Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityLogical Security

Organizations Think They Know Who’s Visiting Their Sites. They Don’t.

By Marshall Erwin
Colorful laptop
Sharad Bhat via Unsplash
June 12, 2026

AI is reshaping the internet in real-time. Every day, internet users are getting information faster than ever as they incorporate AI-powered chatbots and search summaries into their daily lives. As large-language model (LLM) based applications like ChatGPT and Claude continue to advance, these apps, which require online content to pull from, strain networks with AI scrapers and introduce performance, security, and cost challenges for companies. 

Today’s bots have gotten very good at blending in — and that’s not an accident. For years, bots have been part of how the internet operates, whether it’s helping users find content or quietly powering workflows in the background. What’s changed is the scale and the stakes, with recent research revealing that AI bots account for nearly half of web traffic, 99% of which sit in an unverifiable ‘gray area.’

Bots can pretend to be real users, posing risks ranging from fraud to account takeovers. These bots carry out nefarious activities under the guise of legitimate web traffic, which can impact business decisions due to false bot traffic insights. 

The Bot Impersonation Problem

Unwanted bots are routinely disguising themselves as trusted and legitimate services to slip past policy controls that were designed with good bots in mind. Organizations believe they’re letting in known, good bots when they’re actually granting access to bots that are impersonating well-known and verifiable bots.

The consequences of bot impersonation are surfacing across every industry, impacting publishing, e-commerce, and beyond. The publishing industry is navigating new infrastructure and operational challenges as bots shift their operating model. Publishers create content through a business model that is reliant on revenue generated through clicks. As AI bots consume and scrape publishers’ content, the original content can be served directly through an LLM, which means publishers lose out on the desired traffic and revenue from users. In e-commerce, bots can simulate human behavior, from cart activity to product page visits. Automated traffic distorts genuine customer journeys and conversion metrics, making it harder for businesses to accurately measure demand and optimize spend. Across industries, AI-driven bot traffic is fundamentally shifting how companies operate and make business decisions.

Ghost Traffic Has Real Costs

Without understanding the intent behind bot requests, organizations absorb the cost and risks associated with unwanted bot scrapers. AI bot scrapers can lead to massive, unwanted, and unplanned spikes in traffic. This can degrade performance and experiences for legitimate users and result in bandwidth overage charges for organizations across industries, as their infrastructure is typically built to manage human traffic spikes. 

The costs and risks associated with AI content scraping can quickly skyrocket if left unchecked. It is difficult to pinpoint and mitigate specific AI scraper activity, even with traditional bot detection strategies. Security and IT teams need to be able to detect and identify the presence of bots before they either block them or launch more sophisticated countermeasures to intercept or enforce monetization. This unwanted bot traffic does not provide real value to the business, and instead drains it with little visibility into what organizations are actually paying for. 

Assess Bots by Behavior, Not Identity

Understanding bot behavior is no longer just about defense, and requires more than a broad assessment that asks “is it a bot?”. It’s about making and demanding strategic business decisions that protect your networks, while still allowing your business to be agile. As bots increasingly use machine learning to mimic human behavioral patterns to bypass traditional defenses, organizations need to consider how bots are interacting with their website or application. 

This is where bot behavioral analysis comes in. This method includes analyzing user behavior patterns to identify and distinguish between human users and bots. Bots are more likely to exhibit unusual or suspicious activities, including uniform browsing patterns, rapid page requests, or unusual click patterns. 

Analyzing this type of behavior empowers organizations to make decisions grounded in what is actually happening at the tactical level by examining access patterns and request cadence. This approach does not assume all unverified bots are hostile, but instead seeks to understand a bot’s intent to better inform decisions. With this context, organizations are able to protect content, control costs, and maintain data integrity with confidence. 

Adapting in the Era of AI

Bots aren’t a niche security problem anymore. They’re embedded in how your content gets consumed, how your infrastructure gets taxed, and how your brand gets represented online. The organizations that recognize this and build a real strategy around it will be in a fundamentally better position than those still treating bot traffic as a background concern.

KEYWORDS: botnets bots brand protection online online security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Marshall erwin headshot

Marshall Erwin is CISO at Fastly. Image courtesy of Erwin

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

American flag lit with people

Protecting America’s Critical Infrastructure: A Shared Responsibility in an Era of Escalating Cyber Threats

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

5 Minutes with Johnson

Can Organizations Trust Their Own AI?


AlertMedia sponsored webinar

Events

September 22, 2026

How to Detect, Verify, and Respond to AI-Driven Disinformation

LIVE: September 22, 2026 at 2 PM EDT Identify emerging threats, validate information with confidence, and coordinate an effective response across your organization. Learn how to build the people, processes, and technology needed to improve speed-to-truth.

September 24, 2026

Physical Security Under the Microscope: The Top 4 Gaps That Fail Compliance Audits

LIVE: September 24, 2026 at 2 PM EDT Security and compliance reviews of physical security devices tend to fail for the same reasons. Learn the gaps that trip up these reviews, and why they're getting harder to ignore as scrutiny on connected devices increase. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Who's Visiting the Facility?

    See More
  • Identification: Who’s Visiting? And Why?

    See More
  • Face mask pandemic

    Survey finds most COVID-19 patients don't know who infected them

    See More

Related Products

See More Products
  • 150 things.jpg

    Physical Security: 150 Things You Should Know 2nd Edition

  • CPTED.jpg

    CPTED and Traditional Security Countermeasures: 150 Things You Should Know

  • contemporary.jpg

    Contemporary Security Management, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing