AI-driven automation is no longer emerging; it is becoming embedded in internet traffic. The 2026 Thales Bad Bot Report explores how AI-driven automation is transforming the way applications and APIs are accessed, with bots now accounting for the majority of global web traffic. As agentic AI introduces a new class of automated traffic, organizations must navigate an increasingly complex environment where intent is harder to detect, distinguish, and control.
Based on analysis of full-year 2025 bot activity, this report combines insights from Thales Threat Research and Security Analyst Services (SAS) teams, who investigate and mitigate bot attacks across industries worldwide.
17.2 Trillion
The number of bot requests blocked by Thales in 2025.
21%
Bot attacks targeting business logic.
40%
The percentage of internet traffic made up of bad bots.
12.5x
The year-over-year increase in AI-enabled bot attacks.
20%
The percentage of AI bot attacks are targeting Retail sites.
53%
The percentage of internet traffic made up of bots.
42%
Simple bot attacks.
41%
The percentage of bot attacks using Chrome to appear as legitimate traffic.
24%
The percentage of bot attacks targeting Financial Services sites.
47%
Percentage of internet traffic attributed to human traffic.
27%
Bot attacks targeting APIs.
46%
The percentage of account takeover attacks targeting Financial Services.