News

Malicious AI bots now account for nearly half of all web traffic as agentic shift creates new blind spot for security stacks

04 June 2026
2 minutes
The rapid growth of AI assistants and autonomous agents is creating a structural gap in web security infrastructure, as traffic patterns shift away from browsers and towards HTTP-level access that conventional detection tools were not built to handle.

Nearly half of all web traffic in 2025 originated from malicious bots, according to cybersecurity leader Thales.

Fingerprint warns the figure will continue to rise as AI assistants become the primary means through which a growing share of users navigate the internet. The challenge for operators and security teams is no longer simply volume, it is intent.

The core problem is architectural. Tools built to detect automated traffic rely heavily on JavaScript signals generated by browsers. AI assistants including OpenAI’s ChatGPT, Google’s Gemini and Anthropic’s Claude access web properties directly over HTTP, pulling content and conducting research without loading a page or executing client-side code.

That makes them effectively invisible to conventional bot detection, a blind spot that malicious actors are already exploiting by spoofing the user-agent strings of legitimate assistants to bypass filters.

The shift is accelerating. Google’s Gemini Spark, announced at I/O 2026, runs on dedicated cloud virtual machines without any browser involvement, representing a broader move towards always-on, browserless AI infrastructure that security stacks were not designed to anticipate.

Fingerprint has launched an Automation Intelligence API and AI Assistant Detection capability operating at the HTTP level, designed to verify whether traffic claiming to originate from a known assistant is genuine and to enrich each detection with network risk context including proxy, VPN and geolocation signals.

Valentin Vasilyev, co-founder and chief technology officer of Fingerprint, said the question facing operators had fundamentally changed. “It’s no longer ‘is this a bot or a human?’ It’s ‘can I trust this visitor, whoever it is?’”

RELATED STORIES

AI now lies, denies, and plots: OpenAI’s o1 model caught attempting self-replication

AI agents are starting to talk: Are the networks ready?

Capacity Europe 2026

13 October 2026

The 24th anniversary edition of Capacity Europe 2025 will bring together 3,500+ decision-makers from the global connectivity and digital infrastructure community.