Build1 publisher2 min readPublished
DataDome's threat research VP puts AI login traffic at 1.08 percent of classified requests
The 51.7 percent in DataDome's 2026 bot report is login's share of five sensitive endpoint types, and Jerome Segura told Lets Data Science the same 313 million requests work out to about 1.08 percent of the 29.02 billion requests the company could classify by path.
The Engineer · Build desk

What happened
- DataDome's VP of threat research, Jerome Segura, told Lets Data Science in writing that login pages took just over half of the AI requests aimed at one selected group of sensitive endpoints. The denominator is that group, not all AI traffic in the analysis.
- Of the first-half 2026 AI requests DataDome could classify by path, 605.6 million, or about 2.1 percent, reached endpoints it labels high risk: login, forms, cart, payment and account creation.
- The report also states approximately 124 percent growth in traffic DataDome classified as bad bots across the 12-month study period.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Anyone budgeting bot defense from the login share now has to say which denominator it is a share of, since the two true readings differ by about 48 times in the volume they imply.
- constraint Because a deliberate allow and a missing defense look identical to the scan, the 65.3 percent cannot support any conclusion about the login or API surfaces of the sites tested.
- exposure Lets Data Science had to ask DataDome to reconcile its supplied release wording with the report's endpoint analysis, so anyone who quoted the release already has the looser share in their slides.
- precedent Segura putting the absence of a filtering-controlled comparison on the record gives buyers one specific question to put to every vendor's year-over-year bot growth number.
Two denominators are in play. Some 630 million requests separate them. The report gives a first-half 2026 AI total of 29.65 billion requests [6]. The endpoint analysis runs on 29.02 billion, the subset with enough path-level data to classify [3]. Segura said the difference reflects scope, not an additional category of attacks [7]. Subtract one from the other and the excluded remainder comes to about 630 million requests [1], which exceeds the entire high-risk group by roughly 24 million [5].
Inside that group, login took 313 million requests [5]. Forms, cart, payment and account creation divide 292.6 million between them [4]. "Worked through fully, login traffic is about 1.08% of total AI requests," Segura told Lets Data Science [17]. Both percentages describe the same requests while answering different questions [5]. Quote the 51.7 percent as a share of all AI traffic and you overstate login volume by about 48 times [2].
For 1.08 percent to say anything about a particular site, that site's traffic would have to resemble what DataDome observed across more than 75,000 customer sites and over a trillion requests between July 2025 and June 2026 [2]. Its login paths would also have to be legible to the same path-level classification that excluded 630 million requests [3][1]. The counts are requests. DataDome does not report confirmed account compromises, and reaching a login page does not establish malicious intent, stolen credentials or successful access [8]. An agent hitting a login endpoint may be running an authorized task, and knowing that a request is automated does not tell the operator which case it is [18].
The homepage scan is a different instrument. About 14,030 of the tested homepages fell into the unprotected bucket [3], because none of the ten request types drew an observable block or challenge [10]. Segura said the test cannot separate a site with no bot management from one that intentionally permits crawling or one that logs bots without blocking them [11]. "This test also only covers homepages, not login pages or APIs, so it can't establish anything about the security of those surfaces for the 21,491 sites tested," he said [12]. The login-page findings come from the customer-traffic dataset, not from this scan [13].
Lets Data Science also asked whether the growth comparison held customer sites and upstream filtering consistent. "For the 124% bad-bot figure: no same-customer, filtering-controlled comparison exists, and we don't disclose whether the customer base and their sites were stable or changed over the 12 months," Segura said [14]. The supplied evidence therefore does not separate changing activity at the same sites from changes in which sites the dataset represents [16].
What to watch
- Whether DataDome publishes a same-customer, filtering-controlled version of the 124 percent bad-bot growth figure.
- Whether the next edition breaks the high-risk endpoint counts out by class so login can be compared with payment and account creation.
- Whether the public-site test is extended beyond homepages to login endpoints and APIs.