By early June 2026, bots had overtaken people on the web. Traffic measurements from that period put automated traffic ahead of human traffic.
That upends the usual assumptions behind measurement, security, and monetization. In the early June 2026 numbers, 57.5% of all HTML traffic was automated requests, while real people accounted for 42.5%. Those same measurements suggest the crossover happened roughly 18 months sooner than many people expected.
Some agents are useful. They can improve your search visibility, show you up more often in answer engines, and send referral traffic your way. Others are just scraping your content to train models. And plenty of companies still can’t clearly tell which agents are hitting their servers, because metrics like pageviews, sessions, and referrals were built to track human behavior.
The security side looks worse. Early 2026 traffic data shows Meta-ExternalAgent was spoofed more than 16 million times, while ChatGPT-User piled up nearly 8 million fake requests. In that same dataset, even 2.4% of traffic presenting itself as PerplexityBot turned out to be fraudulent.
If you’re relying on a basic user-agent allowlist, take that as a warning. Tests across 700,000 high-traffic sites found that most of them gave spoofed agents full access without any real verification.
Agentic browsers are harder to deal with still, because they imitate full browsing sessions, especially on ecommerce and retail sites. One report put 7,851% year-over-year growth in agentic browser traffic, and some site owners reported spikes as high as 20x.
Zero-click answer engines can also keep users from reaching your site at all. And traffic observations from early 2026 found that this activity often appeared to come from data-center hubs such as Gibraltar, Singapore, and Iran, not from the places where your actual audience is based.