Industry Impact2 min read

AI Agent Traffic to Websites Grew 7,851% in 2025

By , Senior AI ConsultantPublished

AI agent traffic to websites grew 7,851 percent in 2025, and businesses that simply block this traffic risk turning away real customers along with attackers.

Something changed on company websites in the past year that most business owners have not noticed. A growing share of the traffic hitting product pages, search bars, and checkout screens is not people anymore. It is software acting on people's behalf.

The security firm HUMAN tracked more than a quadrillion web interactions in 2025 and found that traffic from AI agents grew 7,851 percent in a single year, with all automated traffic growing eight times faster than human traffic. That is not a niche trend. It is a structural shift in who, or what, is visiting a business online.

Most of this traffic is not buying yet. Roughly 79 percent of agent activity is concentrated on product and search pages, while only about 2 percent reaches checkout, according to HUMAN's tracking. Agents are currently doing the research: comparing prices, reading product details, checking what is in stock. The actual purchases are still mostly done by humans, but that gap is closing, and by the time it closes, whoever has figured out how to handle this traffic will already have an advantage.

The instinct for most security teams is to block anything that looks automated, and that instinct is not unreasonable. Attacks disguised as bots are real: scraper attacks grew 597 percent in the same period, and account takeover attempts on retail sites quadrupled. But blocking everything punishes real customers along with attackers, because a shopping agent and a scraping attack often look the same from the outside. HUMAN's own data shows the share of agent traffic getting blocked roughly tripled in a single month, mostly without any real policy behind the decision, just an old reflex applied to a new kind of visitor.

The harder problem underneath all of this is proving who an agent belongs to. Right now, if an AI agent shows up on a website, there is no reliable way to know whether it is a real customer's shopping assistant or a competitor's scraper. That proof cannot really be built by individual businesses. It has to come from the companies that build the agents in the first place, meaning OpenAI, Anthropic, Google, and similar firms, along with the browsers and payment networks that route agent activity.

This is already starting to happen. Visa launched a Trusted Agent Protocol in October 2025 specifically to help merchants tell legitimate shopping agents apart from bots, and Google, Mastercard, PayPal, and others have built similar agent-payment systems over the same period. A technical standard called Web Bot Auth, backed by OpenAI, Cloudflare, Amazon, and Akamai, lets websites cryptographically verify a bot's identity rather than guessing from behavior alone. None of this is finished, but the direction is clear: trust in agent traffic will be vouched for by large platforms, the same way certificate authorities and app stores built trust for earlier waves of the internet.

Meanwhile, most companies have not even assigned anyone to watch this. Surveyed marketers were split on who owns AI agent traffic: some said analytics teams, some said nobody, and almost none said security. That is the real gap right now, not a missing piece of technology, but a missing meeting. Any business running a website, whether it sells steel beams, insurance policies, or vacation packages, now has automated visitors that its existing tools were not built to recognize. Figuring out who owns that problem internally is the first step, and it costs nothing but a meeting to start.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable