AI Bots Are Now 57% of Web Traffic, and Nobody Reports It
Published September 30, 2026
Cloudflare counts 57.5 percent of web traffic as bots. The number is not as simple as it looks, and here is how to read it.

On 3 June 2026, Matthew Prince, founder and chief operating officer of Cloudflare, put a single number in front of the public. Bots accounted for 57.5 percent of web requests, humans for 42.5 percent. The reaction in the press was immediate. For the first time in the history of the internet, machines held the majority of traffic.
The number is not wrong. What almost nobody reported is the other half of the same story, which is that most of that bot traffic is collected without giving anything back to the site it came from. That is where the real problem sits.
Where the 57.5 percent figure comes from
Cloudflare holds a position no other network has. They run one of the largest content delivery networks in the world, so they see requests from a large share of the internet.
Prince's claim landed on 3 June 2026. Cloudflare's own forecast had put the crossover a year later, and the forecast was wrong. What came out of Prince amounted to a single line: it happened faster than he predicted.
Cloudflare Radar then showed a more complicated picture. Limited to HTML responses over the previous seven days, bots accounted for 35.6 percent and humans for 64.4 percent. Statcounter reported 23.44 percent bots for July 2026. One large network, three different numbers, all of them defensible.
The difference is not that one number is wrong. Cloudflare Radar deliberately measures only HTML traffic, while much machine traffic runs over APIs that are not counted. Statcounter is pageview-based on a different measurement network, so its mix is not the same. No single figure applies to every case.
Whether the bots that arrive are dangerous
Not all of them. The breakdown inside that 57.5 percent is far more useful than the headline number.
Of verified bot traffic, AI crawlers account for roughly 20.3 percent, and AI search bots add about 6.5 percent. So around a quarter of bot activity involves AI. The rest is the older kind that has existed for decades: search engine crawlers, uptime monitors, web archiving, and link checkers.
For AI bots the distinction is what matters. A training crawler fetches pages to train a model and never sends a single visitor back. Search and agent bots do the opposite. They index or answer a question, and what arrives at your site is a human.
The finer numbers make that split clearer. In 2026, most crawlers are oriented toward training rather than search. GPTBot's share of AI crawl traffic rose from 4.7 percent to 11.7 percent within a year, while ByteSpider fell sharply from 14.1 percent to 2.4 percent.
The ratio that matters most to site owners
There is one figure that matters most to anyone who runs a site, and it rarely appears in the news: how many pages a single crawler fetches for every visitor it sends back.
Cloudflare Radar data from 31 May 2026 has an uncomfortable answer.
| Bot | Pages fetched per visitor |
|---|---|
| ClaudeBot | 10,300 : 1 |
| GPTBot | 904 : 1 |
| PerplexityBot | 193 : 1 |
| Bingbot | 35 : 1 |
| Googlebot | 5 : 1 |
| DuckAssistBot | 1.5 : 1 |
Googlebot fetches about five pages for every visitor it sends. That is the web's economic model as most people know it. There is a trade, and that trade is what keeps the web running without anyone being paid.
ClaudeBot fetches 10,300 pages for every visitor. That ratio is roughly 2,000 times larger than Googlebot's. A site with long explanations or a large catalogue will have its entire inventory read for data that never returns as traffic.
Why e-commerce became the main target
Akamai's State of the Internet report, published 15 July 2026, gives the other side of this. It is not about the ethics of crawling, it is about traffic that gets corrupted.
At the platform level, 47.9 percent of e-commerce traffic on Akamai's network in December 2025 already came from AI bots. More than 70 percent of AI bot triggers came from training crawlers. OpenAI, ByteDance and Anthropic occupy the top three positions.
The most painful number is in the response. E-commerce companies placed more than 90 percent of their bot activity in the monitor category alone, and let three quarters of the rest pass unrestricted.
Two figures do not cancel each other out. Eighty-five percent of e-commerce respondents experienced at least one API incident in the past year, yet only 22 percent know which of their APIs hold sensitive data. Most of the organisations being attacked do not know where the attack came from.
Layer 7 attacks against e-commerce came close to 3 trillion times in 2025, with retail bearing 84 percent of that volume. In Asia-Pacific, bot activity surged 63 percent within a year, the largest rise of any region Akamai tracks.
Asia-Pacific, the fastest growing region
The Asia-Pacific rise is worth separating out, because that is where you are reading this from.
Bot activity in the region rose 63 percent in a year, the highest of any region Akamai monitors. For comparison, North America rose 7 percent and EMEA rose 16 percent. That sounds like ordinary growth, but 63 percent means the region's bot activity passed its previous total within a single year.
Akamai records EMEA as contributing 26 billion AI bot counts for retail between July and December 2025, which is 12.4 percent of all tracked AI bot activity. North America recorded 33 billion, the highest in the world.
The report offers a reasonable explanation for that pattern. Travel markets and loyalty programmes in Asia-Pacific are fragmented across many operators and many separate apps, so there is far more surface area to attack than in a concentrated market.
What this means for you
Three consequences apply to you as a reader who runs a blog, a small shop, or is simply wondering why the hosting bill went up.
First, crawlers that fetch pages for training generally do not send visitors back. If you run a site with long-form content or a large catalogue, it is reasonable to ask whether that should be blocked. The answer depends on your platform, and most networks ship a bot management tool for it.
Second, robots.txt still works for compliant bots but not for the ones that ignore it. In 2025 a seven-person company with 65,000 products went offline because a single bot sent requests from 600 IP addresses at once. Its founder described it as a denial-of-service attack. The company lost customers during business hours and received a sharply higher cloud bill.
Third, do not use the 57.5 percent figure to draw conclusions about your own site. It is one measurement network over one period, not a mirror of every site. The more universal measure is the crawl-to-visitor ratio, and you can check that yourself today.
Analysis: a pattern nobody raised
Something follows from all of the data above that is not merely a statistic.
The centre of gravity has moved. Two years ago the conversation about AI bots was about security: is this crawler dangerous, does it steal, should it be blocked. Now the shift is economic: does this crawler give anything back.
That shift explains why there is no urgency. There is no single incident large enough to reach a newsroom. What is happening is small erosion across many sites at once, and it only becomes visible once the bill has risen.
The second thing, and the one most often missed, is that this data is measured by vendors who sell bot management products. Cloudflare has an interest in reporting high numbers, and so does Akamai. That does not make the numbers wrong, but it is worth remembering who is doing the counting.
There is one thing this data does not measure at all: how many small sites have quietly stopped publishing because nobody came to read them. The big reports count who was attacked, not who gave up. None of them counts the writers who stopped writing, and that is the one number that actually determines whether the web is still worth maintaining.
| Figure | Source | What it actually measures |
|---|---|---|
| 57.5% | Cloudflare, 3 Jun 2026 | all requests across Cloudflare's network |
| 35.6% | Cloudflare Radar, 7 days | HTML responses only, API traffic excluded |
| 23.4% | Statcounter, Jul 2026 | pageviews from a different measurement network |
| 47.9% | Akamai, Dec 2025 | e-commerce traffic on Akamai's network only |
None of the four contradict each other. Each measures something different, and none of them can be used to name any country as the most trafficked.
The figure most likely to outlast the news cycle is the least discussed one, the 10,300 to 1 ratio. A headline about 57.5 percent will be stale within a year because the data moves. That ratio changes how people think about who is actually paying for the internet.
For now the conclusion is simple. The web is not under attack. The web is being read, and whatever reads it sends nothing back.
Related tools
Free browser tools that apply to this topic.
Share this article
Share to
Related articles

September 30, 2026
20 Countries Cap Social Media for Kids, Indonesia Moves First
Australia from December 2025, Indonesia from March 2026. At least 20 countries have similar rules, but only some are actually in force.

September 29, 2026
G30S From a Historian's View: The Numbers Nobody Counted
Historian Anhar Gonggong reads G30S as the end of a 45-year ideological argument. What remains is not a verdict but a number nobody ever counted.

September 29, 2026
The World's Most Advanced Chip Is Not NVIDIA's or AMD's
The most advanced chip out of the lab is not a GPU. IonQ traps individual atoms above silicon, and NVIDIA is now its partner, not its rival.



