Bots Have Taken Over the Internet. The Battle Is No Longer Between Humans and Machines
AI is lowering the barrier to entry for attackers, and the new era of bots is forcing the cybersecurity defense world to rethink machine-to-machine trust. Nadav Avital, CTO at Imperva, breaks down the changing rules of the game
More than half of internet traffic is no longer generated by humans. According to Thales’ Bad Bots in the Agentic Age report, automated traffic on the web surged in 2025 to 53% of total internet traffic, while human traffic dropped to 47%. At the same time, malicious bots – used for identity theft, fraud, and cyberattacks – already account for around 40% of all traffic, driven in part by a 12.5x surge in AI-powered attacks.
For Nadav Avital, AI & Application Security Field CTO at Imperva, a Thales company, this is not just another statistical data point, but a historic shift in how the internet operates.
“This is the first time we are seeing that more than half of internet traffic is no longer performed by people, but by automated systems,” he says. “This change affects everyone – users, organizations, and attackers alike. Artificial intelligence has completely changed the rules of the game.”
According to him, the most significant impact of AI is lowering the barrier to entry for attackers.
“In the past, you needed to be an expert with many years of experience to develop sophisticated attacks or build high-quality offensive tools. Today, even less experienced actors can create effective attacks using AI models. As a result, we are seeing more actors entering the arena, more AI-powered attacks, and significantly more malicious traffic reaching organizations.”
At first glance, if more attackers are also less skilled, one might expect the risk to decrease. In practice, the opposite is happening.
“Many of the attacks we see are still not the most sophisticated, but they create enormous load on organizations,” Avital explains. “Security systems have to handle much larger volumes of events, and defense teams need to go through all the alerts, understand what is critical and what is not, and prioritize. Even a relatively simple attack can become a major problem when it arrives at this scale.”
At the same time, attacks themselves are becoming more sophisticated.
“We are already seeing tools that mimic human behavior at a very high level, making them much harder to detect. One example is in e-commerce – buying tickets to popular events, limited-edition products, or high-demand items. Attackers automate the entire purchasing process, but in a way that looks almost identical to real user behavior.”
However, according to Avital, the real shift is still ahead – and it comes with the rise of artificial intelligence agents, or AI Agents.
“It’s not only attackers using AI. Organizations and individuals are also increasingly using autonomous agents that perform tasks for them – from screening CVs and procurement processes to handling emails and repetitive tasks.”
The challenge is that attackers are already aware of the potential.
“We see that the most sophisticated attackers, usually those with significant funding, are starting to target environments where AI agents operate. Once malicious activity blends into legitimate autonomous agent activity, it becomes much harder to detect.”
According to him, this represents a profound shift in security thinking.
“The challenge is no longer just distinguishing between a human and a bot. The question is how to manage trust between machines. If one agent communicates with another and performs actions automatically, how do you detect the moment when one of them starts behaving abnormally? That is where security is heading.”
This shift is also evident in modern state-level conflicts.
“Cyber has become an integral part of modern warfare,” Avital says. “We have seen it in Israel, in the Russia–Ukraine war, and in almost every major conflict.”
He explains that the accelerated digitalization of recent years has significantly expanded the attack surface.
“Today, far more critical services are available online – banking, healthcare, government systems, municipal services, and more. So when a country is attacked, one of the main goals is to disrupt the services citizens rely on. It is no longer just an attack on computers; it is an attack on a country’s ability to function.”
These dynamics were also evident during the recent escalation with Iran, where Imperva observed a sharp increase in DDoS attacks against Israeli organizations, along with attempts to disrupt financial systems and critical infrastructure.
In this reality, Avital emphasizes that the baseline assumption for organizations has not changed – but it has become more important than ever.
“You always need to start from the assumption that the organization has already been breached. That was true in the past, and it is even more true today. There is no single layer of defense that provides complete protection.”
This is exactly why the cybersecurity industry has relied for years on a layered defense model.