AI bots move from web scraping to user accounts
AI-powered bots are moving beyond simple web scraping and increasingly interacting with login pages, user accounts and sensitive areas of websites.
According to a new DataDome report, malicious bot traffic increased by 124% between July 2025 and June 2026. During the first half of 2026, AI bot requests to website login pages grew more than eightfold.
Web scraping was the fastest-growing threat, rising by 185% and accounting for nearly 71% of malicious bot traffic. The growing demand for data to train AI models, power AI agents and support research tools is one of the key drivers.
At the same time, AI is making bots more sophisticated. Modern agents can navigate websites, fill out forms, click buttons and adapt their behavior to what they encounter. This makes them harder to distinguish from legitimate users.
The biggest concern is the shift toward account-level access. Bots targeting login pages can potentially be used for credential stuffing, account takeover, session abuse and automated fraud.
This means businesses can no longer rely on a simple question: “Is this a human or a bot?”
Instead, security teams need to understand who or what is operating the agent, whether it is authorized, and what it is trying to do.
As AI agents become more autonomous, organizations will need to treat them as a new type of digital identity - with clearly defined permissions, monitoring and security controls.



