
A new report from Hydrolix, The State of AI Bots in 2026: Risk, Readiness, and Governance, which is based on a survey of 300 enterprise leaders across IT security, engineering, infrastructure, and site reliability engineering, shows a significant gap between perception and reality when it comes to AI bot detection and readiness. While seventy-nine percent of respondents said they can detect bot activity on their networks, only 23% have a proactive strategy in place to do anything about it. That 56-point gap is a central finding in the report because it shows that companies are not as ready as they think to detect, manage, and mitigate AI bots.
Part of what makes the detection gap so vast is that most organizations cannot separate human vs. nonhuman traffic. Survey respondents estimated that AI bots generate roughly 17% of their traffic. That’s a much lower percentage than in most industry reports. According to Imperva's 2026 Bad Bot Report, automated traffic accounted for more than 53% of all web traffic last year, with malicious bots alone making up 40% of that. The difference in the findings shows that companies still can’t see all of their bot traffic, despite thinking they can.
"When we look at traffic logs alongside the security incident data, adversarial bots and legitimate automation are increasingly showing up as identical," said Simon Ouderkirk, VP of Product at Hydrolix. "The old model of flagging what 'looks wrong' is failing because these bots are designed blend in. They're built to look exactly like your best customers."
Modern AI bots can rotate identities, adapt in real time, and defeat most CAPTCHA variants with near-perfect accuracy. Researchers have documented credential-based attacks growing at triple-digit rates year over year. But perhaps the more disorienting shift is that bots aren't just bad actors anymore.
More than half of survey respondents rely on bots for uptime monitoring. Nearly as many use automated agents for SEO. Others depend on them for analytics, performance testing, and operational tasks that would otherwise require significant human hours.
This matters because it changes the "block all bots" strategy. A machete-like approach isn't an option when your own infrastructure depends on automation to function. The question has shifted from whether to block bots to whether you can tell the difference between the ones benefiting you and the ones working against you.
Currently, only 23% of enterprises report they can't reliably make that distinction at all.
Dr. Chase Cunningham, the cybersecurity strategist known as "Dr. Zero Trust," has been making this argument for a while. "Zero trust has always been about verifying identity before granting access," he said. "That principle doesn't change just because the actor is a bot. AI-driven bots require the same authentication, authorization, and continuous verification you'd expect from human users because they're faster, more persistent, and harder to distinguish from legitimate traffic."
What's less discussed is the cost dimension. Bot traffic that bypasses perimeter controls and reaches origin infrastructure drives up cloud and network provider bills in ways that don't show up on a security dashboard. They show up on a finance report, months later, attached to a spike no one can explain.
"Unwanted bot traffic is no longer just a security problem," Cunningham said. "It's a six-figure infrastructure and revenue problem that AI is only accelerating."
A classification problem sits at the root of most of this.
Existing detection tools are built to raise flags. They aren’t designed to explain what's actually happening. They can tell you the “what,” such as that traffic spiked. They can't tell you the “why” such as whether the crawler generating those spikes is training a competitor's AI model on your content, probing for vulnerabilities, or indexing your site for a search engine that's about to send you qualified leads. Only 33% of respondents said their WAF or bot detection solution blocked more than 50% of AI bot traffic in the last 12 months. And for most of those who did block traffic, it wasn't clear whether what they blocked was harmful.
The Hydrolix report frames this as a governance question. The organizations closing the readiness gap aren't necessarily spending more. They're operating with an understanding that bot management is something that requires understanding intent, not just volume.
"You're flying blind if you're only looking at whether traffic is human or not," Ouderkirk said. "You need to understand what that traffic is trying to accomplish. A legitimate crawler that's hammering your origin server is a cost problem even if it has no malicious intent. An adversarial bot operating within normal behavioral bounds is a security problem even if it never triggers an alert."
Forty percent of survey respondents cited budget constraints as a barrier. Thirty percent pointed to fragmented systems and insufficient visibility. Another 27% said they were simply overwhelmed by telemetry volume: too much data, not enough context.
That last problem is worth diving deeper into. The answer to too much data is rarely more alerts.
What the research doesn't answer is which of these risks is the most urgent for any given organization, and that depends on industry, infrastructure, and what bots are already in your environment. A media company worried about content scraping for AI training has a different problem than a financial services firm dealing with credential stuffing. Both are real but require different responses.
The full report maps the readiness gaps by organization type and outlines what a governance-led approach to bot management actually requires.

