Skip to content

Product1 publisher3 min readPublished

Login pages draw eight times the AI bot traffic they did last year

Automated traffic is now aimed at the screens where customers sign in and pay, and DataDome's year of request data shows how concentrated that pressure has become. Filtering it means deciding which humans get let in too.

The Product Desk · Product desk

Illustration accompanying Login pages draw eight times the AI bot traffic they did last year

What happened

  • AI bots reached login pages at eight times the rate recorded in the 2025 edition, while scraping rose more than 185% and bot-driven scalping ran at nearly three times the previous year's pace.
  • Of 20,000 websites DataDome tested, 65.3% had no protection against any of the 10 bot types in the study, and 2.4% were fully protected, down from 2.8% last year and 8.4% in 2024.
  • DataDome counted 52.7 billion crawler requests from AI agents and LLMs, with more than 46% coming from Meta-affiliated systems and nearly 35% from OpenAI.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision The filter now runs on login forms, account creation, carts and payment endpoints, so the block rules need sign-off from whoever answers for conversion on those screens as well as whoever owns the WAF.
  • cost A bad rule costs money twice: customers who are wrongly stopped call support, and abuse that gets through arrives later as fraud, chargebacks and refunds.
  • constraint DataDome's Segura argues static identity-based controls are no longer sufficient. A per-request judgement made at runtime needs a policy on which automation is welcome, written before the traffic arrives.
  • exposure A site can have bought bot protection and still fail this test, because coverage is counted per bot type. The gap sits at whichever endpoint the vendor was never pointed at.

A bot control on a homepage can be wrong all day and nobody files a ticket. Put the same control on the login form and it is deciding which customers get into their own accounts. Jerome Segura, VP of threat research at DataDome, said: "Automated traffic isn't just a volume problem at the edge of the internet anymore. It's growing fast, and it's going deeper: into the login, account, and transaction flows at the center of the customer journey." [8]

DataDome measured requests. Segura's list of endpoints tells you whose screens the control lands on, and each of those screens has someone answering for its conversion rate: "Login pages, account-creation flows, carts, and payment end points connect directly to customer accounts, personal information, inventory, promotions, and transactions," he said [15].

Bad automated traffic grew 124% in the twelve months to June, which DataDome puts at nine times the growth rate of human traffic [1][2]. Work back from those two figures and human traffic grew about 14% [1]. Humans still sent 73.4% of the requests DataDome saw across its customer sites, leaving automation at 26.6% [19][2]. Cloudflare's data put bots at 57.4% of web traffic and 62.5% since [18]. The gap between the two readings is a sampling one: DataDome is counting traffic on sites that are its customers [4].

The company detected 52.7 billion crawler requests from AI agents and LLMs during the period, more than 46% of them from Meta-affiliated systems and nearly 35% from OpenAI [10][11][12]. Those shares add to about 81%, or roughly 42.7 billion requests [3]. Allowing or blocking AI crawling is mostly a decision about those two operators.

Of the 20,000 sites DataDome tested, 65.3% had no protection against any of the 10 bot types in the study, and 2.4% were protected against all of them [13][14]. That leaves about 32.3% partly covered [4]. Full protection has fallen two years running, from 8.4% in 2024 to 2.8% last year to 2.4% now, six percentage points in total [14][5]. The test is DataDome's own, against bot types it chose.

Scalping bots ran at nearly three times the previous year's pace [6]. Ted Miracco, chief executive of the cloud software platform Approov, said: "Scalping turns a company's best customers into its angriest ones." [17]

Segura said the challenge is "no longer simply identifying automation; it is determining whether that activity is beneficial or harmful" [9]. Sort your traffic on two axes, automated or human, wanted or unwanted, and then do it once per endpoint: login, account creation, cart, payment. Most teams can fill in three cells and stall on the fourth, the automated traffic they want and have no way to recognise. Tighten the login check and some genuine sign-ins fail; loosen it and credential testing reaches the account [15]. DataDome's login figures count attempts, not successful attacks, so they cannot tell you how many accounts were lost [16].

What to watch

  • Whether the next edition of the report shows full protection falling below 2.4% for a third straight year.
  • Any vendor or retailer data on successful account takeovers as well as attempted logins.
  • Whether Meta or OpenAI offers site owners crawling terms that turn the allowlist into a commercial deal.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories