Safety

Rapid Increase in AI-Driven Web Traffic, Human Security Report Finds

A Human Security report analyzing over one quadrillion internet interactions in 2025 found that AI-driven traffic nearly tripled that year, driven largely by crawlers gathering training data and scrapers collecting information for immediate use.

Rapid Increase in AI-Driven Web Traffic, Human Security Report Finds

A report from the cybersecurity firm Human Security found that AI-driven traffic on the internet nearly tripled in 2025. The 2026 State of AI Traffic and Cyberthreat Benchmark Report analyzes more than 1 quadrillion internet interactions observed by Human Security, which serves roughly 1,200 customers across more than 200 countries and territories.

What types of AI activity increased?

The report breaks down AI-driven traffic as follows:

  • Crawlers that collect data en masse for training AI systems: these accounted for 68 percent of AI-driven traffic for the year, more than double their volume from the prior year.
  • Scrapers that harvest data for immediate use (for example, prices): these represented 32 percent of AI-driven traffic and saw a sevenfold increase in volume year over year.
  • Agentic browsers and agents that perform browser-like tasks: these made up 1.7 percent of AI-driven interactions in December, marking nearly an 80x increase year over year.

Among agentic interactions, 77 percent occurred on product and search pages; the remainder involved account pages, authentication, and completing transactions, in that order.

Which organizations generated this automated traffic?

Human Security attributes much of the automated traffic to three companies: OpenAI was responsible for about 69 percent (including ChatGPT users and crawlers such as OAI-SearchBot and GPTBot), Meta for roughly 16 percent, and Anthropic for around 11 percent.

Security implications and malicious activity

The researchers judged a substantial portion of automated traffic to be malicious. Key findings include:

  • Malicious scraping activity — defined by the authors as scrapers that spoof identity, follow recognized attack patterns, or otherwise behave suspiciously, often to gather competitive intelligence or systematically undercut prices — rose nearly 47 percent from the previous year. Of the 750,000 threat profiles identified, over 60 percent were tied to malicious scraping.
  • Attempts by bots to take over user accounts fell by more than 30 percent over the year. However, attacks that occurred after an account was already logged in increased fourfold. Also, the number of accounts created by agents rose by 89 percent year over year.
  • The share of transaction traffic involving a compromised payment card remained "low and stable," but the volume of transactions blocked by card issuers grew by 20 percent, which may reflect more transactions overall, agents’ improved ability to cycle through card numbers, or both.

Report limitations

The authors note that the report covers only activity seen on Human Security’s platform, not the entire internet. They also acknowledge that malicious traffic often falsifies its origin, so classifications for specific data points may be incorrect.

Why this matters

Autonomous systems are adding substantial additional traffic to the web, and this trend is likely to continue. That has implications for infrastructure planning and upgrades, and for cybersecurity: legitimate AI agents now perform many of the same actions that historically signaled malicious bots, complicating detection and defense.

Summary

Human Security’s analysis shows a dramatic increase in AI-driven web activity in 2025: crawlers and scrapers expanded sharply, and agentic traffic — while still a small proportion of total traffic — grew rapidly. The increase brings elevated security concerns, particularly around malicious scraping profiles and agent-created accounts.