IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
Security leaders warn as AI bot traffic overtakes humans

Security leaders warn as AI bot traffic overtakes humans

Fri, 31st Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Cloudflare reports that automated bot activity has overtaken human traffic on the internet. Security experts say the same automation trend is beginning to shape both cyber risk and everyday digital services.

Cloudflare Radar data shows bot traffic now accounts for most global web requests. The finding came earlier than some industry forecasts and highlights the growing volume of agentic artificial intelligence tools acting online without direct human input.

Pat Breen, Head of ANZ at Cloudflare, said organisations can no longer assume traffic growth reflects human interest or commercial demand. As autonomous systems generate more of the load handled by websites and applications, marketing metrics, infrastructure spending, and security models all come under pressure.

"Cloudflare Radar (https://t.co/2zX5bHdhsa) recently recorded a critical milestone ahead of schedule: internet bot traffic has officially surpassed human traffic. This does not merely represent an increase in volume, but a fundamental shift towards the agentic web. While bots have long supported human web traffic, agentic AI introduces autonomous actors that make decisions and execute actions at scale. For businesses, this challenges the traditional relationship between conversion rates and customer acquisition cost. These calculations are now being skewed by machine demand that may not generate commercial value. Traffic also risks becoming an infrastructure liability, inflating compute and bandwidth costs, distorting underlying business metrics, and ultimately affecting bottom-line results. Security and platform teams must move beyond reactive bot blocking to proactive 'Traffic Integrity'. This requires a robust framework to distinguish high-value automation from the noise of agentic discovery and malicious scraping." said Pat Breen, Head of ANZ at Cloudflare.

The rise of agentic traffic comes as governments and businesses face a parallel surge in AI-driven fraud and credential theft. In Australia, the next national Census is expected to rely heavily on online responses, increasing the scope for phishing campaigns that imitate official digital channels.

Yubico warns that many citizens may struggle to distinguish genuine government websites from synthetic phishing sites generated by AI. It argues that design-level security and stronger authentication matter more than user vigilance when people are disclosing sensitive data.

The guidance recommends phishing-resistant methods such as passkeys and hardware security keys, which bind the login process to a verified service. It also stresses basic digital hygiene, including navigating directly to known web addresses, treating urgent Census-themed messages with caution, and using up-to-date personal devices rather than shared computers.

These cloud trends and public-service risks are converging with a third development in the security landscape. The latest incident involving Anthropic's AI testing has renewed scrutiny of how autonomous agents behave once they can probe live infrastructure.

According to Arctic Wolf, a cybersecurity and AI company, the episode shows that long-standing weaknesses, not exotic new techniques, are giving automated agents room to move.

"This second breach confirms what security teams feared: the Hugging Face incident was not a one-off, but a preview of how far an autonomous agent can travel once it is off the leash. This is now a demonstrated AI capability, no longer a hypothetical risk," said Dan Schiappa, President of Technology and Services at Arctic Wolf.

"What's notable here is not the AI's sophistication, but the mundane opening it walked through. An unauthenticated, internet-facing endpoint let anyone run code inside a sandbox. That is a basic exposure that has appeared on pen-test reports for a decade, not a novel AI attack technique. The agent was not clever. It just needed a gap that should already have been closed," said Schiappa.

"The real warning for security leaders is that attacker autonomy will keep improving, but the entry points it exploits will remain the same ones organisations already know about: exposed endpoints, excess permissions, and infrastructure that nobody is watching closely enough. Security hygiene is more important than ever because, if you have a weak spot, AI will find it. Defenders do not need to out-innovate the AI. The best defence against increasingly autonomous threats is a resilient security operation that can rapidly identify exposure, detect attacks early, and take action," said Schiappa.