
Akamai just dropped a warning that feels less like a report and more like a digital smoke alarm going off across the industry. The company’s newest State of the Internet report points to a 300% spike in AI bot traffic over the past year — and the pace shows no signs of slowing. AI systems are scraping content, copying text, lifting images, training models, and hammering servers. All without paying a penny to the businesses creating that content.
Publishers, retailers, healthcare platforms, and every site that depends on users, ad impressions, and accurate data are feeling the pressure. One cybersecurity expert I spoke to shrugged and said, “If you thought ad fraud was bad, wait until the bots start training on your entire site in real time.” We just arrived at that moment.
A 300% Surge in Automated Traffic
AI bots now represent a rising share of traffic across Akamai’s platform. They stand at just under 1% of bot volume today, but that number masks volume at scale — billions of automated requests over a short window. And unlike old bot networks, these new ones act smarter, disguise their intent, and trigger scraping patterns that mimic normal users.
Old bots hit a site like a sledgehammer. These new ones pick the lock, slip in quietly, and empty the cupboards.
Industries Under Pressure
Publishing Takes the Hardest Hit
According to Akamai, the publishing industry sees 63% of AI bot triggers. That means newsrooms, blogs, and content operations are getting scraped aggressively. Original work flows out; traffic flows down; ad revenue drains as automated systems consume content without delivering page views.
It’s like running a restaurant where half the food goes out the back door before customers ever see the menu.
Commerce Under Attack
Retail sites logged more than 25 billion bot requests over just two months. Everything from pricing data to product listings gets scraped. Bots spoof shoppers. Fake activity clutters analytics dashboards. Conversion data turns muddy. Decisions based on false patterns lead to wasted spend and poor ad targeting.
In simpler terms: companies are paying to serve ads to ghosts.
Healthcare Scrapers Surge
More than 90% of AI bot activity in healthcare comes from scraping by search and training systems. Health information, guides, and research pages are being mined at volume. Sensitive industries face both security and ethical concerns — and once bad actors pair stolen medical data with AI-generated identity assets, fraud moves to a new tier.
The Fraud Tools in Play
Akamai highlights AI-generated attacker kits such as FraudGPT and WormGPT. These tools help criminals automate phishing campaigns, fake identities with AI-produced documents, and impersonate users at scale. And they don’t require a seasoned hacker to run them. A curious teenager could execute a scheme that once required an expert.
The digital threat landscape is flattening. Skill is no longer a barrier. The toolset does the heavy lifting.
Defensive Guidance
Akamai points to OWASP frameworks designed to protect web applications, APIs, and large language models. These resources help map weaknesses such as access control gaps, injection flaws, and data exposure risks. The report stresses linking security priorities with business tolerance — meaning security leaders need alignment with boardrooms, finance teams, and analytics groups.
The message: AI risk can’t sit only with the security team. Leadership needs a seat at the table, and fast.
Why It Matters
Akamai processes more than a third of global web traffic. When a company with that vantage point says AI bots are reshaping online behavior, businesses should listen. Web analytics distort. SEO (Search Engine Optimization) reporting loses accuracy. Content value erodes as models train on it without contributing referral traffic. Ad budgets waste funds on fake clicks and inflated user counts. Monitoring blind spots grow.
It feels like the early spam era all over again — only now the spam can think.
Rupesh Chokshi of Akamai said it plainly: “Business leaders must act now… or find themselves playing catch-up.” In other words, if companies don’t treat AI exploitation as a board-level issue today, they may end up filing risk reports after the damage is already public.
This is the kind of shift we talk about in digital forensics and SEO circles often. Web visibility depends on trust, quality, and real user patterns. If bot noise drowns those signals, the whole model cracks. It’s the equivalent of flooding an election with fake ballots — eventually the numbers stop meaning anything.
Akamai isn’t throwing cold water on AI. They’re saying control matters. Measurement matters. And scraping is now a business threat, not a hobbyist experiment.
Expect more bot controls, AI traffic filtering, LLM firewalls, and lawsuits over scraped content. The arms race has begun, and this time the attackers write code that learns as fast as the defenders do.
The internet has thrived on open access and shared data for decades. That era is hitting friction. The next phase demands authentication, content rights, and verification layers. Otherwise, businesses wake up one day and realize half their customers never existed — and the other half left when the site slowed to a crawl from bot overlords pulling data like it’s free produce at a street stand.
AI gives us incredible capability. It also gives adversaries scale. This report makes one thing clear: defense now requires smart controls, aligned leadership, and, frankly, a willingness to stop treating bots as background noise. They’re here, they’re learning, and they don’t sleep.