A 2026 report from the French technology company Thales, titled 2026 Bad Bot Report: Bad Bots in the Agentic Age, finds that artificial intelligence is reshaping internet usage and the threat landscape. According to the report, AI now produces more than half of all internet traffic, and roughly 40 percent of that AI-generated traffic is classified as malicious.
Sharp increase in AI-driven attacks
The report highlights that AI-powered attacks in 2025 increased to 12.5 times the number recorded in 2024. This surge indicates rapid scaling of automated, AI-driven malicious activity and growing use of sophisticated techniques to exfiltrate data or disrupt services.
Three structural shifts
Thales identifies three fundamental changes likely to affect the architecture and security of the internet going forward:
- AI agents as a new traffic category: AI agents have emerged as a distinct type of actor in internet traffic, exhibiting their own behaviors and objectives.
- Automated activities surpassing human interactions: web operations are increasingly executed by automated processes, while the proportion of human-initiated interactions is falling.
- Rapid spread of attacks against APIs and identity systems: attacks targeting application programming interfaces (APIs) and identity-management systems, which underpin digital business, are proliferating quickly.
Agents blur the line between legitimate and malicious behavior
As noted by Interesting Engineering summarizing the findings, beyond the conventional "good" and "bad" bots a new class of AI-driven agents has appeared that directly interact with applications and APIs to fetch data and perform tasks. This change blurs previous distinctions: malicious actors often emulate legitimate requests and authentication flows, making intent harder to detect.
In practice, defensive systems may struggle to distinguish lawful automated services from deceptive or data-exfiltrating activity.
Implications for cybersecurity
The increasing automation of the web and the growth of AI-generated traffic present significant challenges for cybersecurity professionals. The Thales report implies that defenses must evolve: organizations will need improved identification and behavior-analysis techniques, stronger API usage monitoring, and advanced identity protection measures to detect and block malicious AI activity.
Given the speed of change, it remains an open question which specific technical and regulatory responses will most effectively curb the new types of fraud and malicious automation.


