
Elon Musk has endorsed Cloudflare's forecast that AI agent traffic will vastly exceed human internet usage, calling the trend certain rather than uncertain. According to Cloudflare CFO Thomas Seifert, who made these remarks during the company's second-quarter earnings call, non-human traffic could reach 1,000 times human levels within 5 years. The crossover point arrived earlier than expected, with machine-generated traffic overtaking humans in May 2026, significantly ahead of Cloudflare's previous 2027 projection. Musk shared an article reporting Seifert's remarks, describing the trend as certain rather than a close call.
According to the Thales Bad Bot Report 2026, bots accounted for 53% of global internet traffic in 2025, marking the second consecutive year that automated traffic has outpaced human activity. The breakdown reveals that approximately 40% of all web traffic consists of bad or unverified bot activity, while only 13% comes from bots performing legitimate, verified tasks. This fundamental shift means platforms are no longer filtering occasional automated requests but attempting to identify human activity within an internet where automation has become the dominant source of traffic. The HUMAN Security 2026 State of AI Traffic report found automated traffic growing eight times faster than human activity, with monthly volumes of AI-driven traffic growing 187% from January to December 2025.
Search Engine Roundtable reported that Google has begun testing a prompt in Incognito mode asking users to sign in 'to verify you're a human and see more results.' The test appears specifically after users browse several pages of results, suggesting Google may be treating anonymous browsing itself as a weaker signal warranting additional verification. This development represents a shift from traditional behavior-based verification to identity-based authentication, as AI-powered bots can now mimic human behavior patterns that were previously reliable indicators of genuine users.
Bad bot traffic carries direct costs including server resource consumption and bandwidth usage that platforms would otherwise allocate to genuine users. Bots are primary tools behind credential stuffing, account takeovers, and fraudulent transactions, while retailers report bots used to hoard inventory and distort pricing signals. Publishers have moved to restrict AI crawlers and shift to licensing arrangements, as AI scraping allows systems to retrieve and repackage content directly, eliminating publisher visits, ad impressions, and subscription opportunities. The commercial dimension extends beyond security concerns to protecting revenue models that assume human engagement. According to ARK's projections, AI agents could account for nearly 25% of digital spending by 2030, up from about 2% in 2025, with agents facilitating roughly $8 trillion in online commerce by the end of the decade.
Anonymous browsing serves purposes beyond avoiding personalized advertising, including research by journalists, security investigations, product testing by developers, and privacy preferences of ordinary users. However, the shift toward identity-based verification suggests anonymous access may face additional friction while authenticated users receive faster or uninterrupted access. This development reflects the broader industry trend where platforms require mechanisms capable of distinguishing between people, trusted machines, and malicious automation as autonomous software becomes a routine participant in online activities. The Fastly data shows bots at 49% of January 2026 requests but flagged 99% of them as unwanted, highlighting the ongoing challenge of distinguishing legitimate from malicious automated traffic.