iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
AI agents are beginning to do more on the web than retrieve information: they can navigate pages, fill out forms and carry out multi-step tasks. That makes automated activity more consequential, but it does not mean the internet has literally lost its humanity—or that most automation is malicious. The evidence points to a measurable rise in AI-driven traffic and documented cases of AI-enabled cyber misuse, not a global verdict on how human the internet has become.
What is the agentic internet?
The “agentic internet” is a way of describing web activity in which AI systems can take actions, not just generate text or fetch pages. HUMAN Security defines agentic AI as systems that plan, decide and act autonomously across multi-step web tasks. In its examples, an agent can navigate a site, interact with forms and proceed through transactions.
That capability matters because a request to find public information is different from an automated system acting inside an account, at checkout or on a payment flow. The same ability to carry out a delegated task can support a legitimate user—or be misused. HUMAN’s observations come from its own customer platform, not a census of every website. HUMAN’s 2026 State of AI Traffic and Cyberthreat Benchmark describes its definitions and methodology.
How is AI traffic different from bot traffic?
“Automated traffic” and “AI-driven traffic” are related, but they are not interchangeable. HUMAN defines automated traffic broadly as non-human internet traffic; AI-driven traffic is the portion generated by or on behalf of AI systems. Its report distinguishes among training crawlers, real-time scrapers and agentic AI.
#1 Best Overall
Those categories can have different purposes and behaviors. A crawler collecting material for training, a scraper retrieving current data, and an agent completing a multi-step task should not automatically be treated as the same kind of activity—or as malicious simply because they are automated. Intent and observed behavior matter more than the word “bot.”
What do the reported growth figures actually show?
Security vendors have reported sharp changes in the traffic they observe, but their figures describe separate datasets and definitions. They should not be combined into a single estimate of internet-wide activity.
| Report and measure | Reported finding | Scope and qualification |
|---|---|---|
| HUMAN Security, AI-driven traffic | Monthly AI-driven traffic increased 187% from January to December 2025. | Traffic observed on HUMAN’s platform; not a measure of all internet traffic. |
| HUMAN Security, agentic AI | Agentic AI traffic grew 7,851% during 2025; it represented 1.7% of observed AI-driven traffic in December 2025. | The growth rate starts from a small observed category and reflects HUMAN’s customer dataset. |
| HUMAN Security, platform scale | More than one quadrillion interactions were processed in 2025. | Interactions across HUMAN’s customer base, not all internet interactions. |
| DataDome, malicious automated traffic | Increased 124% between July 2025 and June 2026. | DataDome’s own customer dataset; its 2026 release also describes tests of more than 20,000 websites and analysis of more than one trillion requests. |
| Thales, bots’ share of web traffic | Its 2026 report landing page says bots accounted for 53% of web traffic in 2025. | A vendor-reported estimate, not a settled census of the whole internet. |
HUMAN says its report uses aggregated, anonymized observations across its customers from 2022 through 2025 and does not represent the totality of internet traffic. The figures are useful evidence of change within observed environments, but they cannot establish that AI agents are “taking over” the web as a whole.
How is automation being weaponized?
Malicious automation can use speed and scale to support activities such as scraping, fraud or account abuse. AI systems may also help coordinate complex sequences of actions. That makes protection of authentication, account and payment flows especially important for site operators. But the existence of those risks does not make every crawler, agent or automated request harmful.
Rank #3
Anthropic reported analyzing 832 accounts associated with malicious activity over March 2025 to March 2026. The accounts were selected from those it investigated and banned, and included only cases with sufficient information for mapping techniques. The report describes autonomous chaining of attack stages as a concern. This is evidence of documented misuse in a selected, platform-specific sample—not a measure of how common such activity is across all platforms or actors.
Other vendor findings reinforce the need to distinguish behavior from mere automation. HUMAN reported that the rate of benign and malicious automation in its observed interactions differed by only half a percentage point. That result is specific to its dataset and classifications; it does not show that the internet’s automation overall is evenly split, or that the two types can be identified from a single signal.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can a site distinguish a useful agent from a harmful bot?
There is no reliable one-word answer such as “AI” or “bot.” Site operators need to consider what the system is doing, what it can access and whether its actions are visible and accountable. A practical assessment should include:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Identity and behavior: Does the system declare who it is, and do its observed actions match that declared purpose? A declared identity is informative, but behavior and intent still need to be assessed.
- Access level: Is it reading public content, or attempting authentication, changing account details, placing orders or making payments? Actions affecting accounts and money carry higher stakes.
- Purpose and impact: Does the activity support legitimate discovery, accessibility or a task delegated by a user, or does it resemble scraping, fraud or account abuse?
- Visibility and auditability: Can the site see what the agent did and connect consequential actions to an accountable user or system?
- Blocking trade-offs: Would a rule stop harmful activity while preserving useful automation, or would it block both? Overly broad controls can deny beneficial access as well as abuse.
These are decision axes, not a vendor-neutral test or a guarantee of intent. The cited reports document why the distinctions matter; they do not provide an independent comparison proving that any specific product or signal can separate good agents from bad ones.
Has the internet really lost its humanity?
That phrase works as a cultural argument or a question about how people experience the web, not as a finding established by these traffic reports. HUMAN, DataDome and Thales report classifications or estimates of activity in their respective datasets. Anthropic examines selected investigated accounts. None of these measures whether online life has become less human socially or culturally.
The supported conclusion is narrower: AI-driven and agentic activity are growing in some security vendors’ observations, and AI-enabled cyber misuse has been documented. The evidence does not establish a global “dead internet,” prove that most automation is malicious, or settle claims about effects on publishing, culture, work or human relationships.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

