惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Securelist
K
Kaspersky official blog
Scott Helme
Scott Helme
C
CXSECURITY Database RSS Feed - CXSecurity.com
GbyAI
GbyAI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
Cisco Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - Franky
Security Latest
Security Latest
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Y
Y Combinator Blog
T
Threat Research - Cisco Blogs
L
LINUX DO - 热门话题
C
Cyber Attacks, Cyber Crime and Cyber Security
Project Zero
Project Zero
Cisco Talos Blog
Cisco Talos Blog
月光博客
月光博客
I
Intezer
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
人人都是产品经理
人人都是产品经理
L
Lohrmann on Cybersecurity
Recorded Future
Recorded Future
Latest news
Latest news
V2EX - 技术
V2EX - 技术
T
The Exploit Database - CXSecurity.com
H
Heimdal Security Blog
F
Fortinet All Blogs
Cloudbric
Cloudbric
IT之家
IT之家
博客园 - 叶小钗
Microsoft Security Blog
Microsoft Security Blog
P
Proofpoint News Feed
博客园 - 司徒正美
Apple Machine Learning Research
Apple Machine Learning Research
PCI Perspectives
PCI Perspectives
AWS News Blog
AWS News Blog
H
Help Net Security
S
Security @ Cisco Blogs
酷 壳 – CoolShell
酷 壳 – CoolShell
Recent Announcements
Recent Announcements
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
F
Full Disclosure
S
Schneier on Security
S
Security Affairs
T
Tenable Blog

Fastly Blog

Fastly Fastly Fastly Fastly Fastly Fastly Fastly Six Common Live Streaming Mistakes (And How to Avoid Them) How Fastly and Skyfire Enable Trusted Agentic Commerce at the Edge Bot Defense is Table Stakes. Machine Traffic Requires a Business Strategy AI Traffic Grew 6.5x Faster Than Human Traffic This Year Python SDK Beta: How the Language of AI Runs Faster and Safer with Fastly Give AI Agents the Markdown They Actually Want How to Configure Local Logging for an On-Prem Next-Gen WAF Agent Accountability Without Control Is Breaking Security Leadership Fastly Joins the Agentic AI Foundation (AAIF) to Guide Edge AI Interoperability The E-commerce Industry in the AI Era: Has the Agentic Flood Hit? No Margin for Error: What the FIFA World Cup Teaches Us About Performance at the Edge Why iGaming Infrastructure is Breaking and What Comes Next The Publishing Industry in the AI Era: Why Bot Strategy is Now a Business Strategy Bad Performance Kills SaaS/PaaS Growth — Why Your CDN Matters Why your code is safe from Copy Fail on Fastly Compute Myth or Marvel: Claude Mythos and What it Means for Security Introducing Compliance Audit Reports Supporting Google Private AI Compute with Privacy-Preserving Edge Infrastructure Fastly Media over QUIC: Can Streaming Finally Have Both Scale and Low Latency? Introducing Fastly’s Redesigned Homepage: Your Central Hub for Actionable Insights The False Choice of Indiscriminate Blocking: Why Technical Precision is the New Standard for an Open Internet What is CVE-2026-23869? React Server Components Security Alert Fastly enables first-party tagging for Google Advertisers Shrink Your Bill With Efficient Software Your AI coding agent just got better at Fastly Fastly Ranked as a Leader in the 2026 Forrester Wave™ for Edge Development Platforms Fastly at RSAC 2026: New Advances in AppSec, Bot Management, and Deception Mastering the Edge: What Golf Can Teach Us About Speed, Precision, and Performance Real-Time CDN Monitoring for Live Events with Bronto Imperva Alternatives Fastly + Scalepost: Extending the Fastly platform to manage AI Crawlers Best content delivery networks for bot management Vibe Shift? Senior Developers Ship nearly 2.5x more AI Code than Junior Counterparts Maximizing Compute Performance with Log Explorer & Insights Fastly CDN Expands Scaling Fastly Network: Balancing Requests | Fastly Best Practices for Multi-CDN Implementations | Fastly Compute@Edge: Serverless Insights by Company | Fastly Fastly can teach you about the Wasm future in just 6 talks Fastly's Observability Unleashed: New Updates and Insights Optimizing your multi-CDN infrastructure to improve performance Stay ahead of attackers by pushing your security perimeter to the edge Are APIs the Key to Digital Innovation or a Trojan Horse? Fastly Academy: on-demand learning at your fingertips. | Fastly 30 Years of Web: Building for Tomorrow 4 Ways Legacy WAF Fails to Protect Your Apps Adobe boosts performance and MTTR with Epsagon and Fastly logs | Fastly Beta" A New Serverless Compute Environment Early TLS at Fastly Technical trainings & the future of edge delivery at Altitude 2016: a year in review Innovation Capacity Defined: Tech Stack Values | Fastly Deep Log Visibility Offered by Logentries | Fastly Caching the Uncacheable: CSRF Security Increase Your Hit Ratio With This Simple Tip
Nearly Half the Web Isn’t Human: Inside Fastly’s Threat Insight Report
David King, Natalie Griffeth · 2026-04-16 · via Fastly Blog

TL;DR:

  • Bots now make up 49% of all traffic, nearly equal to humans (51%)

  • 99% of bot traffic is unwanted, including scrapers, impersonators, automated attackers, and generic automation

  • Only 1% of bots are verified/wanted, with AI representing a small but high-impact subset

  • Bot traffic is unique to every business, industry, and region, JAPAC saw the least humans, the most unwanted bots, and the least wanted bots, while LATAM saw the opposite

Bottom line: Bots aren’t just part of your traffic; they’re shaping how your content is accessed, consumed, and exposed, and their presence comes with different impacts for every business.

----

AI isn’t just changing how people use the internet – it’s changing how the internet uses you. 

Behind the scenes, bots are now responsible for nearly half of all traffic across applications and APIs. But the real story isn’t just volume; it’s where bots are going, what they’re accessing, and how little visibility most organizations have into it.

In our latest Threats Insights Report, we analyzed trillions of requests across Fastly’s network to understand how bots interact with cached and origin content. What we found challenges some long-held assumptions about performance, cost, and control, and highlights why your bot strategy may need a serious reconsideration.

Nearly Half of Your Traffic Isn’t Human, and Most of it Isn’t Verifiable

In January 2026, bots accounted for 49% of all requests, nearly matching human traffic at 51%. That alone isn’t surprising, but this was: 99% of that bot traffic is unwanted or unverifiable.

These aren’t harmless crawlers, they’re:

  • Impersonating legitimate services

  • Scraping competitive intelligence

  • Probing for vulnerabilities

  • Automating attacks like account takeovers (ATO)

And because many of them attempt to disguise themselves as verified bots, organizations are often making policy decisions based on bad data. If you think you’re allowing “ChatGPT,” by looking at just their declared User Agent, for example, there’s a real chance you’re actually allowing bots pretending to be it too.

This is where most bot strategies break down. They stop at “is this a bot?” when the real question is: what is this bot doing – and should it be allowed to do it?

Your Most Valuable Content is More Exposed Than You Think

Cached content has typically been seen as low-risk. It’s faster, cheaper to deliver, and often overlooked from a security perspective. But nearly half of requests to cached content (47%) come from bots. That raises an important question: who is accessing your most visible and valuable content – and why.

For many organizations, that answer isn’t clear. Some of this activity may be expected. Some of it may be strategic. But without deeper visibility, it’s difficult to determine:

  • Which bots are creating value

  • Which are creating risk

  • And which should be allowed at all

Bots are Quietly Driving Up Infrastructure Costs

When bots move beyond cache, the impact shifts from visibility to cost. These requests hit your infrastructure directly, bypassing cache, increasing egress costs, and adding load where it matters most.

Not all of this traffic is malicious, but much of it is: low-value, redundant, and (potentially!) entirely unnecessary.

Without understanding the intent behind these requests, organizations are left absorbing the cost without understanding the tradeoff. The report found that 60% of all origin traffic is from bots, forcing organizations to understand what’s being accessed and the value derived from allowing it.

AI Bots: Small Slice, Outsized Impact

Everywhere you look, it’s there, AI. So we’d be remiss to not give it the attention it deserves. But our data has unearthed a bit of nuance to the (all-consuming) AI conversation.

Only 1% of bots are verified or “wanted”, and AI represents a subset of that traffic. Yet their influence is disproportionate. 

AI bots don’t just access content – they reshape how it's surfaced, summarized, and consumed. In some cases, they can decouple content from its original source entirely. One trend we highlight in the report: 57% of AI fetcher requests target non-cached content, often tied to real-time or highly specific queries.

What this Means: Bot Strategy is Now Business Strategy

Previously, bot management lived in the background, a security or infrastructure concern. That model doesn’t hold anymore. 

When bots account for half your traffic, drive the majority of origin load, and determine how your content is surfaced in AI systems, they stop being a technical edge case and start becoming a business variable. What our data makes clear is that the real shift isn’t just volume. It’s decision-making.

Every request now carries implicit questions:

  • Should this bot be allowed to access this content, and under what context?

  • What is the business impact if it does?

Most organizations can’t answer that question today. Not because they lack data, but because they lack the ability to connect bot identity with intent in a meaningful way.

That’s the gap. And it’s where strategy needs to evolve. 

Because in an AI-driven ecosystem, access is leverage. The bots you allow shape how your brand appears, how your data is used, and how your infrastructure is consumed – often long after the original request is made.

The organizations that adapt won’t be the ones that simply block more or allow more. They’ll be the ones that make deliberate, granular decisions about who gets access to what, and why.

Read the full Threat Insights Report to see how bot identity, intent, and access are redefining performance, cost, and control across the web and learn how you can respond.