Rise of the Bots: AI-Driven Automated Attacks at Scale
By Nick Kelly, Senior Security Solutions Architect
Most of the traffic hitting your network isn’t human anymore.
As AI gets widely adopted, jokes and memes about the robot uprising are everywhere. Even before we witness the inevitable takeover by our future robot overlords, we should recognize that bots have already taken over the internet.
In 2025, bots generated 53% of all internet traffic – the second straight year machines outpaced people. More striking: 40% of all traffic came from malicious bots, up from 37% the year before. That means two out of every five requests to your applications are hostile by design. [1]
The volume is only half the story. AI-driven bot attacks jumped 12.5x last year. Daily blocked AI-driven requests climbed from 2 million to 25 million. And the United States absorbed 59% of global bot attacks. [1]
Not all bots are bad, and that’s the problem
Bots are just software built to repeat a task. Plenty of them are useful:
- Search crawlers that index your pages so customers can find you
- Chatbots that answer questions and route service requests
- Monitoring tools that have watched uptime and connectivity for decades [2]
Others perform much more malicious activity:
- DDoS bots that overwhelm systems until they fail
- Scrapers that lift content, pricing, and customer data
- Credential stuffing bots that brute-force their way into user accounts [3]
What effective defense actually looks like
Protecting your users, data, and systems from malicious bots requires components to an organization’s risk acceptance. This is similar to considerations for traffic generated by bad actors, but at a much higher rate of proliferation. Widespread adoption of Generative AI tools means that this acceleration of traffic generated by automated applications will only continue to grow.
Organizations must engage people, processes, and technology when addressing threats at the scale generated by bots. Leveraging role-based, contextual human risk management is an excellent first step to building a level of understanding and awareness for users.
People: train for the risk each user actually carries
Blanket security awareness training doesn’t move the needle when threats are this targeted. Role-based, contextual human risk management does.
The approach combines security awareness training, phishing simulations, and both informal resources and formal evaluations then uses human risk intelligence to:
- Assess employee behavior in real business context
- Segment users by role, data access, behavior, and threat exposure
- Deploy targeted interventions: short videos and in-the-moment coaching to the groups actually at risk
The result is a training program that spends its effort where exposure is highest, rather than spreading it evenly across an org chart.
Process: your acceptable use policy needs an AI section
Most acceptable use policies were written before generative AI was on anyone’s desktop. Extend yours to cover: [4]
- Data classification and privacy: what can and cannot be entered into an AI tool
- Sanctioned tools only: an approved list, and a path to request additions
- Human oversight: required review of AI-generated content before it ships
- Transparent disclosure: when AI was used, say so
- Ethical use standards: written down, not assumed
A policy nobody can find won’t help. Pair it with the training above so people encounter the rules where they work.
Technology: see the traffic before you try to control it
You cannot govern what you cannot track. Core capabilities include:
- Visibility and classification of every bot and AI agent touching your environment
- Traffic inspection, device fingerprinting, and behavioral analysis to judge intent, not just identity
- Least-privilege access for automated identities, the same as human ones
- Rate limiting to cap request volume from any single source
- Multi-factor authentication wherever AI tools are in use
- Data loss prevention on outbound traffic, to keep sensitive data and IP from leaving in a prompt
- Prompt review to limit prompt injection and manipulation of AI agents
- Human-led input validation built into your development and iteration cycles as a checkpoint
Bots are generating traffic at a scale that greatly outpaces human detection. Organizations need to consider automating defenses. The first step is visibility into the traffic profile of the organization. An AI Assessment is an excellent first step to provide visibility and to inventory and prioritize response actions around automated traffic. It surfaces:
- How many AI apps are in use across the organization
- Which identities are exposed to those apps, or being targeted through them
- Which apps are already blocked, and which could be controlled through technical policy
- Where shadow AI is operating outside IT’s line of sight
Establishing a baseline of traffic allows security teams to identify anomalous and unusual patterns. Reducing the manual processes administrators must perform by accessing siloed tools can also help reduce the mean-time-to-response (MTTR).
Talk to Aspire
Aspire delivers AI Assessments that give IT and security leaders a clear inventory of AI activity in their environment, plus a structured, prioritized roadmap to close the gaps it uncovers.
Schedule a 30-minute conversation to walk through what an assessment would surface in your organization.
—
Sources
1. Thales Group. (2026). 2026 Bad Bot Report: Bad Bots in the Agentic Age. https://cpl.thalesgroup.com/sites/default/files/content/campaigns/badbot/2026-thales-bad-bot-report.pdf
2. Siddiqui, L. & Dunn, S. (8 Sep 2025). A Guide to Bots: Good vs. Bad Bots, Common Types, and Online Safety in 2026. Splunk Blogs. https://www.splunk.com/en_us/blog/learn/bots-types.html
3. N.A. (2026). Credential Stuffing Overview. Fortinet. https://www.fortinet.com/resources/cyberglossary/credential-stuffing
4. N.A. (1 Apr 2025). Artificial Intelligence Acceptable Use Policy. Security Industry Association. https://www.securityindustry.org/about-sia/bylaws-policies-and-rules/artificial-intelligence-acceptable-use-policy/