Bot Traffic Statistics 2026: How Much of the Web Is Bots? (August 2026 Update)
Live Cloudflare Radar data: bots are 34.9% of web traffic, Meta retook the #2 operator slot as Anthropic slid to 10.5%, and human traffic has a weekly rhythm bots can't fake.
Published •Updated •46 min read

Updated August 1, 2026 with July 2026 data. The June and July editions of this report are preserved below, annotated where the new data supersedes them.
Anthropic is no longer the web's #2 bot operator. Meta took the slot back over the course of July. On Cloudflare Radar's trailing 28 days Anthropic runs 10.53% of verified-bot requests against Meta's 15.01%, down from the 13.2% this report published in June. The headline share barely moved: bots are 34.94% of all web traffic and humans 65.06%. Source: Cloudflare Radar — radar/bots/summary/bot_operator and radar/http/summary/bot_class, 28d (2026-07-04 to 2026-08-01). Pulled 2026-08-01.
One AI company now out-crawls every rival relative to what it gives back: Anthropic reads roughly 4,580 pages for every visitor it refers (28-day window ending June 22, 2026; it reads 1,782 on the trailing 28 days as of August 1). Overall, bots make up 35.2% of all web traffic as of June 2026, with humans still the majority at 64.8%, according to Cloudflare Radar. Other estimates exceed 50%, explained below.

Last updated July 2026. This refresh verifies the June figures against the full Q2 quarter and adds a year-over-year view (2025 vs 2026).
These figures come from data we pulled from Cloudflare Radar on June 22, 2026, and re-pull on publish. As a team that runs crawlers across more than 50 million domains every month, we read other operators' crawl behavior directly in this data. The pattern that jumps out isn't the headline percentage. It's who is doing the crawling, and how little they return.
What July 2026 Changed
The "(August 2026 Update)" in the title is a publish stamp. It says when we re-pulled. The data in this section covers July 2026, and it is layered on top of the June and July editions rather than replacing them.
The bot share held. The operator league did not. Across calendar July 2026, bots were 34.75% of all web traffic against 34.79% in June, a month of no movement at all. Over the same month Anthropic's share of verified-bot requests fell from 12.69% to 10.97% while Meta's climbed from 12.77% to 14.60%, which swapped the #2 and #3 slots. Source: Cloudflare Radar — radar/http/summary/bot_class and radar/bots/summary/bot_operator, calendar months (2026-06-01 to 2026-06-30 and 2026-07-01 to 2026-07-31). Pulled 2026-08-01.
The table below uses whole calendar months at both ends, so the month-over-month and year-over-year columns are measured on the same-length window. That is a different window type from the rolling 7-day and 28-day figures quoted elsewhere in this report, and the two are not interchangeable.
| Metric (calendar month) | July 2025 | June 2026 | July 2026 | Month over month | Year over year |
|---|---|---|---|---|---|
| Bot share of all web traffic | 30.76% | 34.79% | 34.75% | −0.04pt | +3.98pt |
| Crawler requests blocked (4xx) | 14.04% | 36.47% | 35.79% | −0.68pt | +21.75pt |
| Crawler requests served (2xx) | 73.50% | 47.23% | 47.66% | +0.43pt | −25.84pt |
| Google share of verified-bot requests | 38.71% | 28.24% | 27.05% | −1.19pt | −11.66pt |
| Meta share of verified-bot requests | 17.94% | 12.77% | 14.60% | +1.83pt | −3.34pt |
| Anthropic share of verified-bot requests | below 1.80% | 12.69% | 10.97% | −1.72pt | +9.2pt or more |
| AI crawling for model training | 35.74% | 47.25% | 44.54% | −2.70pt | +8.80pt |
Sources: radar/http/summary/bot_class, radar/bots/crawlers/summary/response_status_category, radar/bots/summary/bot_operator, radar/ai/bots/summary/crawl_purpose. Calendar-month windows 2025-07-01 to 2025-07-31, 2026-06-01 to 2026-06-30, and 2026-07-01 to 2026-07-31. Pulled 2026-08-01.
One cell needs explaining rather than a number. Anthropic does not appear in Cloudflare's top nine bot operators for July 2025 at all. The ninth entry that month is Huawei at 1.80%, so all we can honestly say is that Anthropic sat somewhere below 1.80% and is at 10.97% now, a year-over-year gain of at least 9.2 points. We have not filled in a figure Cloudflare doesn't publish.
Anthropic's slide is five weeks long, not one bad week
A single monthly number can hide a spike. This one doesn't. Weekly buckets inside the trailing 28-day window read 12.94%, 11.82%, 10.63%, 9.65%, 9.46% for Anthropic, falling in every bucket. Meta's read the other way over the same weeks: 12.69%, 13.05%, 14.49%, 16.47%, 16.73%. Google held flat near 27% throughout, so this is not the whole table being rescaled by one operator's surge. Source: Cloudflare Radar — radar/bots/timeseries_groups/bot_operator, 28d weekly (2026-06-29 to 2026-07-27). Pulled 2026-08-01.
On the shortest rolling window this report uses, the 7 days to August 1, Anthropic is down to 9.45% and Meta up to 16.79%. Both directions hold on every window we checked.
We cross-checked the two headline figures against a second endpoint before publishing them. The daily bot-share series averages 34.96% over the trailing 28 days against the summary endpoint's 34.94%, and the weekly crawler-response series averages 35.87% for 4xx against the summary's 35.86%. Both agree to within a rounding step.
What held unchanged
Most of this report survived July intact, which is worth stating as plainly as the parts that moved.
- Bot share. 35.2% in the June 7-day pull, 34.94% on the trailing 28 days now. Humans are still the majority either way.
- The block rate. 36.9% of crawler requests got a 4xx in June; 35.86% do now, and the most recent weekly bucket reads 37.10%. More than one in three, same as we published.
- Success rate. 46.8% in June, 47.57% now.
- AI's share of bot traffic. 33.8% in June, 34.30% now (AI crawler 19.31%, AI assistant 8.23%, AI search 6.76%), still ahead of search-engine crawlers at 26.13%.
- Claude-User's rank. Still the #2 busiest individual bot at 7.57%, behind GoogleBot's 12.87%.
- Google's position. Still the largest operator by a wide margin, at 27.11%.
Source for this block: Cloudflare Radar — radar/http/summary/bot_class, radar/bots/crawlers/summary/response_status_category, radar/bots/summary/bot_category, radar/bots/summary/bot, radar/bots/summary/bot_operator, 28d (2026-07-04 to 2026-08-01). Pulled 2026-08-01.
Two figures did move enough to flag. AI crawling for model training reads 44.21% on the trailing 28 days against the 52.3% published in June, so the "training dominates by five to one" ratio in the June text is now closer to four to one against live search at 11.66%. Our AI crawler statistics report carries the crawl-purpose analysis in full. And the extraction gap narrowed sharply: Anthropic reads 1,782 pages per referral on the trailing 28 days, down from 4,580 in June and from 38,744 in July 2025. It is still the widest gap among the large operators, and Google still sits at 4.79 (Mistral's 29,586 sits on a referral base too small to rank against them). Remember this is a ratio, never a percentage. The crawl-to-refer analysis lives in our robots.txt AI crawler blocking report. Source: radar/bots/crawlers/summary/crawl_refer_ratio and radar/ai/bots/summary/crawl_purpose, 28d and calendar months. Pulled 2026-08-01.
The new number: bots are 87% desktop, and that is bending the web's device split
Here is a figure this report has never carried. In July 2026 bot traffic was 87.04% desktop, up from 85.51% a year earlier. Human traffic went the other way, 54.64% mobile against 45.34% desktop. Source: Cloudflare Radar — radar/http/summary/device_type filtered by botClass, calendar July 2025 and July 2026. Pulled 2026-08-01.
That gap does real work on the headline device numbers everyone quotes. Blended across humans and bots, the web reads 60.84% desktop in July 2026, up from 54.73% in July 2025. Only 2.37 points of that 6.11-point rise came from humans actually moving to desktop. The rest is arithmetic: a desktop-heavy bot population grew from 30.76% to 34.75% of all requests, so it pulls the blended average with it. Roughly 61% of the shift is composition rather than behaviour.
Our mobile internet usage by country and mobile vs desktop usage in the UK reports carry that decomposition properly. The number that belongs in a bot report is the bot side of it: at 87% desktop, automated traffic is now heavy enough to move a global device statistic on its own.
Bot Traffic in 2026: Key Findings
Here are the headline numbers from our June 2026 Cloudflare Radar pull. Each one is attributed to a specific endpoint below, so you can lift any single stat and keep its source.
- Bots are 35.2% of all web traffic; humans are 64.8%. By Cloudflare's measure, humans are still the majority. Source: Cloudflare Radar — radar/http/summary/bot_class (radar.cloudflare.com), 7d (2026-06-15 to 2026-06-22).
- Anthropic is the #2 bot operator at 13.2% of verified bot traffic, ahead of Meta (12.2%) and nearly double OpenAI (7.2%). Only Google (28.4%) runs more. ⚠️ superseded by the August update above; preserved as originally published. Anthropic is #3 at 10.53% on the trailing 28 days, behind Meta at 15.01%.
- Claude-User is the web's #2 busiest individual bot at 11.3%, behind GoogleBot (14.2%) and nearly double GPTBot (5.8%). Rank still holds in August; the share reads 7.57% on the trailing 28 days.
- Anthropic crawls ~4,580 pages per referral it sends back, vs OpenAI's 848, Perplexity's 186, and Google's 5. This is a ratio, not a percentage. ⚠️ superseded by the August update above; preserved as originally published. The trailing-28-day ratio is 1,782.
- AI-related bots are 33.8% of all bot traffic. Crawlers, assistants, and AI search combined now rival traditional search-engine crawlers (26.8%). Holds: 34.30% on the trailing 28 days.
- More than 1 in 3 crawler requests (36.9%) gets a 4xx error. Only 46.8% get a successful 2xx response. Holds: 35.86% and 47.57% on the trailing 28 days.
- 52.3% of AI crawling is for model training, not live search indexing (10.1%). ⚠️ superseded by the August update above; preserved as originally published. Training reads 44.21% and search 11.66% on the trailing 28 days.
- Bot share swings from 76.6% in Singapore to 11.8% in Mexico. The most-automated countries are data-center hubs (Singapore, Ireland, the Netherlands); the most-human are mobile-first consumer markets. The US sits at 49.4%.
- Humans browse on phones; bots run on servers. Human web traffic is 55% mobile, but bot traffic is 84% desktop, and bots claim Chrome (78.6%) even more often than humans do (68.3%). The contrast widened in July: bots read 87.04% desktop and humans 54.64% mobile.
- NEW year-over-year (2025 vs 2026): the web slammed the door on crawlers. Across full calendar quarters, the share of crawler requests served (2xx) fell from 80.5% to 49.2% while 4xx blocks rose from 10.2% to 35.8%. Bot share of all traffic also rose from 30.4% to 33.2%. Source: Cloudflare Radar — radar/bots/crawlers/summary/response_status_category and radar/http/summary/bot_class, Q2 2025 vs Q2 2026. Pulled 2026-07-03.
How Much of the Web Is Bots in 2026?
Bots account for 35.2% of all web traffic as of June 2026 (roughly one in three requests), while humans account for 64.8%. That's the verified-and-likely-automated share Cloudflare sees across its global network. Source: Cloudflare Radar — radar/http/summary/bot_class (radar.cloudflare.com), 7d (2026-06-15 to 2026-06-22). August 2026 update: 34.94% bot and 65.06% human on the trailing 28 days to August 1, and 34.75% across calendar July. One in three still holds.
So why do you keep reading that bots have "overtaken humans"? Because different measurements ask different questions. Bot traffic share is the percentage of web requests that come from automated clients rather than people. But what counts as "automated," and which slice of the internet you measure, changes the answer a lot. Cloudflare measures requests across a large neutral network and separates verified bots and likely-automated traffic from human sessions. Security vendors like Imperva (owned by Thales) and HUMAN Security report higher figures because they weight toward the application-layer attack surface they defend (login endpoints, checkout flows, APIs) where automated abuse concentrates, and they fold more "likely-automated" requests into a broader bucket. Same internet, different lens.
Here's the reconciliation no single-source news post offers. Every major 2026 estimate sits side by side below, with how each one is measured.
| Source | Reported bot / automated share | How it's measured | Date |
|---|---|---|---|
| Cloudflare Radar | 35.2% | Verified + likely-automated requests across a global CDN network (general web traffic) | June 2026 |
| Imperva / Thales Bad Bot Report | Roughly half (more than 50% by their measure) | "Automated traffic" across application-layer traffic the firm defends; broader bot definition weighted to attack surface | 2026 annual |
| HUMAN Security | More than half of traffic by some measures | Enterprise fraud/bot-defense telemetry; emphasis on sophisticated and malicious automation | 2026 |
Treat the precise figure (35.2%) as the network-wide measurement and the "around half" figures as attack-surface-weighted estimates. According to the Imperva (Thales) Bad Bot Report, automated traffic sits near half of all traffic by their definition. That's directionally consistent with Cloudflare's growth trend, just measured against a different denominator. Both can be true at once.
For the human side of this split, see the country, device, and browser breakdowns later in this report, plus our web traffic statistics post on the 64.8% that isn't a bot.
The Extraction Gap: Which AI Companies Take the Most and Give Back the Least
The extraction gap is the ratio of pages an AI crawler reads to visitors it refers back to the open web, and Anthropic's is the widest of any major operator. Anthropic crawls roughly 4,580 pages for every 1 referral it sends back, versus OpenAI's 848, Perplexity's 186, and Google's 5. Source: Cloudflare Radar — radar/bots/crawlers/summary/crawl_refer_ratio (radar.cloudflare.com), 28d (2026-05-25 to 2026-06-22).
⚠️ The June ratios below are superseded by the August update above and preserved as originally published. On the trailing 28 days to August 1, 2026: Anthropic 1,782, Perplexity 303, OpenAI 233, Microsoft 37, Google 4.79. Mistral reads 29,586 but on a referral base small enough that its ratio swings by orders of magnitude month to month, which is why we don't headline it. Source: radar/bots/crawlers/summary/crawl_refer_ratio, 28d (2026-07-04 to 2026-08-01). Pulled 2026-08-01.
Read this table as "pages crawled per 1 referral," not as a percentage. It's a ratio, so a bigger number means a more one-sided exchange, not a larger share of traffic.

| AI operator | Pages crawled per 1 referral | Reading |
|---|---|---|
| Anthropic | 4,580 | Reads ~4,580 pages for each visitor sent back |
| OpenAI | 848 | Reads ~848 pages per referral |
| Perplexity | 186 | Reads ~186 pages per referral |
| Mistral | 84 | Reads ~84 pages per referral |
| Microsoft | 35 | Reads ~35 pages per referral |
| Yandex | 25 | Reads ~25 pages per referral |
| Baidu | 11 | Reads ~11 pages per referral |
| ByteDance | 10 | Reads ~10 pages per referral |
| 5 | Reads ~5 pages per referral | |
| DuckDuckGo | 2 | Reads ~2 pages per referral |
Google sits at 5:1 because its crawl still feeds a search engine that sends clicks back to publishers. The ratio is roughly the old bargain of the open web: you let the crawler in, it sends you traffic. AI assistants break that bargain. They read your page to answer a question inside a chat window, and the user rarely clicks through. Anthropic's 4,580:1 is that broken bargain at its most extreme, nearly a thousand times more lopsided than Google's.
This isn't a moral verdict. It's the mechanics of how answer engines work, and it's the same shift driving our Claude usage statistics and ChatGPT statistics. If your content fuels AI answers without earning a click, the referral ratio is where you see it first.
Who Operates the Internet's Bots?
⚠️ The June ranking below is superseded by the August update above and preserved as originally published. On the trailing 28 days to August 1, 2026 the order is Google 27.11%, Meta 15.01%, Anthropic 10.53%, OpenAI 6.50%, Microsoft 5.50%, Amazon 4.73%, Ahrefs 3.47%, Apple 3.47%, Baidu 3.07%. Source: Cloudflare Radar — radar/bots/summary/bot_operator, 28d (2026-07-04 to 2026-08-01). Pulled 2026-08-01.
Google operates the largest share of verified bot traffic at 28.4%, and Anthropic is now second at 13.2%, ahead of Meta and nearly double OpenAI. The operator league below counts each company's share of verified-bot requests. Source: Cloudflare Radar — radar/bots/summary/bot_operator (radar.cloudflare.com), 7d (2026-06-15 to 2026-06-22).

| Rank | Operator | Share of verified-bot requests |
|---|---|---|
| 1 | 28.4% | |
| 2 | Anthropic | 13.2% |
| 3 | Meta | 12.2% |
| 4 | OpenAI | 7.2% |
| 5 | Microsoft | 5.2% |
| 6 | Amazon | 4.1% |
| 7 | Apple | 3.5% |
| 8 | Ahrefs | 3.1% |
| 9 | Baidu | 2.7% |
| — | Others | 20.4% |
A year ago, the runner-up to Google in any bot-operator chart would have been Microsoft (Bing) or Amazon. Now it's Anthropic, a company with no search engine and no ad network, whose bots exist almost entirely to read pages for an AI assistant. That single fact reshapes how site owners should think about their server logs. The second-heaviest crawler hitting your site probably isn't indexing you for search; it's reading you for a chatbot.
August 2026 note: Meta reclaimed second place through July, so the second-heaviest crawler is now a social-platform bot again. Anthropic at #3 and OpenAI at #4 still put two AI labs in the top four, which is the part of this read that held.
We track which companies sit behind the technology and crawlers on millions of sites. See how we detect technologies and crawlers for the methods behind reads like this.
The Busiest Bots on the Web Right Now
GoogleBot is still the single busiest bot at 14.2% of verified-bot requests, but Claude-User is now #2 at 11.3%, nearly double GPTBot (5.8%). An AI assistant agent now out-crawls every search engine except Google. Source: Cloudflare Radar — radar/bots/summary/bot (radar.cloudflare.com), 7d (2026-06-15 to 2026-06-22).
August 2026 update: the top two hold. On the trailing 28 days GoogleBot reads 12.87% and Claude-User 7.57%, with Meta-ExternalAgent third at 6.88% and GPTBot fourth at 5.28%. Watch the labelling here: in the final week of July, Cloudflare began reporting a separate Claude agent (4.23%) alongside Claude-User (3.33%), so a single-label read of that week understates Anthropic's user-fetch volume. Source: radar/bots/summary/bot, 28d (2026-07-04 to 2026-08-01). Pulled 2026-08-01.

| Rank | Bot | Operator | Share of verified-bot requests |
|---|---|---|---|
| 1 | GoogleBot | 14.2% | |
| 2 | Claude-User | Anthropic | 11.3% |
| 3 | GPTBot | OpenAI | 5.8% |
| 4 | Meta-ExternalAgent | Meta | 5.5% |
| 5 | BingBot | Microsoft | 4.7% |
| 6 | FacebookExternalHit | Meta | 3.7% |
| 7 | Google AdsBot | 3.6% | |
| 8 | Applebot | Apple | 3.5% |
| 9 | Meta-ExternalAds | Meta | 3.0% |
The name to sit with is Claude-User. The "-User" suffix means these are user-initiated fetches: a person asks Claude a question, and Claude goes and reads live pages to answer. That's different from a training crawler quietly building a dataset. It means Claude's reach into the live web is being pulled by real demand, in real time, at a volume that now trails only GoogleBot. GPTBot, OpenAI's heavier crawler, sits at less than half Claude-User's share. The agentic web isn't a forecast anymore; it's the #2 entry in this table.
What AI Crawlers Actually Want: Training vs Search
⚠️ The June split below is superseded by the August update above and preserved as originally published. On the trailing 28 days to August 1, 2026: Training 44.21%, Mixed Purpose 40.18%, Search 11.66%, User Action 2.65%, Undeclared 1.29%. Training is still the largest slice, but the five-to-one dominance over live search has narrowed to about four to one. Source: radar/ai/bots/summary/crawl_purpose, 28d (2026-07-04 to 2026-08-01). Pulled 2026-08-01.
More than half of AI crawler activity (52.3%) is for model training, while only 10.1% is for live search indexing. The rest is mixed-purpose (34.2%) or unspecified. Source: Cloudflare Radar — radar/ai/bots/summary/crawl_purpose (radar.cloudflare.com), 28d (2026-05-25 to 2026-06-22).

Most AI crawling feeds model training (52.3%), not live search (10.1%).
| Crawl purpose | Share of AI crawler activity |
|---|---|
| Training | 52.3% |
| Mixed purpose | 34.2% |
| Search | 10.1% |
| User action | 2.6% |
| Undeclared | 0.8% |
This breakdown matters for one practical reason: the page an AI reads today to train on shapes the answer it gives a user tomorrow. When training is 52.3% of AI crawling and live search is only 10.1%, most of what assistants "know" about your brand is being baked in during training runs, not fetched fresh at query time. If your content isn't in the training pass, you may simply be absent from the answer, with no live-search step to recover the omission. The same dynamic shows up in our open-source AI adoption data, where models trained on public code and docs inherit whatever was crawlable.
AI Bots Are Now a Third of All Bot Traffic
AI-related bots make up 33.8% of all bot traffic, combining AI crawlers (17.7%), AI assistants (9.0%), and AI search (7.0%), rivaling traditional search-engine crawlers at 26.8%. Source: Cloudflare Radar — radar/bots/summary/bot_category (radar.cloudflare.com), 28d (2026-05-25 to 2026-06-22).
| Bot category | Share of bot traffic |
|---|---|
| Search-engine crawler | 26.8% |
| AI crawler | 17.7% |
| SEO | 12.5% |
| AI assistant | 9.0% |
| Advertising & marketing | 7.5% |
| Page preview | 7.1% |
| AI search | 7.0% |
| Webhooks | 4.6% |
| Monitoring & analytics | 3.2% |
| Other | 4.4% |
Add the three AI rows and you get 33.8%. A third of every automated request hitting the web is now AI-driven. Stack that against the single largest traditional category, search-engine crawlers at 26.8%, and the direction is clear: AI has already passed classic search crawling as a category of bot traffic. For most of the web's history, "a bot is crawling my site" meant a search engine wanted to rank you. In 2026, it's more likely an AI system wants to read you. That reframes AI adoption trends from a product story into an infrastructure one: the adoption is visible in raw crawl volume.
Bot Traffic by Country: Where the Web Is Most Automated
Bot share is wildly uneven by country, from more than 76% of requests in Singapore to under 12% in Mexico. The countries with the highest bot share are the ones that host the internet's data centers, not the places where the most "attacks" originate. Source: Cloudflare Radar — radar/http/summary/bot_class with a per-country location filter (radar.cloudflare.com), 7d (2026-06-15 to 2026-06-22).

| Country | Bot share | Human share |
|---|---|---|
| Singapore | 76.6% | 23.4% |
| Ireland | 72.9% | 27.1% |
| Netherlands | 70.5% | 29.5% |
| Germany | 50.2% | 49.8% |
| Russia | 49.6% | 50.4% |
| United States | 49.4% | 50.6% |
| France | 41.2% | 58.8% |
| Sweden | 34.9% | 65.1% |
| United Kingdom | 25.8% | 74.2% |
| Canada | 25.0% | 75.0% |
| Australia | 22.4% | 77.6% |
| Brazil | 18.1% | 81.9% |
| Japan | 17.0% | 83.0% |
| Turkey | 16.5% | 83.5% |
| India | 16.2% | 83.8% |
| Mexico | 11.8% | 88.2% |
The top of this list is a map of cloud infrastructure. Singapore, Ireland, and the Netherlands are majority-bot because they host hyperscale data-center regions for AWS, Google Cloud, and Azure, and bots run inside those data centers, so their traffic originates there. That's why "which country has the most bot traffic" is really asking "which country hosts the most servers," not "which country is under attack." It also explains the headline gap from earlier: the United States reads at 49.4% bot and Germany at 50.2%, right around the "half the internet is bots" figure security vendors report, because both are huge economies that also host enormous data-center capacity. Measure a server-dense country and you get roughly half; measure the whole neutral network and you get 35.2%. At the other end, mobile-first consumer markets like Mexico (11.8%), India (16.2%), and Turkey (16.5%) are the most human, because they generate huge volumes of real phone browsing and host comparatively few data centers. One caveat: a few mid-table countries (Russia here, and Nigeria at 53%) rank high less because of hosting and more because of proxy and VPN exit nodes plus lower human request volume, so read single countries with care.
Bots vs Humans by Device and Browser
Humans and bots look completely different at the device level: human web traffic is 55% mobile, but bot traffic is 84% desktop. People browse on phones; bots run on servers. Source: Cloudflare Radar — radar/http/summary/device_type, split by likely-human and likely-automated (radar.cloudflare.com), 7d (2026-06-15 to 2026-06-22).
| Device | Human traffic | Bot traffic |
|---|---|---|
| Mobile | 55.0% | 15.0% |
| Desktop | 45.0% | 84.4% |
August 2026 update: the gap widened. In calendar July 2026 bots read 87.04% desktop and 12.87% mobile, while humans read 54.64% mobile and 45.34% desktop. A year earlier bots were 85.51% desktop and humans 57.01% mobile. Source: radar/http/summary/device_type filtered by botClass, calendar July 2025 and July 2026. Pulled 2026-08-01.
That single contrast is one of the more dependable ways to tell automated traffic from people. A user-agent string is trivial to fake, but the overall shape of traffic is not: humans skew mobile because that's where real browsing happens, while bots skew desktop because they run on servers and headless browsers that present as desktop clients. The operating-system mix underneath confirms it: among human traffic, Android leads at 36.0%, ahead of Windows (32.9%), iOS (20.1%), and macOS (8.8%), so mobile operating systems (Android plus iOS) now carry roughly 56% of human browsing.
Browser share tells a subtler story. Among humans, Chrome leads at 68.3%, followed by Safari (18.2%), Edge (6.5%), and Firefox (3.7%). Bots claim a similar lineup, but they over-index on Chrome and barely touch Safari.

| Browser | Human traffic | Bot traffic |
|---|---|---|
| Chrome | 68.3% | 78.6% |
| Safari | 18.2% | 7.6% |
| Edge | 6.5% | 3.7% |
| Firefox | 3.7% | 4.7% |
| Samsung Internet | 1.7% | 4.2% |
| Opera | 1.3% | 1.0% |
August 2026 update: re-pulled on the 28 days to 5 August 2026, the lineup holds and the Chrome gap widens slightly. Humans: Chrome 68.66%, Safari 17.57%, Edge 6.93%, Firefox 3.63%, Samsung Internet 1.74%, Opera 1.25%. Bots: Chrome 79.59%, Safari 8.52%, Firefox 4.93%, Edge 3.65%, Samsung Internet 1.97%, Opera 1.08%. The one real mover is Samsung Internet on the bot side, down from 4.2% to 1.97%. Every conclusion in this section is unchanged. Source: radar/http/summary/browser_family filtered by botClass, 28 days to 2026-08-05. Pulled 2026-08-05. For the human side over time see our Chrome, Safari and Firefox market share reports.
Bots report Chrome even more often than humans (78.6% vs 68.3%) because headless Chrome, driven by automation frameworks like Puppeteer and Playwright, is the default tool for scraping and AI fetching. Safari, by contrast, is far rarer among bots (7.6% vs 18.2%): almost nobody automates WebKit at scale. The practical read for site owners is that a desktop client claiming the latest Chrome, with no matching mobile traffic, is a classic headless-scraper fingerprint. Just remember these browser labels come from user-agent strings, which bots can set to anything, so treat the bot-side browser numbers as claimed identity rather than verified fact. For the human side, our Chrome market share and Safari market share reports track those browsers over time.
The weekly rhythm is a bot detector, and it's harder to fake than a user agent
Device level is the signal this section has described so far: humans skew mobile, bots skew desktop. There is a second signal sitting underneath it that is considerably harder for an operator to imitate, because it is not a property of any single request. It is a property of the traffic over time.
Human traffic breathes on a seven-day cycle. Bot traffic does not. Aggregating by day of week across 1 June to 5 August 2026:
| Traffic type | Weekday mobile | Weekend mobile | Swing | Consistency across 9 weeks |
|---|---|---|---|---|
| Human | 53.42% | 58.74% | +5.32 pt | positive 9/9, range +4.93 to +5.50 |
| Bot | 13.28% | 14.11% | +0.83 pt | positive 8/9, range −0.83 to +1.72 |
Source: Cloudflare Radar — http/timeseries_groups/device_type filtered by botClass, daily aggregation, 1 June–5 August 2026 (9 full weeks). Pulled 2026-08-05.
Read the consistency column rather than the swing column, because that is where the two populations genuinely separate. Human device mix moves by more than six times as much, but more tellingly it moves the same way every single week, nine weeks out of nine, never straying outside a 0.6-point band. Bot device mix wanders around roughly zero and changed direction in one of the nine weeks, which is what a series with no underlying weekly driver looks like.
The reason is straightforward once stated. Humans have weekends: the work laptop goes down on Friday and the phone comes up, and that shift is visible in aggregate traffic with metronomic reliability. Servers do not observe Saturday. A crawler fleet runs the schedule its operator set, and that schedule has no particular reason to know what day it is.
This matters because it is cheap to check and expensive to defeat. A user agent is one header and can claim anything, which is why the bot-side browser figures above are claimed identity rather than verified fact. Device type is harder to fake convincingly at scale but still forgeable per request. A weekly rhythm, though, would require an operator to deliberately model human weekend behaviour across their whole fleet and sustain it for months — possible, but nobody scraping at volume bothers, because until now nobody was looking for it.
One honest limitation before you use it. This is an aggregate-population signal, not a per-visitor one: it tells you something about a segment of thousands of sessions over weeks, and nothing at all about whether one particular request is a bot. It is a good tool for auditing whether a traffic source, referrer, or campaign is delivering real people, and a bad tool for gating an individual request.
More Than 1 in 3 Crawler Requests Gets Blocked
About 37% of crawler requests now receive a 4xx error (more than one in three), while only 46.8% get a successful 2xx response. Source: Cloudflare Radar — radar/bots/crawlers/summary/response_status_category (radar.cloudflare.com), 7d (2026-06-15 to 2026-06-22). August 2026 update: this one held. The trailing 28 days to August 1 read 4xx 35.86%, 2xx 47.57%, 3xx 14.49%, 5xx 2.08%, and the most recent weekly bucket puts 4xx back up at 37.10%.

More than 1 in 3 crawler requests (about 37%) now gets a 4xx block.
| Response status | Share of crawler requests | Meaning |
|---|---|---|
| 2xx (success) | 46.8% | Request served |
| 4xx (client error / blocked) | 36.9% | Rejected, forbidden, or not found |
| 3xx (redirect) | 14.0% | Redirected |
| 5xx (server error) | 2.3% | Server failure |
A 4xx response on more than a third of crawler requests is the web pushing back. Sites are returning 403s and 429s to crawlers they don't want, and a lot of that pushback now targets AI crawlers specifically, through robots.txt rules, firewall rules, and CDN toggles. We dug into exactly who's blocking which AI bots in our robots.txt AI crawler blocking report, and the short version is that blocking has gone mainstream among large publishers. The tension is real: block too aggressively and you vanish from AI answers; allow everything and you hand over your content for a referral ratio of 4,580:1.
Bot Traffic in 2026 vs 2025: The Year-Over-Year Shift
The single biggest change since last year isn't the bot share; it's how hard the web now pushes crawlers away. A year ago (Q2 2025), more than four in five crawler requests succeeded and barely one in ten hit a 4xx block. Over the full Q2 2026 quarter, fewer than half succeed and more than a third are blocked. Source: Cloudflare Radar — radar/bots/crawlers/summary/response_status_category, full-quarter windows (2025-04-01 to 2025-06-30 vs 2026-04-01 to 2026-06-30). Pulled 2026-07-03.
The figures earlier in this report use Cloudflare's rolling 7-day and 28-day windows, which react fast to the latest week. The table below instead compares three full calendar quarters, so the year-over-year change is measured on the same-length window at both ends.
| Metric (full-quarter window) | Q2 2025 | Q1 2026 | Q2 2026 | Year-over-year |
|---|---|---|---|---|
| Bot share of all web traffic | 30.4% | 30.5% | 33.2% | +2.8pt |
| Crawler requests blocked (4xx) | 10.2% | 34.1% | 35.8% | +25.6pt |
| Crawler requests served (2xx) | 80.5% | 50.9% | 49.2% | −31.3pt |
| AI crawling for model training | 28.7% | 41.4% | 44.9% | +16.1pt |
August 2026 note: the quarter table above stands as published. A calendar-month cut of the same comparison, July 2025 against July 2026, is in the What July 2026 Changed section near the top of this report and points the same way: bot share 30.76% to 34.75%, 4xx blocks 14.04% to 35.79%, 2xx responses 73.50% to 47.66%. July 2025 on its own already had a higher block rate than the Q2 2025 quarter average, so the crackdown was underway before the quarter closed. Month windows and quarter windows are not interchangeable, so read each row against its own label.
Read down that 4xx row and you can watch the open web's posture toward crawlers change in a single year. In Q2 2025, letting a crawler in was still the default: 80.5% of crawler requests got a clean 2xx. By Q2 2026 that default is gone, with success down to 49.2% and blocks up to 35.8%. The rolling 7-day figure earlier in this report (36.9%) shows the same wall, just measured on the most recent week. This is the infrastructure side of the story we tracked in our robots.txt AI crawler blocking report: the blocking went from niche to mainstream, and the aggregate request logs now show it plainly.
The operator league looks just as different a year on. Anthropic, the runner-up in the recent-week ranking at the top of this report, did not appear in the operator top nine at all in Q2 2025, and still didn't through Q1 2026. It broke into the full-quarter league only in Q2 2026, at #5. Source: Cloudflare Radar — radar/bots/summary/bot_operator, full-quarter windows. Pulled 2026-07-03.
| Operator | Q2 2025 (share, rank) | Q2 2026 (share, rank) |
|---|---|---|
| 46.8% (#1) | 30.1% (#1) | |
| Meta | 14.6% (#2) | 14.9% (#2) |
| OpenAI | 8.7% (#3) | 7.6% (#3) |
| Microsoft | 5.2% (#4) | 5.3% (#4) |
| Anthropic | not in top 9 | 4.9% (#5) |
Two things are worth separating here. Over the full quarter, Anthropic averages #5 at 4.9%, because it was a small operator for most of the quarter and surged late. In the most recent 7-day window it jumps to #2 at 13.5%, which is the figure the top of this report quotes. ⚠️ That 13.5% is superseded by the August update above and preserved as originally published; the 7-day window to August 1, 2026 reads 9.45% and #3. Both are correct: the full-quarter average captures where Anthropic sat across all of Q2, and the rolling week captures where it is right now. The direction is the story either way, because a year ago Anthropic was not on the board at all. The same pattern holds for individual bots: Claude-User is absent from the Q2 2025 busiest-bot top nine, sits at #8 across the full Q2 2026 quarter, and reaches #2 in the current week. Meanwhile GoogleBot's own share of verified-bot requests roughly halved over the year (from 31.0% to 15.6%) as the field fragmented across many more crawlers.
One thing has not changed: the extraction gap. Anthropic read the most pages per referral of any major operator in Q2 2025, and it still does. If anything the gap was even wider a year ago, before Claude began sending meaningful referral traffic back; the exact ratio swings sharply week to week, but Anthropic sits at the top of it in both years. That widening-then-narrowing arc is the same shift we cover in our Claude usage statistics.
Good Bots vs Bad Bots: Not All Automated Traffic Is Equal
Not all automated traffic is equal: "good bots" identify themselves and obey rules, while "bad bots" spoof user agents, ignore robots.txt, and drive scraping, credential stuffing, and fraud. The bot share (35.2% in June, 34.94% on the trailing 28 days to August 1, 2026) isn't one undifferentiated swarm. It's search crawlers and AI assistants on one end, and impersonators on the other.

The cleanest signal here is verification. A verified bot proves its identity (Cloudflare and others confirm it via published IP ranges or signed requests), so GoogleBot, Claude-User, and BingBot in the tables above are bots you can trust to be what they claim. An unverified or spoofed bot sets a user-agent string it has no right to, pretending to be GoogleBot to slip past filters, and these are where most scraping and attack traffic hides. That's exactly why security vendors report higher bot percentages: they're counting the malicious, often-spoofed layer that a verified-bot view filters out.
So should you block bots? It depends on which ones. Blocking verified search and AI-search crawlers costs you visibility in both Google and AI answers. Blocking spoofed and abusive automation protects your infrastructure and data. The honest position is that "block bots" is the wrong instruction. "Block the right bots, by verified identity" is the right one. Getting that distinction wrong is how sites accidentally delist themselves while leaving the actual scrapers untouched.
Frequently Asked Questions
What is bot traffic?
Bot traffic is any web traffic generated by automated software (bots) rather than a person using a browser. It spans search-engine crawlers, AI crawlers, monitoring tools, link previewers, and scrapers. As of August 1, 2026, bots account for 34.94% of all web traffic and humans for the other 65.06%, according to Cloudflare Radar's trailing 28-day window. Bot traffic can be legitimate (verified crawlers that identify themselves) or malicious (spoofed scrapers, credential-stuffing, and attack bots).
What percentage of internet traffic is bots in 2026?
Bots account for 34.94% of all web traffic on Cloudflare Radar's trailing 28-day window to August 1, 2026, with humans at 65.06%. Across calendar July 2026 the figure is 34.75%, against 30.76% in July 2025. Other reports put automated traffic above 50% using broader definitions weighted toward application-layer attack surface.
How much has bot traffic grown since last year?
Bots rose from 30.76% of all web traffic in July 2025 to 34.75% in July 2026, a gain of 3.98 percentage points measured on matching calendar months (Cloudflare Radar, radar/http/summary/bot_class, pulled August 1, 2026). Month over month the number is flat: June 2026 read 34.79%. The growth is a year-scale trend, not a July event.
Do bots outnumber humans on the internet?
By Cloudflare Radar's network-wide measurement, no: humans are still the majority at 65.06% of web traffic versus 34.94% for bots on the trailing 28 days to August 1, 2026. Security vendors such as Imperva (Thales) and HUMAN Security report automated traffic at or above 50%, because they measure the attack surface they defend with a broader "automated traffic" definition. Whether bots "outnumber humans" depends entirely on what you measure.
Is Anthropic still the #2 bot operator?
No. Meta retook second place during July 2026. On the trailing 28 days to August 1, Anthropic is #3 at 10.53% of verified-bot requests, behind Google (27.11%) and Meta (15.01%), and ahead of OpenAI (6.50%). Anthropic's share fell in every weekly bucket of that window, from 12.94% to 9.46% (Cloudflare Radar, radar/bots/summary/bot_operator).
Which company operates the most bots?
Google operates the largest share of verified bot traffic at 27.11%, followed by Meta at 15.01%, Anthropic at 10.53%, and OpenAI at 6.50%, per Cloudflare Radar's trailing 28-day window to August 1, 2026. Anthropic held #2 through June but slipped to #3 across July as Meta's share climbed. Two of the top four operators are still AI labs rather than search engines.
What is the most active bot on the web?
GoogleBot is the single busiest bot at 12.87% of verified-bot requests, followed by Anthropic's Claude-User at 7.57% and Meta-ExternalAgent at 6.88% (Cloudflare Radar, 28-day window to August 1, 2026). Claude-User performs user-initiated fetches, reading live pages in response to real Claude queries, which keeps it second only to GoogleBot.
How much of bot traffic is AI?
AI-related bots make up 34.30% of all bot traffic on the trailing 28 days to August 1, 2026, combining AI crawlers (19.31%), AI assistants (8.23%), and AI search (6.76%), per Cloudflare Radar. That total exceeds traditional search-engine crawlers (26.13%), making AI the largest category of automated traffic on the web.
What do AI crawlers do with the data they collect?
Most AI crawling, 44.21%, collects data for model training, while 11.66% is for live search indexing and 40.18% is mixed-purpose (Cloudflare Radar, 28-day window to August 1, 2026). In practice, the pages an AI crawler reads during training shape the answers an assistant gives later. Content absent from the training pass risks being missing from AI answers entirely.
Why do estimates of bot traffic range from 35% to 50%?
The range comes from different measurement methods, not contradictory facts. Cloudflare Radar measures verified and likely-automated requests across a neutral global network, reporting 34.94% on the trailing 28 days to August 1, 2026. Security vendors like Imperva (Thales) and HUMAN Security report roughly half or more, because they weight toward login pages, checkout flows, and APIs where automated abuse concentrates, using a broader automated-traffic definition.
Are good bots or bad bots more common?
The most active individual bots on the web are verified "good bots": GoogleBot, Claude-User, and BingBot lead the rankings (Cloudflare Radar, June 2026). But security vendors report large volumes of "bad bots" that spoof user agents and ignore robots.txt, which a verified-bot view filters out. The answer depends on whether you measure verified identity or total automated activity including impersonators.
How much of AI crawling is for training versus search?
AI crawling is 44.21% training and 11.66% live search, with 40.18% mixed-purpose and the remainder user-action or undeclared (Cloudflare Radar, 28-day window to August 1, 2026). Training dominates by roughly 4 to 1 over search, down from 5 to 1 in June. Most of what AI assistants "know" is still set during training rather than fetched fresh at query time.
How often are AI crawlers blocked?
About 35.9% of crawler requests receive a 4xx error, more than one in three, while 47.6% get a successful 2xx response (Cloudflare Radar, 28-day window to August 1, 2026). The most recent weekly bucket reads 37.1% blocked, so the rate is still edging up. Much of this pushback targets AI crawlers through robots.txt rules and CDN settings, though over-blocking can remove a site from AI answers along with the unwanted scrapers.
Which country has the most bot traffic?
Singapore has the highest bot share of any major country at 76.6% of web traffic, followed by Ireland (72.9%) and the Netherlands (70.5%), because all three host large cloud data-center regions where automated traffic concentrates (Cloudflare Radar, June 2026). The United States (49.4%) and Germany (50.2%) sit near 50/50, while mobile-first markets like Mexico (11.8%), India (16.2%), and Turkey (16.5%) are the most human.
Do bots use mobile or desktop?
Bots are overwhelmingly desktop: 87.04% of bot traffic is desktop-class versus 12.87% mobile, because automated clients run on servers rather than phones (Cloudflare Radar, calendar July 2026). Human traffic is the reverse, at 54.64% mobile and 45.34% desktop. Because device type is harder to fake than a user-agent string, the mobile-versus-desktop split is one of the more reliable ways to distinguish bots from people.
Why does bot traffic skew so heavily to desktop, and does it matter?
Bots run on servers and headless browsers that present as desktop clients, so 87.04% of bot requests read desktop against 45.34% for humans (Cloudflare Radar, July 2026). It matters because bots now bend blended statistics: the web's overall desktop share rose 6.11 points year over year, and roughly 61% of that came from bot composition rather than people switching devices.
What web browser do most people use?
Among human web traffic, Chrome is the most-used browser at 68.3%, followed by Safari (18.2%), Edge (6.5%), and Firefox (3.7%) (Cloudflare Radar, human-only, June 2026). Bots claim Chrome even more often (78.6%), because headless Chrome dominates scraping and AI fetching, so a very high Chrome share with no matching mobile traffic can itself be a sign of automation.
What is the bot-to-human ratio on the internet?
The bot-to-human ratio is roughly 1 to 2: bots make up 34.94% of web traffic and humans 65.06%, so there is about one automated request for every two human ones (Cloudflare Radar, 28-day window to August 1, 2026). The ratio is far higher in data-center-heavy countries (in the United States it is nearly 1 to 1, at 49.4% bot) and much lower in mobile-first markets like Mexico, where bots are just 11.8% of traffic.
How can you tell bot traffic from human traffic?
The most reliable signals are device type and verification. Human traffic is 54.64% mobile, but bot traffic is 87.04% desktop, because bots run on servers rather than phones (Cloudflare Radar, July 2026). Bots also over-claim Chrome (78.6% vs humans' 68.3%) and rarely use Safari. The strongest tell is identity: verified bots like GoogleBot and Claude-User confirm themselves through published IP ranges, while spoofed bots set a user-agent string they cannot prove.
What is the difference between a crawler and a bot?
A bot is any automated program that makes web requests; a crawler (or spider) is a specific type of bot that systematically fetches pages to index or collect them. All crawlers are bots, but not all bots are crawlers — chat-fetch agents, monitoring tools, and webhooks are bots that don't crawl. On Cloudflare's trailing 28 days to August 1, 2026, the two largest bot categories are search-engine crawlers (26.13% of bot traffic) and AI bots (34.30% combined).
Are AI crawlers legal?
AI crawling sits in a legal gray area. robots.txt is a voluntary standard, not a binding law in most jurisdictions, so ignoring it is not automatically illegal — but copyright lawsuits against major AI labs and rules like the EU AI Act are actively testing the limits. In practice, the enforceable control is technical: more than 1 in 3 crawler requests (37%) already gets a 4xx block, and many sites restrict AI bots by user agent. See which sites block which AI bots in our robots.txt blocking report.
Are bots taking a bigger share of web traffic than a year ago?
Yes, but modestly. On a full-quarter basis, bots rose from 30.4% of all web traffic in Q2 2025 to 33.2% in Q2 2026, a gain of about 2.8 points (Cloudflare Radar, pulled July 2026). On matching calendar months the gain is larger: 30.76% in July 2025 to 34.75% in July 2026, up 3.98 points (pulled August 1, 2026). The sharper year-over-year change is on the crawler side: 4xx blocks climbed from 14.04% to 35.79% between those two Julys, while successful 2xx responses fell from 73.50% to 47.66%.
Was Anthropic a major bot operator a year ago?
No. Anthropic does not appear in Cloudflare Radar's top nine bot operators for July 2025, where the ninth entry is Huawei at 1.80%, so its share that month was below 1.80%. It was also absent from the Q2 2025 and Q1 2026 quarterly leagues, breaking in only in Q2 2026 at #5 with 4.9%. It reached 10.97% across July 2026, a year-over-year gain of at least 9.2 points, then gave the #2 slot back to Meta (Cloudflare Radar, pulled August 1, 2026).
Methodology and Data Sources
August 2026 refresh. The What July 2026 Changed section and every figure marked "August 2026" or "trailing 28 days" was pulled on August 1, 2026. Two window types run side by side in this report and they are not interchangeable, so each figure carries its own label:
- Rolling windows (7d and 28d) are Cloudflare's own trailing windows and react fast to the latest week. The 28-day window used throughout the August layer covers 2026-07-04 to 2026-08-01; the 7-day window covers 2026-07-25 to 2026-08-01.
- Calendar months (July 2025, June 2026, July 2026) are used for the month-over-month and like-for-like year-over-year comparisons, so both ends of each comparison are the same length.
- Calendar quarters (Q2 2025, Q1 2026, Q2 2026) remain in the year-over-year section below as originally published.
Two headline figures were cross-checked against a second endpoint before publication, because Cloudflare occasionally revises a series after the fact. The trailing-28-day bot share reads 34.94% on radar/http/summary/bot_class and 34.96% as the mean of radar/http/timeseries_groups/bot_class daily buckets over the same window. The crawler 4xx rate reads 35.86% on the summary endpoint and 35.87% as the mean of the weekly radar/bots/crawlers/timeseries_groups/response_status_category series. Both agree.
Where Cloudflare does not publish a value we say so rather than estimating one. Anthropic is absent from the top nine bot operators for July 2025 (the ninth is Huawei at 1.80%), so its July 2025 share is expressed as a bound rather than a number. The same applies to Claude-User, which is absent from the July 2025 busiest-bot top nine. One labelling change is worth flagging: in the final week of July 2026, Cloudflare began reporting a separate Claude agent alongside Claude-User, so a single-label read of that week understates Anthropic's user-fetch volume.
Every figure in this report comes from the Cloudflare Radar API, pulled on June 22, 2026, with the year-over-year comparison added on July 3, 2026 and the July 2026 layer added on August 1, 2026. We re-pull these endpoints on publish and update the date stamps, because bot traffic shifts week to week and a year-old number is a stale number. Cloudflare Radar reports aggregate, anonymized traffic observed across Cloudflare's global network; it is one large, neutral vantage point on the web, not a census of all internet traffic. Read it as a high-quality sample, and read the security-vendor estimates as a different, attack-surface-weighted sample.
Watch one technical detail: Cloudflare normalizes some datasets as percentages and one as a ratio. The bot-vs-human, operator, busiest-bot, crawl-purpose, category, block-rate, country, device, and browser figures are all percentages. The crawl-to-refer figure is a ratio (pages crawled per referral), so it is never expressed as a percentage and never charted as a share. A value of 4,580 means 4,580 pages per referral, not 4,580%.
The endpoints and windows used:
- Bot vs human: radar/http/summary/bot_class — 7d (2026-06-15 to 2026-06-22)
- Operator league: radar/bots/summary/bot_operator — 7d (2026-06-15 to 2026-06-22)
- Busiest bots: radar/bots/summary/bot — 7d (2026-06-15 to 2026-06-22)
- Crawl-to-refer ratio: radar/bots/crawlers/summary/crawl_refer_ratio — 28d (2026-05-25 to 2026-06-22)
- Crawl purpose: radar/ai/bots/summary/crawl_purpose — 28d (2026-05-25 to 2026-06-22)
- Bot category: radar/bots/summary/bot_category — 28d (2026-05-25 to 2026-06-22)
- Crawler block rate: radar/bots/crawlers/summary/response_status_category — 7d (2026-06-15 to 2026-06-22)
- Bot share by country: radar/http/summary/bot_class with a per-country
locationfilter — 7d (2026-06-15 to 2026-06-22) - Human vs bot device: radar/http/summary/device_type, filtered by
botClass=likely_humanandbotClass=likely_automated— 7d (2026-06-15 to 2026-06-22) - Human vs bot browser: radar/http/summary/browser_family, filtered by
botClass— 7d (2026-06-15 to 2026-06-22) - Human operating system: radar/http/summary/os, filtered by
botClass=likely_human— 7d (2026-06-15 to 2026-06-22)
The August 2026 layer re-pulled the following on 2026-08-01, on the trailing 28-day window (2026-07-04 to 2026-08-01) unless noted: radar/http/summary/bot_class, radar/bots/summary/bot_operator, radar/bots/summary/bot, radar/bots/summary/bot_category, radar/bots/crawlers/summary/response_status_category, radar/bots/crawlers/summary/crawl_refer_ratio, radar/ai/bots/summary/crawl_purpose, and radar/http/summary/device_type with botClass filters. The same endpoints were pulled on calendar-month windows for July 2025 (2025-07-01 to 2025-07-31), June 2026 (2026-06-01 to 2026-06-30) and July 2026 (2026-07-01 to 2026-07-31). Verification used radar/http/timeseries_groups/bot_class (daily), radar/bots/timeseries_groups/bot_operator (weekly) and radar/bots/crawlers/timeseries_groups/response_status_category (weekly). All percentage endpoints return PERCENTAGE normalization; radar/bots/crawlers/summary/crawl_refer_ratio returns RATIO and is never charted as a share.
The year-over-year section uses full calendar-quarter windows instead of rolling ones, so both ends of each comparison are measured on the same-length window: Q2 2025 (2025-04-01 to 2025-06-30), Q1 2026 (2026-01-01 to 2026-03-31), and Q2 2026 (2026-04-01 to 2026-06-30). Those figures were pulled on July 3, 2026 from radar/http/summary/bot_class, radar/bots/summary/bot_operator, radar/bots/summary/bot, radar/bots/crawlers/summary/response_status_category, radar/ai/bots/summary/crawl_purpose, and radar/bots/summary/bot_category. Because a full quarter is a smoother, larger window than a rolling week, some full-quarter figures (for example the 33.2% bot share and Anthropic's #5 operator rank) sit below the latest 7-day readings quoted earlier in the report; both are correct for their window.
The country, device, browser, and OS splits use Cloudflare's botClass filter to separate likely-human from likely-automated requests. Browser and OS are read from user-agent strings, which bots can spoof, so the bot-side browser figures reflect claimed identity rather than verified bots.
Source for all Cloudflare figures: Cloudflare Radar (radar.cloudflare.com). The Imperva (Thales) and HUMAN Security estimates are cited for the methodology reconciliation only and use those firms' own broader definitions of automated traffic.
We bring our own vantage point to this too. TechnologyChecker detects the technologies and crawlers behind more than 50 million domains every month, which is how we read operator patterns like these directly rather than secondhand. If you want to see what's running on a specific site, or which companies use a given technology, start with our technology detection & lookup data, or read how the detection works in our technology detection methods guide. For the broader picture of who is building on what, our most popular technologies by category rankings cover the live web behind these bots.


