Legacy defences are collapsing as AI-driven traffic continues to overwhelm the web, with new research finding that just 2.8% of domains are fully protected.
After analysis of more than 16,900 websites across twenty-two industries, DataDome’s latest Global Bot Security Report found that most businesses remain dangerously unprepared to manage AI-generated traffic, which now makes up more than 1 in 10 verified bot requests.
The study found that LLM crawler traffic has skyrocketed, going from 2.6% of verified bot traffic in January to over 10.1% by August, with DataDome alone detecting nearly 1.7 billion requests from OpenAI crawlers in a single month.
While these crawlers scrape massive amounts of web content, the report found that, unlike older automation, AI-driven traffic doesn’t stop at scraping. According to DataDome, in 2025, 64% of AI bot traffic reached forms, 23% login pages, and 5% checkout flows, creating new vectors for fraud, account takeover, and compliance risk.
However, businesses are failing to keep up with this emerging risk. Though the vast majority (88.9%) of domains disallow GPTBot in their robots.txt files, DataDome said this measure offers little real protection as AI-powered crawlers and browsers can simply ignore these directives, rendering static blocking strategies obsolete.
The report found that only 2.8% of websites were fully protected this year, down from 8.4% in 2024, with most businesses still unable to stop even basic bots or classify intent, meaning businesses risk blocking innovation as well as opening the door to abuse.
Only 2% of domains with over 30 million monthly visits were fully protected. Even among enterprises with more than 10,000 employees, just 2.2% had full protection, and 61% were completely unprotected.
Recommended reading
Advanced bots are escalating the threat, slipping past most defences with ease. Anti-fingerprinting bots, for example, were blocked by just 7% of websites, leaving most exposed to account takeovers, carding, and high-level scraping. Fake Chrome and curl bots, meanwhile, were detected only 21% of the time.
The study found that although the governmental, non-profit, and telecom sectors had the weakest protection, even among the top-performing industries, full protection remains rare, and partial protection alone isn’t enough to stop sophisticated bots.
“AI agents are rewriting the rules of online engagement,” said Jérôme Segura, VP of threat research at DataDome.
“They mimic human behaviour, spawn synthetic browsers, bypass CAPTCHAs, and adapt in real time. Traditional defences, built to spot static automation, are collapsing under this complexity.
“Businesses can’t tell if the AI traffic they’re seeing is good or bad, which leaves them both exposed to fraud and blind to opportunity. What’s needed is adaptive, intent-based protection that can make sense of this AI-driven chaos in real time.”





