. Ireland absorbs the heaviest load, with 71% of its web traffic coming from bots. Germany follows at 67%, and the United States at 48%. In the gaming sector, bad bots account for 57% of all traffic. Telecoms face 45%. These are not marginal numbers — they represent the majority of activity on some of the busiest platforms on the internet.
Today's bots are far harder to catch than those of a decade ago. Security firm Arkose Labs calls the latest attacks "hybrid": bots use machine learning to move a mouse erratically and mimic human typing patterns, then pass unresolved challenges to human workers in CAPTCHA-solving farms. Standard security checks no longer work.
Three forces have supercharged this evolution. First, data has become enormously valuable for training AI, making web scraping a high-profit business. Second, automation tools that once required expert programmers are now sold as ready-to-use services — "Bot-as-a-Service." Third, bots now learn on the fly, adapting to defenses in real time. The result is an arms race that defenders say they are currently losing.
The economic damage is mounting fast. Research firm Juniper Research estimates that bot-driven ad fraud will cost advertisers more than $100 billion globally over the next two years. Up to 25% of digital ad budgets may already be wasted on fake clicks. Every time a bot clicks an ad, a real advertiser pays — and gets nothing in return.
Publishers are also under attack. Outlets like The New York Times have sued AI companies whose bots scrape articles to train language models — without sending human readers back to the original site. Meanwhile, account takeover attacks, where bots test stolen passwords at login pages, rose 10% in 2023. Some 44% of all login attempts on e-commerce sites now come from bots, according to Imperva.
Security experts say traditional defenses are obsolete. CAPTCHAs — the distorted-text puzzles designed to block bots — are now routinely solved by AI. The next line of defense is behavioral biometrics: software that tracks how a user moves, types, and scrolls to decide if they are human. But that raises a hard question. Cloudflare and others acknowledge that proving you are not a bot increasingly means handing over more personal data.
Privacy advocates, including the Electronic Frontier Foundation, warn that aggressive bot-blocking can become a tool of mass surveillance. If every internet user must prove their humanity through biometric checks, the cure may be worse than the disease. The challenge for the next decade is building a web that stays open to people — while closing the door on machines pretending to be them.
Publishers
12
Articles
0
Reach
12