The dead internet theory has floated around internet forums since the 2010s, and the idea that the internet is dominated by non-human activity was often dismissed as a fringe conspiracy. Now it has become a measurable fact. Not only do multiple cybersecurity firms agree that bots outnumber humans online, they likewise are struggling to answer when the flip happened or what metrics to use to measure it.
CloudFlare, the Internet security and performance giant used by millions of websites worldwide, says the crossover occurred in June, with bots generating 57.5% of webpage requests. Thales, a French tech group that protects data security for organizations and governments, dates the crossover back to 2023, issuing a “Bad Bot Report” that put bot traffic at 53% in 2026.
The discrepancies reflect that there’s no one standard way to measure bot traffic, as no single provider has access to activity across the entire web, according to Rudy Yang, Pitchbook’s enterprise and retail fintech analyst who wrote the firm’s July report about agentic AI traffic.
“There’s a lot of missing pieces of information, but a lot of the observed data suggests the same thing, which is like there is more bot activity,” Yang told Fortune. “Agentic AI activity is driving a lot of the browser activity you’re seeing.”
The surge of agents is massive everywhere you look. Traffic generated by agents that actually take action on the web, like clicking links and filling out forms, grew 7,851% year over year, according to cybersecurity firm HUMAN Security’s 2026 State of AI Traffic & Cyberthreat Benchmark Report. Scraper traffic, by comparison, grew 597% over the same stretch, and AI training crawlers, while still 67.5% of AI-driven traffic, are a shrinking share of the total.
The timing caught even bot-watchers off guard. CloudFlare CEO Matthew Prince had predicted in March that bots wouldn’t cross the halfway mark until the end of 2027. Instead, the crossover arrived more than a year early.
“For companies and developers, this means that building for agent traffic will become nonnegotiable,” Yang wrote in the report.
The Internet’s business model—ad impressions, conversion funnels, pageview-based analytics— was built on the assumption that the visitor is a human being. If most of them are now agents, that assumption is upended and reshapes how companies monetize web traffic The same autonomy driving that agentic AI traffic is what let an OpenAI model slip its cage this week—meaning the volume surge is just the visible symptom of a shift businesses can neither fully measure nor, yet, fully control.
“They consume the web completely differently than humans do,” Yang told Fortune. “It’s almost like an entire new category, customer category, was created, and it means a lot for businesses because no one, as a business owner, is going to want to silo themselves from being able to serve a completely new customer segment.”
Change of strategy for the ‘machine economy’ and the limits of AI agents
Companies are noticing this shift, and developers have started adapting to this reality.
Stripe reported that 70% of its commands used to access data through an API are coming from agents. API brokerage firm Alpaca also noted that its monthly API calls grew from single digits in Q4 2025 to 30% in Q1 2026 driven by agents. In response, approximately 25% of developers now design APIs with agents as the primary end consumer rather than humans, and over half of them cite unauthorized agent access as a security concern.
Yang listed Visa, Ramp, Mercury, ElevenLabs, Stripe, Coinbase, MoonPay, and
DoorDash as companies that have launched command line interfaces (CLIs) – commands that retrieve data from an API – geared toward agents.
“As more companies launch agent-native CLIs, agents gain broader access to execute work, driving further adoption,” Yang wrote. “Companies will then build more agent-first infrastructure, accelerating the cycle.”
The issue is that bot-detection systems can only measure traffic that explicitly identifies itself as automated or trips a known signature, while agentic browsers that mimic human behavior patterns routinely slip past traditional filters. A recent academic study of bot-detection systems from the University of Bamberg found soft block rates of 7%-15% simply from detection systems misfiring on real traffic, let alone the reverse problem of agents undetected entirely. Seer Interactive, a digital marketing firm, has been warning clients since 2023 that agentic browsers can “inflate engagement, artificially depress bounce rates, and distort session duration” in ways standard analytics tools don’t catch.
Still, Yang is careful to note that what Pitchbook calls the “machine economy” remains small relative to the broader economy—for now.
The firm estimates only about 1% of the roughly $20 trillion in work that could plausibly be handed to AI agents is actually flowing through them today. A separate estimate from the startup Forsy puts total global “agent GDP”—economic value directly attributable to deployed agents—at $36 billion a year on a run-rate basis.
Yang told Fortune that AI agents can’t fully participate in the online economy yet because payments and liability aren’t solved.
“If we don’t have the infrastructure to do proper payments for agents, then agents aren’t buying and selling, and if agents aren’t buying and selling, then they aren’t generating economic activity,” Yang said.











